Edit: Ok got scan going... blocked everything with router stupidly and that's the hold up. Sorry. Thanks for the help as well!!!
;*******************************************************************************
********************************************************************************
*
*******************
ANALYSIS: 2008-08-02 15:47:10
PROTECTIONS: 1
MALWARE: 6
SUSPECTS: 0
;*******************************************************************************
********************************************************************************
*
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
================================================================================
=
===================
Windows Defender 1.1.3806.0 No Yes
;===============================================================================
================================================================================
=
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
================================================================================
=
===================
00199231 HackTool/EvID HackTools No 0 Yes No C:\System Volume Information\_restore{CC5AE3F0-BCA3-4E06-82D3-FB125AD23EB0}\RP1\A0000001.exe
00199231 HackTool/EvID HackTools No 0 Yes No C:\System Volume Information\_restore{CC5AE3F0-BCA3-4E06-82D3-FB125AD23EB0}\RP26\A0015271.exe
00415224 Generic Trojan Virus/Trojan No 0 Yes No E:\System Volume Information\_restore{045C5380-3D8B-45F5-9D26-24F4D31E9FB0}\RP117\A0022488.exe
00889019 Generic Trojan Virus/Trojan No 0 Yes No E:\System Volume Information\_restore{61DA53DC-13A9-4C37-8915-6AD8DA1A3053}\RP92\A0009772.exe
01895149 Malicious Packer SecRisk No 0 Yes No C:\System Volume Information\_restore{CC5AE3F0-BCA3-4E06-82D3-FB125AD23EB0}\RP26\A0014221.exe
01895149 Malicious Packer SecRisk No 0 Yes No C:\System Volume Information\_restore{CC5AE3F0-BCA3-4E06-82D3-FB125AD23EB0}\RP1\A0000002.exe
03117151 Trj/Zapchast.CK Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{CC5AE3F0-BCA3-4E06-82D3-FB125AD23EB0}\RP46\A0019730.dll
03253603 Bck/Hupigon.AZG Virus/Trojan No 1 Yes No C:\Program Files\AviDvdBurner\Patch.exe
;===============================================================================
================================================================================
=
===================
SUSPECTS
Sent Location t
;===============================================================================
================================================================================
=
===================
;===============================================================================
================================================================================
=
===================
VULNERABILITIES
Id Severity Description t
;===============================================================================
================================================================================
=
===================
;===============================================================================
================================================================================
=
===================
Combofix
ComboFix 08-08-01.05 - Patrick1 2008-08-02 15:51:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.613 [GMT -5:00]
Running from: C:\Documents and Settings\Patrick1\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Patrick1\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\grouppolicy\machine\scripts\scripts.ini
.
((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.
2008-08-02 15:08 . 2008-08-02 15:08 <DIR> d-------- C:\WINDOWS\LastGood
2008-08-02 15:08 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-08-02 14:57 . 2008-08-02 14:57 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-08-02 14:56 . 2007-08-13 18:52 66,048 --a------ C:\WINDOWS\ieResetIcons.exe
2008-08-02 13:03 . 2008-08-02 13:03 <DIR> d-------- C:\Program Files\COMODO
2008-08-02 13:03 . 2008-08-02 13:03 <DIR> d-------- C:\Documents and Settings\Patrick1\Application Data\Comodo
2008-08-02 13:03 . 2008-08-02 13:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-08-02 13:03 . 2008-08-02 13:03 143,104 --a------ C:\WINDOWS\system32\guard32.dll
2008-08-02 13:03 . 2008-08-02 13:03 87,056 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-08-02 13:03 . 2008-08-02 13:03 24,208 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-08-02 10:45 . 2008-08-02 10:45 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-02 09:46 . 2008-08-02 09:46 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-08-02 09:46 . 2008-08-02 09:46 <DIR> d-------- C:\Program Files\MSECACHE
2008-07-26 06:07 . 2008-07-26 06:07 <DIR> d-------- C:\Program Files\Xvid
