Hello, thanks tomk for taking the time to help me out.
My computer basically wouldnt turn on last night so i ran a repair install. As a result im back to service pack 1 with Xp.
Here is my combofix report. I tried to look through it and understand some of it. A lot of the files a recognize, but some i dont. My copy paste and drag work again. I can now again see my start menu and bar. I'm still concerned though. I pulled my important data and put it onto flashes and cd's, so it could break now and not much would be lost.
I tried to load service pack 2, but it just freezes. I know a repair install doesnt fix everything and the only way to do so really is a fresh install of xp. So, my plan is, if you can't help me identify the problems here, i will just go through the trouble of doing a fresh install.
thank you tom, I hope you can help me identify what exactly went wrong.
-----------------------------------------------------
ComboFix 08-11-29.01 - Owner 2008-11-29 13:55:30.1 - NTFSx86
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\Tvm.log
c:\program files\INSTALL.LOG
c:\winnt\bar.exe
c:\winnt\didduid.ini
c:\winnt\Downloaded Program Files\setup.inf
c:\winnt\Readme.txt
c:\winnt\system32\foyz.exe
c:\winnt\system32\fpifurs.exe
c:\winnt\system32\wnjwrlc.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SVCPROC
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-29 )))))))))))))))))))))))))))))))
.
2008-11-29 12:15 . 2008-11-29 12:17 <DIR> d-------- C:\4830a2c041b2b3a704
2008-11-29 12:00 . 2008-11-29 12:01 <DIR> d-------- C:\f9b443ae62945c483f7b
2008-11-28 23:12 . 2001-08-17 22:36 112,640 --a--c--- c:\winnt\system32\dllcache\xrxwiadr.dll
2008-11-28 23:12 . 2001-08-17 22:37 99,865 --a--c--- c:\winnt\system32\dllcache\xlog.exe
2008-11-28 23:12 . 2001-08-17 22:37 27,648 --a--c--- c:\winnt\system32\dllcache\xrxftplt.exe
2008-11-28 23:12 . 2001-08-17 22:36 23,040 --a--c--- c:\winnt\system32\dllcache\xrxwbtmp.dll
2008-11-28 23:12 . 2001-08-17 12:49 18,688 --a--c--- c:\winnt\system32\dllcache\wvchntxx.sys
2008-11-28 23:12 . 2001-08-17 22:36 17,408 --a--c--- c:\winnt\system32\dllcache\xrxscnui.dll
2008-11-28 23:12 . 2001-08-17 12:11 16,970 --a--c--- c:\winnt\system32\dllcache\xem336n5.sys
2008-11-28 23:12 . 2001-08-17 12:49 12,160 --a--c--- c:\winnt\system32\dllcache\wsiintxx.sys
2008-11-28 23:12 . 2001-08-17 22:36 7,680 --a--c--- c:\winnt\system32\dllcache\wshirda.dll
2008-11-28 23:12 . 2001-08-17 22:37 4,608 --a--c--- c:\winnt\system32\dllcache\xrxflnch.exe
2008-11-28 23:10 . 2001-08-17 13:28 899,146 --a--c--- c:\winnt\system32\dllcache\r2mdkxga.sys
2008-11-28 23:09 . 2002-08-29 01:04 1,947,904 --a--c--- c:\winnt\system32\dllcache\ntkrnlpa.exe
2008-11-28 23:08 . 2001-08-17 13:28 802,683 --a--c--- c:\winnt\system32\dllcache\ltsm.sys
2008-11-28 23:07 . 2001-08-17 14:56 1,733,120 --a--c--- c:\winnt\system32\dllcache\g400d.dll
2008-11-28 23:06 . 2001-08-17 12:13 980,034 --a--c--- c:\winnt\system32\dllcache\cicap.sys
2008-11-28 23:05 . 2002-08-29 02:03 2,042,240 --a--c--- c:\winnt\system32\dllcache\ntoskrnl.exe
2008-11-28 23:05 . 2001-08-17 14:56 66,048 --a--c--- c:\winnt\system32\dllcache\s3legacy.dll
2008-11-28 23:02 . 2008-11-29 13:59 <DIR> d--hs---- c:\documents and settings\NetworkService.NT AUTHORITY
2008-11-28 23:02 . 2008-11-28 23:02 <DIR> d--hs---- c:\documents and settings\LocalService.NT AUTHORITY
2008-11-28 22:55 . 2003-03-31 07:00 13,463,552 --a--c--- c:\winnt\system32\dllcache\hwxjpn.dll
2008-11-28 22:54 . 2001-08-17 22:36 2,134,528 --a--c--- c:\winnt\system32\dllcache\EXCH_smtpsnap.dll
2008-11-28 22:53 . 2001-08-17 22:36 171,008 --a------ c:\winnt\system32\LXAESUI.DLL
2008-11-28 22:53 . 2001-07-21 14:40 3,144 --a--c--- c:\winnt\system32\dllcache\srgb.icm
2008-11-28 22:52 . 2003-03-31 07:00 3,346,432 --a--c--- c:\winnt\system32\dllcache\msgr3en.dll
