Hope this is the right log. thanks for the help!
ComboFix 09-05-04.09 - hmong 05/05/2009 20:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.511.246 [GMT 8:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\WeatherDPA
c:\documents and settings\Administrator\Application Data\WeatherDPA\Weather\WeatherStartup.xml
c:\documents and settings\All Users\Start Menu\Internet Explorer.lnk
c:\documents and settings\All Users\Start Menu\Programs\Internet Explorer.lnk
c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
c:\windows\patch.exe
c:\windows\system32\
0021-bdl94126.EXE
c:\windows\system32\bs5-nt15v.exe
c:\windows\system32\config\systemprofile\Application Data\Zango
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\avatar.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\btntrans.idx
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\btntrans1.dat
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\buttondir.txt
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\components.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\cursors.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_1000.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_2000.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_3000.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_bar.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_bbar1.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_logos.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_other.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\d_icons_weather.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\default.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_511745-514279.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-ca.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-us.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_categorize.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_comparison.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_explorer-Mails.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_explorer-people.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_favorites.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_Games.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_Hide.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_hotbarcom.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_Hotmail.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_hsskin.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_jemster.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_jemsterie.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_jemsteruk.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_jobsearch.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_Mails.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_MobileSidewalk.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_new.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_premium.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_reun.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_ringtones.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_SearchBoxTrapper.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_searchfor.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_searchgo.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_weather.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Default_yellowpages.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\editblbuttons.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\email-def-511724-548964.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\email-def-511724-9595.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\email-t1-bg.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\hotbar-premium-hotbar-premium.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\hotbar-premium.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\icons2.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\ie_games_icon.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\ie_video.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\keywords.idx
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\keywords1.dat
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\layout.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\linkpathlegal.txt
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\progress.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\s_icons_buttons.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\sales_buttons.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\sdfmodifier.xml
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\t2_bg.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\theweb.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\top7.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\Top7_theweb.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\tsd_bg.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\zango_btn.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\1\zango_ie_menu.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\avatar.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\btntrans.idx
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\btntrans1.dat
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\buttondir.txt
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\components.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\cursors.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_1000.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_2000.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_3000.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_bar.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_bbar1.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_logos.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\d_icons_buttons_other.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\d_icons_weather.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\default.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_511745-514279.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_bidzC_ZT_IE-ca.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_bidzC_ZT_IE-us.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_categorize.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_comparison.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_explorer-Mails.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_explorer-people.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_favorites.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_Games.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_Hide.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_hotbarcom.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_Hotmail.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_hsskin.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_jemster.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_jemsterie.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_jemsteruk.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_jobsearch.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_Mails.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_MobileSidewalk.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_new.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_premium.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_reun.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_ringtones.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_SearchBoxTrapper.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_searchfor.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_searchgo.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_weather.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Default_yellowpages.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\editblbuttons.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\email-def-511724-548964.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\email-def-511724-9595.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\email-t1-bg.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\hotbar-premium-hotbar-premium.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\hotbar-premium.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\icons2.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\ie_games_icon.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\ie_video.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\keywords.idx
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\keywords1.dat
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\layout.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\linkpathlegal.txt
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\progress.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\s_icons_buttons.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\sales_buttons.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\sdfmodifier.xml
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\t2_bg.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\theweb.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\top7.cdf
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\Top7_theweb.mnu
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\tsd_bg.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\zango_btn.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\2\zango_ie_menu.res
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\avatar.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans1.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\cursors.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_1000.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_2000.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_3000.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bar.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bbar1.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_logos.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_other.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_weather.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\default.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\editblbuttons.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\email-t1-bg.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\hotbar-premium.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\icons2.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_games_icon.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_video.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords1.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\layout.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\linkpathlegal.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\progress.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\s_icons_buttons.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\sales_buttons.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\samplegroups2.txt
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\sdfmodifier.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\t2_bg.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\top7.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\tsd_bg.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_btn.xip
c:\windows\system32\config\systemprofile\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_ie_menu.xip
c:\windows\system32\CS4P028.exe
c:\windows\system32\setup.ini
c:\windows\system32\silent.exe
.
((((((((((((((((((((((((( Files Created from 2009-04-05 to 2009-05-05 )))))))))))))))))))))))))))))))
.
