Okay, this one was complicated. I had to end up doing it twice because the first time I did it, it went through and deleted a lot files and said it was going to restart my system. On the Shut Down screen it told me it was installing updates and would then shut down and not to turn off my computer... normally I would just wait... but I waited on this for 3 hours and it never changed so I ended up having to turn off my computer and then turn it back on. Apparently, it still deleted the files, etc. and this is the new scan, sorry for being such a noob!!!:
ComboFix 08-01-11.1 - Admin 2008-01-11 13:32:42.2 - NTFSx86
Running from: C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\9KYF2PST\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-12-11 to 2008-01-11 )))))))))))))))))))))))))))))))
.
2008-01-11 01:22 . 2000-08-31 08:00 58,368 --a------ C:\WINDOWS\NirCmd.exe
2008-01-11 00:06 . 2008-01-11 00:06 <DIR> d-------- C:\Program Files\Moleskinsoft Clone Remover 2.7
2008-01-10 23:48 . 2008-01-10 23:48 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Hardcoded Software
2008-01-10 23:47 . 2008-01-10 23:47 <DIR> d-------- C:\Program Files\Hardcoded Software
2008-01-10 21:02 . 2008-01-10 21:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-10 21:02 . 2008-01-10 21:02 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-10 18:46 . 2008-01-10 18:46 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-10 00:04 . 2008-01-10 00:04 <DIR> d-------- C:\Program Files\Luminositi
2008-01-07 23:05 . 2008-01-08 18:57 <DIR> d-------- C:\Program Files\AIM Music Link
2008-01-05 13:28 . 2008-01-05 13:32 <DIR> d-------- C:\Program Files\CeRegEditor
2008-01-05 12:36 . 2008-01-05 12:36 <DIR> d-------- C:\Program Files\T-Mobile Shadow User Manual
2008-01-03 22:46 . 2008-01-03 22:46 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-01-03 22:46 . 2008-01-03 22:46 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-01-03 22:44 . 2008-01-03 22:44 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared
2008-01-03 22:44 . 2006-11-13 14:45 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-01-03 22:44 . 2006-12-13 17:52 20,992 --a------ C:\WINDOWS\system32\drivers\motmodem.sys
2008-01-03 20:48 . 2008-01-03 20:49 <DIR> d-------- C:\Mobile2Mobile
2007-12-30 15:17 . 2007-12-15 12:37 218,624 --a------ C:\WINDOWS\system32\uxtheme.backup
2007-12-30 15:17 . 2007-12-30 15:17 218,624 --a------ C:\WINDOWS\system32\dllcache\uxtheme.dll
2007-12-30 14:07 . 2007-12-30 14:07 85,568 --a------ C:\WINDOWS\system32\ledkqxtr.exe
2007-12-29 13:36 . 2007-12-29 13:36 2,432 --a------ C:\WINDOWS\system32\unpr.sys
2007-12-29 13:03 . 2007-12-29 13:03 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\QQ Games Plugin
2007-12-29 13:02 . 2007-12-29 13:02 <DIR> d-------- C:\Program Files\Tencent
2007-12-28 22:20 . 2007-12-29 13:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-28 21:50 . 2007-12-28 21:50 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-12-27 22:20 . 2008-01-07 19:41 <DIR> d-------- C:\VundoFix Backups
2007-12-27 21:40 . 2007-12-29 01:05 <DIR> d-------- C:\Program Files\SuperAdBlocker.com
2007-12-27 21:40 . 2007-12-27 21:40 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\SuperAdBlocker.com
2007-12-27 21:39 . 2007-12-27 21:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-27 20:41 . 2007-12-27 20:41 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Intel
2007-12-27 20:41 . 2007-12-27 20:41 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Intel
2007-12-27 20:41 . 2007-12-27 20:41 21,361 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2007-12-27 20:41 . 2007-12-27 20:41 21,361 --a------ C:\WINDOWS\AegisP.sys
2007-12-27 20:41 . 2007-12-27 20:41 13,984 --a------ C:\WINDOWS\AegisP.inf
2007-12-27 20:41 . 2007-12-27 20:41 10,640 --a------ C:\WINDOWS\AegisP.cat
2007-12-27 20:41 . 2007-12-27 20:41 155 --a------ C:\version.ini
2007-12-27 20:39 . 2007-12-27 20:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Intel
2007-12-27 20:39 . 2007-12-27 20:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2007-12-27 20:39 . 2007-02-12 12:41 2,732,032 --a------ C:\WINDOWS\system32\Netw2r32.dll
2007-12-27 20:39 . 2007-02-12 12:40 557,056 --a------ C:\WINDOWS\system32\Netw2c32.dll
2007-12-27 20:37 . 2007-12-27 20:39 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\Intel
2007-12-27 20:08 . 2007-12-27 20:08 <DIR> d-------- C:\Intel
2007-12-23 15:23 . 2007-12-25 23:16 <DIR> d-------- C:\Program Files\Thoosje Vista Sidebar v1.7.8
2007-12-15 12:14 . 2007-12-15 12:14 <DIR> d-------- C:\Program Files\Stardock
2007-12-13 23:43 . 2007-12-14 00:03 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-12-13 23:29 . 2007-12-13 23:46 <DIR> d-------- C:\Program Files\Konami
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-11 06:31 --------- d-----w C:\Program Files\Spyware Terminator
2008-01-11 06:31 --------- d-----w C:\Program Files\QuickTime
2008-01-11 06:30 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-11 06:30 --------- d-----w C:\Program Files\iTunes
2008-01-11 06:30 --------- d-----w C:\Program Files\Apoint
2008-01-11 06:30 --------- d-----w C:\Program Files\AIM6
2008-01-11 06:17 --------- d-----w C:\Documents and Settings\Admin\Application Data\Azureus
2008-01-11 00:51 --------- d-----w C:\Documents and Settings\Admin\Application Data\LimeWire
2008-01-10 06:00 --------- d-----w C:\Documents and Settings\Admin\Application Data\Spyware Terminator
2008-01-10 05:35 --------- d-----w C:\Program Files\Yahoo!
