Hello LDTate. Thanks for your time.
Computer is running fine at the moment. I'm just extremely wary about having passwords stolen (it happened last year).
Here's the ComboFix log…
ComboFix 08-11-21.05 - Owner 2008-11-22 10:00:29.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.160 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-10-22 to 2008-11-22 )))))))))))))))))))))))))))))))
.
2008-11-21 21:02 . 2008-11-21 21:02 d——– c:\documents and settings\Owner\Application Data\Teleca
2008-11-21 21:01 . 2007-04-24 11:33 108,680 -ra—— c:\windows\system32\drivers\s125mdm.sys
2008-11-21 21:01 . 2007-04-24 11:33 100,488 -ra—— c:\windows\system32\drivers\s125mgmt.sys
2008-11-21 21:01 . 2007-04-24 11:33 98,696 -ra—— c:\windows\system32\drivers\s125obex.sys
2008-11-21 21:01 . 2007-04-24 11:33 83,336 -ra—— c:\windows\system32\drivers\s125bus.sys
2008-11-21 21:01 . 2007-04-24 11:33 15,112 -ra—— c:\windows\system32\drivers\s125mdfl.sys
2008-11-21 21:01 . 2007-04-24 11:33 12,424 -ra—— c:\windows\system32\drivers\s125whnt.sys
2008-11-21 21:01 . 2007-04-24 11:33 12,424 -ra—— c:\windows\system32\drivers\s125wh.sys
2008-11-21 21:01 . 2007-04-24 11:33 12,424 -ra—— c:\windows\system32\drivers\s125cmnt.sys
2008-11-21 21:01 . 2007-04-24 11:33 12,424 -ra—— c:\windows\system32\drivers\s125cm.sys
2008-11-21 20:59 . 2008-11-21 20:59 d—-c— c:\windows\system32\DRVSTORE
2008-11-21 20:58 . 2008-11-21 20:58 d——– c:\documents and settings\Owner\Application Data\Sony Ericsson
2008-11-21 20:57 . 2008-11-21 20:57 d——– c:\program files\Sony Ericsson
2008-11-21 20:57 . 2008-11-21 20:59 d——– c:\program files\Common Files\Teleca Shared
2008-11-21 20:57 . 2008-11-21 20:57 d——– c:\program files\Common Files\Sony Ericsson Shared
2008-11-21 20:54 . 2008-11-21 20:57 d——– c:\documents and settings\All Users\Application Data\Teleca
2008-11-21 20:54 . 2008-11-21 20:54 d——– c:\documents and settings\All Users\Application Data\Sony Ericsson
2008-11-21 19:21 . 2008-11-21 19:21 d——– c:\program files\Mp3tag
2008-11-21 19:21 . 2008-11-21 20:17 d——– c:\documents and settings\Owner\Application Data\Mp3tag
2008-11-21 18:47 . 2008-11-21 20:18 d——– c:\program files\MediaMonkey
2008-11-21 10:41 . 2008-11-21 10:41 0 –a—— c:\windows\JDSecure20.INI
2008-11-20 16:13 . 2008-11-20 16:11 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2008-11-20 16:11 . 2008-11-20 17:00 d——– c:\documents and settings\Owner\.housecall6.6
2008-11-19 22:33 . 2008-06-19 17:24 28,544 –a—— c:\windows\system32\drivers\pavboot.sys
2008-11-19 22:32 . 2008-11-19 22:32 d——– c:\program files\Panda Security
2008-11-19 20:23 . 2008-04-13 18:12 159,232 –a—— c:\windows\system32\ptpusd.dll
2008-11-19 20:23 . 2008-04-13 12:45 15,104 –a—— c:\windows\system32\drivers\usbscan.sys
2008-11-19 20:23 . 2008-04-13 12:45 15,104 –a—— c:\windows\system32\dllcache\usbscan.sys
2008-11-19 20:23 . 2001-08-17 22:36 5,632 –a—— c:\windows\system32\ptpusb.dll
2008-11-19 11:02 . 2008-11-22 09:58 d——– c:\documents and settings\Owner\Application Data\SiteAdvisor
2008-11-19 11:02 . 2008-11-19 11:02 d——– c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-11-19 11:02 . 2008-11-19 11:02 d——– c:\documents and settings\All Users\Application Data\McAfee
2008-11-19 02:10 . 2008-11-19 09:22 d——– c:\program files\VirtualDub (delete folder to uninstall)
2008-11-19 01:59 . 2008-11-19 01:59 3,850 –a—— C:\statistics.xml
2008-11-19 01:22 . 2008-11-19 01:23 d——– c:\program files\MPEG Mediator
2008-11-19 00:53 . 2008-11-19 00:53 d——– c:\program files\Common Files\Moonlight
