Here's my combofix log
ComboFix 08-10-01.06 - Yvonne 2008-10-02 15:35:13.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.232 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-09-02 to 2008-10-02 )))))))))))))))))))))))))))))))
.
2008-10-02 00:01 . 2008-10-02 00:01 268 –ah—– C:\sqmdata17.sqm
2008-10-02 00:01 . 2008-10-02 00:01 244 –ah—– C:\sqmnoopt17.sqm
2008-10-01 17:57 . 2008-10-01 17:59 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-01 17:57 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-01 17:57 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-01 17:29 . 2008-10-01 17:29 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\AdobeUM
2008-10-01 15:33 . 2008-10-01 15:33 244 –ah—– C:\sqmnoopt16.sqm
2008-10-01 15:33 . 2008-10-01 15:33 232 –ah—– C:\sqmdata16.sqm
2008-10-01 15:14 . 2008-10-01 15:14 244 –ah—– C:\sqmnoopt15.sqm
2008-10-01 15:14 . 2008-10-01 15:14 232 –ah—– C:\sqmdata15.sqm
2008-10-01 12:45 . 2008-10-01 12:45 244 –ah—– C:\sqmnoopt14.sqm
2008-10-01 12:45 . 2008-10-01 12:45 232 –ah—– C:\sqmdata14.sqm
2008-10-01 05:34 . 2008-10-01 05:34 244 –ah—– C:\sqmnoopt13.sqm
2008-10-01 05:34 . 2008-10-01 05:34 232 –ah—– C:\sqmdata13.sqm
2008-10-01 05:23 . 2008-10-01 05:23 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Template
2008-10-01 05:23 . 2008-10-01 21:40 484 –a—— C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\wklnhst.dat
2008-09-30 17:23 . 2008-09-30 17:23 244 –ah—– C:\sqmnoopt12.sqm
2008-09-30 17:23 . 2008-09-30 17:23 232 –ah—– C:\sqmdata12.sqm
2008-09-30 16:21 . 2008-09-30 16:21 d——– C:\Program Files\Panda Security
2008-09-30 16:21 . 2008-06-19 17:24 28,544 –a—— C:\WINDOWS\system32\drivers\pavboot.sys
2008-09-30 15:36 . 2008-09-30 15:36 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Malwarebytes
2008-09-30 15:36 . 2008-09-30 15:36 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-30 15:17 . 2008-09-30 15:17 244 –ah—– C:\sqmnoopt11.sqm
2008-09-30 15:17 . 2008-09-30 15:17 232 –ah—– C:\sqmdata11.sqm
2008-09-30 10:24 . 2008-09-30 10:24 244 –ah—– C:\sqmnoopt10.sqm
2008-09-30 10:24 . 2008-09-30 10:24 232 –ah—– C:\sqmdata10.sqm
2008-09-29 21:50 . 2008-09-29 21:50 244 –ah—– C:\sqmnoopt09.sqm
2008-09-29 21:50 . 2008-09-29 21:50 232 –ah—– C:\sqmdata09.sqm
2008-09-29 15:43 . 2008-10-01 15:54 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Contacts
2008-09-29 14:22 . 2008-09-29 14:22 244 –ah—– C:\sqmnoopt08.sqm
2008-09-29 14:22 . 2008-09-29 14:22 232 –ah—– C:\sqmdata08.sqm
2008-09-29 05:12 . 2008-09-29 05:12 d——– C:\Program Files\Raxco
2008-09-29 05:12 . 2008-09-29 05:12 d——– C:\Documents and Settings\All Users\Application Data\Raxco
2008-09-29 05:11 . 2008-09-29 05:11 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\InstallShield
2008-09-27 22:34 . 2008-09-27 22:34 95 –a—— C:\WINDOWS\wininit.ini
2008-09-27 22:02 . 2008-09-28 14:25 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-27 20:33 . 2008-09-27 20:33 268 –ah—– C:\sqmdata07.sqm
2008-09-27 20:33 . 2008-09-27 20:33 244 –ah—– C:\sqmnoopt07.sqm
2008-09-27 12:53 . 2008-09-27 12:53 d——– C:\temp
2008-09-27 10:40 . 2008-09-27 10:40 268 –ah—– C:\sqmdata06.sqm
2008-09-27 10:40 . 2008-09-27 10:40 244 –ah—– C:\sqmnoopt06.sqm
2008-09-27 10:36 . 2008-09-27 10:36 268 –ah—– C:\sqmdata05.sqm
2008-09-27 10:36 . 2008-09-27 10:36 244 –ah—– C:\sqmnoopt05.sqm
2008-09-27 01:41 . 2008-09-27 01:41 268 –ah—– C:\sqmdata04.sqm
2008-09-27 01:41 . 2008-09-27 01:41 244 –ah—– C:\sqmnoopt04.sqm
2008-09-26 23:01 . 2008-09-26 23:01 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Yvonne
2008-09-26 21:30 . 2008-09-26 21:30 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Bell
2008-09-26 21:29 . 2004-08-11 05:06 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\WINDOWS
2008-09-26 21:29 . 2008-08-19 00:52 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\SampleView
2008-09-26 21:29 . 2008-08-19 00:50 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\McAfee
