I ran ComboFix. It kept saying REGT wasn't a recognized command. Is this something to be concerned about.
Here's the combofix log:
ComboFix 08-06-20.4 - mitcson 2008-06-29 19:56:17.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1463 [GMT -4:00]
Running from: C:\Documents and Settings\mitcson\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\DLoXHkkj.ini
C:\WINDOWS\system32\DLoXHkkj.ini2
.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.
2008-06-29 18:58 . 2008-06-29 18:58 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\Malwarebytes
2008-06-29 18:58 . 2008-06-29 18:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-29 18:58 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-29 18:57 . 2008-06-29 19:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-29 18:57 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-29 17:15 . 2008-06-29 17:17 <DIR> d-------- C:\Program Files\Dofus
2008-06-28 15:33 . 2008-06-28 15:33 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-27 21:31 . 2008-06-27 21:31 <DIR> d-------- C:\Program Files\General File Splitter
2008-06-27 20:13 . 2008-06-27 20:13 <DIR> d-------- C:\Program Files\Executive Software
2008-06-27 20:09 . 2008-06-27 20:09 <DIR> d-------- C:\Program Files\CodeStuff
2008-06-24 12:59 . 2008-06-24 12:59 62,910 --a------ C:\Program Files\Uninstall.exe
2008-06-24 12:59 . 2008-06-24 12:59 0 --a------ C:\Program Files\uninstall.dat
2008-06-23 20:07 . 2008-06-28 16:38 <DIR> d-------- C:\Program Files\Gpotato
2008-06-22 20:12 . 2008-06-22 20:12 <DIR> d-------- C:\Program Files\WoW-2.3.0.7561-enUS
2008-06-22 20:12 . 2008-06-22 20:12 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-06-22 20:12 . 2008-06-22 20:12 1,283,912 --a------ C:\Program Files\WoW-2.3.0.7561-enUS-downloader.exe
2008-06-21 08:07 . 2008-06-21 08:07 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-06-21 07:40 . 2008-06-21 07:40 <DIR> d-------- C:\Program Files\winLAME
2008-06-20 19:25 . 2008-06-20 19:25 <DIR> d--h----- C:\WINDOWS\PIF
2008-06-20 19:06 . 2008-06-20 19:25 <DIR> d-------- C:\cygwin
2008-06-20 18:52 . 2008-06-20 18:52 <DIR> d-------- C:\Documents and Settings\mitcson\.netbeans
2008-06-20 18:49 . 2008-06-20 18:49 <DIR> d-------- C:\Documents and Settings\mitcson\.netbeans-registration
2008-06-20 18:42 . 2008-06-20 18:48 <DIR> d-------- C:\Program Files\NetBeans 6.1
2008-06-20 18:01 . 2008-06-20 18:31 <DIR> d-------- C:\Documents and Settings\mitcson\.SunDownloadManager
2008-06-20 17:57 . 2008-06-20 18:52 <DIR> d-------- C:\Documents and Settings\mitcson\.nbi
2008-06-20 16:59 . 2008-06-20 16:59 <DIR> d-------- C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-06-20 16:59 . 2008-06-21 08:11 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\Audacity
2008-06-20 15:01 . 2008-06-20 15:01 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\dyyno-vlc
2008-06-19 12:35 . 2008-06-20 21:29 <DIR> d-------- C:\Program Files\IMVU
2008-06-19 12:35 . 2008-06-19 12:40 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\IMVU
2008-06-19 11:17 . 2008-06-19 11:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Laconic Software
2008-06-19 09:13 . 2008-06-19 09:13 94,208 --a------ C:\WINDOWS\DIIUnin.exe
2008-06-19 09:13 . 2008-06-19 09:39 36,776 --a------ C:\WINDOWS\DIIUnin.dat
2008-06-19 09:13 . 2008-06-19 09:13 2,829 --a------ C:\WINDOWS\DIIUnin.pif
2008-06-19 09:09 . 2008-06-21 08:35 <DIR> d-------- C:\Program Files\Diablo II
2008-06-18 15:42 . 2008-06-18 15:42 <DIR> d-------- C:\Games
