Hey Rudy,
Here is the log
ComboFix 08-02-15.1 - Jim 2008-02-15 15:47:07.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.491 [GMT -5:00]
Running from: C:\Documents and Settings\Jim\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp:
.
((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.
2008-02-14 19:14 . 2008-02-14 19:14 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\Grisoft
2008-02-14 19:10 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-13 16:34 . 2007-04-17 04:28 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-02-13 16:34 . 2007-02-09 08:26 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-02-12 17:15 . 2008-02-09 11:20 31,280 --a------ C:\WINDOWS\system32\rrMon.sys
2008-02-12 15:40 . 2008-02-12 15:40 <DIR> d-------- C:\Program Files\Avira
2008-02-12 15:40 . 2008-02-12 15:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-12 15:37 . 2008-02-12 17:15 <DIR> d-------- C:\Program Files\Registrar Registry Manager
2008-02-11 18:43 . 2008-02-11 18:43 <DIR> d-------- C:\Documents and Settings\Jim\DoctorWeb
2008-02-11 13:06 . 2008-02-11 15:13 250 --a------ C:\WINDOWS\gmer.ini
2008-02-11 13:02 . 2008-02-11 13:02 <DIR> d-------- C:\Program Files\rootkitrevealer
2008-02-11 12:55 . 2008-02-11 12:55 <DIR> d-------- C:\Program Files\CleanUp!
2008-02-11 08:35 . 2004-08-04 07:00 388,608 --a------ C:\kmd.exe
2008-02-09 08:52 . 2008-02-09 10:07 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\DMCache
2008-02-08 17:29 . 2008-02-08 17:29 <DIR> d-------- C:\Deckard
2008-02-07 10:58 . 2003-03-13 12:51 51,200 --a------ C:\WINDOWS\system32\camcodec.dll
2008-02-07 10:58 . 2003-03-13 12:51 1,461 --a------ C:\WINDOWS\system32\drivers\camcodec.inf
2008-02-05 16:43 . 2008-02-05 16:43 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-03 11:03 . 2008-02-03 11:03 <DIR> d-------- C:\Program Files\AVSMedia
2008-02-03 09:51 . 2008-02-15 15:31 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-03 09:51 . 2008-02-03 09:51 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-02 09:49 . 2008-02-02 09:49 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-02-01 09:48 . 2008-02-01 09:49 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-01-31 23:03 . 2008-02-05 20:34 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\Search Settings
2008-01-31 22:37 . 2008-01-31 22:37 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-01-31 22:36 . 2008-01-31 22:40 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\Dealio
2008-01-31 20:21 . 2008-01-31 20:21 <DIR> d-------- C:\SICKO
2008-01-30 16:04 . 2008-02-14 18:50 2,544 --a------ C:\rollback.ini
2008-01-30 15:44 . 2007-11-14 16:05 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-01-29 19:48 . 2008-01-29 19:48 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\MailFrontier
2008-01-29 19:43 . 2008-02-15 15:52 23,607,840 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-29 19:43 . 2008-02-15 08:19 316,868 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-29 19:37 . 2008-01-29 20:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-01-29 19:36 . 2007-11-14 16:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-01-29 19:35 . 2008-02-12 15:48 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2008-01-29 19:35 . 2008-01-29 19:35 <DIR> d-------- C:\Program Files\Zone Labs
2008-01-29 19:35 . 2008-02-15 15:32 355,090 --a------ C:\WINDOWS\system32\vsconfig.xml
2008-01-28 17:53 . 2008-01-31 23:23 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\Vso
2008-01-28 17:53 . 2008-01-28 17:53 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-28 17:53 . 2008-01-31 23:23 47,360 --a------ C:\Documents and Settings\Jim\Application Data\pcouffin.sys
2008-01-22 19:46 . 2008-01-28 17:44 <DIR> d-------- C:\Documents and Settings\Jim\dwhelper
2008-01-20 17:44 . 2008-01-20 17:44 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\MozillaControl
2008-01-20 16:27 . 2008-01-21 18:09 <DIR> d-------- C:\Program Files\Opera
2008-01-19 22:36 . 2008-02-13 20:03 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\SiteAdvisor