2008-11-19 00:53 . 2008-11-19 00:53 d——– c:\program files\Common Files\Elecard
2008-11-19 00:42 . 2008-11-19 00:42 d——– c:\documents and settings\Owner\Application Data\Media Player Classic
2008-11-18 23:30 . 2008-11-21 20:36 d——– c:\program files\CDex
2008-11-18 23:25 . 2008-11-18 23:25 d——– c:\program files\K-Lite Codec Pack
2008-11-18 23:15 . 2008-11-18 23:16 d——– c:\program files\QuickTime
2008-11-18 23:15 . 2008-11-18 23:15 d——– c:\program files\Common Files\Apple
2008-11-18 23:15 . 2008-11-18 23:15 d——– c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-18 23:14 . 2008-11-18 23:14 d——– c:\program files\Apple Software Update
2008-11-18 23:14 . 2008-11-18 23:14 d——– c:\documents and settings\All Users\Application Data\Apple
2008-11-18 23:12 . 2008-11-18 23:14 d——– c:\program files\FlaskMPEG (delete folder to uninstall)
2008-11-18 23:11 . 2008-11-18 23:11 d——– c:\program files\DVD Decrypter
2008-11-18 22:59 . 2008-11-18 23:00 d——– c:\program files\Winamp
2008-11-18 22:59 . 2008-11-18 23:10 d——– c:\documents and settings\Owner\Application Data\Winamp
2008-11-18 22:39 . 2008-11-18 22:39 d——– c:\windows\ShellNew
2008-11-18 22:38 . 2008-11-18 22:38 d——– c:\documents and settings\Owner\Application Data\Microsoft Web Folders
2008-11-18 22:22 . 2008-11-18 22:31 d——– c:\documents and settings\Owner\Application Data\ImgBurn
2008-11-18 22:16 . 2008-11-18 22:17 d——– c:\program files\ImgBurn
2008-11-18 20:55 . 2008-11-18 20:55 d——– c:\documents and settings\Owner\Application Data\Sonic
2008-11-18 20:55 . 2008-11-18 20:55 d——– c:\documents and settings\Owner\Application Data\Leadertech
2008-11-18 20:43 . 2008-11-18 20:43 d——– c:\program files\Common Files\Adobe AIR
2008-11-18 20:28 . 2008-11-18 20:42 d——– c:\program files\Common Files\Adobe
2008-11-18 20:11 . 2008-04-13 12:45 26,368 –a—— c:\windows\system32\dllcache\usbstor.sys
2008-11-18 20:10 . 2008-11-18 20:10 d——– c:\documents and settings\Owner\Application Data\HP
2008-11-18 20:10 . 2008-11-18 20:10 d——– c:\documents and settings\Owner\Application Data\CyberLink
2008-11-18 20:01 . 2008-11-18 20:01 d——– c:\program files\Windows Installer Clean Up
2008-11-18 20:01 . 2008-11-18 20:01 d——– c:\program files\MSECACHE
2008-11-18 19:50 . 2008-11-18 15:22 d——– c:\documents and settings\Administrator\Application Data\Symantec
2008-11-18 19:50 . 2008-11-18 15:22 d——– c:\documents and settings\Administrator\Application Data\Intuit
2008-11-18 19:50 . 2008-11-18 19:50 d——– c:\documents and settings\Administrator
2008-11-18 19:38 . 2008-05-15 22:53 873,134 –a—— c:\windows\system32\oem25.inf
2008-11-18 19:37 . 2008-11-18 19:37 d——– c:\program files\Windows Media Connect 2
2008-11-18 19:35 . 2008-11-18 19:35 d——– c:\windows\system32\LogFiles
2008-11-18 19:35 . 2008-11-18 19:36 d——– c:\windows\system32\drivers\UMDF
2008-11-18 18:50 . 2008-11-18 18:50 d——– c:\documents and settings\Owner\Application Data\Grisoft
2008-11-18 18:50 . 2008-11-18 18:50 d——– c:\documents and settings\All Users\Application Data\Grisoft
2008-11-18 18:50 . 2007-05-30 06:10 10,872 –a—— c:\windows\system32\drivers\AvgAsCln.sys
2008-11-18 18:11 . 2008-11-21 20:52 2,354,720 –ahs—- c:\windows\system32\drivers\fidbox.dat
2008-11-18 18:11 . 2008-11-21 20:52 12,860 –ahs—- c:\windows\system32\drivers\fidbox.idx
2008-11-18 18:08 . 2008-11-18 18:08 d——– c:\documents and settings\All Users\Application Data\MailFrontier
2008-11-18 18:08 . 2008-07-09 09:05 75,248 –a—— c:\windows\zllsputility.exe
