Hey, Ran both as ordered… here's the new combofix log…
ComboFix 08-03-08.2 - Jesterex 2008-03-08 22:57:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1476 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Programs\WinReanimator
C:\Documents and Settings\All Users\Start Menu\Programs\WinReanimator\Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinReanimator\WinReanimator.lnk
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\
000B00D5.urr
C:\Program Files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\Messenger\liquxigin89104.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache\
00053715.bin
C:\Program Files\MyWebSearch\bar\Cache\
00053909.bin
C:\Program Files\MyWebSearch\bar\Cache\
00053D9D.bin
C:\Program Files\MyWebSearch\bar\Cache\
00054185.bin
C:\Program Files\MyWebSearch\bar\Cache\
0009C47D
C:\Program Files\MyWebSearch\bar\Cache\
0009CC3D
C:\Program Files\MyWebSearch\bar\Cache\
0009CE60.bin
C:\Program Files\MyWebSearch\bar\Cache\
0009D044.bin
C:\Program Files\MyWebSearch\bar\Cache\
0009D10F.bin
C:\Program Files\MyWebSearch\bar\Cache\
0009D1DA.bin
C:\Program Files\MyWebSearch\bar\Cache\
005DFC6C
C:\Program Files\MyWebSearch\bar\Cache\
0134A83C.bin
C:\Program Files\MyWebSearch\bar\Cache\
0134A955.bin
C:\Program Files\MyWebSearch\bar\Cache\
0134AABC.bin
C:\Program Files\MyWebSearch\bar\Cache\
0134AC14.bin
C:\Program Files\MyWebSearch\bar\Cache\
0523E10D
C:\Program Files\MyWebSearch\bar\Cache\
0AFE02C7
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Message\COMMON\ask_logo.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\center.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\index.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\mid_dots.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\mws_logo.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\protect.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\shocked.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\stop.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\systray.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\systrayp.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\tp_grad.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\warn.gif
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\Program Files\web buying
C:\Program Files\web buying\v1.8.8\wbuninst.exe
C:\Program Files\web buying\v1.8.8\webbuying.exe
C:\Program Files\WinReanimator
C:\Program Files\WinReanimator\data\daily.cvd
C:\Program Files\WinReanimator\htmlayout.dll
C:\Program Files\WinReanimator\install.exe
C:\Program Files\WinReanimator\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
C:\Program Files\WinReanimator\Microsoft.VC80.CRT\msvcm80.dll
C:\Program Files\WinReanimator\Microsoft.VC80.CRT\msvcp80.dll
C:\Program Files\WinReanimator\Microsoft.VC80.CRT\msvcr80.dll
C:\Program Files\WinReanimator\pthreadVC2.dll
C:\Program Files\WinReanimator\un.ico
C:\Program Files\WinReanimator\unzip32.dll
C:\Program Files\WinReanimator\WinReanimator.cfg
C:\Program Files\WinReanimator\WinReanimator.dll
C:\Program Files\WinReanimator\WinReanimator.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\temp\tn3
C:\WINDOWS\BM53f89f9b.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\'
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bgcyrkqs.dll
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\c2
C:\WINDOWS\system32\c4
C:\WINDOWS\system32\c4\np89104.exe
C:\WINDOWS\system32\ddayy.dll
C:\WINDOWS\system32\drivers\ndisuioo.sys
C:\WINDOWS\system32\fmxebhqx.dll
C:\WINDOWS\system32\ftvmtasm.dll
C:\WINDOWS\system32\fviaarnj.dll
C:\WINDOWS\system32\gxhyswwq.dll
C:\WINDOWS\system32\iiicylti.dll
C:\WINDOWS\system32\k8
C:\WINDOWS\system32\k8\ravecom3.exe
C:\WINDOWS\system32\kmfpbom.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mljihec.dll
C:\WINDOWS\system32\oybaghcg.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qasgkppp.dll
C:\WINDOWS\system32\rolcegcr.dll
C:\WINDOWS\system32\s7
C:\WINDOWS\system32\s7\gbsu011.exe
C:\WINDOWS\system32\sqkrycgb.ini
C:\WINDOWS\system32\ttrajelv.dll
C:\WINDOWS\system32\users32.dat
C:\WINDOWS\system32\vlejartt.ini
C:\WINDOWS\system32\vsbmovoh.dll
C:\WINDOWS\system32\vtusttr.dll
C:\WINDOWS\system32\winivstr.exe
C:\WINDOWS\system32\x3
C:\WINDOWS\system32\yyadd.ini
C:\WINDOWS\system32\yyadd.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_NDISUIOO
——-\ndisuioo
((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.
