i did wat you said and this is the new Combofix log:
ComboFix 08-07-15.4 - user1 2008-07-17 18:42:50.3 -
FAT32x86
Running from: H:\Vishal\Work\fix\ComboFix.exe
Command switches used :: H:\Vishal\Work\fix\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\UniFish3.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Messenger Plus!
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#01008771324C.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#01A8A6F9D2A6.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#03E86B3BCCF7.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#05200C0B9E7E.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#053806836E67.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#0568F6F7B5C3.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#0669C9B206E5.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#06E8736C710E.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#06E8E11BAE95.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#08F21EF8EDCD.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#0A90449F406F.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#0BC89CD507B6.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#0BF858280462.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#10A87468ED52.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#12581F2E85C5.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#12D01326B75F.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#1A7858B98BCE.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#206B39145F71.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#2AD02D181FDB.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#2B5804B9B5E8.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#2CF00325B964.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#33C417A89674.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#389BF811A896.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#3C2005C83A9D.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#3CA8A0B89571.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#3CF8155907CC.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#43284C287A59.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#45385B4006EB.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#4699FE47C279.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#4870F3EAF3F8.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#48EC4ECC88B6.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#499064A72A52.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#4DFB95DD68BC.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#4F1C0FF9A271.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#4FC7EAC60880.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#514C55CA04E3.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#54B0477ACE40.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#56242A84B2EB.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#59F001F709CE.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#5B6EB7DCBDFA.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#5E02444E58C7.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#5E8EF2B5484D.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#6041E2DDC9A2.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#64B5C05ED1AC.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#69886C058222.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#6A7F97659856.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#6F2CFC29B0F6.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#6FE022C621E3.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#715F9C729624.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#717DE9B95C72.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#77300C3C59A2.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#787405EF37B9.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#812C1B85B075.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#82600D2272EF.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#82701CD4F0E0.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#83A01D576A65.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#83A851310A29.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#86A812B92DA4.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#8B41F5F6331A.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#8BB81E434752.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#8DA7C06B76B0.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#8DE0BA562BA3.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#90386D905EF4.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#93E001AF268B.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#944C093F7060.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#97880B2BD7D8.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#9BB8750C9E51.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#A02A3B3F3F9E.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#A12AEF2B4A51.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#A14A66B485A5.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#A23803530CAE.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#A448015C0927.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#A81A0299C737.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#AB3804A90E77.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#AB3F0898C85C.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#AC1A3758CCA1.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#AF18BCEDE7EB.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#BBD0AC22F978.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#BEA049170202.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#C26C3149E42A.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#D73C5B9DDBFE.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#DB74D982BD5F.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#DBC8977FB8A4.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#E5B834261DEF.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#E8886905B811.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#E984828792DA.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#EA38555C1053.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#F11C1F2CA452.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#F2F08D39AB44.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#F63827CE2293.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#FA88755E15BB.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#FDE8352596D0.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\#FE300F44AD41.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\BuiltIn33.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\BuiltIn35.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\BuiltIn36.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\BuiltIn37.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\BuiltIn42.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\BuiltIn44.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\BuiltIn50.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\BuiltIn53.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\Custom Sounds\BuiltIn64.dat
C:\Documents and Settings\All Users\Application Data\Messenger Plus!\global.dat
C:\Documents and Settings\user1\Application Data\32 MOVE
C:\WINDOWS\UniFish3.exe
G:\Program Files\Search Settings\
G:\Program Files\Search Settings\\SearchSettings.exe
.
((((((((((((((((((((((((( Files Created from 2008-06-17 to 2008-07-17 )))))))))))))))))))))))))))))))
.