2008-01-10 05:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-01-10 05:18 --------- d-----w C:\Program Files\Chattage
2008-01-08 23:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-07 23:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-01-05 17:50 --------- d-----w C:\Documents and Settings\Admin\Application Data\AdobeUM
2007-12-30 20:17 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-12-29 18:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-28 02:44 --------- d-----w C:\Program Files\NetWaiting
2007-12-26 12:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-26 12:02 --------- d-----w C:\Program Files\Viewpoint
2007-12-25 17:18 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-23 00:48 --------- d-----w C:\Program Files\LimeWire
2007-12-23 00:04 --------- d-----w C:\Program Files\Azureus
2007-12-15 17:52 --------- d-----w C:\Program Files\DupeEliminator
2007-12-15 17:37 1,956,352 ----a-w C:\WINDOWS\system32\logonui.exe
2007-12-15 17:37 1,956,352 ----a-w C:\WINDOWS\system32\logonui(2)(2)(2).exe
2007-12-14 18:21 --------- d-----w C:\Program Files\Amazon
2007-12-14 04:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-07 04:27 --------- d-----w C:\Program Files\Google
2007-12-01 17:28 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-01 01:03 138,624 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-12-01 00:58 374 ----a-w C:\Documents and Settings\Admin\Application Data\internaldb6334.dat
2007-12-01 00:53 18,432 ----a-w C:\Documents and Settings\Admin\Application Data\internaldb41.dat
2007-12-01 00:38 555 ----a-w C:\Documents and Settings\Admin\Application Data\internaldb8467.dat
2007-11-29 00:33 --------- d-----w C:\Program Files\Cloudbrain
2007-11-28 05:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2007-11-18 02:54 363,980 ----a-w C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe
2007-11-17 23:40 --------- d-----w C:\Program Files\iPod
2007-11-17 23:37 --------- d-----w C:\Program Files\Common Files\Apple
2007-11-17 23:37 --------- d-----w C:\Program Files\Apple Software Update
2007-11-17 23:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:39 230,912 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-27 22:37 2,109,440 ----a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-11_ 4.06.54.85 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 13:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2000-08-31 13:00:00 174,080 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
- 2008-01-11 06:23:55 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-11 18:32:23 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-11 06:23:55 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-11 18:32:23 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-11 06:23:55 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-11 18:32:24 4,108,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\ntuser.dat
- 2008-01-11 06:23:55 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-11 18:32:24 147,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-11 06:23:55 4,104,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\ntuser.dat
+ 2008-01-11 18:32:24 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-11 06:23:56 147,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-11 18:32:24 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2008-01-11 09:04:20 16,384 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-01-11 18:27:56 16,384 -c--a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-01-11 09:04:20 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-01-11 18:27:56 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-01-11 09:04:20 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-11 18:27:56 32,768 -c--a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2000-08-31 13:00:00 156,160 ----a-w C:\WINDOWS\system32\swreg.exe
+ 2000-08-31 13:00:00 163,840 ----a-w C:\WINDOWS\system32\swreg.exe
- 2000-08-31 13:00:00 49,152 ----a-w C:\WINDOWS\system32\VFind.exe
+ 2000-08-31 13:00:00 60,996 ----a-w C:\WINDOWS\system32\VFind.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [ ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2008-01-10 00:14 3810544]
"H/PC Connection Agent"="C:\PROGRA~1\MI3AA1~1\wcescomm.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [ ]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [ ]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [ ]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-01-14 20:54:48]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-27 11:30:15]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000D7}"= C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL [2006-11-07 12:58 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SABWinLogon]
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL 2007-08-01 09:28 176128 C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a--c--- 2005-05-12 22:00 352256 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowLOMControl]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
R0 UNPR;UNPR;C:\WINDOWS\system32\unpr.sys [2007-12-29 13:36]
R1 SABDIFSV;SABDIFSV;C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABDIFSV.SYS [2005-09-21 11:17]
R1 SABKUTIL;SABKUTIL;C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys [2007-02-20 16:02]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2007-11-30 20:03]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 17:46]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2006-12-13 17:52]
S3 SMNDIS5;SMNDIS5 NDIS Protocol Driver;C:\PROGRA~1\VERIZO~1\VZACCE~1\SMNDIS5.SYS []
.
Contents of the 'Scheduled Tasks' folder
"2008-01-03 21:57:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-11 13:34:40
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-11 13:35:22
ComboFix-quarantined-files.txt 2008-01-11 18:35:06
ComboFix2.txt 2008-01-11 09:07:09
.
2008-01-05 05:46:07 --- E O F ---