2009-05-03 14:34 . 2009-05-03 14:34 61440 ----a-w c:\windows\system32\drivers\pikejpj.sys
2009-05-03 14:18 . 2009-05-03 14:18 61440 ----a-w c:\windows\system32\drivers\dvovm.sys
2009-05-02 17:52 . 2009-05-02 17:52 61440 ----a-w c:\windows\system32\drivers\kqjexg.sys
2009-04-25 20:36 . 2009-04-25 20:36 -------- d-----w C:\_OTListIt
2009-04-25 08:11 . 2009-04-25 08:11 -------- d-----w C:\_OTMoveIt
2009-04-24 14:37 . 2009-04-24 14:40 -------- d-----w C:\Rooter$
2009-04-23 13:52 . 2009-04-23 13:52 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-04-22 13:51 . 2009-04-22 13:51 -------- d-----w c:\program files\Trend Micro
2009-04-21 13:54 . 2009-04-21 13:52 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-18 02:30 . 2009-04-18 02:30 -------- d-----w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-04-18 02:30 . 2009-04-06 07:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-18 02:30 . 2009-04-06 07:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-18 02:30 . 2009-04-18 02:30 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-18 02:30 . 2009-04-18 02:30 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 12:02 . 2002-09-23 18:51 -------- d-----w c:\program files\C4ebreg
2009-04-25 08:16 . 2005-09-15 14:31 54496 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-21 13:52 . 2006-01-01 17:55 -------- d-----w c:\program files\Java
2009-04-05 07:19 . 2006-03-06 14:46 -------- d-----w c:\program files\Google
2009-04-05 07:13 . 2009-04-05 07:13 -------- d-----r c:\program files\Skype
2009-04-05 07:13 . 2009-04-05 07:13 -------- d-----w c:\program files\Common Files\Skype
2009-03-09 09:48 . 2002-09-24 16:50 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-08 06:43 . 2007-11-26 03:56 -------- d-----w c:\program files\Norton Security Scan
2009-01-11 04:54 . 2009-01-11 04:54 49152 --sha-w c:\windows\system32\dutajija.dll.tmp
2009-01-11 04:54 . 2009-01-11 04:54 49152 --sha-w c:\windows\system32\vojebeje.dll.tmp
2009-01-11 04:54 . 2009-01-11 04:54 49152 --sha-w c:\windows\system32\zusojulo.dll.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-01 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2003-03-31 86016]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-03-31 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-03-31 454656]
"C4EBReg"="c:\program files\c4ebreg\c4ebreg.exe" [2005-01-22 294912]
"ISSI EZUpdate Service"="c:\sdwork\issimsvc.exe" [2004-12-14 197632]
"ISAM SMT Service"="c:\program files\c4ebreg\isamsmt.exe" [2002-11-15 102400]
"ACUMon"="c:\program files\Cisco Systems\Aironet Client Monitor\ACUMon.Exe" [2004-02-23 217088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-21 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-10-30 256576]
"EPSON Stylus CX4100 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEP.EXE" [2005-03-08 98304]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-03-31 87037]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2003-03-31 28672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-20 171448]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"pcsmig"="c:\program files\IBM\Personal Communications\pcsmig.exe" [2001-08-21 126976]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Lotus QuickStart.lnk - c:\lotus\wordpro\ltsstart.exe [2002-6-26 32768]
Photo Loader supervisory.lnk - c:\program files\CASIO\Photo Loader\Plauto.exe [2006-4-23 229376]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"IBMconfig"=dword:00000001
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [3/31/2003 9:21 PM 12288]
R2 AppnApi;AppnApi;c:\windows\system32\drivers\appnapi.sys [8/21/2001 2:50 PM 117216]
R2 bwcdrv;BUFFALO Wireless Configuration;c:\windows\system32\drivers\BWCDRV.SYS [4/16/2004 4:09 PM 7680]
R2 NsTrcNT;NsTrcNT;c:\windows\system32\drivers\nstrcnt.sys [8/21/2001 2:50 PM 10808]
R2 pdlnctdl;Twinax CUT Adapter;c:\windows\system32\drivers\pdlnctdl.sys [8/21/2001 2:50 PM 10752]
R2 pdlndldl;IBM Enterprise Extender (HPR/IP);c:\windows\system32\drivers\pdlndldl.sys [8/21/2001 2:50 PM 57344]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/25/2008 3:50 PM 24652]
R3 Anydlc;Anydlc;c:\windows\system32\drivers\anydlc.sys [8/21/2001 2:50 PM 36856]
R3 Appn;Appn;c:\windows\system32\drivers\appn.sys [8/21/2001 2:50 PM 1263968]