2008-07-17 12:27 . 2008-07-17 12:27 106 --a------ C:\delete.bat
2008-07-17 08:36 . 2008-07-17 08:36 <DIR> d-------- C:\NoLopBackups
2008-07-16 17:05 . 2008-07-16 17:05 <DIR> d-------- C:\WINDOWS\
0E6AB9FC76C2431B9C066C1CFFFEA8EB.TMP
2008-07-16 13:03 . 2008-07-16 13:03 <DIR> d-------- C:\VundoFix Backups
2008-07-16 12:10 . 2008-07-16 12:10 <DIR> d-------- G:\Program Files\Trend Micro
2008-07-16 11:09 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pavboot.sys
2008-07-16 11:06 . 2008-07-16 11:06 <DIR> d-------- G:\Program Files\Panda Security
2008-07-16 09:47 . 2008-07-16 09:47 <DIR> d-------- G:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-16 09:46 . 2008-07-17 14:03 <DIR> d-------- G:\Program Files\SUPERAntiSpyware
2008-07-16 09:25 . 2008-07-16 09:25 <DIR> d-------- C:\Documents and Settings\user1\Application Data\Malwarebytes
2008-07-16 09:24 . 2008-07-16 09:24 <DIR> d-------- G:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-15 18:41 . 2008-07-16 13:26 <DIR> d-------- G:\Documents and Settings\All Users\Application Data\avg8
2008-07-15 18:20 . 2008-07-15 18:20 <DIR> d-------- G:\Program Files\Lavasoft
2008-07-15 18:20 . 2008-07-15 18:20 <DIR> d-------- G:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-15 13:53 . 2008-07-15 13:53 <DIR> d-------- C:\Documents and Settings\user1\Application Data\Uniblue
2008-07-15 12:53 . 2008-07-15 20:37 <DIR> d-------- G:\Program Files\Circle Developement
2008-07-15 12:53 . 2008-07-15 12:53 <DIR> d-------- G:\Program Files\32 MOVE
2008-07-15 12:49 . 2008-07-15 12:53 <DIR> d-------- G:\Program Files\MSN Messenger
2008-07-11 13:24 . 2008-07-11 13:24 <DIR> d-------- C:\Documents and Settings\user1\Application Data\LimeWireTurbo
2008-07-11 11:51 . 2008-07-17 14:03 <DIR> d-a------ G:\Documents and Settings\All Users\Application Data\TEMP
2008-07-11 10:15 . 2008-07-11 10:15 <DIR> d-------- G:\Program Files\AVG
2008-07-10 21:26 . 2008-07-10 21:26 <DIR> d-------- C:\WINDOWS\'Full Speed' Internet Booster + Performance Tests
2008-07-10 21:26 . 2008-07-10 21:26 <DIR> d-------- C:\aidualc3
2008-07-08 11:42 . 2008-07-08 11:47 <DIR> d-------- G:\Program Files\Common Files\Nero
2008-07-08 11:33 . 2006-03-26 13:30 105 --a------ C:\WININF.DAT
2008-07-08 11:21 . 2008-07-08 11:41 <DIR> d-------- G:\Program Files\Dachshund Software
2008-07-08 11:21 . 2006-03-26 13:30 105 --ah----- C:\WINDOWS\wininf.dat
2008-07-07 13:24 . 2008-07-07 13:24 5,632 --ahs---- C:\Thumbs.db
2008-07-07 13:24 . 2008-07-07 13:27 167 --a------ C:\WINDOWS\CorelDrw.ini
2008-07-05 20:25 . 2008-07-05 20:25 <DIR> d-------- G:\Program Files\TI Education
2008-07-05 20:25 . 2008-07-05 20:25 <DIR> d-------- G:\Program Files\Common Files\TI Shared
2008-07-05 13:53 . 2008-07-05 13:53 227 --a------ C:\WINDOWS\PowerReg.dat
2008-07-04 21:45 . 2008-07-04 21:46 <DIR> d-------- G:\Program Files\Cpukiller3
2008-06-23 13:08 . 2008-06-23 13:08 <DIR> d-------- C:\Documents and Settings\user1\temp
2008-06-23 13:08 . 2008-06-23 13:08 <DIR> d-------- C:\Documents and Settings\user1\Application Data\TeamViewer
2008-06-23 12:38 . 2008-06-23 12:38 <DIR> d-------- C:\Documents and Settings\user1\Tracing
