Thank you so much! Here's what came out:
ComboFix 09-06-20.04 - Justin 06/21/2009 10:58.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.306 [GMT -4:00]
Running from: c:\documents and settings\Justin\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\podmena
c:\windows\SYSTEM32\796525
c:\documents and settings\Justin\Application Data\wiaserva.log
c:\documents and settings\Justin\Application Data\wiaservg.log
c:\documents and settings\Justin\Start Menu\Programs\Startup\fmnupd32.exe
c:\documents and settings\Justin\Start Menu\Programs\Startup\zqosys32.exe
C:\giyghshu.exe
c:\program files\podmena\podmena.dll
c:\program files\podmena\podmena.sys
c:\windows\$NtServicePackUninstall$\dmc.bak2
c:\windows\9129837.exe
c:\windows\ADDINS\cpcm.bak2
c:\windows\AppPatch\dmc.bak2
c:\windows\Config\rvsbk.bak2
c:\windows\Cursors\wsnd.bak2
c:\windows\Fonts\cpkab.bak2
c:\windows\Fonts\pateni.bak1
c:\windows\Fonts\pateni.ini
c:\windows\Fonts\yeksii.bak2
c:\windows\Help\SBSI\capxe.bak2
c:\windows\INF\codofni.bak2
c:\windows\ld08.exe
c:\windows\ld09.exe
c:\windows\MSAGENT\evawyek.bak1
c:\windows\MSAGENT\evawyek.bak2
c:\windows\MSAGENT\evawyek.ini
c:\windows\MSAGENT\INTL\cbac.bak1
c:\windows\MSAGENT\INTL\cbac.bak2
c:\windows\MSAGENT\INTL\cbac.ini
c:\windows\MSAGENT\INTL\evawcm.bak1
c:\windows\MSAGENT\INTL\evawcm.bak2
c:\windows\MSAGENT\INTL\evawcm.ini
c:\windows\MSAGENT\niamcvsm.bak2
c:\windows\MSAGENT\yektac.bak2
c:\windows\pacvs.bak2
c:\windows\ptfbd.bak2
c:\windows\Registration\vrscfm.bak2
c:\windows\REPAIR\pctbil.bak1
c:\windows\REPAIR\pctbil.ini
c:\windows\SECURITY\dmcrc.bak1
c:\windows\SECURITY\dmcrc.ini
c:\windows\SECURITY\LOGS\spvrs.bak1
c:\windows\SECURITY\LOGS\spvrs.bak2
c:\windows\SECURITY\LOGS\spvrs.ini
c:\windows\SYSTEM\elosp.bak1
c:\windows\SYSTEM\elosp.ini
c:\windows\SYSTEM\lldsa.bak2
c:\windows\SYSTEM\lmxpa.bak2
c:\windows\SYSTEM32\796525\796525.dll
c:\windows\SYSTEM32\DLLCACHE\papct.bak1
c:\windows\SYSTEM32\DLLCACHE\papct.bak2
c:\windows\SYSTEM32\DLLCACHE\papct.ini
c:\windows\system32\gsf83iujid.dll
c:\windows\system32\SYSDLL.exe
c:\windows\system32\wbem\proquota.exe
c:\windows\SYSTEM32\XIRCOM\ssvipat.bak1
c:\windows\SYSTEM32\XIRCOM\ssvipat.bak2
c:\windows\SYSTEM32\XIRCOM\ssvipat.ini
c:\windows\Tasks\sw.bak2
c:\windows\yalpbac.bak2
c:\windows\yekten.bak2
c:\windows\zaponce52689.dat
c:\windows\zaponce53173.dat
c:\windows\zaponce53290.dat
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_podmena
-------\Legacy_podmenadrv
-------\Service_podmena
-------\Service_podmenadrv
((((((((((((((((((((((((( Files Created from 2009-05-21 to 2009-06-21 )))))))))))))))))))))))))))))))
.