2008-11-18 18:08 . 2008-11-18 18:09 4,212 —h—– c:\windows\system32\zllictbl.dat
2008-11-18 18:07 . 2008-11-18 18:07 d——– c:\program files\Zone Labs
2008-11-18 18:06 . 2008-11-22 09:59 d——– c:\windows\Internet Logs
2008-11-18 18:00 . 2008-11-18 18:00 d——– c:\program files\Lavasoft
2008-11-18 18:00 . 2008-11-19 18:58 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-18 17:59 . 2008-11-18 17:59 d——– c:\program files\Common Files\Wise Installation Wizard
2008-11-18 17:54 . 2008-11-18 17:55 d——– c:\program files\SpywareBlaster
2008-11-18 17:54 . 2008-11-19 16:55 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-11-18 17:49 . 2008-11-18 17:49 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-18 17:49 . 2008-11-18 17:49 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-18 17:49 . 2008-11-18 17:49 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-18 17:49 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-18 17:49 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-18 16:48 . 2008-11-18 17:34 d——– c:\program files\Spybot - Search & Destroy
2008-11-18 16:48 . 2008-11-18 17:35 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-18 16:45 . 2008-11-18 16:45 d——– c:\program files\Trend Micro
2008-11-18 16:41 . 2008-11-20 14:28 d–hs—- c:\documents and settings\Owner\Temporary Internet Files
2008-11-18 16:41 . 2008-11-18 15:31 d–hs—- c:\documents and settings\Owner\History
2008-11-18 16:40 . 2008-11-18 16:40 1,716 -rahs—- c:\windows\system32\drivers\103C_HP_NTBK_Presario V5000 (EZ429UA#ABA)_YN_0Pres_QCND6260HY3_E413900001_46_I30A8_SHP_V56.37_BF.13_T060510_
WXH2_L409_M503_J40_7Intel_8Celeron M 410_91.46_#081118_N14E44311_(EZ429UA#ABA)_XMOBILE_CN10_Z_2F.13.MRK
2008-11-18 16:38 . 2008-11-18 15:22 d——– c:\windows\system32\config\systemprofile\Application Data\Symantec
2008-11-18 16:38 . 2008-11-18 15:22 d——– c:\windows\system32\config\systemprofile\Application Data\Intuit
2008-11-18 16:26 . 2008-11-18 16:26 d——– c:\program files\Alwil Software
2008-11-18 16:25 . 2008-11-18 16:25 d——– c:\windows\Sun
2008-11-18 16:13 . 2008-11-18 16:13 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-18 16:13 . 2008-11-18 16:13 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-18 16:08 . 2008-11-18 16:08 0 –a—— c:\windows\nsreg.dat
2008-11-18 15:57 . 2008-11-18 15:57 d——– c:\program files\MSXML 4.0
2008-11-18 15:41 . 2008-06-13 05:05 272,128 ——— c:\windows\system32\dllcache\bthport.sys
2008-11-18 15:41 . 2008-08-14 04:04 138,496 ——— c:\windows\system32\dllcache\afd.sys
2008-11-18 15:38 . 2008-09-15 06:12 1,846,400 ——— c:\windows\system32\dllcache\win32k.sys
2008-11-18 15:38 . 2008-09-08 04:41 333,824 ——— c:\windows\system32\dllcache\srv.sys
2008-11-18 15:37 . 2008-08-14 04:11 2,189,184 ——— c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-18 15:37 . 2008-08-14 04:09 2,145,280 ——— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-18 15:37 . 2008-08-14 03:33 2,066,048 ——— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-18 15:37 . 2008-08-14 03:33 2,023,936 ——— c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-18 15:34 . 2008-04-11 13:04 691,712 ——— c:\windows\system32\dllcache\inetcomm.dll
2008-11-18 15:34 . 2008-10-24 05:21 455,296 ——— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-18 15:34 . 2008-05-01 08:33 331,776 ——— c:\windows\system32\dllcache\msadce.dll
2008-11-18 15:34 . 2008-05-08 08:02 203,136 ——— c:\windows\system32\dllcache\rmcast.sys
2008-11-18 15:33 . 2008-09-04 11:15 1,106,944 ——— c:\windows\system32\dllcache\msxml3.dll
