sorry about the late reply, here is the combofix log:
ComboFix 08-08-13.05 - User 2008-08-14 10:24:57.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.274 [GMT -4:00]
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\User\Application Data\macromedia\Flash Player\#SharedObjects\4WSB2C2H\interclick.com
C:\Documents and Settings\User\Application Data\macromedia\Flash Player\#SharedObjects\4WSB2C2H\interclick.com\ud.sol
C:\Documents and Settings\User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\User\Cookies.\user@~~local~~[2].txt
C:\Documents and Settings\User\Cookies.\
[email protected][1].txt
C:\Documents and Settings\User\Cookies.\
[email protected][2].txt
C:\Documents and Settings\User\Cookies.\
[email protected][4].txt
C:\Documents and Settings\User\Cookies.\
[email protected][6].txt
C:\Documents and Settings\User\Cookies.\user@2o7[1].txt
C:\Documents and Settings\User\Cookies.\user@2o7[3].txt
C:\Documents and Settings\User\Cookies.\
[email protected][10].txt
C:\Documents and Settings\User\Cookies.\
[email protected][2].txt
C:\Documents and Settings\User\Cookies.\
[email protected][3].txt
C:\Documents and Settings\User\Cookies.\
[email protected][4].txt
C:\Documents and Settings\User\Cookies.\
[email protected][5].txt
C:\Documents and Settings\User\Cookies.\
[email protected][6].txt
C:\Documents and Settings\User\Cookies.\
[email protected][7].txt
C:\Documents and Settings\User\Cookies.\
[email protected][8].txt
C:\Documents and Settings\User\Cookies.\
[email protected][6].txt
C:\Documents and Settings\User\Cookies.\
[email protected][7].txt
C:\Documents and Settings\User\Cookies.\
[email protected][3].txt
C:\Documents and Settings\User\Cookies.\
[email protected][1].txt
C:\Documents and Settings\User\Cookies.\
[email protected][10].txt
C:\Documents and Settings\User\Cookies.\
[email protected][11].txt
C:\Documents and Settings\User\Cookies.\
[email protected][2].txt
C:\Documents and Settings\User\Cookies.\
[email protected][4].txt
C:\Documents and Settings\User\Cookies.\
[email protected][5].txt
C:\Documents and Settings\User\Cookies.\
[email protected][6].txt
C:\Documents and Settings\User\Cookies.\
[email protected][7].txt
C:\Documents and Settings\User\Cookies.\
[email protected][8].txt
C:\Documents and Settings\User\Cookies.\
[email protected][1].txt
C:\Documents and Settings\User\Cookies.\
[email protected][10].txt
C:\Documents and Settings\User\Cookies.\
[email protected][11].txt
C:\Documents and Settings\User\Cookies.\
[email protected][12].txt
C:\Documents and Settings\User\Cookies.\
[email protected][13].txt
C:\Documents and Settings\User\Cookies.\
[email protected][14].txt
C:\Documents and Settings\User\Cookies.\
[email protected][15].txt
C:\Documents and Settings\User\Cookies.\
[email protected][16].txt
C:\Documents and Settings\User\Cookies.\
[email protected][17].txt
C:\Documents and Settings\User\Cookies.\
[email protected][18].txt
C:\Documents and Settings\User\Cookies.\
[email protected][19].txt
C:\Documents and Settings\User\Cookies.\
[email protected][2].txt
C:\Documents and Settings\User\Cookies.\
[email protected][20].txt
C:\Documents and Settings\User\Cookies.\
[email protected][21].txt
C:\Documents and Settings\User\Cookies.\
[email protected][22].txt
C:\Documents and Settings\User\Cookies.\
[email protected][23].txt
C:\Documents and Settings\User\Cookies.\
[email protected][3].txt
C:\Documents and Settings\User\Cookies.\
[email protected][4].txt
C:\Documents and Settings\User\Cookies.\
[email protected][5].txt
C:\Documents and Settings\User\Cookies.\
[email protected][6].txt
C:\Documents and Settings\User\Cookies.\
[email protected][7].txt