2008-06-23 11:42 . 2008-06-23 11:44 <DIR> d--hsc--- G:\Program Files\Common Files\WindowsLiveInstaller
2008-06-23 11:42 . 2008-07-15 13:02 <DIR> d-------- G:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-22 10:11 . 2008-06-22 10:11 <DIR> d-------- G:\Program Files\ENGLISH
2008-06-21 15:13 . 2008-06-21 15:15 <DIR> d-------- G:\Program Files\SystemRequirementsLab
2008-06-21 15:13 . 2008-06-21 15:13 <DIR> d-------- C:\Documents and Settings\user1\Application Data\SystemRequirementsLab
2008-06-20 16:14 . 2008-06-20 17:37 <DIR> d-------- G:\Program Files\Counter-Strike 1.6
2008-06-20 14:27 . 2008-06-20 14:27 <DIR> d--h----- C:\Documents and Settings\user1\Application Data\ijjigame
2008-06-20 14:24 . 2008-06-20 14:24 <DIR> d-------- G:\Documents and Settings\All Users\Application Data\IJJIGame
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 18:03 --------- d-----w G:\Program Files\Common Files\Wise Installation Wizard
2008-07-15 16:53 --------- d-----w G:\Program Files\Messenger Plus! Live
2008-07-15 16:36 --------- d-----w G:\Program Files\Windows Live
2008-07-14 17:29 --------- d-----w G:\Program Files\Soulseek
2008-07-14 01:37 --------- d-----w G:\Program Files\Winamp
2008-07-11 17:44 --------- d-----w G:\Documents and Settings\All Users\Application Data\Creative
2008-06-09 01:47 --------- d-----w G:\Program Files\Avidemux 2.4
2008-06-09 01:21 --------- d-----w G:\Program Files\Free FLV Converter
2008-06-01 14:06 --------- d-----w C:\Documents and Settings\user1\Application Data\Thinstall
2008-05-31 19:20 --------- d-----w G:\Program Files\Google
2008-05-31 19:12 --------- d-----w G:\Program Files\AVSMedia
2008-05-31 19:10 --------- d-----w G:\Program Files\Common Files\AVSMedia
2008-05-25 22:51 --------- d-----w C:\Documents and Settings\user1\Application Data\gtk-2.0
2008-05-25 22:31 --------- d-----w G:\Program Files\Solveig Multimedia
2008-05-25 22:31 --------- d-----w G:\Program Files\Common Files\Solveig Multimedia
2008-05-15 15:30 208,896 ----a-w C:\WINDOWS\SYSTEM32\TubeFinder.exe
2006-05-23 22:19 1,940 ----a-w C:\Documents and Settings\user1\Application Data\ViewerApp.dat
2004-08-04 04:56 24,244 ---h--w C:\Documents and Settings\user1\Application Data\fix.dat
2004-05-11 19:59 560 ----a-w C:\Documents and Settings\user1\PCDOC.BAT
2000-02-18 21:35 353 ----a-w C:\Documents and Settings\DesignWorkshop Lite Installer\layout.bin
1997-08-26 17:02 8,192 ----a-w C:\Documents and Settings\DesignWorkshop Lite Installer\_ISDEL.EXE
1997-08-26 17:02 59,904 ----a-w C:\Documents and Settings\DesignWorkshop Lite Installer\SETUP.EXE
1997-08-26 17:01 11,264 ----a-w C:\Documents and Settings\DesignWorkshop Lite Installer\_SETUP.DLL
1997-05-30 16:31 4,557 ----a-w C:\Documents and Settings\DesignWorkshop Lite Installer\lang.dat
1997-05-06 19:15 417 ----a-w C:\Documents and Settings\DesignWorkshop Lite Installer\os.dat
2003-09-30 21:46 32 --sha-w C:\WINDOWS\SYSTEM\{E2CD2910-F36D-11D7-B847-000AE6CB12FC}.dat
2005-08-31 18:14 3,913,435 --sha-w C:\WINDOWS\SYSTEM32\xcrfsys.dat
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\SYSTEM32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\SYSTEM32\msfDX.dll
.