2008-07-26 06:07 . 2008-04-27 10:33 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-07-26 06:07 . 2008-04-27 10:35 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-07-26 06:07 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2008-07-26 05:44 . 2008-03-04 12:33 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-07-26 05:44 . 2008-03-04 12:32 6,144 --a------ C:\WINDOWS\system32\ff_acm.acm
2008-07-26 05:44 . 2007-07-10 17:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-07-26 05:09 . 2008-08-02 09:02 <DIR> d-------- C:\Program Files\mplayerc_20080308
2008-07-26 05:09 . 2008-07-26 05:09 <DIR> d-------- C:\Documents and Settings\Patrick1\Application Data\Media Player Classic
2008-07-25 23:58 . 2008-07-25 23:58 <DIR> d-------- C:\Program Files\AnalogX
2008-07-22 03:49 . 2008-07-22 03:49 <DIR> d-------- C:\Program Files\uTorrent
2008-07-22 03:49 . 2008-06-20 06:51 361,600 -----c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2008-07-22 03:49 . 2008-06-20 06:08 225,856 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-07-22 03:48 . 2008-08-02 09:02 <DIR> d-------- C:\Documents and Settings\Patrick1\Application Data\uTorrent
2008-07-14 19:06 . 2008-05-08 06:24 155,648 -----c--- C:\WINDOWS\system32\dllcache\wscript.exe
2008-07-14 19:06 . 2008-05-09 05:53 90,112 -----c--- C:\WINDOWS\system32\dllcache\wshext.dll
2008-07-03 20:34 . 2008-07-03 20:34 <DIR> d-------- C:\Documents and Settings\Patrick1\Application Data\ATI
2008-07-03 20:34 . 2008-07-03 20:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-07-03 20:34 . 2008-07-03 20:34 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-07-03 20:32 . 2008-06-02 21:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-07-03 20:31 . 2008-07-03 20:32 <DIR> d-------- C:\Program Files\ATI Technologies
2008-07-03 20:31 . 2008-07-03 20:31 <DIR> d-------- C:\ATI
2008-07-03 20:09 . 2008-02-12 01:00 104,960 --a------ C:\WINDOWS\system32\drivers\atinrvxx.sys
2008-07-03 20:09 . 2008-02-12 01:00 36,463 --a------ C:\WINDOWS\system32\drivers\ati1tuxx.sys
2008-07-03 20:09 . 2008-02-12 01:00 28,672 --a------ C:\WINDOWS\system32\drivers\atinsnxx.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-02 20:08 --------- d-----w C:\Program Files\Panda Security
2008-08-02 19:45 --------- d-----w C:\Program Files\PeerGuardian2
2008-08-02 19:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-02 17:26 --------- d-----w C:\Program Files\SpywareBlaster
2008-08-02 15:48 12,960 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2008-08-02 15:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-02 15:46 --------- d-----w C:\Program Files\Lavasoft
2008-08-02 15:03 --------- d-----w C:\Documents and Settings\Patrick1\Application Data\AVG7
2008-08-02 14:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-02 11:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-02 11:29 --------- d-----w C:\Program Files\The Witcher
2008-08-02 11:28 --------- d-----w C:\Program Files\FlashGet
2008-08-02 09:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-26 10:45 --------- d-----w C:\Program Files\AviSynth 2.5
2008-07-26 10:44 --------- d-----w C:\Program Files\ffdshow
2008-07-26 10:08 --------- d-----w C:\Program Files\QuickTime
2008-07-26 10:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-26 10:07 --------- d-----w C:\Program Files\AC3Filter
2008-07-26 04:13 --------- d-----w C:\Program Files\VideoLAN
2008-07-22 08:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-05 09:41 --------- d-----w C:\Program Files\Winamp
2008-07-04 10:31 --------- d-----w C:\Program Files\Picasa2
2008-07-04 01:29 --------- d-----w C:\Program Files\Google
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-03 10:44 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-06-03 10:44 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-06-03 10:43 --------- d-----w C:\Program Files\Futuremark
2008-06-03 06:20 3,100,160 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-06-03 03:46 10,276,864 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-06-03 03:22 413,696 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-06-03 03:21 306,688 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-06-03 03:11 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-06-03 03:11 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-06-03 03:11 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-06-03 03:11 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-06-03 03:11 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-06-03 03:09 552,960 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-06-03 03:08 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-06-03 03:04 245,760 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-06-03 03:02 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-06-03 02:59 3,500,352 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-06-03 02:48 2,120,832 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-06-03 02:33 48,128 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-06-03 02:29 348,160 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-06-03 02:28 23,040 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-06-03 02:28 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-06-03 02:27 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-06-03 02:22 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-06-03 02:21 557,056 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-05-20 21:40 1,753,088 ----a-w C:\WINDOWS\dd-wrt.v24_micro_wrt54gv8.bin