2008-11-18 15:33 . 2008-10-15 10:34 337,408 ——— c:\windows\system32\dllcache\netapi32.dll
2008-11-18 15:24 . 2008-11-18 15:24 d——– c:\windows\system32\scripting
2008-11-18 15:24 . 2008-11-18 15:24 d——– c:\windows\system32\en
2008-11-18 15:24 . 2008-11-18 15:24 d——– c:\windows\system32\bits
2008-11-18 15:24 . 2008-11-18 15:24 d——– c:\windows\l2schemas
2008-11-18 15:21 . 2008-11-18 15:21 d——– c:\windows\ServicePackFiles
2008-11-18 15:17 . 2008-11-18 15:17 d——– c:\windows\EHome
2008-11-18 15:12 . 2004-08-03 22:41 1,309,184 ——— c:\windows\system32\drivers\mtlstrm.sys
2008-11-18 15:12 . 2004-08-03 22:41 1,041,536 ——— c:\windows\system32\drivers\hsfdpsp2.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-20 15:08 2,864 —-a-w c:\windows\system32\winsock.dll
2008-11-20 15:08 2,864 —-a-w c:\windows\system32\dllcache\winsock.dll
2008-11-19 04:37 ——— d—–w c:\program files\microsoft frontpage
2008-11-18 23:30 ——— d—–w c:\program files\Quicken
2008-11-18 23:27 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-18 23:20 ——— d—–w c:\program files\Common Files\Sonic Shared
2008-11-18 22:26 ——— d—–w c:\program files\HPQ
2008-11-18 22:13 ——— d—–w c:\program files\Java
2008-11-18 21:40 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-18 21:31 ——— d—–w c:\program files\WildTangent
2008-11-18 21:31 ——— d—–w c:\program files\Synaptics
2008-11-18 21:31 ——— d—–w c:\program files\Sonic
2008-11-18 21:31 ——— d—–w c:\program files\Quickensetup
2008-11-18 21:29 ——— d—–w c:\program files\NetWaiting
2008-11-18 21:29 ——— d—–w c:\program files\Netscape
2008-11-18 21:29 ——— d—–w c:\program files\music_now
2008-11-18 21:29 ——— d—–w c:\program files\MSN Encarta Plus
2008-11-18 21:28 ——— d—–w c:\program files\Microsoft Office Trial Wizard
2008-11-18 21:27 ——— d—–w c:\program files\Intel
2008-11-18 21:26 ——— d—–w c:\program files\Google
2008-11-18 21:26 ——— d—–w c:\program files\CONEXANT
2008-11-18 21:26 ——— d—–w c:\program files\Common Files\TiVo Shared
2008-11-18 21:25 ——— d—–w c:\program files\Common Files\SureThing Shared
2008-11-18 21:25 ——— d—–w c:\program files\Common Files\LightScribe
2008-11-18 21:25 ——— d—–w c:\program files\Common Files\Java
2008-11-18 21:25 ——— d—–w c:\program files\Common Files\InstallShield
2008-11-18 21:22 ——— d—–w c:\documents and settings\Owner\Application Data\Intuit
2008-11-18 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\Sonic
2008-11-18 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\SBSI
2008-11-18 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\Intuit
2008-11-18 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\InstallShield
2008-11-18 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\HP
2008-11-18 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\CyberLink
2008-11-18 20:50 ——— d—–w c:\program files\Hp
2008-11-18 20:50 ——— d—–w c:\program files\Hewlett-Packard
2008-11-10 21:17 2,296,339 —-a-w c:\windows\system32\x264vfw.dll
2008-11-02 14:02 7,680 —-a-w c:\windows\system32\ff_vfw.dll
2008-10-28 22:35 684,032 —-a-w c:\windows\system32\divx.dll
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 20:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 20:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 20:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 20:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 20:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 20:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 20:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 20:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 20:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 20:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-03 17:41 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
