Here is the report from the combofix!
ComboFix 08-12-07.04 - Kishkoway 2008-12-09 13:39:03.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.379 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jennifer\Desktop\CFScript.txt
* Created a new restore point
FILE ::
e:\frostwiresounds\Lawless party\Iron and Wine - Boy with a Coin.mp3
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\frostwiresounds\Lawless party\Iron and Wine - Boy with a Coin.mp3
.
((((((((((((((((((((((((( Files Created from 2008-11-09 to 2008-12-09 )))))))))))))))))))))))))))))))
.
2008-12-09 03:18 . 2008-12-09 03:18 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-12-09 02:48 . 2008-12-09 03:19 d——– c:\documents and settings\Jennifer\.SunDownloadManager
2008-12-09 02:46 . 2008-12-09 03:18 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-09 00:51 . 2008-12-09 00:51 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-09 00:51 . 2008-12-09 00:51 d——– c:\documents and settings\Jennifer\Application Data\Malwarebytes
2008-12-09 00:51 . 2008-12-09 00:51 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-09 00:51 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-09 00:51 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-08 20:45 . 2008-12-08 20:45 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-08 20:02 . 2008-12-08 20:03 d——– C:\rsit
2008-12-08 20:02 . 2008-12-08 21:55 d——– c:\program files\trend micro
2008-12-05 15:18 . 2008-12-05 15:19 d——– c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition Classic
2008-12-03 22:53 . 2008-12-03 22:53 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-16 07:29 . 2008-11-16 07:29 d——– c:\program files\Kiwee Toolbar
2008-11-16 07:29 . 2008-11-16 07:29 d——– c:\documents and settings\LocalService\Application Data\agi
2008-11-16 07:27 . 2008-11-16 07:27 2,117,632 –a—— c:\windows\system32\python25.dll
2008-11-16 07:27 . 2008-09-16 11:26 1,332,197 –a—— c:\windows\system32\pythondll.zip
2008-11-16 07:27 . 2008-11-16 07:27 339,968 –a—— c:\windows\system32\pythoncom25.dll
2008-11-16 07:27 . 2008-11-16 07:27 114,688 –a—— c:\windows\system32\pywintypes25.dll
2008-11-14 05:32 . 2008-11-14 05:32 d——– c:\documents and settings\All Users\Application Data\Blizzard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 08:18 ——— d—–w c:\program files\Java
2008-12-09 07:38 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-09 07:38 ——— d—–w c:\documents and settings\Jennifer\Application Data\Aim
2008-12-09 05:20 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-08 20:35 ——— d—–w c:\documents and settings\Jennifer\Application Data\BitTorrent
2008-12-06 09:03 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-04 15:36 3,396 –sha-w c:\windows\system32\dllcache\winsvcmgmnt.dll
2008-12-02 12:04 ——— d—–w c:\documents and settings\Jennifer\Application Data\Skype
2008-12-02 04:54 ——— d—–w c:\program files\CA Yahoo! Anti-Spy
2008-11-21 23:22 ——— d—–w c:\documents and settings\Jennifer\Application Data\SecondLife
2008-11-18 03:50 ——— d—–w c:\program files\MySpace
2008-11-01 15:55 ——— d—–w c:\program files\MSXML 6.0
2008-10-10 18:37 ——— d—–w c:\documents and settings\Jennifer\Application Data\Winamp
2008-10-09 19:25 ——— d—–w c:\program files\Netflix
2006-08-15 03:28 24,096 -c–a-w c:\documents and settings\Jennifer\Application Data\GDIPFONTCACHEV1.DAT
2008-01-15 14:13 861 –sha-w c:\windows\system32\dllcache\aamonit.dll
2008-01-15 14:13 847,872 –sha-r c:\windows\system32\dllcache\libeay32.dll
2008-01-15 14:13 159,744 –sha-r c:\windows\system32\dllcache\ssleay32.dll
2008-01-15 14:13 64,000 –sha-r c:\windows\system32\dllcache\syschk32.dll
2008-01-15 14:13 488 –sha-r c:\windows\system32\dllcache\winsvcf.dll
2008-01-15 14:13 895 –sha-r c:\windows\system32\dllcache\winsvcn.dll
2007-07-31 22:42 55,296 -csha-r c:\windows\system32\spool\drivers\raddrv.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-08_22.35.02.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-12 05:22:00 135,168 -c–a-w c:\windows\system32\java.exe
+ 2008-12-09 08:18:21 144,792 —-a-w c:\windows\system32\java.exe
- 2007-07-12 05:22:04 135,168 -c–a-w c:\windows\system32\javaw.exe
+ 2008-12-09 08:18:21 144,792 —-a-w c:\windows\system32\javaw.exe
- 2007-07-12 06:22:38 139,264 -c–a-w c:\windows\system32\javaws.exe
+ 2008-12-09 08:18:21 148,888 —-a-w c:\windows\system32\javaws.exe
+ 2008-12-09 08:18:44 16,384 —-atw c:\windows\temp\Perflib_Perfdata_e28.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 4662776]
"SpybotSD TeaTimer"="e:\spybot - search & destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-01-19 339968]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-05-26 180269]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"WinampAgent"="e:\winamp\winampa.exe" [2007-10-10 36352]
"avgnt"="c:\program files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 327720]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-09 136600]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-05-16 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2005-02-24 573440]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
WinZip Quick Pick.lnk - e:\winzip\WZQKPICK.EXE [2006-05-03 122880]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"e:\\World of Warcraft\\WoW-1.2.4-to-1.3.0-enUS-downloader.exe"=
"e:\\World of Warcraft\\WoW-1.2.3-patch-enUS-Downloader.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\SAM\\SAMBC.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"e:\\SecondLife\\SLVoice.exe"=
"e:\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"e:\\Soulseek\\SoulseekNS\\slsk.exe"=
"e:\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:WoW
"6112:TCP"= 6112:TCP:WoW
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s []
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s []
R3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\DRIVERS\getnd5b.sys [2005-02-24 44544]
S2 PostgreSQL;PostgreSQL Database Server;"c:\program files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe" runservice -N "PostgreSQL" -D "c:\program files\PostgreSQL\8.0-beta2-dev3\data\" []
*Newly Created Service* - JAVAQUICKSTARTERSERVICE
.
Contents of the 'Scheduled Tasks' folder
2008-12-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
c:\windows\Downloaded Program Files\DoggieDash.1.0.0.6.dll - O16 -: {6715D12F-213F-4C6E-ACE1-8A363F550B96}
hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab
c:\windows\Downloaded Program Files\DoggieDash.1.0.0.6.inf
FireFox -: Profile - c:\documents and settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-amo&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
FF -: plugin - c:\documents and settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07051001.dll
FF -: plugin - c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
FF -: plugin - e:\divx web player\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - e:\divx web player\DivX\DivX Player\npDivxPlayerPlugin.dll
FF -: plugin - e:\divx web player\DivX\DivX Web Player\npdivx32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-09 13:41:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(480)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2008-12-09 13:42:43
ComboFix-quarantined-files.txt 2008-12-09 18:41:46
ComboFix2.txt 2008-12-09 05:46:04
ComboFix3.txt 2008-12-09 03:36:17
Pre-Run: 3,453,833,216 bytes free
Post-Run: 3,500,134,400 bytes free
176 — E O F — 2007-11-14 08:25:25