2008-11-28 22:52 . 2003-03-31 07:00 106,562 --a--c--- c:\winnt\system32\dllcache\srchctls.dll
2008-11-28 22:52 . 2008-11-28 22:52 749 -rah----- c:\winnt\WindowsShell.Manifest
2008-11-28 22:52 . 2008-11-28 22:52 749 -rah----- c:\winnt\system32\wuaucpl.cpl.manifest
2008-11-28 22:52 . 2008-11-28 22:52 749 -rah----- c:\winnt\system32\sapi.cpl.manifest
2008-11-28 22:52 . 2008-11-28 22:52 749 -rah----- c:\winnt\system32\ncpa.cpl.manifest
2008-11-28 22:52 . 2008-11-28 22:52 488 -rah----- c:\winnt\system32\logonui.exe.manifest
2008-11-28 22:50 . 2003-03-31 07:00 1,267,712 --a--c--- c:\winnt\system32\dllcache\cimwin32.dll
2008-11-28 22:49 . 2002-08-29 01:06 182,400 --a------ c:\winnt\system32\drivers\rdpdr.sys
2008-11-28 22:49 . 2002-08-29 01:06 182,400 --a--c--- c:\winnt\system32\dllcache\rdpdr.sys
2008-11-28 22:47 . 2002-08-29 01:27 56,576 --a------ c:\winnt\system32\drivers\redbook.sys
2008-11-28 22:47 . 2002-08-29 01:27 56,576 --a--c--- c:\winnt\system32\dllcache\redbook.sys
2008-11-28 22:47 . 2001-08-17 13:59 50,048 --a------ c:\winnt\system32\drivers\DMusic.sys
2008-11-28 22:47 . 2001-08-17 13:59 50,048 --a--c--- c:\winnt\system32\dllcache\dmusic.sys
2008-11-28 22:47 . 2002-08-29 01:32 5,888 --a------ c:\winnt\system32\drivers\splitter.sys
2008-11-28 22:47 . 2002-08-29 01:32 5,888 --a--c--- c:\winnt\system32\dllcache\splitter.sys
2008-11-28 22:36 . 2002-08-29 03:46 38,024 --a------ c:\winnt\system32\drivers\termdd.sys
2008-11-28 22:36 . 2002-08-29 03:46 38,024 --a--c--- c:\winnt\system32\dllcache\termdd.sys
2008-11-28 20:58 . 2008-11-28 20:58 <DIR> d-------- c:\program files\Trend Micro
2008-11-28 20:49 . 2008-11-28 20:49 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-28 20:49 . 2008-11-28 20:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-28 20:49 . 2008-10-26 21:53 38,496 --a------ c:\winnt\system32\drivers\mbamswissarmy.sys
2008-11-28 20:49 . 2008-10-26 21:53 15,504 --a------ c:\winnt\system32\drivers\mbam.sys
2008-11-28 17:24 . 2008-11-29 11:14 1,609,388,032 --a------ c:\winnt\MEMORY.DMP
2008-11-28 00:58 . 2008-11-28 00:58 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2008-11-27 15:45 . 2008-11-27 15:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\ATI
2008-11-27 15:15 . 2003-06-26 13:02 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Symantec
2008-11-27 15:15 . 2003-06-26 12:58 <DIR> d-------- c:\documents and settings\Administrator\Application Data\InterTrust
2008-11-27 15:15 . 2008-11-27 15:15 <DIR> d-------- c:\documents and settings\Administrator
2008-11-27 10:21 . 2008-11-27 10:21 <DIR> d-------- c:\winnt\tmp
2008-11-26 12:53 . 2008-11-26 12:53 <DIR> d-------- c:\program files\iTunes
2008-11-26 12:53 . 2008-11-26 12:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-26 12:50 . 2008-11-26 12:51 <DIR> d-------- c:\program files\QuickTime
2008-11-20 15:44 . 2008-11-20 15:44 42,320 --a------ c:\winnt\system32\xfcodec.dll
2008-11-20 01:34 . 2007-10-07 21:24 60,041 --a------ C:\300-1.jpg
2008-11-20 01:33 . 2004-09-07 14:29 41,190 --a------ C:\pie.jpg
2008-11-19 16:02 . 2008-08-13 12:10 170,920 --a------ C:\yowzurrr.jpg
2008-11-19 16:02 . 2007-10-13 21:18 48,872 --a------ C:\rear.jpg
2008-11-19 16:02 . 2008-11-15 01:23 15,380 --a------ C:\lips.jpg
2008-11-19 08:28 . 2008-11-19 08:35 <DIR> d-------- c:\documents and settings\Owner\Contacts
2008-11-19 08:25 . 2008-11-19 08:25 268 --ah----- C:\sqmdata00.sqm
2008-11-19 08:25 . 2008-11-19 08:25 244 --ah----- C:\sqmnoopt00.sqm
2008-11-19 08:24 . 2008-11-19 08:24 <DIR> d-------- c:\program files\MSN Messenger
2008-11-12 13:07 . 2008-11-12 13:07 82,934 --a------ C:\hph.jpg
2008-11-12 11:00 . 2008-11-12 11:00 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-04 10:30 . 2008-11-04 10:30 90,112 --a------ c:\winnt\system32\QuickTimeVR.qtx
