Hi Scotty,
sorry for the delay. Here is the latest combofix log.
ComboFix 07-10-29.1 - Owner 2007-10-31 21:26:37.10 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.115 [GMT -4:00]
Running from: E:\ComboFix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point
FILE::
C:\3A4.tmp
C:\3A5.tmp
C:\3A6.tmp
C:\77D.tmp
C:\77E.tmp
C:\77F.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\3A4.tmp
C:\3A5.tmp
C:\3A6.tmp
C:\77D.tmp
C:\77E.tmp
C:\77F.tmp
C:\Documents and Settings\Owner\Desktop\SDFix
C:\Documents and Settings\Owner\Desktop\SDFix\apps\assosfix.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\cliptext.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\download.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\dummy.sys
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Enable_Command_Prompt.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERDNT.E_E
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERDNTDOS.LOC
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERDNTWIN.LOC
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERUNT.EXE
C:\Documents and Settings\Owner\Desktop\SDFix\apps\ERUNT.LOC
C:\Documents and Settings\Owner\Desktop\SDFix\apps\fix.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixBH.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FIXCU.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FIXLM.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixPath.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixRedir.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixWebCheck.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\fixXP.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\FixXPsp2.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\HPFix.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\HPFix2.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\HPFix3.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\isadmin.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\leg2.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\legacy.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\legacybk.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\locate.com
C:\Documents and Settings\Owner\Desktop\SDFix\apps\LS.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\MD5File.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\moveex.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\MyGcpvFix.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\MyGkFix2.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Process.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\procs.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\psservice.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\RegDACL.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\regedit.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Rem.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Rem2.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Replace\W2K.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Replace\w2k\null.sys
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Replace\XP.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Replace\xp\null.sys
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Reset_AppInit_DLLs.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\RestartIt!.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Restore_SecurityCenter.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\Restore_SharedAccess.reg
C:\Documents and Settings\Owner\Desktop\SDFix\apps\sc.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\SF.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\shutdown.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\srv2.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\svc.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\svcbk.txt
C:\Documents and Settings\Owner\Desktop\SDFix\apps\swreg.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\swsc.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\unzip.exe
C:\Documents and Settings\Owner\Desktop\SDFix\apps\WINMSG.EXE
C:\Documents and Settings\Owner\Desktop\SDFix\apps\zip.exe
C:\Documents and Settings\Owner\Desktop\SDFix\backups\attrib.exe
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backupreg.zip
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip
C:\Documents and Settings\Owner\Desktop\SDFix\backups\find.exe
C:\Documents and Settings\Owner\Desktop\SDFix\backups\findstr.exe
C:\Documents and Settings\Owner\Desktop\SDFix\backups\HOSTS
C:\Documents and Settings\Owner\Desktop\SDFix\backups\regedit.exe
C:\Documents and Settings\Owner\Desktop\SDFix\catchme.exe
C:\Documents and Settings\Owner\Desktop\SDFix\dummy.sys
C:\Documents and Settings\Owner\Desktop\SDFix\Report.txt
C:\Documents and Settings\Owner\Desktop\SDFix\RunThis.bat
C:\Documents and Settings\Owner\Desktop\SDFix\SDFIX_ReadMe_Online.url
.
((((((((((((((((((((((((( Files Created from 2007-10-01 to 2007-11-01 )))))))))))))))))))))))))))))))
.
2007-10-28 17:01 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-10-28 17:01 d——– C:\WINDOWS\LastGood
2007-10-28 17:01 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-27 19:14 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-27 18:46 d——– C:\WINDOWS\ERUNT
2007-10-27 11:46 218,112 –a—— C:\Program Files\HijackThis.exe
2007-10-22 21:39 d——– C:\UBCD4Win
2007-10-20 18:37 d——– C:\Program Files\iTunes
2007-10-20 17:48 d——– C:\Program Files\Apple Software Update
2007-10-20 13:12 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-20 12:57 d——– C:\WINDOWS\system32\DRVSTORE
2007-10-20 12:56 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-10-20 12:55 d——– C:\Program Files\The Learning Company
2007-10-07 08:34 d——– C:\Program Files\iTunes(2)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-20 22:38 ——— d—–w C:\Program Files\iPod
2007-10-20 16:57 ——— d—–w C:\Program Files\QuickTime
2007-10-20 16:57 ——— d—–w C:\Program Files\Arcavista
2007-10-20 16:56 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-10-20 16:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-20 16:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-20 15:49 ——— d—–w C:\Program Files\Common Files\Network Associates
2007-10-07 23:48 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2007-09-21 19:41 ——— d—–w C:\Program Files\Common Files\Apple
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2006-10-30 02:49 59,728 —-a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 11:46]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 13:55]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-08-18 08:00]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 09:48]
"HostManager"="C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe" [2006-04-20 13:10]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2002-08-01 16:13]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 12:59]
"Alogserv"="C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe" [2002-01-04 06:02]
"McAfee Guardian"="C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" [2001-12-18 02:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 14:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 16:00]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 11:29]
"AIM"="C:\Program Files\aim\aim.exe" [2005-08-05 15:08]
"McAfee.InstantUpdate.Monitor"="C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" [2002-02-11 00:03]
"ISMPack7"="C:\Program Files\ISM2\ISMPack7.exe" []
"ISMModule8"="C:\Program Files\ISM\ISMModule8.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-09-28 22:28:40]
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys
R2 AvSynMgr;AVSync Manager;"C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe"
R3 NETGEAR NETGEAR_MA101_USB_Adapter®;NETGEAR NETGEAR_MA101_USB_Adapter® Service for NETGEAR MA101 USB Adapter;C:\WINDOWS\system32\DRIVERS\ma1012kr.sys
S3 NaiFiltr;NaiFiltr;C:\WINDOWS\system32\DRIVERS\NaiFiltr.sys
S3 USBFVNETR;NETGEAR MA101 USB Adapter;C:\WINDOWS\system32\DRIVERS\ma101rndxp.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 19:23:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************
catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-31 21:29:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-31 21:30:30
C:\ComboFix2.txt … 2007-10-29 18:07
C:\ComboFix3.txt … 2007-10-29 17:56
.
— E O F —
thanks for all your help,
Gracesdad