I deleted a folder called uTorrent, and now here's my Combofix log:
ComboFix 08-10-08.02 - Christopher 2008-10-08 18:27:06.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.264 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\3913605.exe
C:\WINDOWS\system32\c.ico
C:\WINDOWS\system32\config\systemprofile\Desktop\Search Online.url
C:\WINDOWS\system32\config\systemprofile\Desktop\VIP Casino.url
C:\WINDOWS\system32\config\systemprofile\Favorites\Search Online.url
C:\WINDOWS\system32\config\systemprofile\Favorites\VIP Casino.url
C:\WINDOWS\system32\config\systemprofile\Start Menu\Search Online.url
C:\WINDOWS\system32\config\systemprofile\Start Menu\VIP Casino.url
C:\WINDOWS\system32\lsystipl64.dll
C:\WINDOWS\system32\m.ico
C:\WINDOWS\system32\msupdate.exe
C:\WINDOWS\system32\s.ico
.
((((((((((((((((((((((((( Files Created from 2008-09-08 to 2008-10-08 )))))))))))))))))))))))))))))))
.
2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Program Files\iTunes
2008-10-07 00:31 . 2008-10-07 00:31 d——– C:\Program Files\iPod
2008-10-07 00:31 . 2008-10-07 00:32 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-04 10:13 . 2008-10-04 10:13 58 –a—— C:\WINDOWS\system32\winwp.bmp
2008-10-04 10:07 . 2008-10-04 10:07 139,264 –a—— C:\WINDOWS\system32\mkrnl.exe
2008-10-04 10:07 . 2008-10-04 10:07 139,264 ——— C:\WINDOWS\sx2_77000531.exe
2008-10-04 10:07 . 2008-10-04 10:07 44 –a—— C:\WINDOWS\$$$$$$$$.bat
2008-10-02 17:23 . 2008-10-02 17:32 d——– C:\Program Files\SpywareBlaster
2008-10-02 17:23 . 2008-10-08 17:06 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-01 10:04 . 2008-10-01 15:16 98,332 –a—— C:\WINDOWS\yambafile.exe
2008-09-30 14:51 . 2008-10-08 10:20 d——– C:\Documents and Settings\All Users\Application Data\Soulseek
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Program Files\BillP Studios
2008-09-30 14:35 . 2008-09-30 14:35 d——– C:\Documents and Settings\Christopher\Application Data\WinPatrol
2008-09-28 16:42 . 2008-09-28 16:52 d——– C:\Lop SD
2008-09-26 10:30 . 2008-09-26 10:30 d——– C:\WINDOWS\ERUNT
2008-09-25 12:34 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-25 12:32 . 2008-09-25 12:32 d——– C:\Program Files\Common Files\Java
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Program Files\Avira
2008-09-25 11:01 . 2008-09-25 11:01 d——– C:\Documents and Settings\All Users\Application Data\Avira
2008-09-24 12:16 . 2008-09-24 12:16 d——– C:\Documents and Settings\Christopher\Application Data\Malwarebytes
2008-09-24 12:16 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-24 12:16 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-24 12:15 . 2008-09-24 12:19 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-24 12:15 . 2008-09-24 12:15 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-23 17:15 . 2008-09-23 17:15 d——– C:\Program Files\ERUNT
2008-09-21 00:02 . 2008-09-21 00:02 d——– C:\Program Files\Apple Software Update
2008-09-18 19:36 . 2008-09-18 19:36 d——– C:\Program Files\Trend Micro
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Program Files\Security Task Manager2
2008-09-18 19:22 . 2008-09-24 07:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-09-18 19:21 . 2008-09-18 19:21 d——– C:\Program Files\Security Task Manager
2008-09-18 15:05 . 2008-10-02 13:31 d——– C:\WINDOWS\system32\wTR19
2008-09-18 15:05 . 2008-09-18 15:05 d——– C:\Temp\dax41
2008-09-16 08:19 . 2008-09-18 17:35 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-12 08:51 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 22:22 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-10-01 17:01 32,000 —-a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-09-25 16:34 ——— d—–w C:\Program Files\Java
2008-09-23 19:10 ——— d—–w C:\Program Files\Soulseek
2008-09-21 04:06 ——— d—–w C:\Program Files\Bonjour
2008-09-21 04:04 ——— d—–w C:\Program Files\QuickTime
2008-09-21 04:04 ——— d—–w C:\Program Files\Common Files\Apple
2008-09-18 20:46 ——— d—–w C:\Program Files\Norton Security Scan
2008-09-12 12:42 ——— d—–w C:\Program Files\Safari
2008-09-12 12:39 ——— d—–w C:\Program Files\Common Files\Macromedia
2008-09-12 12:35 ——— d—–w C:\Program Files\iTunes(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\iPod(4)
2008-09-12 12:35 ——— d—–w C:\Program Files\Apple Software Update(2)
2008-08-29 14:18 87,336 —-a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 13:53 61,440 —-a-w C:\WINDOWS\system32\dnssd.dll
2008-07-19 02:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-08 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-07 159744]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-11 335872]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2003-09-26 237568]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-21 185632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-09-18 333120]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"AGRSMMSG"="AGRSMMSG.exe" [2003-09-30 C:\WINDOWS\AGRSMMSG.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-15 108544]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2003-10-07 23:41 28672 C:\WINDOWS\system32\Ati2mdxx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 IFP300;iRiver Internet Audio Player IFP-300;C:\WINDOWS\system32\DRIVERS\ifp300.sys [2003-03-06 13543]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-10-02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-10-08 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-08 17:22]
2008-10-08 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2008-10-08 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-04-19 22:42]
.
- - - - ORPHANS REMOVED - - - -
Notify-c00EC64 - (no file)
Notify-m0_glkp_011008 - (no file)
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Christopher\Application Data\Mozilla\Firefox\Profiles\579bhqqr.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://news.google.com/nwshp?hl=en&tab=wn
FF -: plugin - C:\Documents and Settings\Christopher\Application Data\Mozilla\Firefox\Profiles\579bhqqr.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF -: plugin - C:\Documents and Settings\Christopher\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 18:42:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe??????????~????|?????? ?deB???????????????B? ??????
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seneka]
"imagepath"="\systemroot\system32\drivers\seneka.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-10-08 18:48:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-08 22:48:06
ComboFix2.txt 2008-09-29 14:31:45
Pre-Run: 65,385,902,080 bytes free
Post-Run: 65,479,950,336 bytes free
187 — E O F — 2008-09-18 21:35:03