Here you go,
ComboFix 10-02-12.01 - Compaq_Owner 02/15/2010 14:55:38.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.446.159 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Compaq_Owner\Local Settings\Application Data\av.exe
c:\documents and settings\Compaq_Owner\Local Settings\Temporary Internet Files\0mpM1aMx.jpg
c:\documents and settings\Compaq_Owner\Local Settings\Temporary Internet Files\5la08Abm3.jpg
c:\documents and settings\Compaq_Owner\Local Settings\Temporary Internet Files\aMaLy.jpg
c:\documents and settings\Compaq_Owner\Local Settings\Temporary Internet Files\YoM4Xy8.jpg
C:\LOG.TXT
c:\recycler\S-1-5-21-1073784688-2959234363-1786228294-1009
c:\recycler\S-1-5-21-1697849268-237260021-285423700-1009
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-01-15 to 2010-02-15 )))))))))))))))))))))))))))))))
.
2010-01-26 03:32 . 2010-01-26 03:32 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-01-26 03:27 . 2010-01-26 03:27 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-01-26 02:21 . 2009-11-22 23:42 69000 —-a-w- c:\windows\system32\zlcomm.dll
2010-01-26 02:21 . 2009-11-22 23:42 103816 —-a-w- c:\windows\system32\zlcommdb.dll
2010-01-26 02:20 . 2009-11-22 23:42 1238408 —-a-w- c:\windows\system32\zpeng25.dll
2010-01-24 22:19 . 2010-01-28 00:25 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Temp
2010-01-24 22:18 . 2010-01-24 22:19 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Deployment
2010-01-24 20:20 . 2010-01-24 20:20 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-01-24 18:27 . 2004-08-04 08:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2010-01-24 18:27 . 2004-08-04 08:56 21504 —-a-w- c:\windows\system32\dllcache\hidserv.dll
2010-01-24 18:26 . 2004-08-04 06:58 14848 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2010-01-24 18:26 . 2004-08-04 06:58 14848 —-a-w- c:\windows\system32\dllcache\kbdhid.sys
2010-01-24 18:26 . 2004-08-04 07:08 31616 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2010-01-24 18:26 . 2004-08-04 07:08 31616 —-a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-01-24 05:56 . 2006-10-27 03:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-01-24 05:56 . 2006-10-27 03:56 32592 —-a-w- c:\windows\system32\msonpmon.dll
2010-01-24 05:54 . 2010-01-24 05:54 ——– d—–w- c:\program files\Microsoft.NET
2010-01-24 05:51 . 2010-01-24 05:52 ——– d—–w- c:\windows\SHELLNEW
2010-01-24 05:51 . 2010-01-24 05:51 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Microsoft Help
2010-01-24 05:50 . 2010-01-24 05:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-24 05:50 . 2010-01-24 05:50 ——– d—–r- C:\MSOCache
2010-01-24 01:09 . 2010-01-24 01:09 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\Yahoo!
2010-01-23 22:50 . 2001-08-17 21:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2010-01-23 22:50 . 2001-08-17 21:48 12160 —-a-w- c:\windows\system32\dllcache\mouhid.sys
2010-01-23 22:49 . 2001-08-17 22:02 9600 —-a-w- c:\windows\system32\drivers\hidusb.sys
2010-01-23 22:49 . 2001-08-17 22:02 9600 —-a-w- c:\windows\system32\dllcache\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 20:51 . 2010-02-15 22:47 1634816 —-a-w- c:\windows\Internet Logs\xDB2.tmp
2010-02-14 20:51 . 2010-02-15 22:47 617472 —-a-w- c:\windows\Internet Logs\xDB1.tmp
2010-02-14 20:44 . 2010-01-27 00:17 7196699 —-a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-02-11 22:45 . 2009-06-07 05:54 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-02-11 18:53 . 2010-02-11 18:57 1630720 —-a-w- c:\windows\Internet Logs\xDB6.tmp
2010-02-10 19:44 . 2007-12-23 23:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-26 03:27 . 2005-08-08 23:05 ——– d—–w- c:\program files\Google
2010-01-26 02:14 . 2008-09-12 03:19 ——– d—–w- c:\program files\COMODO
2010-01-26 02:13 . 2009-06-11 03:36 1474832 —-a-w- c:\windows\system32\drivers\sfi.dat
2010-01-24 22:18 . 2006-02-15 03:45 46192 —-a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-24 05:55 . 2005-08-08 22:44 ——– d—–w- c:\program files\Microsoft Works
2010-01-24 01:08 . 2006-02-19 04:49 ——– d—–w- c:\program files\Yahoo!
2010-01-24 00:34 . 2007-12-23 23:58 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-03 22:30 . 2006-02-12 23:09 11510 —-a-w- c:\documents and settings\Compaq_Owner\Application Data\wklnhst.dat
2009-11-23 17:33 . 2009-11-23 17:28 152576 —-a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-23 17:33 . 2009-11-23 17:28 79488 —-a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-01-24 135664]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-26 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-08-08 180269]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-06-14 1282048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-11-22 1037192]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-08 98304]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/2008 11:02 AM 1213728]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/25/2010 7:27 PM 135664]
S3 NdisWDM;Dynex Wireless G USB Network Adapter Service;c:\windows\system32\drivers\NdisWDM.sys [9/9/2008 5:54 PM 198528]
.
Contents of the 'Scheduled Tasks' folder
2010-02-15 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 22:54]
2010-02-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-26 03:27]
2010-02-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-26 03:27]
2010-02-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1157138965-3435557069-191181050-1009Core.job
- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-24 22:19]
2010-02-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1157138965-3435557069-191181050-1009UA.job
- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-24 22:19]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PCDrProfiler - (no file)
Notify-dimsntfy - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-15 15:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1157138965-3435557069-191181050-1009\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:43,16,9a,15,fe,7f,db,eb,d7,22,3f,6f,13,4b,ac,fa,25,76,2e,d0,cb,97,17,
0c,f2,0b,cb,b7,6b,ee,b6,0a,b3,ee,f4,22,0f,39,97,a9,a4,0f,1d,00,ed,9d,b7,a0,\
"??"=hex:20,30,ea,ab,8a,bb,2a,8a,4e,88,ba,2f,a4,f9,4b,15
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(548)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(3400)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-15 15:09:47 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-15 23:09
Pre-Run: 57,909,420,032 bytes free
Post-Run: 58,187,448,320 bytes free
- - End Of File - - 96E88D1F4E23A9DAFB8664B6A017F022