Here is Michael T combofix report
ComboFix 08-03-08.1 - Michael 2008-03-08 22:11:56.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.476 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.
2008-03-08 19:02 . 2008-03-08 19:02 20,262 –a—— C:\catchme2008-03-08_194625.79.zip
2008-03-08 18:05 . 2008-03-08 21:52 d——– C:\hijack this-202
2008-03-08 17:33 . 2008-03-08 17:31 1,427,992 –a—— C:\mbam-setup.exe
2008-03-08 17:32 . 2008-03-08 17:30 50,688 –a—— C:\ATF-Cleaner.exe
2008-03-07 23:53 . 2008-03-07 23:53 812,344 –a—— C:\HJTInstall.exe
2008-03-07 23:21 . 2008-03-07 23:21 d——– C:\spybotS&D
2008-03-07 22:57 . 2008-03-07 22:57 d–hs—- C:\Documents and Settings\Michael\UserData
2008-03-07 22:22 . 2008-03-07 22:22 d——– C:\Documents and Settings\Michael\Contacts
2008-03-07 22:22 . 2008-03-07 22:22 d——– C:\Documents and Settings\Michael\Application Data\AdobeUM
2008-03-07 22:21 . 2008-03-07 22:21 d——– C:\Documents and Settings\Michael\Application Data\Intuit
2008-03-07 22:21 . 2008-03-07 22:21 d——– C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-03-07 22:21 . 2008-03-07 22:21 d——– C:\Documents and Settings\Michael\Application Data\Corel
2008-03-07 22:21 . 2008-03-07 22:21 d——– C:\Documents and Settings\Michael\Application Data\Apple Computer
2008-03-07 22:21 . 2008-03-07 22:21 d——– C:\Documents and Settings\Michael\Application Data\Aim
2008-03-07 22:20 . 2008-03-07 22:20 d——– C:\Documents and Settings\Michael\Application Data\WeatherBug
2008-03-07 22:20 . 2008-03-07 22:20 d——– C:\Documents and Settings\Michael\Application Data\Snapfish
2008-03-07 22:20 . 2008-03-07 22:20 d——– C:\Documents and Settings\Michael\Application Data\Sammsoft
2008-03-07 22:20 . 2008-03-07 22:20 d——– C:\Documents and Settings\Michael\Application Data\Roxio
2008-03-07 22:20 . 2008-03-07 22:20 d——– C:\Documents and Settings\Michael\Application Data\MSNInstaller
2008-03-07 22:20 . 2008-03-07 22:20 d——– C:\Documents and Settings\Michael\Application Data\MSN6
2008-03-07 22:20 . 2008-03-07 22:20 d——– C:\Documents and Settings\Michael\Application Data\Motive
2008-03-07 22:20 . 2008-03-07 22:20 d——– C:\Documents and Settings\Michael\Application Data\Lycos
2008-03-07 22:20 . 2008-03-07 22:20 d——– C:\Documents and Settings\Michael\Application Data\Lavasoft
2008-03-07 22:04 . 2008-03-07 22:21 d——– C:\Documents and Settings\Michael\Application Data\GTek
2008-03-07 22:02 . 2003-08-27 09:14 d——– C:\Documents and Settings\Michael\WINDOWS
2008-03-07 21:28 . 2008-03-07 22:03 d–hs—- C:\WINDOWS\Installer
2008-03-07 20:49 . 2008-03-07 20:49 22 –a—— C:\WINDOWS\SYSTEM32\ati64hlp.stb
2008-03-07 20:16 . 2001-09-26 20:22 93,722 –a—— C:\WINDOWS\SYSTEM32\atmenuxx.hlp
2008-03-07 20:16 . 2008-03-07 20:49 10,842 –ah—– C:\WINDOWS\SYSTEM32\ATMenuxx.GID
2008-03-07 00:35 . 2008-03-08 01:03 d——– C:\WINDOWS\CAVTemp
2008-03-06 20:57 . 2008-03-08 21:38 257,654 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k0
2008-03-06 20:57 . 2008-03-08 21:38 64 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k7
2008-03-06 20:57 . 2008-03-08 21:38 64 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k6
2008-03-06 20:57 . 2008-03-08 21:38 64 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k5
2008-03-06 20:57 . 2008-03-08 21:38 64 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k4
2008-03-06 20:57 . 2008-03-08 21:38 64 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k3
2008-03-06 20:57 . 2008-03-08 21:38 64 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k2
2008-03-06 20:57 . 2008-03-08 21:38 64 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k1
2008-03-06 20:20 . 2008-03-06 20:20 d——– C:\Program Files\Common Files\Scanner
2008-03-06 20:20 . 2007-11-23 11:48 879,784 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\vetefile.sys
2008-03-06 20:20 . 2007-11-22 15:37 250,544 –a—— C:\WINDOWS\SYSTEM32\KeyHelp.ocx
2008-03-06 20:20 . 2007-11-23 11:48 108,312 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\veteboot.sys
2008-03-06 20:20 . 2008-03-06 20:24 99,592 –a—— C:\WINDOWS\SYSTEM32\isafeif.dll
2008-03-06 20:20 . 2008-03-06 20:24 91,400 –a—— C:\WINDOWS\SYSTEM32\isafprod.dll
2008-03-06 20:20 . 2008-03-06 20:24 83,256 –a—— C:\WINDOWS\SYSTEM32\vetredir.dll
2008-03-06 20:20 . 2008-03-06 20:24 32,264 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\vetmonnt.sys
2008-03-06 20:20 . 2008-03-06 20:24 26,376 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\vet-filt.sys
2008-03-06 20:20 . 2008-03-06 20:24 21,512 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\vetfddnt.sys