2008-11-04 10:30 . 2008-11-04 10:30 57,344 --a------ c:\winnt\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-29 18:40 --------- d-s---w c:\program files\Xfire
2008-11-29 18:36 --------- d-----w c:\documents and settings\Owner\Application Data\Xfire
2008-11-29 18:35 --------- d-----w c:\program files\Steam
2008-11-27 20:47 --------- d-----w c:\program files\ATI
2008-11-27 20:42 --------- d-----w c:\program files\ATI Technologies
2008-11-26 17:53 --------- d-----w c:\program files\iPod
2008-11-26 17:53 --------- d-----w c:\program files\Common Files\Apple
2008-11-25 23:29 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-25 19:14 --------- d-----w c:\program files\Viewpoint
2008-11-24 08:34 --------- d-----w c:\documents and settings\Owner\Application Data\uTorrent
2008-10-29 03:10 3,341,824 ----a-w c:\winnt\system32\drivers\ati2mtag.sys
2008-10-29 01:18 53,248 ----a-w c:\winnt\system32\drivers\ati2erec.dll
2008-10-16 18:35 --------- d-----w c:\program files\Activision
2008-10-16 17:24 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-13 19:33 --------- d-----w c:\documents and settings\Owner\Application Data\ATI
2008-10-13 19:23 --------- d-----w c:\program files\DAEMON Tools Lite
2008-10-13 19:17 717,296 ----a-w c:\winnt\system32\drivers\sptd.sys
2008-10-13 17:03 --------- d-----w c:\program files\SAS
2008-10-03 20:15 --------- d-----w c:\program files\Creative
2008-10-01 20:21 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-01 20:01 --------- d-----w c:\documents and settings\Owner\Application Data\Creative
2008-10-01 19:49 --------- d-----w c:\program files\Decisioneering
2008-10-01 19:33 --------- d-----w c:\program files\Bonjour
2008-09-30 16:11 --------- d-----w c:\program files\Common Files\InstallShield
2008-09-30 16:11 --------- d-----w c:\documents and settings\Owner\Application Data\Decisioneering
2008-09-30 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2008-09-30 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\Decisioneering
2008-09-30 15:29 --------- d-----w c:\program files\Microsoft ActiveSync
2008-01-21 07:06 32 -c--a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2005-03-16 05:08 41 -c--a-w c:\documents and settings\Owner\Application Data\tvmuknwrd.dll
2005-03-16 05:08 34 -c--a-w c:\documents and settings\Owner\Application Data\tvmcwrd.dll
2005-03-15 13:01 268,607 ----a-w c:\documents and settings\Owner\Application Data\tvmknwrd.dll
2004-10-18 20:40 60,288 -c--a-w c:\documents and settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2004-09-26 02:46 430,315 -c--a-w c:\documents and settings\Owner\CdStart.exe
2004-01-23 21:24 9,380,112 ------w c:\documents and settings\GameSpot DLX Secure Delivery\ff7demo.zip
1784-02-06 00:28 65,536 -c----w c:\winnt\inf\copyinf.exe
1784-02-06 00:28 242,432 -c----w c:\winnt\inf\rt2500usb.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"GWMDMMSG"="GWMDMMSG.exe" [2002-08-06 c:\winnt\GWMDMMSG.exe]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 c:\winnt\system32\SK9910DM.EXE]
"P17Helper"="P17.dll" [2006-03-17 c:\winnt\system32\P17.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2002-12-03 c:\winnt\MIDIDEF.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\winnt\system32\tscupgrd.exe" [2003-03-31 40960]
"DefaultP17MIDI"="MIDIDEF.EXE" [2002-12-03 c:\winnt\MIDIDEF.EXE]
"DefaultP17"="P17Def.Exe" [2005-05-03 c:\winnt\P17DEF.EXE]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - c:\program files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-05-04 2913840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\winnt\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\winnt\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\winnt\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^WkCalRem.LNK]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\WkCalRem.LNK