2008-06-18 13:32 . 2008-06-21 11:56 <DIR> d-------- C:\Program Files\Silkroad
2008-06-13 18:40 . 2008-06-13 18:40 <DIR> d-------- C:\Program Files\Dyyno
2008-06-13 15:04 . 2008-06-13 15:04 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\Nexon
2008-06-13 13:13 . 2008-06-13 13:13 <DIR> d-------- C:\Nexon
2008-06-12 09:53 . 2008-06-12 09:53 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-06-12 09:52 . 2003-07-17 14:17 5,174 --a------ C:\WINDOWS\system32\nppt9x.vxd
2008-06-12 09:52 . 2005-01-01 05:43 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2008-06-12 09:51 . 2008-06-20 20:09 31 --a------ C:\WINDOWS\GunzLauncher.INI
2008-06-12 09:44 . 2008-06-22 08:31 <DIR> d--h----- C:\Documents and Settings\mitcson\Application Data\ijjigame
2008-06-12 09:42 . 2008-06-12 09:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IJJIGame
2008-06-12 09:31 . 2008-06-12 09:31 <DIR> d-------- C:\ijji
2008-06-11 13:31 . 2008-05-08 10:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-11 13:30 . 2008-06-13 07:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 16:03 . 2008-06-10 16:03 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Xfire
2008-06-10 13:51 . 2008-06-10 13:51 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Xfire
2008-06-10 13:49 . 2008-06-25 15:04 <DIR> d-------- C:\Program Files\Xfire
2008-06-10 13:49 . 2008-06-29 18:33 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\Xfire
2008-06-09 18:54 . 2008-06-09 18:54 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-09 17:31 . 2008-06-09 17:31 <DIR> d-------- C:\Program Files\AskSBar
2008-06-09 17:31 . 2008-06-09 17:31 249,592 --a------ C:\WINDOWS\system32\cssdll32.dll
2008-06-09 17:30 . 2008-06-09 17:31 <DIR> d-------- C:\Program Files\COMODO
2008-06-09 17:30 . 2008-06-09 17:30 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\Comodo
2008-06-09 17:30 . 2008-06-09 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-06-09 17:30 . 2008-06-09 17:30 143,104 --a------ C:\WINDOWS\system32\guard32.dll
2008-06-09 17:30 . 2008-06-09 17:30 87,056 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-06-09 17:30 . 2008-06-09 17:30 24,208 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-06-09 17:19 . 2008-06-09 17:19 <DIR> d-------- C:\Program Files\Komodo Labs
2008-06-09 13:50 . 2008-06-09 13:54 <DIR> d-------- C:\Program Files\Google
2008-06-09 13:50 . 2008-06-12 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-09 09:32 . 2008-06-09 09:32 <DIR> d-------- C:\Program Files\FileZilla FTP Client
2008-06-09 09:32 . 2008-06-09 14:45 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\FileZilla
2008-06-04 10:13 . 2008-06-04 10:13 <DIR> d-------- C:\Documents and Settings\mitcson\WINDOWS
2008-06-03 14:28 . 2008-06-03 14:28 <DIR> d-------- C:\Program Files\SpeedBit Video Accelerator
2008-06-02 20:55 . 2008-06-02 20:55 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-06-02 18:54 . 2008-06-05 15:25 <DIR> d-------- C:\Program Files\DAP
2008-06-02 18:54 . 2008-06-29 19:26 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-02 18:54 . 2008-06-02 18:54 479,298 --a------ C:\WINDOWS\system32\wbocx.ocx
2008-06-02 18:54 . 2008-06-02 18:54 172,032 --a------ C:\WINDOWS\system32\AniGIF.ocx
2008-06-02 18:54 . 2008-06-02 18:54 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2008-05-31 11:36 . 2008-05-31 11:36 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\Ethereal
2008-05-31 11:33 . 2008-05-31 11:33 <DIR> d-------- C:\Program Files\Ethereal
