Here's the combofix text also i noted that my time changed from regular to military during this scan....
ComboFix 08-08-18.05 - HP_Administrator 2008-08-20 16:33:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.459 [GMT -4:00]
Running from: C:\Documents and Settings\HP_Administrator\Favorites\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Administrator\UserData
C:\Documents and Settings\Administrator\UserData\index.dat
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\#SharedObjects\R2QPT72E\interclick.com
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\#SharedObjects\R2QPT72E\interclick.com\ud.sol
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\HP_Administrator\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\HP_Administrator\UserData
C:\Documents and Settings\HP_Administrator\UserData\CP238DUJ\oXMLStoreUnit[1].xml
C:\Documents and Settings\HP_Administrator\UserData\index.dat
C:\Documents and Settings\HP_Administrator\UserData\O92NC9AR\dmtstore[2].xml
C:\Documents and Settings\HP_Administrator\UserData\ODANSTIJ\IsOnIE6tbPromo[1].xml
C:\Documents and Settings\HP_Administrator\UserData\W12V81MF\oWindowsUpdate[2].xml
C:\Documents and Settings\The Kids\Application Data\macromedia\Flash Player\#SharedObjects\38UEABLR\interclick.com
C:\Documents and Settings\The Kids\Application Data\macromedia\Flash Player\#SharedObjects\38UEABLR\interclick.com\ud.sol
C:\Documents and Settings\The Kids\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\The Kids\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\The Kids\UserData
C:\Documents and Settings\The Kids\UserData\8PM7CXA3\YL[1].xml
C:\Documents and Settings\The Kids\UserData\index.dat
C:\WINDOWS\system32\actskn43.ocx
C:\WINDOWS\system32\bxcmtemg.ini
C:\WINDOWS\system32\psDKkRqr.ini
C:\WINDOWS\system32\psDKkRqr.ini2
.
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.
2008-08-19 15:20 . 2008-08-19 15:20 <DIR> d-------- C:\Program Files\MahJGar Buddy Pogo
2008-08-19 15:14 . 2008-08-19 15:15 <DIR> d-------- C:\Program Files\BadgeHelp
2008-08-19 15:14 . 2008-08-19 15:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EURRNRCPBH
2008-08-18 18:55 . 2008-08-18 19:01 <DIR> d-------- C:\RegSearch
2008-08-18 18:53 . 2008-08-18 18:53 <DIR> d-------- C:\Program Files\HostsXpert
2008-08-15 13:02 . 2008-08-15 13:03 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Go-Go Gourmet Chef of the Year
2008-08-13 07:21 . 2008-04-11 15:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-12 18:18 . 2008-04-13 15:24 2,145,280 --a------ C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-08-08 20:14 . 2008-08-08 20:14 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-08-08 17:58 . 2008-08-08 17:58 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-08 14:34 . 2008-08-08 14:34 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\GTek
2008-08-08 12:47 . 2008-08-08 13:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\RTFWCVROBH
2008-08-07 21:14 . 2008-08-07 21:14 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\McAfee
2008-08-07 21:06 . 2008-08-07 21:06 <DIR> d-------- C:\Documents and Settings\The Kids\Application Data\McAfee
2008-08-07 21:05 . 2008-08-07 21:05 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\McAfee
2008-08-06 20:48 . 2008-08-06 21:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\JFQVRCDPBH
2008-08-03 18:45 . 2008-08-03 18:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NYEIFSVOBH
2008-08-02 21:43 . 2008-08-02 22:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PYEIFSVOBH
2008-08-01 12:38 . 2008-08-01 13:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BZJYVUROBH
2008-08-01 08:29 . 2008-08-01 08:29 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\IObit
2008-08-01 08:28 . 2008-08-01 08:28 <DIR> d-------- C:\Program Files\IObit
2008-07-31 22:31 . 2008-08-08 20:15 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-31 22:31 . 2008-08-14 20:37 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
2008-07-31 22:31 . 2008-07-31 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-31 22:31 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-31 22:31 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-31 21:34 . 2008-07-31 21:40 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\McAfee
2008-07-31 21:31 . 2008-08-20 16:39 15,033 --a------ C:\WINDOWS\system32\Config.MPF
2008-07-31 21:30 . 2006-03-03 08:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-07-31 21:28 . 2008-07-31 21:28 <DIR> d-------- C:\Program Files\McAfee.com
2008-07-31 21:28 . 2008-07-31 21:28 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-07-31 21:28 . 2007-11-22 06:44 201,320 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-07-31 21:28 . 2007-07-13 06:20 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-07-31 21:28 . 2007-11-22 06:44 79,304 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-07-31 21:28 . 2007-12-02 12:51 40,488 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-07-31 21:28 . 2007-11-22 06:44 35,240 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-07-31 21:28 . 2007-11-22 06:44 33,832 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-07-31 21:27 . 2008-08-07 21:03 <DIR> d-------- C:\Program Files\McAfee
2008-07-31 21:22 . 2008-08-05 20:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-30 17:26 . 2008-07-30 17:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ORFHKNTOBH
2008-07-30 17:26 . 2008-07-30 17:27 796 --a------ C:\Backgammon.Dat
2008-07-27 19:51 . 2008-07-27 19:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
2008-07-27 19:48 . 2008-07-27 19:48 <DIR> d-------- C:\WINDOWS\Cache
2008-07-27 19:48 . 2008-07-30 21:50 <DIR> d-------- C:\Program Files\Coupons
2008-07-27 14:15 . 2008-08-19 14:52 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-07-27 09:23 . 2008-07-27 13:04 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-07-26 08:31 . 2008-08-01 15:35 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\U3
2008-07-26 07:43 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-26 07:42 . 2008-07-26 07:42 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-25 12:21 . 2008-07-25 13:40 <DIR> d-------- C:\Program Files\Panda Security
2008-07-24 18:37 . 2008-08-17 07:58 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-24 18:37 . 2008-07-24 18:37 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-23 20:19 . 2008-07-23 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\GWOICMAPBH
2008-07-20 16:11 . 2008-07-20 16:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
2008-07-20 10:20 . 2008-07-20 10:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\YKIQKCDPBH
2008-07-20 09:17 . 2008-07-20 09:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SLIQKCDPBH
