Finally the ComboFix log.....
ComboFix 07-12-09.1 - Stan Schochler 2007-12-09 19:38:03.2 - NTFSx86
Running from: C:\Documents and Settings\Stan Schochler\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\ODCTOOLS
C:\WINDOWS\system32\ajqsuief.dll
C:\WINDOWS\system32\blrmukxf.dll
C:\WINDOWS\system32\clumbxim.dll
C:\WINDOWS\system32\cvhsrqyd.dll
C:\WINDOWS\SYSTEM32\feiusqja.ini
C:\WINDOWS\SYSTEM32\fkxrlgqu.ini
C:\WINDOWS\system32\fxgoptjk.dll
C:\WINDOWS\SYSTEM32\fxkumrlb.ini
C:\WINDOWS\system32\kayvmvlg.dll
C:\WINDOWS\system32\kxxrofkx.dll
C:\WINDOWS\system32\lqeuynio.dll
C:\WINDOWS\SYSTEM32\oinyueql.ini
C:\WINDOWS\system32\ubnqvmms.dll
C:\WINDOWS\system32\uqglrxkf.dll
C:\WINDOWS\system32\xfmsfjne.dll
C:\WINDOWS\SYSTEM32\xkforxxk.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-11-10 to 2007-12-10 )))))))))))))))))))))))))))))))
.
2007-12-09 18:39 . 2004-08-04 02:56 116,224 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xrxwiadr.dll
2007-12-09 18:39 . 2001-08-17 22:37 99,865 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xlog.exe
2007-12-09 18:39 . 2002-08-29 05:00 28,288 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xjis.nls
2007-12-09 18:39 . 2001-08-17 22:37 27,648 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xrxftplt.exe
2007-12-09 18:39 . 2001-08-17 22:36 23,040 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xrxwbtmp.dll
2007-12-09 18:39 . 2001-08-17 22:36 17,408 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xrxscnui.dll
2007-12-09 18:39 . 2001-08-17 12:11 16,970 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xem336n5.sys
2007-12-09 18:39 . 2004-08-04 02:56 8,192 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\wshirda.dll
2007-12-09 18:39 . 2001-08-17 22:37 4,608 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\xrxflnch.exe
2007-12-09 18:37 . 2001-08-17 13:28 794,654 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\usr1801.sys
2007-12-09 18:36 . 2001-08-17 22:36 525,568 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\tridxp.dll
2007-12-09 18:35 . 2001-08-17 22:36 386,560 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sgiul50.dll
2007-12-09 18:34 . 2001-08-17 22:36 495,616 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sblfx.dll
2007-12-09 18:33 . 2001-08-17 13:28 899,146 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\r2mdkxga.sys
2007-12-09 18:32 . 2001-08-17 14:05 351,616 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ovcodek2.sys
2007-12-09 18:31 . 2001-08-17 12:50 198,144 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\nv3.sys
2007-12-09 18:31 . 2001-08-17 12:20 126,080 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\nm5a2wdm.sys
2007-12-09 18:31 . 2001-08-17 22:36 123,776 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\nv3.dll
2007-12-09 18:31 . 2001-08-17 12:20 87,040 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\nm6wdm.sys
2007-12-09 18:31 . 2001-08-17 12:49 51,552 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ntgrip.sys
2007-12-09 18:31 . 2001-08-17 22:36 38,912 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\EXCH_ntfsdrv.dll
2007-12-09 18:31 . 2004-08-04 01:00 28,672 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\nscirda.sys
2007-12-09 18:31 . 2001-08-17 13:47 9,344 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ntapm.sys
2007-12-09 18:31 . 2001-08-17 13:53 7,552 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\nsmmc.sys
2007-12-09 18:29 . 2002-08-29 05:00 111,104 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\mtstocom.exe
2007-12-09 18:29 . 2004-08-04 01:09 49,024 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\mstape.sys
2007-12-09 18:29 . 2001-08-17 13:48 12,416 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\msriffwv.sys
2007-12-09 18:29 . 2001-08-17 14:00 2,944 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\msmpu401.sys
2007-12-09 18:28 . 2002-08-29 05:00 1,875,968 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\msir3jp.lex
2007-12-09 18:28 . 2002-08-29 05:00 98,304 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\msir3jp.dll
2007-12-09 18:28 . 2001-08-17 14:02 35,200 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\msgame.sys
2007-12-09 18:28 . 2004-08-04 01:00 22,016 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\msircomm.sys
2007-12-09 18:28 . 2001-08-17 13:48 6,016 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\msfsio.sys
2007-12-09 18:27 . 2001-08-17 12:50 320,384 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\mgaum.sys
2007-12-09 18:27 . 2001-08-17 14:56 235,648 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\mgaud.dll
2007-12-09 18:27 . 2002-08-29 05:00 92,416 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\mga.sys
2007-12-09 18:27 . 2002-08-29 05:00 92,032 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\mga.dll
2007-12-09 18:27 . 2001-08-17 22:36 47,616 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\memgrp.dll
2007-12-09 18:27 . 2002-08-29 05:00 34,304 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\migisol.exe
2007-12-09 18:27 . 2004-08-04 01:00 26,112 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\memstpci.sys
2007-12-09 18:27 . 2001-08-17 13:58 8,320 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\memcard.sys
2007-12-09 18:27 . 2001-08-17 13:52 6,528 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\miniqic.sys
2007-12-09 18:25 . 2002-08-29 05:00 10,129,408 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hwxkor.dll
2007-12-09 18:24 . 2002-08-29 05:00 13,463,552 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hwxjpn.dll
2007-12-09 18:23 . 2001-08-17 12:15 455,680 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\fus2base.sys
2007-12-09 18:22 . 2001-08-17 12:14 952,007 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\diwan.sys
2007-12-09 18:21 . 2001-08-17 22:36 614,429 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\digiview.exe
2007-12-09 18:20 . 2002-08-29 05:00 1,677,824 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\chsbrkr.dll
2007-12-09 18:19 . 2001-08-17 14:05 314,752 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\camdro21.sys