2008-05-31 11:32 . 2008-05-31 11:32 <DIR> d-------- C:\Program Files\WinPcap
2008-05-29 14:52 . 2008-06-19 09:27 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-05-29 14:46 . 2008-06-19 09:06 21,840 --a----t- C:\WINDOWS\system32\SIntfNT.dll
2008-05-29 14:46 . 2008-06-19 09:06 17,212 --a----t- C:\WINDOWS\system32\SIntf32.dll
2008-05-29 14:46 . 2008-06-19 09:06 12,067 --a----t- C:\WINDOWS\system32\SIntf16.dll
2008-05-28 17:18 . 2008-05-28 17:18 22 --ah----- C:\qpmd8379.bin
2008-05-28 17:17 . 2008-05-28 17:17 36,864 --a------ C:\WINDOWS\system32\cfperfmon_8.dll
2008-05-28 17:15 . 2008-05-28 17:16 <DIR> d--h----- C:\Program Files\Zero G Registry
2008-05-28 17:15 . 2008-05-28 21:18 <DIR> d-------- C:\ColdFusion8
2008-05-28 10:58 . 2008-06-03 10:50 <DIR> d-------- C:\Temp\DMTemp
2008-05-28 10:58 . 2008-05-28 10:58 <DIR> d-------- C:\Temp
2008-05-28 08:17 . 2008-05-28 08:18 <DIR> d-------- C:\Program Files\Packet Tracer 4.11
2008-05-27 17:57 . 2008-05-27 17:58 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\ICAClient
2008-05-27 17:16 . 2008-05-27 17:16 <DIR> d-------- C:\Program Files\Scribus 1.3.3.11
2008-05-27 17:16 . 2008-05-27 18:16 <DIR> d-------- C:\Documents and Settings\mitcson\.scribus
2008-05-27 16:49 . 2008-05-27 16:49 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\Serif
2008-05-27 16:33 . 2008-05-27 16:33 <DIR> d-------- C:\Program Files\No-IP
2008-05-27 09:42 . 2008-05-27 09:44 <DIR> d-------- C:\Program Files\Prima Games
2008-05-27 09:42 . 2008-05-27 09:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2008-05-25 14:48 . 2008-03-05 15:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll
2008-05-25 14:48 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-05-25 14:48 . 2008-03-05 15:56 1,420,824 --a------ C:\WINDOWS\system32\D3DCompiler_37.dll
2008-05-25 14:48 . 2007-10-12 15:14 1,374,232 --a------ C:\WINDOWS\system32\D3DCompiler_36.dll
2008-05-25 14:48 . 2008-03-05 16:03 479,752 --a------ C:\WINDOWS\system32\XAudio2_0.dll
2008-05-25 14:48 . 2008-02-05 23:07 462,864 --a------ C:\WINDOWS\system32\d3dx10_37.dll
2008-05-25 14:48 . 2007-10-02 09:56 444,776 --a------ C:\WINDOWS\system32\d3dx10_36.dll
2008-05-25 14:48 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2008-05-25 14:48 . 2008-03-05 16:03 238,088 --a------ C:\WINDOWS\system32\xactengine3_0.dll
2008-05-25 14:48 . 2008-03-05 16:00 25,608 --a------ C:\WINDOWS\system32\X3DAudio1_3.dll
2008-05-25 14:43 . 2008-05-25 14:48 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2008-05-24 14:38 . 2008-06-28 09:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TrackMania
2008-05-24 14:33 . 2008-05-24 14:36 <DIR> d-------- C:\Program Files\TmNationsForever
2008-05-24 11:42 . 2008-05-24 11:42 <DIR> d-------- C:\Documents and Settings\All Users\temp
2008-05-24 11:42 . 2008-05-24 11:42 <DIR> d-------- C:\Documents and Settings\All Users\Gamespot
2008-05-22 18:40 . 2008-05-22 19:29 <DIR> d-------- C:\Program Files\Frets on Fire
2008-05-22 18:40 . 2008-05-22 18:41 <DIR> d-------- C:\Documents and Settings\mitcson\Application Data\fretsonfire
2008-05-21 21:17 . 2008-05-21 21:17 <DIR> d--h----- C:\Documents and Settings\mitcson\InstallAnywhere
2008-05-20 18:10 . 2008-05-20 18:10 278,984 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2008-05-20 18:10 . 2008-05-20 18:10 25,416 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
2008-05-20 17:58 . 2008-05-24 09:39 <DIR> d-------- C:\Program Files\The Witcher
2008-05-19 17:48 . 2008-05-19 18:11 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-19 16:12 . 2008-05-19 16:12 <DIR> d-------- C:\Program Files\Photosynth