C:\Documents and Settings\User\Cookies.\
[email protected][8].txt
C:\Documents and Settings\User\Cookies.\
[email protected][9].txt
C:\Documents and Settings\User\Cookies.\user@adserver[1].txt
C:\Documents and Settings\User\Cookies.\user@adtrgt[2].txt
C:\Documents and Settings\User\Cookies.\user@adtrgt[3].txt
C:\Documents and Settings\User\Cookies.\user@advancedcleaner[1].txt
C:\Documents and Settings\User\Cookies.\user@antispywaremaster[2].txt
C:\Documents and Settings\User\Cookies.\user@cubics[2].txt
C:\Documents and Settings\User\Cookies.\
[email protected][1].txt
C:\Documents and Settings\User\Cookies.\
[email protected][2].txt
C:\Documents and Settings\User\Cookies.\user@experts-exchange[2].txt
C:\Documents and Settings\User\Cookies.\user@facebook[2].txt
C:\Documents and Settings\User\Cookies.\user@incentaclick[1].txt
C:\Documents and Settings\User\Cookies.\user@mygeek[1].txt
C:\Documents and Settings\User\Cookies.\
[email protected][1].txt
C:\Documents and Settings\User\Cookies.\
[email protected][10].txt
C:\Documents and Settings\User\Cookies.\
[email protected][11].txt
C:\Documents and Settings\User\Cookies.\
[email protected][12].txt
C:\Documents and Settings\User\Cookies.\
[email protected][13].txt
C:\Documents and Settings\User\Cookies.\
[email protected][14].txt
C:\Documents and Settings\User\Cookies.\
[email protected][15].txt
C:\Documents and Settings\User\Cookies.\
[email protected][16].txt
C:\Documents and Settings\User\Cookies.\
[email protected][17].txt
C:\Documents and Settings\User\Cookies.\
[email protected][2].txt
C:\Documents and Settings\User\Cookies.\
[email protected][3].txt
C:\Documents and Settings\User\Cookies.\
[email protected][4].txt
C:\Documents and Settings\User\Cookies.\
[email protected][5].txt
C:\Documents and Settings\User\Cookies.\
[email protected][6].txt
C:\Documents and Settings\User\Cookies.\
[email protected][7].txt
C:\Documents and Settings\User\Cookies.\
[email protected][8].txt
C:\Documents and Settings\User\Cookies.\
[email protected][9].txt
C:\Documents and Settings\User\Cookies.\user@revsci[1].txt
C:\Documents and Settings\User\Cookies.\user@safepctool[2].txt
C:\Documents and Settings\User\Cookies.\user@shareasale[1].txt
C:\Documents and Settings\User\Cookies.\
[email protected][2].txt
C:\Documents and Settings\User\Cookies.\user@trafficmp[1].txt
C:\Documents and Settings\User\Cookies.\user@trafficmp[2].txt
C:\Documents and Settings\User\Cookies.\user@trafficmp[3].txt
C:\Documents and Settings\User\Cookies.\user@trafficmp[4].txt
C:\Documents and Settings\User\Cookies.\user@trafficmp[5].txt
C:\Documents and Settings\User\Cookies.\user@trafficmp[6].txt
C:\Documents and Settings\User\Cookies.\user@tribalfusion[2].txt
C:\Documents and Settings\User\Cookies.\user@trustedantivirus[1].txt
C:\Documents and Settings\User\Cookies.\user@vimby[1].txt
C:\Documents and Settings\User\Cookies.\user@winanonymous[1].txt
C:\Documents and Settings\User\Cookies.\
[email protected][1].txt
C:\WINDOWS\BMf3b05b12.txt
C:\WINDOWS\BMf3b05b12.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aemxqmjt.dll
C:\WINDOWS\system32\aymdxhyh.dll
C:\WINDOWS\system32\bidfoigd.dll
C:\WINDOWS\system32\ctmjkopt.dll
C:\WINDOWS\system32\dgdevo.dll
C:\WINDOWS\system32\dgiofdib.ini
C:\WINDOWS\system32\gdqffujb.dll
C:\WINDOWS\system32\ianbyytn.dll
C:\WINDOWS\system32\iawicevg.dll
C:\WINDOWS\system32\jlUvxyay.ini
C:\WINDOWS\system32\jlUvxyay.ini2
C:\WINDOWS\system32\kcagdvkw.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mqcpxw.dll
C:\WINDOWS\system32\ntyybnai.ini
C:\WINDOWS\system32\tpokjmtc.ini
C:\WINDOWS\system32\wvcmmfwq.dll
C:\WINDOWS\system32\xmkgey.dll
.