2007-12-09 18:18 . 2001-08-17 14:56 342,336 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\banshee.dll
2007-12-09 18:17 . 2004-08-04 01:10 38,912 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\avc.sys
2007-12-09 18:17 . 2001-08-17 14:01 36,096 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\avcaudio.sys
2007-12-09 18:17 . 2004-08-04 01:09 13,696 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\avcstrm.sys
2007-12-09 18:15 . 2001-08-17 13:28 762,780 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\3cwmcru.sys
2007-12-09 18:14 . 2001-08-17 14:56 66,048 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\s3legacy.dll
2007-12-09 08:25 . 2007-12-09 08:25 <DIR> d-------- C:\VundoFix Backups
2007-12-08 20:14 . 2007-12-08 20:14 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-08 13:03 . 2007-12-08 13:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-08 13:02 . 2007-12-08 13:02 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-12-05 17:37 . 2007-12-06 01:14 <DIR> d-------- C:\Program Files\Digital Locker Assistant
2007-12-03 12:48 . 2007-12-04 12:49 805,441 ---hs---- C:\WINDOWS\SYSTEM32\ihauobdm.ini
2007-12-02 12:45 . 2007-12-03 00:03 793,724 ---hs---- C:\WINDOWS\SYSTEM32\cqenkpbd.ini
2007-11-29 23:16 . 2007-11-29 23:16 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2007-11-29 23:15 . 2007-11-29 23:15 <DIR> d-------- C:\Program Files\MSECACHE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 01:35 --------- d-----w C:\Program Files\Java
2007-12-09 14:17 --------- d-----w C:\Documents and Settings\Stan Schochler\Application Data\Paltalk
2007-12-09 10:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-12-08 17:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-07 13:42 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-12-03 08:36 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\SiteAdvisor
2007-12-01 09:13 --------- d-----w C:\Program Files\SiteAdvisor
2007-12-01 07:53 --------- d-----w C:\Documents and Settings\Stan Schochler\Application Data\SiteAdvisor
2007-11-04 15:07 --------- d-----w C:\Program Files\MouseWare
2007-11-04 13:06 --------- d-----w C:\Program Files\MSN Messenger
2007-11-04 12:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-04 12:13 --------- d-----w C:\Documents and Settings\Stan Schochler\Application Data\Yahoo!
2007-11-04 12:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-04 05:56 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-04 05:56 --------- d-----w C:\Program Files\MSN Apps
2007-11-04 05:54 --------- d-----w C:\Documents and Settings\Stan Schochler\Application Data\InstallShield
2007-11-04 04:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-04 04:08 --------- d-----w C:\Program Files\Windows Live
2007-11-04 02:40 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2007-01-30 22:29 76,496 -c--a-w C:\Documents and Settings\Stan Schochler\Application Data\GDIPFONTCACHEV1.DAT
2004-02-21 03:49 457 -c--a-w C:\Program Files\INSTALL.LOG
2003-02-07 06:51 227,147 -c--a-w C:\Program Files\WCLaunch[1].cab
2003-02-07 06:42 1,994,838 -c--a-w C:\Program Files\WCVCM.EXE
2003-01-03 00:52 1,803,464 -c--a-w C:\Program Files\winzip81.exe
1999-07-07 02:59 481,128 -c--a-w C:\Program Files\ie5setup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8628CD9E-3E82-4C8B-8FE6-97FEEF0DD740}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{862d3a4a-3e02-4854-b73a-fdf20ed04b84}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9CF1B352-A041-4FFE-8755-A7D9B4C15F2F}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6122CB3-736C-4DB0-99CC-1C405393C8F1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE1AD2C9-D961-4F78-9F0F-A8AA94BA88A8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b3603b7b-caec-477d-96f8-9203bd525365}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB0B56AE-FB8D-4672-984A-A2F0F8E5F575}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BCAAD310-EB24-48C5-8F8C-40024FE61EBB}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CCD000AC-66F5-4276-A992-B4E8A25DD705}]
C:\WINDOWS\system32\vtutt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DFCE131F-7CA3-4D1E-A4D9-F50B3A99A76F}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2004-03-01 23:05]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 C:\WINDOWS\BCMSMMSG.exe]
"DwlClient"="C:\Program Files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 20:05]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 C:\WINDOWS\LOGI_MWX.EXE]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-16 22:41]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 01:56 C:\WINDOWS\SYSTEM32\rundll32.exe]
"nwiz"="nwiz.exe" [2003-10-06 14:16 C:\WINDOWS\SYSTEM32\nwiz.exe]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 09:33]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-06 15:12]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-02-25 16:15]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-02-25 17:15]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-02-25 17:06]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-25 20:41]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2003-07-13 01:49]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2006-08-10 13:38]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 01:33]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2002-12-20 10:03:26]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-12-02 20:36:15]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-08-07 17:06:54]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updater]
S3 METROP;Hewlett-Packard ScanJet 5300C/5370C;C:\WINDOWS\system32\DRIVERS\hp53pw2k.sys
S3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINDOWS\System32\drivers\NMSCFG.SYS
.
Contents of the 'Scheduled Tasks' folder
"2007-12-08 12:24:13 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\SYSTEM32\cleanmgr.exe
"2007-12-08 10:38:38 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2007-12-08 09:07:07 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-09 19:58:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-09 20:03:35
.
--- E O F ---