heres hoping I did it right, it didnt want to let me back on the internet til I re booted
ComboFix 08-07-19.1 - Debbie 2008-07-19 18:27:58.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1938 [GMT -5:00]
Running from: C:\Users\Debbie\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Debbie\AppData\Roaming\inst.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-06-19 to 2008-07-19 )))))))))))))))))))))))))))))))
.
2008-07-19 15:14 . 2008-07-19 15:14 <DIR> d-------- C:\Program Files\Safari
2008-07-19 09:52 . 2008-07-19 09:52 244 --ah----- C:\sqmnoopt00.sqm
2008-07-19 09:52 . 2008-07-19 09:52 232 --ah----- C:\sqmdata00.sqm
2008-07-19 09:47 . 2008-06-25 19:33 11,722,752 --a------ C:\Windows\System32\NlsLexicons0001.dll
2008-07-19 05:18 . 2008-07-19 05:18 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-07-19 00:35 . 2008-07-19 00:51 <DIR> d-------- C:\Users\Debbie\.SunDownloadManager
2008-07-18 23:52 . 2008-07-18 23:52 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-18 23:44 . 2008-07-18 23:45 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-07-18 23:27 . 2008-07-18 23:27 0 --ah----- C:\Users\Default.LOG2
2008-07-18 23:27 . 2008-07-18 23:27 0 --ah----- C:\Users\Default.LOG1
2008-07-18 23:27 . 2008-07-18 23:27 0 --ah----- C:\ProgramData.LOG2
2008-07-18 23:27 . 2008-07-18 23:27 0 --ah----- C:\ProgramData.LOG1
2008-07-18 22:42 . 2008-07-18 22:42 249,592 --a------ C:\Windows\System32\cssdll32.dll
2008-07-18 22:41 . 2008-07-18 22:41 <DIR> d-------- C:\Users\Debbie\AppData\Roaming\Comodo
2008-07-18 22:41 . 2008-07-18 23:11 <DIR> d-------- C:\Users\All Users\comodo
2008-07-18 22:41 . 2008-07-18 23:11 <DIR> d-------- C:\ProgramData\comodo
2008-07-18 22:41 . 2008-07-18 22:40 143,104 --a------ C:\Windows\System32\guard32.dll
2008-07-18 22:41 . 2008-07-18 22:40 85,008 --a------ C:\Windows\System32\drivers\cmdguard.sys
2008-07-18 22:41 . 2008-07-18 22:40 25,104 --a------ C:\Windows\System32\drivers\cmdhlp.sys
2008-07-18 22:40 . 2008-07-18 22:42 <DIR> d-------- C:\Program Files\COMODO
2008-07-18 20:01 . 2008-07-18 20:01 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-18 18:00 . 2008-05-15 18:18 50,768 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2008-07-18 17:59 . 2008-07-18 17:59 <DIR> d-------- C:\Program Files\Alwil Software
2008-07-18 12:11 . 2008-07-18 12:11 <DIR> d-------- C:\Users\Debbie\AppData\Roaming\Bitdefender
2008-07-18 12:10 . 2008-07-18 12:12 <DIR> d-------- C:\Users\All Users\BitDefender
2008-07-18 12:10 . 2008-07-18 12:12 <DIR> d-------- C:\ProgramData\BitDefender
2008-07-18 12:10 . 2008-07-18 12:11 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2008-07-18 12:10 . 2008-07-18 12:10 <DIR> d-------- C:\Program Files\BitDefender
2008-07-18 11:57 . 2008-07-18 11:57 <DIR> d-------- C:\Windows\BDOSCAN8
2008-07-18 08:09 . 2008-07-18 08:09 <DIR> d-------- C:\Users\Debbie\AppData\Roaming\Malwarebytes
2008-07-18 08:09 . 2008-07-18 08:09 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-07-18 08:09 . 2008-07-18 08:09 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-07-18 08:09 . 2008-07-18 08:09 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-18 08:09 . 2008-07-07 17:35 34,296 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-07-18 08:09 . 2008-07-07 17:35 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-19 20:33 --------- d-----w C:\Users\Debbie\AppData\Roaming\Spare Backup
2008-07-19 15:40 --------- d-----w C:\ProgramData\Microsoft Help
2008-07-19 10:17 --------- d-----w C:\Program Files\Java
2008-07-19 05:13 --------- d-----w C:\Program Files\The Weather Channel FW
2008-07-19 04:48 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-07-18 19:40 --------- d-----w C:\Program Files\Advanced Registry Optimizer
2008-07-18 12:51 --------- d---a-w C:\ProgramData\TEMP
2008-07-17 23:42 --------- d-----w C:\Program Files\Google
2008-07-12 12:43 --------- d-----w C:\Program Files\LimeWire
2008-07-09 20:04 --------- d-----w C:\Users\Debbie\AppData\Roaming\Vso
2008-07-09 08:07 174 --sha-w C:\Program Files\desktop.ini
2008-07-09 08:00 --------- d-----w C:\Program Files\Windows Mail
2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
2008-06-15 08:05 --------- d-----w C:\Users\Debbie\AppData\Roaming\LimeWire
2008-06-09 03:39 --------- d-----w C:\Program Files\iTunes
2008-06-09 03:39 --------- d-----w C:\Program Files\iPod
2008-06-09 03:26 --------- d-----w C:\Program Files\Apple Software Update
2008-05-26 00:17 --------- d-----w C:\Users\Debbie\AppData\Roaming\Apple Computer
2008-05-26 00:17 --------- d-----w C:\ProgramData\Apple Computer
2008-05-26 00:16 --------- d-----w C:\Program Files\QuickTime
2008-05-26 00:16 --------- d-----w C:\Program Files\Bonjour