------- Sigcheck -------
2008-01-03 12:16 359808 8d8949936913b041c6a0e184fbf1030b C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
2008-01-03 12:16 359808 8d8949936913b041c6a0e184fbf1030b C:\WINDOWS\SYSTEM32\dllcache\TCPIP.SYS
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\ServicePackFiles\i386\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 06:15 106496]
"AEZBProc"="c:\ibmtools\aptezbtn\aptezbp.exe" [2001-07-24 16:49 372736]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-10 16:24 151597]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="G:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
"YOP"="G:\PROGRA~1\Yahoo!\YOP\yop.exe" [2007-10-26 15:42 509224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"VIDC.VDOM"= vdowave.drv
"vidc.LEAD"= LCODCCMPE.DLL
"VIDC.AP41"= APmpg4v1.dll
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
"vidc.yv12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Encoder Agent.lnk]
backup=C:\WINDOWS\pss\Encoder Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Filseclab Messenger.lnk]
backup=C:\WINDOWS\pss\Filseclab Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
backup=C:\WINDOWS\pss\Picture Package Menu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
backup=C:\WINDOWS\pss\Picture Package VCD Maker.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^user1^Start Menu^Programs^Startup^Trivial Pursuit_ Unhinged Registration.lnk]
backup=C:\WINDOWS\pss\Trivial Pursuit_ Unhinged Registration.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spc_w
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TuneUp MemOptimizer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Update Manager
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DisableEHCI]
--a------ 2002-08-26 15:49 28672 C:\WINDOWS\S4TSR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
--a------ 2003-08-19 05:43 57344 C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-01-31 07:20 180224 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 23:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
--a------ 2006-06-01 15:26 1003520 C:\Program Files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SHS]
--a------ 2006-03-13 10:52 2939176 C:\Program Files\Rogers\SelfHealing\SHS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2005-10-10 16:24 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
--------- 2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AdobeActiveFileMonitor4.0"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SiS KHooker"=C:\WINDOWS\System32\khooker.exe
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Adobe Photo Downloader"="C:\Program Files\Adobe PhotoShop Elements 4\apdproxy.exe"
"EssSpkPhone"=essspk.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"SiS KHooker"=C:\WINDOWS\SYSTEM32\KHOOKER.EXE
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd
"LVComs"=C:\WINDOWS\SYSTEM32\LVComS.exe
"DXM6Patch_981116"=C:\WINDOWS\p_981116.exe /Q:A
"StillImageMonitor"=C:\WINDOWS\SYSTEM32\STIMON.EXE
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe
"ccRegVfy"=C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
"Advanced Tools Check"=C:\PROGRA~1\NORTON~2\ADVTOOLS\ADVCHK.EXE
"NPROTECT"=C:\PROGRA~1\NORTON~2\ADVTOOLS\NPROTECT.EXE
"LoadQM"=loadqm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\ijji\\ENGLISH\\Gunbound Revolution\\NyxLauncher.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\System32\\rtcshare.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"=
"G:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"G:\\Program Files\\iTunes\\iTunes.exe"=
"G:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"G:\\Program Files\\MSN Messenger\\livecall.exe"=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-17 18:47:28
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
G:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
G:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
C:\WINDOWS\SYSTEM32\GEARSEC.EXE
C:\WINDOWS\SYSTEM32\SESSMGR.EXE
C:\IBMTOOLS\APTEZBTN\RAKUSB.EXE
C:\PROGRAM FILES\IPOD\BIN\IPODSERVICE.EXE
.
**************************************************************************
.
Completion time: 2008-07-17 18:50:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-17 22:50:00
ComboFix3.txt 2008-07-17 12:57:48
ComboFix2.txt 2008-07-17 17:59:58
Pre-Run: 1,064,321,024 bytes free
Post-Run: 1,047,347,200 bytes free
344 --- E O F --- 2006-06-27 02:37:57