2009-06-21 15:00 . 2004-08-04 07:56 50176 ----a-w- c:\windows\system32\proquota.exe
2009-06-21 15:00 . 2004-08-04 07:56 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-06-20 04:08 . 2009-06-20 04:05 19968 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\icwsetup.exe
2009-06-14 21:46 . 2008-01-07 21:36 2216064 ----a-w- c:\windows\system32\drivers\w29n51.sys
2009-06-14 21:46 . 2007-02-12 19:41 2732032 ----a-w- c:\windows\system32\Netw2r32.dll
2009-06-14 21:46 . 2007-02-12 19:40 557056 ----a-w- c:\windows\system32\Netw2c32.dll
2009-06-14 21:42 . 2009-06-14 21:42 -------- d-sh--w- C:\FOUND.003
2009-06-14 17:59 . 2009-06-14 17:59 -------- d-sh--w- C:\FOUND.002
2009-06-14 17:54 . 2009-06-14 17:54 -------- d-sh--w- C:\FOUND.001
2009-06-14 17:48 . 2009-06-14 17:48 -------- d-sh--w- C:\FOUND.000
2009-06-14 17:40 . 2009-06-14 21:11 100684 ----a-w- c:\windows\system32\drivers\2d79df44.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 04:36 . 2009-05-05 04:36 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-05 04:36 . 2009-05-05 04:36 -------- d-----w- c:\program files\Java
2009-05-05 04:35 . 2009-05-05 04:35 152576 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2008-12-21 20:47 . 2005-04-16 21:56 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-21 20:47 . 2005-04-16 21:56 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-21 20:47 . 2005-04-16 21:56 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-12-21 20:47 . 2007-09-02 01:25 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-21 20:47 . 2007-09-02 01:25 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2005-04-13 12:13 . 2005-04-13 12:13 383508 --sh--w- c:\windows\SYSTEM32\DLLCACHE\tcpap.exe
2005-01-24 12:07 . 2005-01-24 12:07 381952 --sh--w- c:\windows\REPAIR\libtcp.exe
2005-06-05 22:41 . 2005-06-05 22:41 91 --sh--w- c:\windows\REPAIR\lib.exe
2005-01-24 12:08 . 2005-01-24 12:08 734849 --sh--w- c:\windows\MSAGENT\smwdrah.tmp
2005-02-05 05:42 . 2005-02-05 05:42 385044 --sh--w- c:\windows\MSAGENT\keywave.exe
2005-01-18 13:48 . 2005-01-18 13:48 388116 --sh--w- c:\windows\MSAGENT\INTL\mcwave.exe
2005-06-04 14:30 . 2005-06-04 14:30 91 --sh--w- c:\windows\SECURITY\crcmd.exe
2005-01-12 13:53 . 2005-01-12 13:52 388116 --sh--w- c:\windows\SECURITY\LOGS\srvps.exe
2005-06-03 23:28 . 2005-06-03 23:27 91 --sh--w- c:\windows\Help\raslib.exe
2005-03-21 12:56 . 2005-03-21 12:56 385044 --sh--w- c:\windows\Fonts\inetap.exe
2005-02-03 13:49 . 2005-02-02 00:26 707313 --sh--w- c:\windows\Driver Cache\dvdrba.bak2
2005-01-10 00:58 . 2005-01-10 00:58 721381 --sh--w- c:\windows\Driver Cache\drahsm.bak2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-02-02 155648]
"PRONoMgr.exe"="c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-19 86016]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-07-17 28672]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-06-02 267048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-05 148888]
"Internet Connection Wizard Setup Tool"="c:\program files\Internet Explorer\Connection Wizard\icwsetup.exe" [2009-06-20 19968]
c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\
icwsetup.exe [2009-6-20 19968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-13 19:17 110592 ----a-w- c:\windows\SYSTEM32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:podmena
S1 2d79df44;2d79df44;c:\windows\SYSTEM32\DRIVERS\2d79df44.sys [6/14/2009 1:40 PM 100684]
S2 CiscoVpnInstallService;Cisco Systems, Inc. Installer service;c:\docume~1\KAT\DESKTOP\VPNCLI~1\VPNCLI~1\INSTAL~1.EXE --> c:\docume~1\KAT\DESKTOP\VPNCLI~1\VPNCLI~1\INSTAL~1.EXE [?]
S3 {E2B953A7-195A-44F9-9BA3-3D5F4E32BB55};AIM 3.0 Part 01 Codec Driver CH-7009-B;c:\windows\SYSTEM32\DRIVERS\wA301b.sys [1/1/1980 33847]
.
Contents of the 'Scheduled Tasks' folder
2008-07-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 18:57]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-LWBMOUSE - c:\program files\Tech\Wheel Mouse\5.0\MOUSE32A.EXE
HKLM-Run-*netkey - c:\windows\netkey.exe
HKLM-Run-*kbsvr - c:\windows\Config\kbsvr.exe
HKLM-Run-CTUPGD - c:\progra~1\toolbar\ct5upd1.exe
HKLM-Run-TBPS - c:\progra~1\Toolbar\TBPS.exe
HKLM-Run-Microsoft System DLL Services Configuration - windir32.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell.com
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-21 11:02
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
*netkey = c:\windows\netkey.exe??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
*kbsvr = c:\windows\Config\kbsvr.exe????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Microsoft System DLL Services Configuration = windir32.exe?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(564)
c:\windows\System32\LgNotify.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\S24EVMON.EXE
c:\windows\SYSTEM32\ZCFGSVC.EXE
c:\windows\SYSTEM32\IGFXSRVC.EXE
c:\program files\APOINT\APNTEX.EXE
c:\program files\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
c:\program files\BONJOUR\MDNSRESPONDER.EXE
c:\windows\SYSTEM32\REGSRVC.EXE
c:\windows\SYSTEM32\TCPSVCS.EXE
c:\windows\SYSTEM32\WDFMGR.EXE
c:\program files\IPOD\BIN\IPODSERVICE.EXE
c:\windows\SYSTEM32\1XCONFIG.EXE
.
**************************************************************************
.
Completion time: 2009-06-21 11:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-21 15:04
Pre-Run: 19,573,964,800 bytes free
Post-Run: 19,582,124,032 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
216 --- E O F --- 2008-06-10 22:30