2008-03-08 22:50 . 2008-03-08 22:52 d——– C:\WINDOWS\LastGood
2008-03-08 22:50 . 2008-03-08 22:50 d——– C:\Program Files\Sigmatel
2008-03-08 22:50 . 2006-07-24 07:20 1,052,672 –a—— C:\WINDOWS\system32\stlang.dll
2008-03-08 22:50 . 2006-07-24 07:20 282,624 –a—— C:\WINDOWS\stsystra.exe
2008-03-08 06:55 . 2007-09-05 16:23 d——– C:\Documents and Settings\Administrator\Application Data\Roxio
2008-03-08 06:55 . 2007-09-05 16:17 d——– C:\Documents and Settings\Administrator\Application Data\GTek
2008-03-08 06:55 . 2007-09-05 16:22 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2008-03-07 17:08 . 2008-03-07 17:08 d——– C:\Program Files\Trend Micro
2008-03-07 07:01 . 2008-03-07 07:01 d——– C:\Program Files\Lavasoft
2008-03-07 07:01 . 2008-03-07 07:03 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-07 06:52 . 2008-03-08 23:09 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-07 06:52 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-07 06:52 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-07 06:52 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-07 06:52 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-07 06:51 . 2008-03-07 06:55 d——– C:\Program Files\Spyware Doctor
2008-03-07 06:51 . 2008-03-07 06:51 d——– C:\Documents and Settings\Jesterex\Application Data\PC Tools
2008-03-07 06:39 . 2008-03-07 06:39 19,771 –a—— C:\WINDOWS\bubama.dl
2008-03-07 06:39 . 2008-03-07 06:39 19,609 –a—— C:\Documents and Settings\Jesterex\Application Data\bicikobitu.vbs
2008-03-07 06:39 . 2008-03-07 06:39 19,315 –a—— C:\Program Files\Common Files\otisexufy.reg
2008-03-07 06:39 . 2008-03-07 06:39 19,261 –a—— C:\WINDOWS\lyqe.sys
2008-03-07 06:39 . 2008-03-07 06:39 18,941 –a—— C:\Documents and Settings\All Users\Application Data\caduwad.exe
2008-03-07 06:39 . 2008-03-07 06:39 18,199 –a—— C:\WINDOWS\system32\lyrusicu.inf
2008-03-07 06:39 . 2008-03-07 06:39 17,504 –a—— C:\WINDOWS\system32\karupiqyce.pif
2008-03-07 06:39 . 2008-03-07 06:39 16,935 –a—— C:\Documents and Settings\All Users\Application Data\ehozemun.scr
2008-03-07 06:39 . 2008-03-07 06:39 16,138 –a—— C:\Documents and Settings\All Users\Application Data\ywabuvati.bin
2008-03-07 06:39 . 2008-03-07 06:39 15,776 –a—— C:\WINDOWS\ybyg.vbs
2008-03-07 06:39 . 2008-03-07 06:39 14,593 –a—— C:\WINDOWS\evyla.reg
2008-03-07 06:39 . 2008-03-07 06:39 13,629 –a—— C:\Documents and Settings\All Users\Application Data\igyxi.exe
2008-03-07 06:39 . 2008-03-07 06:39 13,256 –a—— C:\WINDOWS\ridolob.reg
2008-03-07 06:39 . 2008-03-07 06:39 12,264 –a—— C:\WINDOWS\vewiwuhy.dll
2008-03-07 06:39 . 2008-03-07 06:39 10,996 –a—— C:\WINDOWS\eleg._dl
2008-03-07 00:30 . 2008-03-07 00:30 58,368 –a—— C:\WINDOWS\system32\~.exe
2008-03-06 13:46 . 2008-03-06 13:46 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-06 13:34 . 2008-03-06 18:36 d——– C:\VundoFix Backups
2008-03-06 13:29 . 2008-03-06 13:29 167,545 –a—— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-03-05 21:57 . 2008-03-05 21:57 d——– C:\Documents and Settings\Jesterex\Application Data\TrojanHunter
2008-03-05 21:55 . 2008-03-05 21:55 d——– C:\Program Files\TrojanHunter 4.6
2008-03-05 21:48 . 2008-03-05 21:48 d——– C:\Program Files\Security Task Manager
2008-03-05 21:48 . 2008-03-05 21:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-03-05 12:05 . 2008-03-06 06:53 1,307,623 –ahs—- C:\WINDOWS\system32\mpgtvqof.ini
2008-03-03 12:01 . 2008-03-04 12:01 1,303,138 –ahs—- C:\WINDOWS\system32\mmioguba.ini
2008-03-03 11:50 . 2008-03-03 11:50 d——– C:\Program Files\Common Files\Adobe
