At stage 2-3 of combofix I got one error heading:
CF10390.exe
reading:
(0x0000005)
ComboFix 08-08-01.05 - Jesus 2008-08-04 16:59:56.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1642 [GMT -4:00]
Running from: C:\Documents and Settings\Jesus\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jesus\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\emsf.bat
C:\IPH.PH
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\emsf.bat
C:\IPH.PH
.
((((((((((((((((((((((((( Files Created from 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))
.
2008-08-03 22:58 . 2008-08-03 22:58 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-03 18:30 . 2008-08-03 18:30 <DIR> d-------- C:\_OTMoveIt
2008-08-03 12:29 . 2008-08-03 12:29 <DIR> d-------- C:\Program Files\Alwil Software
2008-08-03 11:11 . 2008-08-03 11:11 <DIR> d-------- C:\Program Files\OpenDNS Updater
2008-08-03 10:37 . 2008-08-03 10:37 <DIR> d-------- C:\Deckard
2008-07-07 13:47 . 2008-07-07 13:47 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-07-07 13:47 . 2008-07-07 13:47 355,584 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-07-07 13:47 . 2008-05-29 09:28 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-07-07 10:50 . 2008-07-07 10:50 <DIR> d-------- C:\Program Files\StreamingStar
2008-07-07 10:50 . 2008-08-03 19:33 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-07 10:47 . 2008-07-07 10:47 <DIR> d-------- C:\WINDOWS\system32\WinFox
2008-07-07 10:47 . 2008-07-07 10:47 <DIR> d-------- C:\WINDOWS\system32\WinFast
2008-07-07 10:47 . 2008-07-07 10:47 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-03 23:34 --------- d-----w C:\Program Files\Opera 9
2008-08-01 05:45 --------- d-----w C:\Program Files\Bazooka Scanner
2008-07-31 20:42 4,224 ----a-w C:\WINDOWS\system32\drivers\beep.sys
2008-07-07 14:50 --------- dc----w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-07 14:50 --------- d-----w C:\Documents and Settings\Jesus\Application Data\uTorrent
2008-07-07 14:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Saitek
2008-07-07 14:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-07 14:47 --------- d-----w C:\Program Files\tamasoftware
2008-07-07 14:47 --------- d-----w C:\Documents and Settings\Jesus\Application Data\U3
2008-07-07 14:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-07 14:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-07 14:46 --------- d-----w C:\Program Files\Absolute Poker
2008-07-07 14:33 --------- d-----w C:\Program Files\QuickTime
2008-07-07 14:33 --------- d-----w C:\Program Files\Apple Software Update
2008-06-29 03:32 --------- d-----w C:\Documents and Settings\Jesus\Application Data\dvdcss
2008-06-23 21:23 --------- d-----w C:\Program Files\Widestep Software
2008-06-23 19:30 --------- d-----w C:\Program Files\Windows Live
2008-06-23 19:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-22 01:44 --------- d-----w C:\Program Files\DC++
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 18:37 --------- d-----w C:\Program Files\Saitek
2008-06-07 20:06 --------- d-----w C:\Program Files\Common Files\Apple
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2004-07-22 14:51 3,432,656 ----a-w C:\Program Files\ManagedDX.CAB
2004-07-20 02:58 1,156,363 ----a-w C:\Program Files\BDANT.cab
2004-07-20 02:53 976,020 ----a-w C:\Program Files\BDAXP.cab
2004-07-16 18:30 3,858 ----a-w C:\Program Files\directx redist.txt
2004-07-09 18:17 13,265,040 ----a-w C:\Program Files\dxnt.cab
2004-07-09 13:13 703,080 ----a-w C:\Program Files\BDA.cab
2004-07-09 13:13 15,493,481 ----a-w C:\Program Files\DirectX.cab
2004-07-09 08:08 472,576 ----a-w C:\Program Files\dxsetup.exe
2004-07-09 08:08 2,242,560 ----a-w C:\Program Files\dsetup32.dll
2004-07-09 07:03 62,976 ----a-w C:\Program Files\DSETUP.dll
.
((((((((((((((((((((((((((((( snapshot_2008-08-03_21.05.58.93 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-04 20:49:36 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_658.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SaiMfd"="C:\Program Files\Saitek\SD6\Software\SaiMfd.exe" [2007-10-02 10:10 131072]
"ProfilerU"="C:\Program Files\Saitek\SD6\Software\ProfilerU.exe" [2007-10-02 10:10 233472]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 18:34 213936]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"ezShieldProtector for Px"="C:\WINDOWS\system32\ezSP_Px.exe" [2002-08-20 11:29 40960]
"OpenDNS Update"="C:\Program Files\OpenDNS Updater\OpenDNS Updater.exe" [2008-06-09 13:07 209408]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 10:38 78008]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-29 16:50 4620288]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ezShieldProtector for Px]
--a------ 2002-08-20 11:29 40960 C:\WINDOWS\system32\ezSP_Px.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2004-10-29 16:50 921600 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ezShieldProtector for Px"=C:\WINDOWS\system32\ezSP_Px.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\DC++\\DCPlusPlus.exe"=
"C:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=
"C:\\Documents and Settings\\Jesus\\Desktop\\SRO_NEW_Full-Client_Downloader.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 10:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 10:37]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
R2 WUSB54GSSVC;WUSB54GSSVC;C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe WUSB54GS.exe []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-07-07 13:47]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7c594d57-6061-11dc-8e27-a4c471764370}]
\Shell\AutoRun\command - LinksysConnectPC.exe
*Newly Created Service* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
2008-08-04 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:09]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-04 17:02:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-04 17:04:18
ComboFix-quarantined-files.txt 2008-08-04 21:03:33
ComboFix2.txt 2008-08-04 01:27:43
ComboFix3.txt 2008-08-04 01:07:15
ComboFix4.txt 2008-08-02 20:53:09
ComboFix5.txt 2008-08-04 20:59:35
Pre-Run: 102,776,942,592 bytes free
Post-Run: 102,764,236,800 bytes free
135 --- E O F --- 2008-08-04 00:48:26