Hi,
I've run combo fix. Please see log below. Thanks.
ComboFix 07-11-08.1 - Angela Walker 2007-11-12 15:53:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.165 [GMT -5:00]Running from: C:\Documents and Settings\Angela Walker\Desktop\ComboFix.exe
* Created a new restore point
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\exxvjgtj.dat
C:\WINDOWS\system32\drivers\rnagadkx.dat
C:\WINDOWS\system32\drivers\rnagadkx.sys
C:\WINDOWS\system32\enmaenm.dll
C:\WINDOWS\system32\enmaenm.dll.bak
C:\WINDOWS\system32\thumdcbr.dll
C:\WINDOWS\winhp32.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_EABYPBHO
-------\LEGACY_HCUGQNQK
-------\eabypbho
-------\hcugqnqk
((((((((((((((((((((((((( Files Created from 2007-10-12 to 2007-11-12 )))))))))))))))))))))))))))))))
.
2007-11-12 15:51 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 14:51 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-12 14:49 812,344 --a------ C:\Program Files\HJTInstall.exe
2007-11-12 13:53 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-12 13:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-12 13:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-12 13:38 <DIR> d-------- C:\Program Files\Comodo
2007-11-12 13:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BOC425
2007-11-12 13:38 235,008 --a------ C:\WINDOWS\UNBOC.EXE
2007-11-12 13:38 208,896 --a------ C:\WINDOWS\CMDLIC.DLL
2007-11-12 13:31 <DIR> d-------- C:\Program Files\Common Files\Java
2007-11-12 10:01 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-12 10:01 <DIR> d-------- C:\Documents and Settings\Angela Walker\Application Data\AVG7
2007-11-12 10:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-12 10:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-11-10 13:49 1,929,216 --a------ C:\WINDOWS\system32\cdintf250.dll
2007-11-10 13:47 <DIR> d-------- C:\Program Files\SPSS Student
2007-11-08 19:44 1,024 --a------ C:\WINDOWS\system32\clauth2.dll
2007-11-08 19:44 1,024 --a------ C:\WINDOWS\system32\clauth1.dll
2007-11-08 19:44 0 --a------ C:\WINDOWS\system32\ssprs.dll
2007-11-08 19:44 0 --a------ C:\WINDOWS\system32\serauth2.dll
2007-11-08 19:44 0 --a------ C:\WINDOWS\system32\serauth1.dll
2007-11-08 19:44 0 --a------ C:\WINDOWS\system32\nsprs.dll
2007-11-08 19:41 1,025 --a------ C:\WINDOWS\system32\sysprs7.dll
2007-11-08 19:41 339 --a------ C:\WINDOWS\system32\lsprst7.dll
2007-11-08 09:17 <DIR> d-------- C:\Program Files\iTunes
2007-11-08 09:17 <DIR> d-------- C:\Program Files\iPod
2007-11-05 11:23 <DIR> d-------- C:\Program Files\Symantec
2007-11-05 09:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-14 15:44 41,728 --a------ C:\WINDOWS\system32\eewhmvev.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-12 18:32 --------- d-----w C:\Program Files\Java
2007-11-12 18:16 --------- d-----w C:\Program Files\SpywareBlaster
2007-11-12 06:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2007-11-09 20:17 --------- d-----w C:\Documents and Settings\Angela Walker\Application Data\AdobeUM
2007-11-08 14:15 --------- d-----w C:\Program Files\QuickTime
2007-11-06 20:58 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-06 20:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-05 23:14 --------- d-----w C:\Program Files\Yahoo!
2007-11-05 23:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-05 17:00 --------- d-----w C:\Documents and Settings\Angela Walker\Application Data\Yahoo!
2007-10-08 16:35 --------- d-----w C:\Program Files\Microsoft Silverlight
2007-09-30 22:54 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-09-15 22:58 --------- d-----w C:\Program Files\Apple Software Update
2007-09-13 00:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-13 00:23 --------- d-----w C:\Program Files\Course Technology
2007-02-07 20:56 92,064 ----a-w C:\Documents and Settings\Angela Walker\mqdmmdm.sys
2007-02-07 20:56 9,232 ----a-w C:\Documents and Settings\Angela Walker\mqdmmdfl.sys
2007-02-07 20:56 79,328 ----a-w C:\Documents and Settings\Angela Walker\mqdmserd.sys
2007-02-07 20:56 66,656 ----a-w C:\Documents and Settings\Angela Walker\mqdmbus.sys
2007-02-07 20:56 6,208 ----a-w C:\Documents and Settings\Angela Walker\mqdmcmnt.sys
2007-02-07 20:56 5,936 ----a-w C:\Documents and Settings\Angela Walker\mqdmwhnt.sys
2007-02-07 20:56 4,048 ----a-w C:\Documents and Settings\Angela Walker\mqdmcr.sys
2007-02-07 20:56 25,600 ----a-w C:\Documents and Settings\Angela Walker\usbsermptxp.sys
2007-02-07 20:56 22,768 ----a-w C:\Documents and Settings\Angela Walker\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64D712D1-84D9-281C-CE7D-32439D631863}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 16:33]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 15:02]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 15:02]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 20:15]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 11:26]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50]
"WatchDog"="C:\Program Files\mobile PhoneTools\WatchDog.exe" [2004-08-14 03:42]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-12 10:00]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"BOC-425"="C:\PROGRA~1\Comodo\CBOClean\BOC425.exe" [2007-08-08 19:49]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"SHS"="C:\Program Files\Rogers\SelfHealing\SHS.exe" [2006-03-13 09:52]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-09-08 09:48:17]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
R3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-08 14:09:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-12 16:28:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-12 16:30:23 - machine was rebooted
.
--- E O F ---