((((((((((((((((((((((((( Files Created from 2008-07-14 to 2008-08-14 )))))))))))))))))))))))))))))))
.
2008-08-14 10:04 . 2008-08-14 10:04 2,048 --a------ C:\WINDOWS\system32\sdagbmwn.exe
2008-08-14 09:16 . 2008-08-14 09:16 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-14 09:16 . 2008-08-14 09:16 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-13 10:04 . 2008-08-13 10:04 2,048 --a------ C:\WINDOWS\system32\wsarwwls.exe
2008-08-12 10:01 . 2008-08-12 10:01 2,048 --a------ C:\WINDOWS\system32\tlnkfeyv.exe
2008-08-12 09:46 . 2008-08-12 09:46 <DIR> d-------- C:\Program Files\skip list road
2008-08-12 09:42 . 2008-08-12 09:42 312,320 --a------ C:\WINDOWS\system32\yayxvUlj.dll
2008-08-12 08:51 . 2008-08-14 03:25 542 --a------ C:\WINDOWS\system32\srclihnt.dat
2008-08-12 08:51 . 2008-08-14 03:25 488 --a------ C:\WINDOWS\system32\wshnxtbs.dat
2008-08-12 08:51 . 2008-08-14 03:25 0 --a------ C:\WINDOWS\system32\sbeoea.dat
2008-08-11 21:34 . 2008-08-14 10:35 9,227 --a------ C:\WINDOWS\system32\msreor40.dat
2008-08-11 21:34 . 2008-08-14 10:35 2,048 --a------ C:\WINDOWS\system32\perfntty.dat
2008-08-11 21:34 . 2008-08-14 10:18 392 --a------ C:\WINDOWS\system32\laprmyd.dat
2008-08-11 21:34 . 2008-08-14 10:34 0 --a------ C:\WINDOWS\system32\kbdplv.dat
2008-08-11 09:38 . 2008-08-11 09:38 2,048 --a------ C:\WINDOWS\system32\humkliuq.exe
2008-08-11 09:23 . 2008-08-11 09:23 <DIR> d-------- C:\Documents and Settings\User\Application Data\True Sword
2008-08-11 09:22 . 2008-08-11 13:12 <DIR> d-------- C:\Program Files\True Sword 5
2008-08-11 09:06 . 2008-08-11 09:06 <DIR> d-------- C:\Program Files\Panda Security
2008-08-10 10:13 . 2008-08-10 10:13 2,048 --a------ C:\WINDOWS\system32\hpafhyuh.exe
2008-08-09 05:37 . 2008-08-09 05:37 2,048 --a------ C:\WINDOWS\system32\sbeiwsmk.exe
2008-08-09 00:46 . 2008-08-09 00:46 <DIR> d-------- C:\Program Files\Ventrilo
2008-08-09 00:44 . 2008-08-09 00:45 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-08 16:06 . 2008-08-08 16:06 2,048 --a------ C:\WINDOWS\system32\peoxgclg.exe
2008-08-07 16:51 . 2008-08-07 16:51 2,048 --a------ C:\WINDOWS\system32\yanlpotf.exe
2008-08-07 13:01 . 2008-08-07 13:01 2,048 --a------ C:\WINDOWS\system32\gxvljewr.exe
2008-08-06 06:13 . 2008-08-06 06:13 2,048 --a------ C:\WINDOWS\system32\orvrfwsh.exe
2008-08-05 12:42 . 2008-08-05 12:42 2,048 --a------ C:\WINDOWS\system32\nllxjakj.exe
2008-08-04 12:18 . 2008-08-04 12:18 2,048 --a------ C:\WINDOWS\system32\jyphanrm.exe
2008-08-04 12:16 . 2008-08-04 12:16 91,648 --a------ C:\WINDOWS\system32\behveprv.dll
2008-08-03 00:46 . 2008-08-03 15:41 <DIR> d-------- C:\Documents and Settings\User\Application Data\OSI
2008-07-27 23:50 . 2008-07-28 09:00 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-13 22:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-08-13 07:02 --------- d-----w C:\Program Files\Steam
2008-08-12 13:49 --------- d-----w C:\Documents and Settings\User\Application Data\skip list road
2008-08-12 13:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Second Keep Coal Burn
2008-08-11 18:12 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-11 17:16 --------- d-----w C:\Program Files\Google
2008-08-11 17:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-06 03:15 --------- d-----w C:\Program Files\MSN Messenger
