fyi…I got that RUNDLL error again while combofix ran, i clicked OK .
Here is the Combofix log:
ComboFix 09-03-14.02 - HP_Administrator 2009-03-15 15:53:44.1 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Administrator\Application Data\WeatherDPA
c:\documents and settings\HP_Administrator\Application Data\WeatherDPA\Weather\WeatherStartup.xml
c:\windows\IE4 Error Log.txt
c:\windows\system32\init32.exe
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_netlogonehsched
——-\Service_netlogonehsched
——-\Service_System
((((((((((((((((((((((((( Files Created from 2009-02-15 to 2009-03-15 )))))))))))))))))))))))))))))))
.
2009-03-15 13:52 . 2009-03-15 13:52 d——– C:\_OTListIt
2009-03-15 11:40 . 2009-03-15 11:40 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-15 11:40 . 2009-03-15 11:40 d——– c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-03-15 11:40 . 2009-03-15 11:40 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-15 11:40 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-15 11:40 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-14 17:56 . 2009-03-14 17:56 d——– c:\program files\ERUNT
2009-03-10 18:18 . 2009-03-15 15:58 10,805 –a—— c:\windows\system32\Config.MPF
2009-03-10 18:17 . 2006-03-03 08:07 143,360 –a—— c:\windows\system32\dunzip32.dll
2009-03-10 18:13 . 2007-11-22 06:44 201,320 –a—— c:\windows\system32\drivers\mfehidk.sys
2009-03-10 18:13 . 2007-07-13 06:20 113,952 –a—— c:\windows\system32\drivers\Mpfp.sys
2009-03-10 18:13 . 2007-11-22 06:44 79,304 –a—— c:\windows\system32\drivers\mfeavfk.sys
2009-03-10 18:13 . 2007-12-02 12:51 40,488 –a—— c:\windows\system32\drivers\mfesmfk.sys
2009-03-10 18:13 . 2007-11-22 06:44 35,240 –a—— c:\windows\system32\drivers\mfebopk.sys
2009-03-10 18:13 . 2007-11-22 06:44 33,832 –a—— c:\windows\system32\drivers\mferkdk.sys
2009-03-10 18:12 . 2009-03-10 18:12 d——– c:\program files\McAfee.com
2009-03-10 18:12 . 2009-03-10 18:13 d——– c:\program files\Common Files\McAfee
2009-03-10 18:11 . 2009-03-11 07:26 d——– c:\program files\McAfee
2009-03-10 17:28 . 2009-03-10 18:18 d——– c:\documents and settings\All Users\Application Data\McAfee
2009-03-09 22:49 . 2009-03-09 22:49 d——– c:\documents and settings\All Users\Application Data\Ascentive
2009-03-09 22:38 . 2009-03-10 17:57 d——– c:\program files\Ascentive
2009-03-09 22:38 . 2008-08-20 17:44 45,056 –a—— c:\windows\system32\CreateLog.dll
2009-03-09 22:38 . 2007-07-03 11:48 20,480 –a—— c:\windows\system32\SysRestore.dll
2009-03-09 21:53 . 2009-03-15 16:01 81,390 –a—— c:\windows\system32\drivers\eccfd102.sys
2009-03-09 18:18 . 2009-03-10 17:59 d——– c:\documents and settings\HP_Administrator\Application Data\Lavasoft
2009-03-07 20:06 . 2009-03-07 20:06 d——– c:\documents and settings\All Users\Application Data\NeptunesAdve
2009-03-07 20:05 . 2009-03-07 21:10 d——– c:\program files\IncrediGames
2009-03-07 20:05 . 2009-03-07 20:05 d——– c:\program files\Common Files\Oberon Media
2009-03-05 01:15 . 2009-03-05 01:15 d——– c:\documents and settings\HP_Administrator\Application Data\Gold Casual Games
2009-03-05 01:15 . 2009-03-05 01:15 d——– c:\documents and settings\All Users\Application Data\Gold Casual Games
2009-03-04 00:11 . 2009-03-04 00:11 d——– c:\documents and settings\All Users\Application Data\FireGlow
2009-03-02 18:42 . 2009-03-02 18:47 d——– c:\documents and settings\HP_Administrator\Application Data\Ancient Quest of Saqqarah__bfg
2009-03-01 19:35 . 2009-03-01 19:36 d——– c:\program files\Solitaire Cruise
2009-02-28 21:41 . 2009-02-28 21:41 d——– c:\documents and settings\HP_Administrator\Application Data\Dreamsdwell Stories
