Here is the text for ComboFix…
ComboFix 09-12-11.05 - Ryan B 12/12/2009 14:17:28.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.637 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\AB.exe.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\RYANB~1\LOCALS~1\Temp\wscsvc32.exe
c:\documents and settings\All Users\Desktop\AntiMalware Support.lnk
c:\documents and settings\All Users\Desktop\AntiMalware.lnk
c:\documents and settings\All Users\Start Menu\Programs\AntiMalware
c:\documents and settings\All Users\Start Menu\Programs\AntiMalware\AntiMalware Support.lnk
c:\documents and settings\All Users\Start Menu\Programs\AntiMalware\AntiMalware.lnk
c:\documents and settings\All Users\Start Menu\Programs\AntiMalware\Uninstall AntiMalware.lnk
c:\windows\system32\drivers\H8SRTrhqaqpulba.sys
c:\windows\system32\H8SRTrumqsntsmr.dll
c:\windows\system32\H8SRTsmkxypupfw.dll
c:\windows\system32\H8SRTsqxgrdhpbw.dat
c:\windows\system32\srcr.dat
c:\windows\system32\st325602.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_H8SRTd.sys
——-\Legacy_H8SRTd.sys
((((((((((((((((((((((((( Files Created from 2009-11-12 to 2009-12-12 )))))))))))))))))))))))))))))))
.
2009-12-10 18:13 . 2009-10-30 16:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-10 18:13 . 2009-11-09 16:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-10 18:13 . 2009-10-06 21:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-10 18:12 . 2009-09-03 14:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-10 18:12 . 2009-12-10 18:13 ——– d—–w- c:\program files\Spyware Doctor
2009-12-10 18:12 . 2009-12-10 18:13 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-10 18:12 . 2009-12-10 18:12 ——– d—–w- c:\documents and settings\Ryan B\Application Data\PC Tools
2009-12-10 18:12 . 2009-12-10 18:12 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-10 18:12 . 2009-12-12 19:02 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-04 04:10 . 2009-12-04 04:10 ——– d—–w- c:\documents and settings\Visitor\Local Settings\Application Data\Mozilla
2009-12-03 01:48 . 2009-12-03 01:48 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2009-12-02 23:17 . 2009-06-21 21:44 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2009-12-02 23:06 . 2009-08-07 00:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2009-12-02 23:06 . 2009-08-07 00:23 215920 —-a-w- c:\windows\system32\muweb.dll
2009-11-23 05:09 . 2009-12-08 14:35 ——– d—–w- c:\documents and settings\Ryan B\Local Settings\Application Data\Yahoo
2009-11-23 05:06 . 2009-11-23 05:06 ——– d—–w- c:\documents and settings\Ryan B\Local Settings\Application Data\Yahoo!
2009-11-23 05:06 . 2009-12-08 14:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-11-23 05:06 . 2009-11-23 05:09 ——– d—–w- c:\documents and settings\Ryan B\Application Data\Yahoo!
2009-11-23 05:05 . 2009-11-23 05:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-11-23 05:05 . 2009-11-10 19:39 607472 —-a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-11-23 05:04 . 2009-11-23 05:06 ——– d—–w- c:\program files\Yahoo!
2009-11-17 04:29 . 2009-11-17 04:29 ——– d—–w- c:\documents and settings\Visitor\Local Settings\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-12 02:44 . 2009-09-13 02:09 ——– d—–w- c:\documents and settings\Ryan B\Application Data\FrostWire
2009-12-10 04:53 . 2009-08-27 00:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-07 23:06 . 2009-09-19 00:13 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-10-29 07:46 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2004-08-04 10:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 10:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 10:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-04 10:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 10:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 10:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-11 16:51 . 2009-10-11 16:51 126970 —-a-w- c:\documents and settings\Ryan B\Application Data\Move Networks\uninstall.exe
2009-10-11 16:51 . 2009-08-03 21:48 4187512 —-a-w- c:\documents and settings\Ryan B\Application Data\Move Networks\plugins\npqmp071505000010.dll
2009-09-14 18:10 . 2009-09-14 18:10 0 —-a-w- c:\documents and settings\Ryan B\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-07-09 49968]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-13 149280]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [12/10/2009 1:13 PM 207792]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/24/2009 10:11 PM 24652]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [8/24/2009 12:27 PM 20160]
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Ryan B\Application Data\Mozilla\Firefox\Profiles\gsusvlym.default\
FF - plugin: c:\documents and settings\Ryan B\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\Ryan B\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-AntiMalware - c:\program files\AntiMalware\antimalware.exe
AddRemove-360Share Pro - c:\program files\360Share Pro\bt-uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-12 14:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(852)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-12-12 14:24:59
ComboFix-quarantined-files.txt 2009-12-12 19:24
Pre-Run: 104,526,307,328 bytes free
Post-Run: 105,771,319,296 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - 686DA2ECDCA38A78D62593B5882EDAA1
Thanks.
-Ryan