backup=c:\winnt\pss\WkCalRem.LNKStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
???? [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
???? [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\winnt\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-09-03 19:12 111936 c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
--a--c--- 2003-01-20 21:57 106574 c:\program files\ATI Multimedia\main\LaunchPd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
--a------ 2007-10-04 17:38 307200 c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2005-08-30 20:05 344064 c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2003-03-31 07:00 13312 c:\winnt\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-08-08 07:11 490952 c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GWMDMpi]
--a------ 2002-08-06 14:24 53248 c:\winnt\GWMDMpi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2004-08-09 05:03 221184 c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-08-09 05:03 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
--a--c--- 2002-07-16 19:21 28672 c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2003-04-02 12:40 4616192 c:\winnt\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-09-16 12:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2008-08-29 16:11 61440 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-10-10 10:28 1410296 c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2006-11-09 15:07 49263 c:\program files\Java\jre1.5.0_10\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
--a--c--- 2005-06-16 10:24 100056 c:\progra~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a--c--- 2004-08-21 14:20 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 01:00 90112 c:\winnt\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
--a--c--- 2004-04-19 11:06 102400 c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GWMDMMSG]
--a------ 2002-08-06 14:24 90112 c:\winnt\GWMDMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hot Key Kbd 9910 Daemon]
--a------ 2001-01-03 13:50 66048 c:\winnt\system32\SK9910DM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
--a------ 2006-03-17 16:11 81408 c:\winnt\system32\P17.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymWSC"=2 (0x2)
"MskService"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SvcProc"=2 (0x2)
"SNDSrvc"=3 (0x3)
"RSVP"=3 (0x3)
"ose"=3 (0x3)
"NetSvc"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"CryptSvc"=3 (0x3)
"aspnet_state"=3 (0x3)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"LiveUpdate"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"0157391197826520mcinstcleanup"=2 (0x2)
"MSK80Service"=2 (0x2)
"MpfService"=2 (0x2)
"McSysmon"=3 (0x3)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
"NVSvc"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"ATI Smart"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kazaa Lite K++\\Kazaa.kpp"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Steam\\SteamApps\\jkenney5@bellsouth.net\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\ABC\\abc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
Contents of the 'Scheduled Tasks' folder
2008-11-26 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{00000000-0000-41CD-A9C3-9E7A8D54F67E} - (no file)
BHO-{00000000-0000-41D0-AC34-2F527C5D73C0} - (no file)
BHO-{00000000-0000-44B9-93E9-7C06E053E603} - (no file)
BHO-{00000000-0000-454D-846D-C58A4703BB13} - (no file)
BHO-{00000000-0000-459C-9431-DCC79EBD28D5} - (no file)
BHO-{00000000-0000-4605-AF20-2FE6FDC0C8BA} - (no file)
BHO-{00000000-0000-471D-B8DD-14A86375FAB8} - (no file)
BHO-{00000000-0000-4902-9464-3B4B93C142DA} - (no file)
BHO-{00000000-0000-4A51-8416-487F2E9D62E4} - (no file)
BHO-{00000000-0000-4A72-8CDA-5F621B3A2BAB} - (no file)
BHO-{00000000-0000-4B5D-9A9D-F09A0D172484} - (no file)