2008-03-02 19:00 . 2008-03-03 11:50 d——– C:\Program Files\Common Files\Adobe(2)
2008-03-02 16:42 . 2008-03-02 16:43 d——– C:\Program Files\TGTSoft
2008-03-02 16:39 . 2008-03-03 11:50 d——– C:\Program Files\iPod Music Converter
2008-03-02 16:18 . 2008-03-02 16:18 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2008-03-02 16:14 . 2008-03-07 00:34 d——– C:\WINDOWS\system32\iDlo18
2008-03-02 16:14 . 2008-03-08 23:00 d——– C:\Temp
2008-03-02 15:56 . 2008-03-02 15:56 d——– C:\Program Files\Free iPod Video Converter
2008-03-02 15:56 . 2004-05-25 17:06 417,792 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-03-02 15:56 . 2005-02-27 21:48 356,352 –a—— C:\WINDOWS\system32\RealMediaSplitter.ax
2008-03-02 15:56 . 2004-01-10 17:02 258,048 –a—— C:\WINDOWS\system32\GplMpgDec.ax
2008-02-29 21:12 . 2005-11-13 22:40 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2008-02-29 21:11 . 2008-02-29 21:23 d——– C:\Unreal Anthology
2008-02-29 21:11 . 1997-07-19 17:01 118,781 –a—— C:\WINDOWS\system32\TABCTL32.ocx
2008-02-29 21:11 . 1998-01-24 03:39 110,725 –a—— C:\WINDOWS\system32\RICHTX32.ocx
2008-02-29 21:11 . 1995-07-26 01:00 98,588 –a—— C:\WINDOWS\system32\THREED32.ocx
2008-02-29 21:11 . 1995-07-26 01:00 48,640 –a—— C:\WINDOWS\system32\GRID32.ocx
2008-02-29 21:11 . 1997-01-16 10:11 44,831 –a—— C:\WINDOWS\system32\PICCLP32.ocx
2008-02-29 21:11 . 1995-07-26 01:00 43,502 –a—— C:\WINDOWS\system32\MSOUTL32.ocx
2008-02-29 18:14 . 2008-03-06 13:41 d——– C:\Program Files\Microsoft IntelliType Pro
2008-02-29 18:14 . 2008-02-29 18:14 d——– C:\Program Files\Microsoft IntelliPoint
2008-02-29 08:30 . 2008-02-29 08:30 d——– C:\WINDOWS\pix_office_wall
2008-02-29 08:30 . 2008-02-29 08:30 3,932,214 –a—— C:\WINDOWS\wall 1280.bmp
2008-02-29 08:27 . 2008-02-29 08:27 0 –a—— C:\WINDOWS\WB.ini
2008-02-27 20:30 . 2008-02-27 20:30 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-27 20:29 . 2008-02-27 20:30 d——– C:\Program Files\Windows Live
2008-02-27 20:29 . 2008-02-27 20:29 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-21 15:50 . 2008-02-21 15:50 d——– C:\Program Files\iTunes
2008-02-21 15:50 . 2008-02-21 15:50 d——– C:\Program Files\iPod
2008-02-21 15:50 . 2008-03-07 16:58 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-21 15:50 . 2008-02-21 15:50 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-21 07:04 . 2008-02-21 07:04 d——– C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-20 15:51 . 2008-02-20 15:51 d——– C:\Program Files\support.com
2008-02-20 15:51 . 2008-02-20 15:51 d——– C:\Documents and Settings\All Users\Application Data\Support.com
2008-02-20 15:51 . 2008-02-20 15:51 1,090 –a—— C:\net_save.dna
2008-02-19 19:42 . 2008-02-19 19:51 d——– C:\Netgear
2008-02-16 22:48 . 2008-02-16 22:48 d——– C:\WINDOWS\Wireless
2008-02-12 19:03 . 2008-02-12 19:05 50 –a—— C:\tmp.bat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 06:52 ——— d—–w C:\Program Files\McAfee
2008-03-08 01:03 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\LimeWire
2008-03-08 00:59 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\Hamachi
2008-03-07 15:01 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-04 15:29 ——— d—–w C:\Program Files\YVD
2008-03-03 00:24 ——— d—–w C:\Program Files\Java
2008-03-01 05:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-29 16:04 1,174 —-a-w C:\Documents and Settings\Jesterex\Application Data\wklnhst.dat
2008-02-28 04:31 ——— d—–w C:\Program Files\MSN Messenger
2008-02-21 15:05 ——— d—–w C:\Program Files\AIM6