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-19 23:16 --------- d-----w C:\Program Files\Hidden Expedition Titanic
2008-08-19 21:01 34,304 ----a-w C:\WINDOWS\system32\drivers\CO_Mon.sys
2008-08-19 19:20 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-17 23:20 --------- d-----w C:\Program Files\Mystery Case Files - Prime Suspects
2008-08-17 19:24 --------- d-----w C:\Program Files\Mystery Case Files - Huntsville
2008-08-15 17:02 --------- d-----w C:\Program Files\Oberon Media
2008-08-12 09:52 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Juniper Networks
2008-08-09 16:28 --------- d-----w C:\Program Files\Enigma Software Group
2008-08-09 15:38 --------- d-----w C:\Program Files\a-squared Free
2008-08-08 18:34 --------- d--ha-w C:\Documents and Settings\All Users\Application Data\GTek
2008-08-01 01:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg8
2008-07-26 15:46 --------- d-----w C:\Program Files\RegScrubVistaXP
2008-07-26 11:43 --------- d-----w C:\Program Files\Java
2008-07-25 17:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-25 15:37 --------- d-----w C:\Program Files\AIM
2008-07-22 23:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\SpinTop Games
2008-07-18 00:43 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Flood Light Games
2008-07-18 00:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Flood Light Games
2008-07-16 22:21 25 ----a-w C:\Board.Dat
2008-07-16 22:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\GDYJUHYOBH
2008-07-11 13:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\WKLOCDDPBH
2008-07-09 16:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\URLOCDDPBH
2008-07-09 01:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\SKUMRUROBH
2008-07-07 21:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\CELTXDWOBH
2008-07-06 16:54 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\GetRightToGo
2008-07-06 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-07-06 14:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\BEAYCWUOBH
2008-07-05 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\EBAYCWUOBH
2008-07-05 14:36 102,664 ----a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-05 13:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\UFKQEEWOBH
2008-07-04 23:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZYJQEEWOBH
2008-07-04 13:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\KTKYDYQOBH
2008-07-01 17:32 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\WholeSecurity
2008-06-28 19:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\ELJQEMAPBH
2008-06-28 17:34 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Costco Photo Organizer
2008-06-26 21:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\LSTFVAAPBH
2008-06-25 17:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\OPTFVAAPBH
2008-06-25 00:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\RBUFVAAPBH
2008-06-20 22:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\WGNERNTOBH
2008-06-20 16:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\BMNERNTOBH
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-05-13 23:06 0 ----a-w C:\Program Files\temp01
2006-07-14 18:57 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-04 10:11 1506544]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-03 11:22 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-03 11:26 118784]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 19:35 49152]
"DMAScheduler"="c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe" [2005-11-01 06:01 90112]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 19:14 237568]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 13:29 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440]
"ISUSPM Startup"="c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-07-27 20:50 221184]
"ISUSScheduler"="c:\progra~1\common~1\instal~1\update~1\issch.exe" [2004-07-27 20:50 81920]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 19:52 849280]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 15:13 988584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 13:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-06-01 19:47 413696]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 20:19 77312 C:\WINDOWS\arpwrmsg.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-09-21 06:24 86016 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
"DisableCAD"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-22 20:59 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2006-11-30 22:49 4662776 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"\\\\ROBYN\\C\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
R3 actccid;ActivCard USB Reader V2;C:\WINDOWS\system32\DRIVERS\actccid.sys [2002-08-02 14:41]
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2008-02-08 19:11]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f39b135-5b0a-11dd-8e3a-00173124921d}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{963dccf6-fa8a-11db-8d38-00173124921d}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-08-20 C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job
- C:\Program Files\ErrorSmart\ErrorSmart.exe []
2008-08-20 C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job
- C:\Program Files\ErrorSmart []
2008-08-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-08-18 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-08-20 C:\WINDOWS\Tasks\SpyHunter Scanner.job
- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe []
.
- - - - ORPHANS REMOVED - - - -
Notify-avldr - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O16 -: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
C:\WINDOWS\Downloaded Program Files\PogoWebLauncher.ocx
O16 -: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://131.158.223.3/dana-cached/setup/JuniperSetupSP1.cab
C:\WINDOWS\Downloaded Program Files\JuniperSetup.INF
C:\WINDOWS\Downloaded Program Files\string_zh_cn.properties
C:\WINDOWS\Downloaded Program Files\string_zh.properties
C:\WINDOWS\Downloaded Program Files\string_ko.properties
C:\WINDOWS\Downloaded Program Files\string_ja.properties
C:\WINDOWS\Downloaded Program Files\string_fr.properties
C:\WINDOWS\Downloaded Program Files\string_es.properties
C:\WINDOWS\Downloaded Program Files\string_de.properties
C:\WINDOWS\Downloaded Program Files\string_en.properties
C:\WINDOWS\Downloaded Program Files\JuniperSetup.ocx
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-20 16:40:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2008-08-20 16:49:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-20 20:48:48
Pre-Run: 205,202,501,632 bytes free
Post-Run: 205,299,613,696 bytes free
302 --- E O F --- 2008-08-19 18:52:47