2009-02-24 20:26 . 2009-02-24 20:26 d——– c:\documents and settings\HP_Administrator\Application Data\Artogon
2009-02-22 16:55 . 2009-02-22 16:55 d——– c:\documents and settings\All Users\Application Data\Big Fish Games Vancouver
2009-02-19 11:37 . 2009-02-19 11:37 d——– c:\documents and settings\HP_Administrator\Application Data\ViquaSoft
2009-02-19 10:32 . 2009-02-19 10:32 d——– c:\documents and settings\All Users\Application Data\PrettyGoodGames
2009-02-18 19:30 . 2009-02-18 19:30 d——– c:\documents and settings\All Users\Application Data\HoverBee Studios
2009-02-17 21:42 . 2009-02-17 21:43 d——– c:\program files\Dream Vacation Solitaire
2009-02-17 09:21 . 2009-02-17 09:21 d——– c:\documents and settings\All Users\Application Data\HipSoft
2009-02-17 08:41 . 2009-02-17 08:41 1,409 –a—— c:\windows\system32\tmpC1FDE.FOT
2009-02-17 08:41 . 2009-02-17 08:41 1,409 –a—— c:\windows\system32\tmp8BFDE.FOT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 15:20 ——— d—–w c:\program files\Yahoo!
2009-03-15 15:19 ——— d—–w c:\program files\Ahead
2009-03-15 15:16 ——— d—–w c:\program files\Common Files\AOL
2009-03-15 15:16 ——— d—–w c:\documents and settings\All Users\Application Data\AOL
2009-03-15 00:19 ——— d—–w c:\program files\Trend Micro
2009-03-14 03:58 ——— d—–w c:\program files\Musicmatch
2009-03-14 03:56 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-14 03:53 ——— d—–w c:\program files\Common Files\Adobe
2009-03-13 04:25 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-11 13:23 ——— d—–w c:\program files\Lexmark 3100 Series
2009-03-11 01:12 ——— d—–w c:\program files\BitTorrent
2009-03-10 21:34 33,280 —-a-w c:\program files\bpxogo1.tmp
2009-03-08 02:07 ——— d—–w c:\program files\Oberon Media
2009-03-06 01:38 ——— d—–w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-02-22 02:59 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\Friday's games
2009-02-15 00:00 ——— d—–w c:\program files\Fairway Solitaire
2009-02-14 03:25 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\BVS Solitaire Collection
2009-02-12 07:15 ——— d—–w c:\program files\Waterscape Solitaire - American Falls
2009-02-11 03:21 ——— d—–w c:\program files\Yahoo! Games
2009-02-07 23:58 ——— d—–w c:\documents and settings\All Users\Application Data\GameXzone
2009-02-04 15:11 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\Jetsetter
2009-02-04 05:18 ——— d—–w c:\program files\Brickshooter Egypt
2009-02-02 23:26 ——— d—–w c:\program files\Common Files\SWF Studio
2009-01-30 03:46 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\RobinsonCrusoe
2009-01-30 01:00 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\URSE Games
2009-01-28 05:26 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\Island
2009-01-28 05:04 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\Sahmon Games
2009-01-27 22:38 ——— d—–w c:\documents and settings\All Users\Application Data\Playrix Entertainment
2009-01-27 16:47 ——— d—–w c:\documents and settings\All Users\Application Data\MumboJumbo
2009-01-26 22:40 ——— d—–w c:\documents and settings\All Users\Application Data\EA
2009-01-24 23:52 ——— d—–w c:\documents and settings\All Users\Application Data\Rumbic Studio
2009-01-21 01:40 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\Meridian93
2009-01-17 03:40 ——— d—–w c:\documents and settings\HP_Administrator\Application Data\JewelMatch2
2009-01-17 00:49 ——— d—–w c:\documents and settings\All Users\Application Data\Gogii
2008-07-21 20:55 110,232 —-a-w c:\documents and settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2006-02-09 01:36 178 —-a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
2005-11-03 00:38 22 –sha-w c:\windows\SMINST\HPCD.sys
.