2008-03-06 20:20 . 2008-03-06 20:24 21,128 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\vet-rec.sys
2008-03-06 20:11 . 2008-03-08 21:52 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-03-06 20:11 . 2008-03-06 20:11 1,409 –a—— C:\WINDOWS\QTFont.for
2008-03-06 19:25 . 2001-08-17 13:48 12,160 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\mouhid.sys
2008-02-24 21:45 . 2008-02-24 21:45 d——– C:\Documents and Settings\Michael\Application Data\Sammsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-08 23:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-07 14:48 ——— d—–w C:\Documents and Settings\Ellen Turturro\Application Data\Lavasoft
2008-03-07 02:36 ——— d—–w C:\Program Files\Common Files\Motive
2008-03-07 02:13 ——— d—–w C:\Documents and Settings\Michael\Application Data\Lycos
2008-03-07 02:13 ——— d—–w C:\Documents and Settings\Ellen\Application Data\Lycos
2008-03-07 01:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\CA
2008-03-07 01:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-03-04 21:24 ——— d—–w C:\Documents and Settings\Michael\Application Data\AdobeUM
2008-01-28 19:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell
2008-01-23 20:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-01-23 20:34 ——— d—–w C:\Program Files\Common Files\supportsoft
2008-01-11 21:35 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-01-11 21:28 ——— d—–w C:\Documents and Settings\Michael\Application Data\GetRightToGo
2008-01-11 05:53 44,544 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
2007-12-20 13:10 499,712 —-a-w C:\WINDOWS\SYSTEM32\msvcp71.dll
2007-12-20 13:10 348,160 —-a-w C:\WINDOWS\SYSTEM32\msvcr71.dll
2007-12-19 23:01 347,136 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mrxdav.sys
1601-01-01 00:00 0 ——w C:\Program Files\
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-10-19 07:59 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-10-19 07:59 126976]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28 684032]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-03-06 20:24 234760]
"cafw"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-03-06 20:24 771336]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-03-06 20:24 173320]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-03-06 20:24 259336]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.32\QOELoader.exe" [2008-03-06 20:24 14088]
"AtiPTA"="atiptaxx.exe" [2001-09-26 22:39 245760 C:\WINDOWS\SYSTEM32\atiptaxx.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-04-09 05:56:24 598150]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2002-03-13 04:08:34 16384]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-01 51984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 2007-05-18 13:30 79368 C:\WINDOWS\SYSTEM32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 11:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2003-08-27 09:18 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\MSN\\MSNCoreFiles\\msn.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys [2007-10-18 10:24]
R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys [2007-05-18 13:30]
R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys [2007-05-18 13:30]
R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys [2007-10-18 14:21]
R2 FileSaver_Service;FileSaver_Service;"C:\Program Files\Energizer FileSaver\UPSMON_Service.Exe" [2003-07-20 16:03]
R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys [2007-10-18 10:24]
R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys [2007-11-02 12:09]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 09:23]
R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-10-18 10:24]
R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-10-18 10:24]
R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2007-05-18 13:30]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2004-08-04 00:29]
R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys [2007-09-13 15:15]
S3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2008-03-06 20:24]
.
Contents of the 'Scheduled Tasks' folder
"2008-03-08 14:11:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-08 02:21:00 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Michael Turturro at 8 21 PM.job"
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-08 22:19:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-08 22:22:19
ComboFix2.txt 2008-03-09 00:57:18
.
2008-03-08 02:20:15 — E O F —