BHO-{00000000-0000-4C21-848F-5E2A5D6D2373} - (no file)
BHO-{00000000-0000-4C22-A31A-0FDB9B1781A4} - (no file)
BHO-{00000000-0000-4E80-83AE-71AC3A168AE7} - (no file)
BHO-{10ADCD4E-EE28-4064-B4E2-6A953BCB32A6} - (no file)
BHO-{1E9DCE57-D1D0-4C51-A7D4-E01677B945F3} - (no file)
BHO-{3196C868-83C9-47A5-8109-177F24711B3D} - (no file)
BHO-{345D7CF0-2C6E-4A47-A422-35232366E9E7} - (no file)
BHO-{3C55DBE7-C6B8-475E-971B-8FB86AB07703} - (no file)
BHO-{48259238-FC92-4AE4-B632-5FE0682D48C7} - (no file)
BHO-{58B0CDBD-0B90-4F6A-89AD-3133C234B375} - (no file)
BHO-{753302A0-037A-4089-967F-5C0F1476039E} - (no file)
BHO-{7908953C-7477-4950-A7BF-B9BDB79C1217} - (no file)
BHO-{8D6A1F08-F7DD-4F85-9B2E-3AF604354328} - (no file)
BHO-{92C260D1-8BAC-4095-85CD-DAF6A1D67CB4} - (no file)
BHO-{AD4BB598-B97A-40F8-A227-F17CCC978192} - (no file)
BHO-{AED2C40A-9BE6-4436-9ACF-16AFF65CD426} - (no file)
BHO-{BAEF0FFA-0068-4B3D-B8F9-188345032399} - (no file)
BHO-{C0F6BFE3-109E-4E66-8699-E78721DB5C76} - (no file)
BHO-{D2574F54-A61B-4915-A64C-DFC15D8B5D93} - (no file)
BHO-{DC8B6358-6D67-4AF6-ACB0-9E9BA5A9099F} - (no file)
BHO-{E64E4E12-84DC-4A1E-A75D-CE60F41B9712} - (no file)
BHO-{F0CF53D0-C629-4EAC-AA96-DFF78E317D72} - (no file)
BHO-{F52973A8-8AA5-4F92-8472-22F85EACB176} - (no file)
BHO-{FAC19AC3-A3B6-4154-9588-0EE7142B2D4E} - (no file)
HKLM-RunServices-System Support - system32.exe
MSConfigStartUp-ATICCC - c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
MSConfigStartUp-BellSouthWCC_McciTrayApp - c:\program files\BellSouthWCC\McciTrayApp.exe
MSConfigStartUp-BJCFD - c:\program files\BroadJump\Client Foundation\CFD.exe
MSConfigStartUp-cintgqkw - c:\winnt\system32\sigsxx.exe
MSConfigStartUp-DAEMON Tools Pro Agent - c:\program files\DAEMON Tools Pro\DTProAgent.exe
MSConfigStartUp-egpqtlt - c:\winnt\system32\pqdvzi.exe
MSConfigStartUp-ixpfqpcp - c:\program files\ixpfqpcp\ixpfqpcp.exe
MSConfigStartUp-Keyboard Preload Check - c:\oemdrvrs\KEYB\Preload.exe
MSConfigStartUp-KLog - c:\program files\Keyboard Logger\Keyspy.exe
MSConfigStartUp-mcagent_exe - c:\program files\McAfee.com\Agent\mcagent.exe
MSConfigStartUp-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
MSConfigStartUp-MPSExe - c:\progra~1\mcafee.com\mps\mscifapp.exe
MSConfigStartUp-MSKDetectorExe - c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
MSConfigStartUp-OASClnt - c:\program files\McAfee.com\VSO\oasclnt.exe
MSConfigStartUp-otxysb - c:\winnt\system32\rgvtzvnb.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
MSConfigStartUp-uxxet - c:\winnt\system32\aqbk.exe
MSConfigStartUp-VirusScan Online - c:\program files\McAfee.com\VSO\mcvsshld.exe
MSConfigStartUp-VSOCheckTask - c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe
MSConfigStartUp-WTSS - c:\winnt\System32\wapitr.exe
MSConfigStartUp-CTXFIREG - CTxfiReg.exe
MSConfigStartUp-System Support - system32.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\yfxom20q.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-29 13:59:55
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\winnt\System32\ODBC32.dll
c:\winnt\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\winnt\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(832)
c:\winnt\System32\dssenh.dll
.
------------------------ Other Running Processes ------------------------
.
c:\winnt\system32\ati2evxx.exe
c:\winnt\system32\ati2evxx.exe
c:\winnt\system32\rundll32.exe
c:\winnt\system32\wpabaln.exe
c:\winnt\system32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2008-11-29 14:04:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-29 19:04:06
Pre-Run: 17,595,215,872 bytes free
Post-Run: 17,698,848,768 bytes free
winxpsp1_en_hom_bf.exe
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Home Edition" /fastdetect /noexecute=optin
395 --- E O F --- 2008-11-12 16:02:12