R3 AppnBase;AppnBase;c:\windows\system32\drivers\appnbase.sys [8/21/2001 2:50 PM 182304]
R3 KLOGNT;KLOGNT;c:\windows\system32\drivers\klognt.sys [8/21/2001 2:50 PM 23272]
R3 PCX504;Cisco Systems Wireless LAN Adapter Driver;c:\windows\system32\drivers\PCX504.sys [1/16/2006 4:38 PM 119296]
R3 pdlnacom;PDLC Adapter -- COM;c:\windows\system32\drivers\pdlnacom.sys [8/21/2001 2:50 PM 73760]
R3 pdlnafac;PDLC Adapter Factory;c:\windows\system32\drivers\pdlnafac.sys [8/21/2001 2:50 PM 34800]
R3 pdlnatcm;Twinax Adapter Common;c:\windows\system32\drivers\pdlnatcm.sys [8/21/2001 2:50 PM 18944]
R3 pdlnatdl;Twinax Adapter;c:\windows\system32\drivers\pdlnatdl.sys [8/21/2001 2:50 PM 16896]
R3 pdlncbas;PDLC CxM Classes;c:\windows\system32\drivers\pdlncbas.sys [8/21/2001 2:50 PM 5552]
R3 pdlncfwk;PDLC Connection Manager;c:\windows\system32\drivers\pdlncfwk.sys [8/21/2001 2:50 PM 159008]
R3 pdlndint;PDLC DLC Classes;c:\windows\system32\drivers\pdlndint.sys [8/21/2001 2:50 PM 11264]
R3 pdlndlpb;PDLC LAPB;c:\windows\system32\drivers\pdlndlpb.sys [8/21/2001 2:50 PM 68608]
R3 pdlndoem;PDLC OEM Interface;c:\windows\system32\drivers\pdlndoem.sys [8/21/2001 2:50 PM 17408]
R3 pdlndqll;PDLC QLLC;c:\windows\system32\drivers\pdlndqll.sys [8/21/2001 2:50 PM 51712]
R3 pdlndsdl;PDLC SDLC;c:\windows\system32\drivers\pdlndsdl.sys [8/21/2001 2:50 PM 65536]
R3 pdlndtdl;Twinax DLC;c:\windows\system32\drivers\pdlndtdl.sys [8/21/2001 2:50 PM 50176]
R3 pdlnebas;PDLC Environment;c:\windows\system32\drivers\pdlnebas.sys [8/21/2001 2:50 PM 7344]
R3 pdlnecfg;PDLC Configuration;c:\windows\system32\drivers\pdlnecfg.sys [8/21/2001 2:50 PM 49088]
R3 pdlnemap;PDLC Mapper;c:\windows\system32\drivers\pdlnemap.sys [8/21/2001 2:50 PM 65872]
R3 pdlnemsg;PDLC Message Driver;c:\windows\system32\drivers\pdlnemsg.sys [8/21/2001 2:50 PM 11504]
R3 pdlnepkt;PDLC Buffer Manager;c:\windows\system32\drivers\pdlnepkt.sys [8/21/2001 2:50 PM 18720]
R3 pdlnshay;PDLC Hayes At signalling;c:\windows\system32\drivers\pdlnshay.sys [8/21/2001 2:50 PM 58256]
R3 pdlnslea;PDLC SDLC Leased;c:\windows\system32\drivers\pdlnslea.sys [8/21/2001 2:50 PM 21136]
R3 pdlnsv25;PDLC V25bis signalling;c:\windows\system32\drivers\pdlnsv25.sys [8/21/2001 2:50 PM 53168]
R3 pdlnsx25;PDLC X.25;c:\windows\system32\drivers\pdlnsx25.sys [8/21/2001 2:50 PM 57184]
S2 gupdate1c9b5be3f1d6640;Google Update Service (gupdate1c9b5be3f1d6640);c:\program files\Google\Update\GoogleUpdate.exe [4/5/2009 3:14 PM 133104]
S3 avpnnic;AGN Virtual Network Adapter;c:\windows\system32\drivers\avpnnic.sys [1/22/2005 2:18 PM 13952]
S3 CBBCM43;BUFFALO WLI-CB-XXX Series Wireless LAN Adapter;c:\windows\system32\drivers\BCMWL5.SYS [4/16/2004 4:09 PM 173056]
S3 ESSIDSET;ESSIDSET;c:\windows\system32\ESSIDSET.SYS [9/24/2003 4:26 PM 9248]
S3 gwiopm;gwiopm;c:\program files\WST\gwiopm.sys [6/4/1998 12:59 AM 3904]
S3 IBMTRP;IBM Token-Ring PCI Adapter (Generic);c:\windows\system32\drivers\IBMTRP.SYS [9/21/2002 1:39 AM 109085]
S3 S3Inc;S3Inc;c:\windows\system32\drivers\s3mt3d.sys [9/12/2002 7:46 AM 41216]
.
Contents of the 'Scheduled Tasks' folder
2008-04-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 09:13]
2009-05-04 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2003-03-31 13:04]
2009-05-04 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-05 07:14]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sg/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.msn.com
mSearch Bar =
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = proxy.hakozaki.ibm.com:8080
uInternet Settings,ProxyOverride = w3.ibm.com;<local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {9DF0BAF2-D7F8-468E-BAD0-8482C68E2C19} = 165.21.100.88,165.21.83.88
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\b88361cj.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-05 20:15
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(484)
c:\windows\System32\ODBC32.dll
c:\windows\System32\msctfime.ime
c:\windows\System32\cswGina.dll
c:\windows\System32\ACrd10SM.dll
c:\windows\System32\NavLogon.dll
- - - - - - - > 'lsass.exe'(540)
c:\windows\System32\dssenh.dll
.
Completion time: 2009-05-05 20:19
ComboFix-quarantined-files.txt 2009-05-05 12:18
Pre-Run: 1,110,007,808 bytes free
Post-Run: 1,208,340,480 bytes free
346