2008-09-26 21:29 . 2008-09-29 15:43 d——– C:\Documents and Settings\Yvonne.TAMBONGFAMILY
2008-09-26 17:31 . 2008-09-26 17:31 268 –ah—– C:\sqmdata03.sqm
2008-09-26 17:31 . 2008-09-26 17:31 244 –ah—– C:\sqmnoopt03.sqm
2008-09-25 15:23 . 2008-09-25 15:23 95,232 –a—— C:\WINDOWS\system32\tjsywdle.dll
2008-09-24 16:36 . 2008-09-24 16:36 354 –ahs—- C:\WINDOWS\system32\lgpxqaon.ini2
2008-09-24 15:33 . 2008-09-24 15:33 902,319 –ahs—- C:\WINDOWS\system32\lgpxqaon.tmp
2008-09-24 15:33 . 2008-09-24 15:33 294 –ahs—- C:\WINDOWS\system32\lgpxqaon.ini
2008-09-24 15:21 . 2008-09-24 15:21 95,232 –a—— C:\WINDOWS\system32\ollpntke.dll
2008-09-23 20:48 . 2008-09-23 20:48 91,136 –a—— C:\WINDOWS\system32\qvvjvami.dll
2008-09-23 20:32 . 2008-09-23 20:32 d——– C:\WINDOWS\Sun
2008-09-23 09:33 . 2008-09-23 09:33 268 –ah—– C:\sqmdata02.sqm
2008-09-23 09:33 . 2008-09-23 09:33 244 –ah—– C:\sqmnoopt02.sqm
2008-09-20 23:47 . 2008-09-20 23:47 268 –ah—– C:\sqmdata01.sqm
2008-09-20 23:47 . 2008-09-20 23:47 244 –ah—– C:\sqmnoopt01.sqm
2008-09-18 18:24 . 2008-09-26 21:38 d——– C:\Program Files\Pilates for Wimps Workout.xvid. DVDRip
2008-09-14 21:29 . 2008-09-14 21:29 89 –a—— C:\WINDOWS\system32\xi?
2008-09-07 22:22 . 2008-09-07 22:22 d——– C:\Program Files\Windows Media Connect 2
2008-09-06 22:20 . 2008-09-06 22:20 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-04 22:52 . 2008-09-04 22:52 244 –ah—– C:\sqmnoopt00.sqm
2008-09-04 22:52 . 2008-09-04 22:52 232 –ah—– C:\sqmdata00.sqm
2008-09-04 18:48 . 2008-09-04 18:48 d——– C:\Program Files\View22
2008-09-03 15:35 . 2008-09-03 15:35 940,794 –a—— C:\WINDOWS\system32\LoopyMusic.wav
2008-09-03 15:35 . 2008-09-03 15:35 146,650 –a—— C:\WINDOWS\system32\BuzzingBee.wav
2008-09-03 15:35 . 2008-09-17 05:00 73,728 –a—— C:\WINDOWS\ALCFDRTM.VER
2008-09-03 15:35 . 2008-09-03 15:35 73,728 –a—— C:\WINDOWS\ALCFDRTM.EXE
2008-09-02 13:33 . 2006-11-16 17:05 12,840 –a—— C:\WINDOWS\BigFixClientOverride.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-29 09:11 53,192 —-a-w C:\WINDOWS\system32\drivers\rp_skt32.sys
2008-09-28 18:48 ——— d—–w C:\Program Files\Common Files\Scanner
2008-09-27 01:39 ——— d—–w C:\Program Files\Symantec
2008-09-08 01:48 ——— d—–w C:\Program Files\CONEXANT
2008-09-02 17:34 ——— d—–w C:\Program Files\BigFix
2008-09-02 17:33 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-02 17:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-08-26 02:26 ——— d—–w C:\Documents and Settings\Melanie\Application Data\CyberLink
2008-08-25 17:15 ——— d—–w C:\Program Files\Windows Live
2008-08-25 17:14 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-25 17:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-23 04:14 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-08-23 04:14 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2008-08-23 04:13 ——— d—–w C:\Program Files\Zune
2008-08-23 03:57 ——— d—–w C:\Program Files\Digital Media Reader
2008-08-23 03:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-22 08:58 ——— d—–w C:\Documents and Settings\Nicole\Application Data\Bell
2008-08-21 17:29 ——— d—–w C:\Program Files\Common Files\Adobe
2008-08-20 05:41 ——— d—–w C:\Documents and Settings\Melanie\Application Data\Bell
2008-08-19 19:43 ——— d—–w C:\Program Files\MSXML 4.0
2008-08-19 19:35 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-19 18:13 294,912 —-a-w C:\WINDOWS\HideWin.exe
2008-08-19 18:13 ——— d—–w C:\Program Files\Realtek
2008-08-19 05:45 ——— d—–w C:\Program Files\Personal Vault
2008-08-19 05:45 ——— d—–w C:\Program Files\Common Files\Authentium
2008-08-19 05:44 ——— d—–w C:\Program Files\CA
2008-08-19 05:44 ——— d—–w C:\Program Files\Bell
2008-08-19 05:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Bell
2008-08-19 05:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-19 05:02 ——— d—–w C:\Program Files\Program Shortcuts
2008-08-19 04:52 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
2008-08-19 04:52 ——— d—–w C:\Documents and Settings\Nicole\Application Data\SampleView