2008-05-18 13:51 . 2008-05-18 13:51 <DIR> d-------- C:\Program Files\WinImage
2008-05-16 20:26 . 2008-05-16 20:33 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-05-16 20:26 . 2008-05-16 20:27 681 --a------ C:\WINDOWS\mozver.dat
2008-05-12 08:05 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-12 08:05 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-05-11 18:36 . 2008-05-24 09:37 <DIR> d-------- C:\Program Files\Windows Media Connect 2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-29 13:53 --------- d-----w C:\Documents and Settings\mitcson\Application Data\HPAppData
2008-06-28 12:48 --------- d-----w C:\Documents and Settings\mitcson\Application Data\Azureus
2008-06-23 13:55 --------- d-----w C:\Documents and Settings\mitcson\Application Data\OpenOffice.org2
2008-06-20 22:36 --------- d-----w C:\Program Files\Java
2008-06-18 00:27 --------- d-----w C:\Program Files\Azureus
2008-06-13 11:05 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 16:05 --------- d-----w C:\Documents and Settings\mitcson\Application Data\gtk-2.0
2008-06-11 14:27 --------- d-----w C:\Program Files\Guild Wars
2008-06-07 12:34 --------- d-----w C:\Program Files\Winamp Remote
2008-06-06 17:34 --------- d-----w C:\Program Files\Project64 1.6
2008-06-03 13:26 --------- d-----w C:\Documents and Settings\mitcson\Application Data\IceChat
2008-05-27 20:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-27 13:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-24 15:42 6,105 ----a-w C:\Program Files\install.log
2008-05-12 11:00 --------- d-----w C:\Program Files\MagicDisc
2008-05-11 00:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-04 14:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-05-04 13:34 --------- d-----w C:\Documents and Settings\mitcson\Application Data\Yahoo!
2008-05-04 12:31 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-30 21:46 --------- d-----w C:\Program Files\GIMP-2.0
2008-04-30 14:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-04-30 01:54 --------- d-----w C:\Documents and Settings\mitcson\Application Data\Winamp
2008-04-30 01:26 --------- d-----w C:\Program Files\Winamp Toolbar
2008-04-30 01:26 --------- d-----w C:\Program Files\Winamp
2008-04-30 01:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-04-28 21:08 --------- d-----w C:\Program Files\MSXML 6.0
2008-04-28 21:01 --------- d-----w C:\Program Files\Okoker ISO Maker
2008-04-14 00:12 69,120 ----a-w C:\WINDOWS\notepad.exe
2008-04-14 00:12 50,688 ----a-w C:\WINDOWS\twain_32.dll
2008-04-14 00:12 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
2008-04-14 00:12 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
2008-04-14 00:12 32,866 ------w C:\WINDOWS\slrundll.exe
2008-04-14 00:12 283,648 ----a-w C:\WINDOWS\winhlp32.exe
2008-04-14 00:12 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
2008-04-14 00:12 146,432 ----a-w C:\WINDOWS\regedit.exe
2008-04-14 00:12 10,752 ----a-w C:\WINDOWS\hh.exe
2008-04-14 00:12 1,033,728 ----a-w C:\WINDOWS\explorer.exe
2008-04-14 00:11 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
2008-04-14 00:11 39,424 ------w C:\WINDOWS\AppPatch\acadproc.dll
2008-04-14 00:11 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
2008-04-14 00:11 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
2008-04-14 00:11 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
2008-04-14 00:11 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
.