2008-09-30 22:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-25 08:03 81,920 —-a-w c:\windows\system32\dpl100.dll
2008-09-19 21:57 3,596,288 —-a-w c:\windows\system32\qt-dx331.dll
2008-09-15 12:12 1,846,400 —-a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ——w c:\windows\system32\msxml6.dll
2008-09-10 01:14 1,307,648 ——w c:\windows\system32\dllcache\msxml6.dll
2008-09-04 17:15 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-08-27 19:54 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
2008-08-25 08:38 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-08-25 08:37 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-08-23 05:56 635,848 ——w c:\windows\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-18 136600]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 454656]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1015808]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2006-02-22 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 528384]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 c:\windows\system32\CHDAudPropShortcut.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^StartUp^Vongo Tray.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\StartUp\Vongo Tray.lnk
backup=c:\windows\pss\Vongo Tray.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 18:12 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
–a—— 2006-03-23 06:13 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
–a—— 2006-03-23 06:17 118784 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
–a—— 2006-03-23 06:17 94208 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a—— 2005-08-11 17:30 249856 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
–a—— 2006-03-07 14:38 131072 c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
–a—— 2006-04-11 22:54 102400 c:\program files\Hp\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
–a—— 2006-02-09 10:52 643072 c:\windows\CREATOR\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-19 28544]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-18 110160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-18 20560]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);c:\windows\system32\DRIVERS\s125bus.sys [2008-11-21 83336]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s125mdfl.sys [2008-11-21 15112]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s125mdm.sys [2008-11-21 108680]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s125mgmt.sys [2008-11-21 100488]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s125obex.sys [2008-11-21 98696]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c74802c-b7e1-11dd-9644-0014a5ad84c0}]
\Shell\AutoRun\command - f:\jdsecure\Windows\JDSecure20.exe
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\4cxnpn6a.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://webmail.mizzou.edu/
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-22 10:02:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ???@L??????(?@???????@
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-22 10:03:46
ComboFix-quarantined-files.txt 2008-11-22 16:03:40
Pre-Run: 12,608,892,928 bytes free
Post-Run: 12,582,113,280 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
310 — E O F — 2008-11-20 15:02:18