2008-01-19 22:36 . 2008-01-19 22:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-01-19 22:36 . 2008-01-19 22:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-01-19 22:16 . 2008-01-19 22:16 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-17 16:50 . 2008-01-17 16:50 <DIR> d-------- C:\Program Files\iPod
2008-01-16 18:42 . 2008-01-16 18:42 27,496 --a------ C:\Documents and Settings\Jim\Application Data\GDIPFONTCACHEV1.DAT
2008-01-16 18:14 . 2008-01-16 18:14 <DIR> d-------- C:\Program Files\MSBuild
2008-01-16 18:09 . 2008-01-16 18:09 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-01-16 18:09 . 2008-01-16 18:09 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-01-16 18:08 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-01-16 17:37 . 2008-01-16 17:37 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-01-16 17:37 . 2008-01-16 17:37 <DIR> d-------- C:\Documents and Settings\Jim\Application Data\SystemRequirementsLab
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-15 13:19 62,464 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-02-15 13:00 --------- d-----w C:\Documents and Settings\Jim\Application Data\AVG7
2008-02-15 02:31 335,872 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2008-02-15 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-11 23:39 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-11 23:38 656,384 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2008-02-11 15:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-11 13:44 1,147,703 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-02-10 20:54 --------- d-----w C:\Program Files\Bonjour
2008-02-09 15:04 --------- d-----w C:\Documents and Settings\Jim\Application Data\LimeWire
2008-02-08 21:44 409,088 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2008-02-08 19:45 2,116,096 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-02-08 17:50 2,116,096 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-02-07 23:43 2,112,000 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-02-07 15:57 --------- d-----w C:\Program Files\CamStudio
2008-02-06 23:49 2,076,160 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-02-05 20:44 78,848 ----a-w C:\WINDOWS\system32\msiexec.exe
2008-02-05 02:29 1,748,480 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-02-02 14:57 --------- d-----w C:\Program Files\SpywareBlaster
2008-02-01 14:48 --------- d-----w C:\Program Files\Common Files\Real
2008-02-01 13:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-31 02:38 1,251,328 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-01-30 22:43 --------- d-----w C:\Documents and Settings\Jim\Application Data\Apple Computer
2008-01-30 01:27 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-23 22:39 --------- d-----w C:\Documents and Settings\Jim\Application Data\dvdcss
2008-01-18 13:46 --------- d-----w C:\Program Files\iTunes
2008-01-17 21:48 --------- d-----w C:\Program Files\QuickTime
2008-01-13 22:14 --------- d-----w C:\Program Files\Yahoo!
2008-01-13 22:14 --------- d-----w C:\Program Files\Common Files\Scanner
2008-01-13 16:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-13 16:42 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-13 02:07 --------- d-----w C:\Documents and Settings\Jim\Application Data\vlc
2008-01-10 01:46 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-10 00:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-09 22:48 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-01-09 00:56 --------- d-----w C:\Program Files\VideoProfessor
2008-01-09 00:55 --------- d-----w C:\Documents and Settings\Jim\Application Data\Media Player Classic
2008-01-07 00:49 --------- d-----w C:\Program Files\Doom 3
2008-01-07 00:17 --------- d-----w C:\Program Files\Doom 3 Demo
2008-01-06 18:25 --------- d-----w C:\Program Files\Total Video Converter
2008-01-06 17:53 --------- d-----w C:\Program Files\Zeallsoft
2008-01-05 23:05 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-01-04 15:24 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVG7
2008-01-03 23:55 --------- d-----w C:\Program Files\Blender Foundation
2008-01-03 23:52 --------- d-----w C:\Program Files\LimeWire
2008-01-03 21:45 --------- d-----w C:\Documents and Settings\Jim\Application Data\Yahoo!