——- Sigcheck ——-
2009-03-14 19:20 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\svchost.exe
2009-03-10 17:58 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\dllcache\svchost.exe
2005-03-02 13:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2004-08-10 14:00 577024 c72661f8552ace7c5c85e16a3cf505c4 c:\windows\$NtUninstallKB890859$\user32.dll
2005-03-02 13:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\system32\user32.dll
2005-03-02 13:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\system32\dllcache\user32.dll
2004-08-10 14:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll
2004-08-10 14:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\dllcache\ws2_32.dll
2005-05-02 22:57 658944 e1e18136f9dd3df1ad9c82193a5898a6 c:\windows\$hf_mig$\KB883939\SP2QFE\wininet.dll
2005-09-02 18:53 660480 97a6fd7cafd688cf2c78939ebaf0cd0c c:\windows\$hf_mig$\KB896688\SP2QFE\wininet.dll
2004-08-10 14:00 656384 c0823fc5469663ba63e7db88f9919d70 c:\windows\$NtUninstallKB883939$\wininet.dll
2005-05-02 22:52 657920 1a078af3f85d10ba56444c23b3a18e74 c:\windows\$NtUninstallKB896688$\wininet.dll
2005-09-02 18:52 658432 af61ebb1f550175eff406d545d6ab086 c:\windows\system32\wininet.dll
2005-09-02 18:52 658432 af61ebb1f550175eff406d545d6ab086 c:\windows\system32\dllcache\wininet.dll
2005-03-14 03:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2004-08-10 14:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB893066$\tcpip.sys
2005-03-14 02:55 359808 1898df9a9d550da97c2ed41ae3c76a25 c:\windows\system32\dllcache\tcpip.sys
2005-03-14 02:55 359808 1898df9a9d550da97c2ed41ae3c76a25 c:\windows\system32\drivers\tcpip.sys
2004-08-10 14:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\winlogon.exe
2004-08-10 14:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\dllcache\winlogon.exe
2004-08-10 14:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\dllcache\ndis.sys
2004-08-10 14:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2004-08-10 14:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\dllcache\ip6fw.sys
2004-08-10 14:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys
2005-03-01 19:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2004-08-04 07:59 2015232 fb142b7007ca2eea76966c6c5cc12150 c:\windows\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 19:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\Driver Cache\i386\ntkrnlpa.exe
2005-03-01 19:34 2015232 3cd941e472ddf3534e53038535719771 c:\windows\system32\ntkrnlpa.exe
2005-03-01 20:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2004-08-04 08:18 2148352 626309040459c3915997ef98ec1c8d40 c:\windows\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 19:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\Driver Cache\i386\ntoskrnl.exe
2005-03-01 19:57 2135552 48b3e89af7074cee0314a3e0c7faffdb c:\windows\system32\ntoskrnl.exe
2004-08-10 14:00 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
2004-08-10 14:00 1032192 a0732187050030ae399b241436565e64 c:\windows\system32\dllcache\explorer.exe
2004-08-10 14:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\services.exe
2004-08-10 14:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\dllcache\services.exe
2004-08-10 14:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\lsass.exe
2004-08-10 14:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\dllcache\lsass.exe
2004-08-10 14:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe
2004-08-10 14:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\dllcache\ctfmon.exe
2005-06-10 19:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2004-08-10 14:00 57856 7435b108b935e42ea92ca94f59c8e717 c:\windows\$NtUninstallKB896423$\spoolsv.exe
2005-06-10 18:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\system32\spoolsv.exe
2005-06-10 18:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\system32\dllcache\spoolsv.exe
2004-08-10 07:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe
2004-08-10 07:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\dllcache\userinit.exe