2008-02-21 15:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-21 15:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 22:01 ——— d—–w C:\Program Files\Pcsx2_0.9.4
2008-02-09 20:56 ——— d—–w C:\Program Files\QuickTime
2008-02-06 17:51 171,400 —-a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-03 03:14 ——— d—–w C:\Program Files\World of Warcraft
2008-01-26 05:36 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\InstallShield Installation Information
2008-01-26 05:22 ——— d—–w C:\Program Files\Unreal Tournament 3
2008-01-26 05:22 ——— d—–w C:\Program Files\AGEIA Technologies
2008-01-24 01:28 ——— d—–w C:\Program Files\2nd Story Software
2008-01-15 05:48 ——— d—–w C:\Program Files\DivX
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-27 11:21 8429568]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 07:20 282624 C:\WINDOWS\stsystra.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqnkh]
awtqnkh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtusttr]
vtusttr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2007-03-05 17:36 140976 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-11-13 20:38]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 07:35]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-05-17 13:45]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-02-14 20:40]
S2 0298751205045554mcinstcleanup;McAfee Application Installer Cleanup (0298751205045554);C:\WINDOWS\TEMP\
029875~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 iLokDrvr;iLok;C:\WINDOWS\system32\DRIVERS\iLokDrvr.sys [2006-10-05 16:06]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]
*Newly Created Service* - 0298751205045554MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder
"2008-03-06 23:45:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-09 06:55:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-15 09:00:01 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-03-01 09:00:01 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-10-30 16:18:12 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job"
- C:\Program Files\Microsoft LifeCam\LifeExp.exe
"2007-10-30 15:55:57 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_setup_exe.job"
- E:\setup.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-08 23:09:34
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
-> C:\WINDOWS\system32\DLAAPI_W.DLL
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
.
**************************************************************************
.
Completion time: 2008-03-08 23:12:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-09 07:12:32
.
2008-02-13 00:08:04 — E O F —
and here's HiJackThis.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:54 PM, on 3/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/…html?p=ZRfox000
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O20 - Winlogon Notify: awtqnkh - awtqnkh.dll (file missing)
O20 - Winlogon Notify: vtusttr - vtusttr.dll (file missing)
O23 - Service: McAfee Application Installer Cleanup (0298751205045554) (0298751205045554mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\029875~1.EXE (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
–
End of file - 6204 bytes
At the current moment, my computer seems to have made it through. Minimal damage done, but still a bit sluggish. Also, reran spyware doctor after everything was completed. There are still the other few viruses with low/medium risks. These include Trojan.Generic, Trojan.Fakealert, and Adaware.Rabio not to mention RogueAntiSpyware.SpywareNo. Currently, none of these are active.