2008-05-20 21:40 1,753,088 ----a-w C:\dd-wrt.v24_micro_wrt54gv8.bin
2008-05-16 16:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-09 10:53 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
2008-05-09 10:53 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:53 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
2008-05-09 08:45 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-11 02:37 8 ----a-w C:\Documents and Settings\Patrick1\Application Data\usb.dat
2007-09-06 04:46 52,494,336 ----a-w C:\Documents and Settings\Patrick1\TRACE_BOOT+DRIVERS_1_1.BIN
2008-04-05 16:32 16,384 --sha-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
2008-04-05 16:32 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2008-04-05 16:32 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008040520080406\index.dat
2008-04-05 16:32 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824]
"HijackThis startup scan"="C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" [2008-01-06 07:24 396288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 13:30 139264]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-08-02 13:03 1655552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\
0\
0]
"Script"=C:\WINDOWS\system32\zzzdeltemp.bat
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerStrip
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ABIT uGuru]
--a------ 2003-09-22 21:34 192512 C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 2008-04-15 08:48 579584 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-02-12 14:59 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
--a------ 2007-09-06 08:08 136136 C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 08:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 13:39 1289000 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2008-01-21 12:17 61440 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
--a------ 2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SandraTheSrv"=3 (0x3)
"SandraDataSrv"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 AC2003;AC2003;C:\WINDOWS\system32\Drivers\AC2003.sys [2003-11-26 10:40]
R0 uGuru;uGuru;C:\WINDOWS\system32\Drivers\uGuru.sys [2004-02-26 17:52]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-08-02 13:03]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-08-02 13:03]
S3 cpuz129;cpuz129;C:\DOCUME~1\Patrick1\LOCALS~1\Temp\cpuz_x32.sys []
S3 FAH@C:+Second Folding+FAH504-Console.exe;FAH@C:+Second Folding+FAH504-Console.exe;C:\Second Folding\FAH504-Console.exe [2007-07-11 02:43]
S3 FAH@C:+Third Folding+FAH504-Console.exe;FAH@C:+Third Folding+FAH504-Console.exe;C:\Third Folding\FAH504-Console.exe [2007-07-11 02:43]
S3 Memctl;Memctl;C:\Program Files\ABIT\FlashMenu\Memctl.sys []
*Newly Created Service* - CATCHME
*Newly Created Service* - PGFILTER
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-08-02 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Adobe Reader Speed Launcher - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-AdobeUpdater - C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
MSConfigStartUp-QuickTime Task - C:\Program Files\QuickTime\qttask.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Patrick1\Application Data\Mozilla\Firefox\Profiles\5y3czrjl.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-02 15:52:48
Windows 5.1.2600 Service Pack 3, v.3311 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
"ServiceDll"="C:\WINDOWS\system32\es.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\FAH@C:+Second Folding+FAH504-Console.exe]
"ImagePath"="C:\Second Folding\FAH504-Console.exe -svcstart -svcstart -verbosity 9 -forceasm -advmethods -local"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\FAH@C:+Third Folding+FAH504-Console.exe]
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\guard32.dll
.
Completion time: 2008-08-02 15:53:20
ComboFix-quarantined-files.txt 2008-08-02 20:53:16
Pre-Run: 47,446,573,056 bytes free
Post-Run: 47,421,661,184 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noguiboot /usepmtimer
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
256 --- E O F --- 2008-08-02 02:07:21
Edited by Congo123, 02 August 2008 - 02:46 PM.