2007-08-31 05:39 17,824 ----a-w C:\Documents and Settings\User\Application Data\GDIPFONTCACHEV1.DAT
2007-01-25 22:44 151,320 ----a-w C:\Documents and Settings\User\Application Data\pcturboproinstallerfree[1].exe
2007-07-11 00:20 1,330,312 --sh--w C:\WINDOWS\AppPatch\wdcm.bak1
2007-07-11 04:53 1,329,838 --sh--w C:\WINDOWS\AppPatch\wdcm.bak2
2007-07-11 08:20 1,334,804 --sh--w C:\WINDOWS\AppPatch\wdcm.ini2
.
((((((((((((((((((((((((((((( snapshot@2008-08-12_10.02.07.92 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-11 16:10:28 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-08-13 17:43:14 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-08-11 16:10:28 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-08-13 17:43:14 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0BA59DA5-C438-4C84-8867-C64EEFB22AE4}]
2008-08-14 10:40 312320 --a------ C:\WINDOWS\System32\wvUnoLEw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5A6F7AC9-6AD9-4C97-9AC0-23C866E07208}]
2008-08-12 09:42 312320 --a------ C:\WINDOWS\System32\yayxvUlj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C514A4E5-E889-4CA8-BE28-CAC7E19F25FE}]
2008-08-03 00:51 274432 --a------ C:\Documents and Settings\User\Application Data\OSI\dlls\EFOToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DA93D885-6248-4A14-8C49-6BAF5E4CA44C}]
2008-07-03 12:08 25840 --a------ C:\WINDOWS\system32\mlJYsssQ.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e1ca5296-423a-421a-93a2-3703e6aaf67f}]
2008-08-14 10:53 107008 --a------ C:\WINDOWS\System32\jyppoz.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{AB26BF6C-BB04-4F00-8F98-BDE786CDE97D}"= "C:\Documents and Settings\User\Application Data\OSI\dlls\EFOToolbar.dll" [2008-08-03 00:51 274432]
[HKEY_CLASSES_ROOT\clsid\{ab26bf6c-bb04-4f00-8f98-bde786cde97d}]
[HKEY_CLASSES_ROOT\EFOToolbar.EFOObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{668611E3-7EC2-44EF-BF11-2D814E19FAA3}]
[HKEY_CLASSES_ROOT\EFOToolbar.EFOObj]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\laprmyd]
@="{DE1B9245-99F1-786C-6C83-8449D888F3EF}"
[HKEY_CLASSES_ROOT\CLSID\{DE1B9245-99F1-786C-6C83-8449D888F3EF}]
2004-09-22 18:45 82944 --a------ C:\WINDOWS\System32\laprmyd.dIl
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"wipeboob"="C:\DOCUME~1\User\APPLIC~1\SKIPLI~1\VC CORN TRANS.exe" [2008-08-12 09:45 503296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Coal Burn Mpeg Inter"="C:\Documents and Settings\All Users\Application Data\Second Keep Coal Burn\1 STYLE.exe" [2008-08-14 10:37 2015744]
"f083688e"="C:\WINDOWS\System32\xtrlungt.dll" [2008-08-14 10:47 82432]
"BMf3b05b12"="C:\WINDOWS\System32\wkslagix.dll" [2008-08-14 10:47 89088]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegedit"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{DA93D885-6248-4A14-8C49-6BAF5E4CA44C}"= "C:\WINDOWS\system32\mlJYsssQ.dll" [2008-07-03 12:08 25840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJYsssQ]
2008-07-03 12:08 25840 C:\WINDOWS\system32\mlJYsssQ.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\System32\wvUnoLEw
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^palstart.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\palstart.exe
backup=C:\WINDOWS\pss\palstart.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalStart.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalStart.lnk.disabled