((((((((((((((((((((((((((((( snapshot_2008-06-24_13.32.11.48 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-24 17:26:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-30 00:00:28 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-28 00:13:41 45,056 ----a-r C:\WINDOWS\Installer\{A3F60446-48FB-48A8-B5FC-BB3430AEF806}\_8BC0A7C913FD_4112_87DA_AE60B3355013.exe
+ 2008-06-28 00:13:41 28,672 ----a-r C:\WINDOWS\Installer\{A3F60446-48FB-48A8-B5FC-BB3430AEF806}\Icon.exe
+ 2006-09-23 17:12:50 1,022,976 -c----w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2007-08-13 22:42:54 17,408 -c----w C:\WINDOWS\system32\dllcache\corpol.dll
+ 2007-08-13 22:45:18 78,336 -c----w C:\WINDOWS\system32\dllcache\ieencode.dll
+ 2007-08-13 22:38:04 491,520 -c----w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2006-09-23 17:12:50 1,497,088 -c----w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2006-09-23 17:12:50 474,112 -c----w C:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2007-08-13 22:54:10 413,696 -c----w C:\WINDOWS\system32\dllcache\vbscript.dll
+ 2008-06-30 00:00:45 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_2b4.dat
+ 2008-06-30 00:00:34 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_748.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05E1B2F4-BDB5-4163-BA09-8A4AC372E4EC}]
C:\WINDOWS\system32\cbXOFvsT.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{238994C0-A56F-4359-83E6-D7F08F12F81C}]
C:\WINDOWS\system32\jkkHXoLD.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2008-03-19 18:36 1267040 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
2007-11-06 01:50 542016 --a------ C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-03-19 18:36 1267040]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2008-03-19 18:36 1267040]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"Creative Detector U"="C:\Program Files\Creative\MediaSource5\CTDetctu.exe" [2006-10-02 17:03 188416]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 19:25 81920]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2007-06-28 12:43 8466432]
"nwiz"="nwiz.exe" [2007-06-28 12:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"CTAPR2"="C:\Program Files\Creative\Sound Blaster X-Fi\Console Launcher\CTAPR2.exe" [2007-02-15 16:39 57344]
"COMODO SafeSurf"="C:\Program Files\COMODO\SafeSurf\cssurf.exe" [2008-06-09 17:31 278264]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-06-09 17:30 1655552]
"SPIRun"="SPIRun.dll" [2006-11-29 06:35 8704 C:\WINDOWS\system32\SPIRun.dll]
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"combofix"="C:\WINDOWS\system32\CF9477.exe" [2008-04-13 20:12 389120]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\cssdll32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WarpSpeeder Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WarpSpeeder Tray Icon.lnk
backup=C:\WINDOWS\pss\WarpSpeeder Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^mitcson^Start Menu^Programs^Startup^Creative Volume Panel.lnk]
path=C:\Documents and Settings\mitcson\Start Menu\Programs\Startup\Creative Volume Panel.lnk
backup=C:\WINDOWS\pss\Creative Volume Panel.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^mitcson^Start Menu^Programs^Startup^GameSpot Download Manager.lnk]
path=C:\Documents and Settings\mitcson\Start Menu\Programs\Startup\GameSpot Download Manager.lnk
backup=C:\WINDOWS\pss\GameSpot Download Manager.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^mitcson^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\mitcson\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^mitcson^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk]
path=C:\Documents and Settings\mitcson\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.0.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^mitcson^Start Menu^Programs^Startup^Smart Guardian.lnk]
path=C:\Documents and Settings\mitcson\Start Menu\Programs\Startup\Smart Guardian.lnk
backup=C:\WINDOWS\pss\Smart Guardian.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^mitcson^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\mitcson\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 20:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