2004-08-10 14:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll
2005-03-10 02:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll
2005-03-10 02:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\dllcache\termsrv.dll
2004-08-10 14:00 983552 888190e31455fad793312f8d087146eb c:\windows\system32\kernel32.dll
2004-08-10 14:00 983552 888190e31455fad793312f8d087146eb c:\windows\system32\dllcache\kernel32.dll
2004-08-10 14:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
2004-08-10 14:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\dllcache\powrprof.dll
2004-08-10 14:00 110080 87ca7ce6469577f059297b9d6556d66d c:\windows\system32\imm32.dll
2004-08-10 14:00 110080 87ca7ce6469577f059297b9d6556d66d c:\windows\system32\dllcache\imm32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 344064]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 c:\windows\sm56hlpr.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Planner Reminders Tray Icon.lnk - c:\program files\Sierra\Planner\Plnrnote.exe [2006-12-24 184320]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\program files\ffdshow\ffdshow.ax
"vidc.xvid"= xvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
R1 b393a234;b393a234; [x]
R1 b9f2003d;b9f2003d; [x]
R1 d3ff6419;d3ff6419; [x]
R1 e1900400;e1900400; [x]
R3 Winkr53;Winkr53; [x]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
— Other Services/Drivers In Memory —
*NewlyCreated* - helpsvc
*Deregistered* - AFD
*Deregistered* - Apple Mobile Device
*Deregistered* - Arp1394
*Deregistered* - Ati HotKey Poller
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - Cdfs
*Deregistered* - DcomLaunch
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - iaStor
*Deregistered* - ImapiService
*Deregistered* - IntelIde
*Deregistered* - IpFilterDriver
*Deregistered* - IpNat
*Deregistered* - iPod Service
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - LexBceS
*Deregistered* - mcmscsvc
*Deregistered* - mcnasvc
*Deregistered* - mcproxy
*Deregistered* - mcshield
*Deregistered* - mcsysmon
*Deregistered* - MDM
*Deregistered* - mfeavfk
*Deregistered* - mfebopk
*Deregistered* - mfehidk
*Deregistered* - mfesmfk
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - mpfp
*Deregistered* - mpfservice
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Spooler
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - ViaIde
*Deregistered* - VolSnap
*Deregistered* - Wanarp
*Deregistered* - X4HSX32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
sromeg
priocukm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{369505d2-4bcb-11da-b4b8-806d6172696f}]
\shell\autorun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{faf34d90-4bd4-11da-b4bd-0013d4c27b29}]
\Shell\AutoRun\command - J:\LaunchU3.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-10 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2009-03-10 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Exobenoguq - c:\windows\ugetaxuh.dll
SafeBoot-Winkr53.sys
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://mystart.magentic.com/english/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\t2f2tpvr.Default User\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://mystart.magentic.com/?loc=FF_Magentic_AddressBar&search=
FF - plugin: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\t2f2tpvr.Default User\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\GameTap\bin\Release\npgametaptool.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-15 16:00:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\eccfd102]
"ImagePath"="\SystemRoot\System32\drivers\eccfd102.sys"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(620)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\LEXPPS.EXE
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2009-03-15 16:05:26 - machine was rebooted [HP_Administrator]
ComboFix-quarantined-files.txt 2009-03-15 21:05:10
Pre-Run: 86,028,865,536 bytes free
Post-Run: 85,927,911,424 bytes free
374