backup=C:\WINDOWS\pss\PalStart.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jrjy]
C:\Documents and Settings\User\Application Data\??pPatch\w?nword.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wqzlz]
C:\WINDOWS\system32\F?nts\i?xplore.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wxfxz]
C:\Documents and Settings\User\Application Data\?dobe\w?nspool.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Athan]
--a------ 2006-05-23 07:32 974848 C:\Program Files\Athan\Athan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2002-10-15 23:05 114688 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2003-12-22 08:38 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2003-12-05 15:41 49152 C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
--a------ 2004-02-02 04:41 495616 C:\WINDOWS\system32\hphmon05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
--a------ 2003-11-12 09:23 49152 C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2002-10-15 23:18 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-09-26 14:42 267064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnappau]
--a------ 2004-07-22 21:53 86016 C:\Program Files\MSN Apps\Updater\
01.02.0002.1001\en-us\msnappau.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2005-03-29 18:28 6815744 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
--a------ 2002-10-23 10:15 86016 c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 07:24 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Quran_AR]
--a------ 2005-10-13 13:59 290816 C:\Program Files\Quran_AR\Quran_AR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RHSI SHS]
--a------ 2003-06-03 14:34 1036288 C:\Program Files\Rogers Hi-Speed Internet\RHSI SelfHealing\SHS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shell]
--a------ 2006-07-13 09:46 8353280 C:\WINDOWS\system32\shell32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-06-24 01:10 1271032 c:\Program Files\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-07-08 21:07 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Wini"="C:\PROGRA~1\SEMBLY~1\notepad.exe" -vt ndrv
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
"Steam"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"IpWins"=C:\Program Files\ipwins\ipwins.exe
"Quran_AR"=C:\Program Files\Quran_AR\Quran_AR.exe
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\System32\DRIVERS\RimSerial.sys [2005-08-16 13:02]
.
Contents of the 'Scheduled Tasks' folder
2008-08-14 C:\WINDOWS\Tasks\A7C8E6BC918F6190.job
- c:\docume~1\user\applic~1\skipli~1\bird defy browse.exe [2008-08-12 09:49]
2008-08-14 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2008-01-09 04:08]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9jv9gb7n.default\
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-14 10:36:57
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\wvUnoLEw.dll 312320 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\mlJYsssQ.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 2008-08-14 11:02:25 - machine was rebooted [User]
ComboFix-quarantined-files.txt 2008-08-14 15:01:48
ComboFix2.txt 2008-08-12 14:05:14
Pre-Run: 3,479,498,752 bytes free
Post-Run: 3,714,895,872 bytes free
343 --- E O F --- 2008-07-03 15:06:59