--a------ 2008-06-02 18:54 3053056 C:\Program Files\DAP\DAP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-10-14 21:17 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
--a------ 2007-08-22 16:31 80896 C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MtdAcqu]
--------- 2006-03-08 08:56 278528 C:\Program Files\Creative\MediaSource5\MtdAcqu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-06-28 12:43 81920 C:\WINDOWS\System32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-06-28 12:43 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
--a------ 2008-03-31 21:54 507904 C:\Program Files\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2006-03-02 07:22 577536 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
--------- 2007-02-28 17:50 180224 C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-04-01 14:49 36352 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinVNC]
--a------ 2007-05-07 19:28 589824 C:\Program Files\TightVNC\WinVNC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"winvnc"=2 (0x2)
"VideoAcceleratorService"=2 (0x2)
"rpcapd"=3 (0x3)
"gusvc"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"MyWebSearchService"=2 (0x2)
"BITS"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\TightVNC\\vncviewer.exe"=
"C:\\Program Files\\IceChat7\\IceChat7.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Adobe\\Adobe Dreamweaver CS3\\Dreamweaver.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\TmNationsForever\\TmForever.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"C:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=
"C:\\Program Files\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"=
"C:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\ijji\\ENGLISH\\u_gunz.exe"=
"C:\\ijji\\ENGLISH\\Gunz\\Gunz.exe"=
"C:\\ijji\\ENGLISH\\u_goonzu.exe"=
"C:\\ijji\\ENGLISH\\u_gbound.exe"=
"C:\\ijji\\ENGLISH\\Gunbound Revolution\\GunBound.gme"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:tightvnc
"5500:TCP"= 5500:TCP:tightvnc2
"5800:TCP"= 5800:TCP:tightvnc3
"2082:TCP"= 2082:TCP:cpannel
"21000:TCP"= 21000:TCP:azures
"21000:UDP"= 21000:UDP:azures2
"2350:TCP"= 2350:TCP:tmnf1
"2350:UDP"= 2350:UDP:tmnf2
"21:TCP"= 21:TCP:ftp
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 19:20]
R1 BIOS;BIOS;C:\WINDOWS\system32\drivers\BIOS.sys [2005-03-16 02:23]
R1 BS_I2cIo;BS_I2cIo;C:\WINDOWS\system32\drivers\BS_I2cIo.sys [2006-04-13 14:33]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-06-09 17:30]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-06-09 17:30]
R1 Ext2fs;Ext2fs;C:\WINDOWS\system32\DRIVERS\ext2fs.sys [2008-01-20 17:53]
R1 IfsMount;IfsMount;C:\WINDOWS\system32\DRIVERS\ifsmount.sys [2007-12-29 19:48]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 19:16]
R2 sbbotdi;sbbotdi;C:\PROGRA~1\SPEEDB~1\sbbotdi.sys [2008-06-03 14:28]
R3 dfmirage;dfmirage;C:\WINDOWS\system32\DRIVERS\dfmirage.sys [2005-11-25 17:43]
R3 t3;Sound Blaster X-Fi Xtreme Audio;C:\WINDOWS\system32\drivers\t3.sys [2007-03-29 04:24]
R3 t3filt;t3filt;C:\WINDOWS\system32\drivers\t3filt.sys [2007-02-20 10:01]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 16:22]
S4 HPSLPSVC;HP Network Devices Support;C:\WINDOWS\system32\svchost.exe [2008-04-13 20:12]
S4 MyWebSearchService;My Web Search Service;C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe []
S4 VideoAcceleratorService;VideoAcceleratorService;C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe [2008-06-03 14:28]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86287b5c-2dad-11dd-a7ce-001b211066e8}]
\Shell\AutoRun\command - E:\SETUP.EXE
.
Contents of the 'Scheduled Tasks' folder
"2008-06-30 00:03:35 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-29 20:01:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-06-29 20:06:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-30 00:06:31
ComboFix2.txt 2008-06-24 17:34:10
ComboFix3.txt 2008-06-09 22:41:56
ComboFix4.txt 2008-06-09 21:02:26
Pre-Run: 205,806,665,728 bytes free
Post-Run: 205,781,188,608 bytes free
423 --- E O F --- 2008-06-29 23:35:29
Edited by riverwind, 29 June 2008 - 06:09 PM.