2008-08-19 04:52 ——— d—–w C:\Documents and Settings\Melanie\Application Data\SampleView
2008-08-19 04:51 ——— d—–w C:\Program Files\CyberLink
2008-08-19 04:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-19 04:50 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\McAfee
2008-08-19 04:50 ——— d—–w C:\Program Files\MSN Encarta Plus
2008-08-19 04:50 ——— d—–w C:\Program Files\Microsoft Money 2005
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\Nicole\Application Data\McAfee
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\Melanie\Application Data\McAfee
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-08-19 04:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-19 04:47 ——— d—–w C:\Program Files\Google
2008-08-19 04:46 ——— d—–w C:\Program Files\Microsoft Works
2008-08-19 04:44 ——— d—–w C:\Program Files\Ahead
2008-08-19 04:43 ——— d—–w C:\Program Files\Microsoft Picture It! 10
2008-08-19 04:43 ——— d—–w C:\Program Files\Intel
2008-08-19 04:43 ——— d—–w C:\Program Files\Common Files\Ahead
2008-08-19 04:40 ——— d—–w C:\Program Files\Java
2008-08-19 04:40 ——— d—–w C:\Program Files\Common Files\New Boundary
2008-08-19 04:40 ——— d—–w C:\Program Files\Common Files\Java
2008-08-19 04:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Prism Deploy
2008-08-19 04:36 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
2008-07-19 04:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 04:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 04:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 04:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 04:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 04:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 04:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 04:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 03:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 03:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"SSA.exe"="C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" [2007-03-27 2061816]
"Sympatico Security Manager"="C:\Program Files\Bell\Security Manager\Rps.exe" [2008-03-10 311024]
"AlcFDMonitor"="C:\WINDOWS\ALCFDRTM.EXE" [2008-09-03 73728]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-04-29 158624]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 C:\WINDOWS\system32\HdAShCut.exe]
"CHotkey"="zHotkey.exe" [2004-05-17 C:\WINDOWS\zHotkey.exe]
"ShowWnd"="ShowWnd.exe" [2003-09-19 C:\WINDOWS\ShowWnd.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-05-12 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2005-05-12 C:\WINDOWS\ALCWZRD.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2008-08-19 2348584]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Digital Media Reader\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
R2 VaultClientUpgrade;Personal Vault Upgrade Service;C:\Program Files\Personal Vault\VaultClientUpgrade.exe [2008-03-07 53248]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 40704]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 61856]
S3 Radialpoint Security Services;Sympatico Security Manager;C:\Program Files\Bell\Security Manager\RpsSecurityAware.exe [2008-03-10 67824]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 245664]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Yvonne.TAMBONGFAMILY\Application Data\Mozilla\Firefox\Profiles\jkr89vla.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.imdb.com
FF -: plugin - c:\Program Files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Digital Media Reader\Veoh\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPJPI142.dll
FF -: plugin - C:\Program Files\Java\j2re1.4.2\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-02 15:36:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-02 15:37:18
ComboFix-quarantined-files.txt 2008-10-02 19:37:15
Pre-Run: 186,111,442,944 bytes free
Post-Run: 186,108,141,568 bytes free
224 — E O F — 2008-09-10 09:56:43
Thanks