2008-05-26 00:13 --------- d-----w C:\ProgramData\Apple
2008-05-26 00:13 --------- d-----w C:\Program Files\Common Files\Apple
2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
2008-04-26 08:02 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-04-25 04:23 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-25 04:23 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-25 04:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-04-23 04:27 428,032 ----a-w C:\Windows\System32\EncDec.dll
2008-04-23 04:27 292,352 ----a-w C:\Windows\System32\psisdecd.dll
2008-04-23 04:27 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-04-17 01:19 81,920 ----a-w C:\Users\Debbie\AppData\Roaming\ezpinst.exe
2008-04-17 01:19 47,360 ----a-w C:\Users\Debbie\AppData\Roaming\pcouffin.sys
2008-02-07 16:16 0 ----a-w C:\Users\Debbie\AppData\Roaming\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\Sidebar.exe" [2008-02-01 01:45 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 11:41 223984]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:36 201728]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 09:57 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 00:15 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 00:15 8466432]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 00:15 81920]
"Spare Backup"="C:\Program Files\Spare Backup\SpareBackup.exe" [2007-09-13 19:22 5252936]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 11:41 223984]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 18:19 79224]
"COMODO SafeSurf"="C:\Program Files\COMODO\SafeSurf\cssurf.exe" [2008-07-18 22:42 278264]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-07-18 22:40 1655552]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"ModPS2"="ModPS2Key.exe" [2006-11-07 17:34 53248 C:\Windows\ModPS2Key.exe]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 17:51 4435968 C:\Windows\RtHDVCpl.exe]
"CHotkey"="zHotkey.exe" [2006-11-07 17:08 547840 C:\Windows\zHotkey.exe]
C:\Users\Debbie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\Windows\system32\guard32.dll C:\Windows\system32\cssdll32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowWnd]
--a------ 2005-01-27 12:13 36864 C:\Windows\ShowWnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F3B64B8D-DDDA-402C-AB9E-7EC6945124B8}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6DA567A6-76E8-47FF-9E4B-832EE591E1F0}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{19D446E2-6C6A-44C4-B39B-2289538DBBC1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{4E66D2FF-8925-4621-BE4C-08585C5F33FD}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{9A9CB61F-CF18-4241-984E-5D07207CC7F1}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{C03DC4FD-D43C-4931-B893-C2ABBFAD7B34}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{5FC100F4-11FA-415D-A5DB-15EB5C8289CE}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{A0DDA765-557D-4074-8D75-E5E9F34A187D}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{138AE8FB-2F3F-4F07-B716-086E3497A4FC}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{1A34CA95-D1C8-46C0-BE56-B0E2E7B42BC5}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{4DFC7B90-A5BC-45ED-AB9B-D0922231B682}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{BF15EFA6-F3DE-49EB-BC9E-3A191ED07922}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{5EE78D69-AA94-4647-AA10-0BB1BB0EE6DA}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-15 18:20]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys [2008-07-18 22:40]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys [2008-07-18 22:40]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-15 18:16]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-15 18:18]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-01-09 13:00]
S3 GameConsoleService;GameConsoleService;C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe [2007-08-29 16:58]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 02:30]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 23:36:38 C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Lexmark 4200 Series - C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
MSConfigStartUp-NapsterShell - C:\Program Files\Napster\napster.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-19 18:30:30
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\system32\winlogon.exe
-> C:\Windows\system32\guard32.dll
PROCESS: C:\Windows\system32\lsass.exe
-> C:\Windows\system32\guard32.dll
.
Completion time: 2008-07-19 18:32:12
ComboFix-quarantined-files.txt 2008-07-19 23:31:46
Pre-Run: 310,547,001,344 bytes free
Post-Run: 312,916,619,264 bytes free
190 --- E O F --- 2008-07-19 15:48:51