2008-01-03 21:33 --------- d-----w C:\Documents and Settings\Jim\Application Data\Talkback
2008-01-03 19:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-03 19:49 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-03 00:52 --------- d-----w C:\Program Files\VideoLAN
2008-01-03 00:44 --------- d-----w C:\Program Files\DVD Decrypter
2008-01-03 00:21 --------- d-----w C:\Program Files\Safari
2008-01-01 18:09 --------- d-----w C:\Program Files\Registry Clean Expert
2007-12-26 20:36 --------- d-----w C:\Program Files\Guitar Pro 5
2007-12-24 15:47 --------- d-----w C:\Program Files\DivX
2007-12-24 15:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-15 02:14 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-15 02:14 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2007-12-15 02:14 --------- d-----w C:\Program Files\Common Files\Merge Modules
2007-12-11 22:34 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-12-11 22:34 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-05 07:53 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-12-05 06:41 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-12-05 06:41 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-12-05 06:41 8,523,776 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-12-05 06:41 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-12-05 06:41 6,901,760 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-12-05 06:41 6,549,504 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-12-05 06:41 5,773,568 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-12-05 06:41 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-12-05 06:41 385,024 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-12-05 06:41 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe
2007-12-05 06:41 35,328 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-12-05 06:41 35,328 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-12-05 06:41 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-12-05 06:41 3,710,976 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-12-05 06:41 3,420,160 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-12-05 06:41 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-12-05 06:41 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-12-05 06:41 2,498,560 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-12-05 06:41 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-12-05 06:41 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-12-05 06:41 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-12-05 06:41 1,228,800 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-12-05 06:41 1,089,536 ----a-w C:\WINDOWS\system32\nvcuda.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-11-20 00:42 256 ----a-w C:\sccfg.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B8A7839C-51E8-4067-ADA3-CA74BABC1976}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="" []
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [ ]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 02:54 77824 C:\WINDOWS\SOUNDMAN.EXE]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 17:20 866584]
"osCheck"="C:\PROGRA~1\Symantec\osCheck.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-03 20:56 579072]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 15:42 249896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 08:01 437160]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 07:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-03 20:56 219136]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Jim^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Jim\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Jim^Start Menu^Programs^Startup^YouTube Uploader.lnk]
path=C:\Documents and Settings\Jim\Start Menu\Programs\Startup\YouTube Uploader.lnk
backup=C:\WINDOWS\pss\YouTube Uploader.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Remote Control]
--a------ 2005-04-15 14:18 1482752 C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 2008-01-03 20:56 579072 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 07:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-01-19 21:58 21488 C:\Documents and Settings\Jim\Local Settings\Application Data\Google\Update\1.0.103.0\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
C:\Program Files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 01:41 81920 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
C:\PROGRA~1\Symantec\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegClean Expert Scheduler]
C:\Program Files\Registry Clean Expert\RCHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-11-03 17:20 866584 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"comHost"=3 (0x3)
"YPCService"=3 (0x3)
R1 AmdPPM;AMD HwPState Processor Driver;C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 21:46]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 04:29]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2007-05-23 04:15]
S3 MEL;MEL;C:\DOCUME~1\Jim\LOCALS~1\Temp\MEL.exe [2008-02-11 15:43]
S3 WSUB;WSUB;C:\DOCUME~1\Jim\LOCALS~1\Temp\WSUB.exe [2008-02-11 13:08]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-13 01:00:00 C:\WINDOWS\Tasks\Ad-Aware SE Personal.job"
- C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
"2008-02-15 20:33:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-05 01:00:00 C:\WINDOWS\Tasks\Norton Security Online - Run Full System Scan - Wyatt.job"
- C:\PROGRA~1\Symantec\Norton AntiVirus\Navw32.exeh/TASK:
"2008-02-11 22:30:00 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe,/AUTOCHECK /AUTOFIX /AUTOUPDATE /AUTOCLOSE+C:\Program Files\Spybot - Search & Destroy
"2008-02-13 01:00:01 C:\WINDOWS\Tasks\SpywareBlaster.job"
- C:\PROGRA~1\SPYWAR~1\SPYWAR~1.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-15 15:52:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-15 15:55:49
ComboFix-quarantined-files.txt 2008-02-15 20:55:37
ComboFix2.txt 2008-02-11 13:53:16
ComboFix3.txt 2008-02-11 01:21:02
ComboFix4.txt 2008-02-08 22:51:44
.
2008-02-15 20:38:47 --- E O F ---