Hi,
Ok, ran the items as requested. attach are the logs
ComboFix log
ComboFix 08-01-23.1 - James 2008-01-24 18:59:20.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.142 [GMT -5:00]
Running from: C:\Documents and Settings\James\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\James\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\SYSTEM32\cmd.exe.tmp
C:\WINDOWS\SYSTEM32\vtstt.dll_old
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\SYSTEM32\cmd.exe.tmp
C:\WINDOWS\SYSTEM32\vtstt.dll_old
.
((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.
2008-01-22 19:37 . 2004-08-03 23:00 260,272 --a------ C:\cmldr
2008-01-22 19:37 . 2004-10-02 08:48 211 --a------ C:\Boot.bak
2008-01-20 13:16 . 2008-01-21 18:36 <DIR> d-------- C:\logs
2008-01-17 20:06 . 2008-01-17 20:06 <DIR> d-------- C:\Program Files\Safer Networking
2008-01-15 21:16 . 2008-01-15 21:16 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-14 19:48 . 2008-01-14 19:48 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-01-14 19:05 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-14 18:45 . 2008-01-14 18:45 76 --a------ C:\WINDOWS\SYSTEM32\ikhcore.cfg
2008-01-12 10:36 . 2008-01-12 10:36 2,335,270 --a------ C:\WINDOWS\SYSTEM32\1a537.mht
2008-01-12 10:36 . 2008-01-12 10:36 54,624 --a------ C:\WINDOWS\SYSTEM32\19038.sys
2008-01-08 20:33 . 2008-01-08 20:33 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-08 19:30 . 2008-01-15 00:36 <DIR> d-------- C:\TEMP\Spyware Doctor
2008-01-08 18:28 . 2008-01-08 18:28 <DIR> d-------- C:\Program Files\TiVo
2008-01-06 17:42 . 2008-01-06 17:43 <DIR> d-------- C:\Program Files\RADVideo
2008-01-05 22:17 . 2008-01-05 22:20 <DIR> d-------- C:\VideoOutput
2007-12-26 23:17 . 2008-01-23 06:00 <DIR> d-------- C:\Program Files\XoftSpySE
2007-12-26 18:12 . 2007-12-26 19:25 63 --a------ C:\WINDOWS\SYSTEM\SysSD.dll
2007-12-25 16:31 . 2008-01-07 16:31 45,056 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\XWMSAPI.EXE
2007-12-25 16:31 . 2008-01-07 16:31 28,672 --a------ C:\WINDOWS\SYSTEM32\DSentry.exe
2007-12-24 15:18 . 2007-12-24 17:15 <DIR> d-------- C:\Program Files\RegCure
2007-12-24 00:26 . 2007-12-24 00:26 <DIR> d-------- C:\Program Files\AVIcodec
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 11:00 --------- d-----w C:\Program Files\QuickTime
2008-01-23 11:00 --------- d-----w C:\Program Files\DellSupport
2008-01-20 16:38 --------- d-----w C:\Program Files\McAfee
2008-01-10 00:19 --------- d-----w C:\Program Files\Common Files\TiVo Shared
2008-01-06 03:15 --------- d-----w C:\Program Files\Common Files\Download Manager
2007-12-23 15:39 --------- d-----w C:\Program Files\Dell Support Center
2007-12-23 15:39 --------- d-----w C:\Program Files\Common Files\supportsoft
2007-12-02 04:44 --------- d-----w C:\Program Files\Verizon
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\SYSTEM32\lsasrv.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\lsasrv.dll
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2005-07-16 11:13 0 ----a-w C:\Program Files\MCAFEE.Cxe
.
((((((((((((((((((((((((((((( snapshot@2008-01-23_18.31.32.81 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-23 10:59:22 1,372,160 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-24 23:58:41 1,372,160 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-23 10:59:22 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-24 23:58:42 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-23 10:59:23 1,327,104 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-24 23:58:42 1,327,104 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-23 10:59:23 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-24 23:58:42 12,288 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-23 10:59:23 8,347,648 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-24 23:58:42 8,347,648 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-23 10:59:23 339,968 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-24 23:58:42 339,968 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2008-01-23 00:06:53 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe
+ 2008-01-24 01:53:56 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe
- 2008-01-23 00:06:55 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat_3D.exe
+ 2008-01-24 01:53:58 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat_3D.exe
- 2008-01-23 00:06:54 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat_Standard.exe
+ 2008-01-24 01:53:58 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat_Standard.exe
- 2008-01-23 00:06:55 25,214 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Distiller.exe
+ 2008-01-24 01:53:58 25,214 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Distiller.exe
- 2008-01-23 00:06:54 7,278 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_ELEMENTS_DT.exe
+ 2008-01-24 01:53:58 7,278 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_ELEMENTS_DT.exe
- 2008-01-23 00:06:53 23,558 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\SC_Designer_PFM.70DBED24_B579_40CB_AB0B_F1221A3E9EC5.exe
+ 2008-01-24 01:53:56 23,558 ----a-r C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\SC_Designer_PFM.70DBED24_B579_40CB_AB0B_F1221A3E9EC5.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-10-06 14:16 5058560]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 23:24 620152]
"@"="" []
C:\Documents and Settings\James\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\WebshotsTray.exe [2003-08-09 09:54:18 208896]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtuvss]
awtuvss.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Pagis Schedule Monitor.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
--a------ 2007-12-25 20:50 202544 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R2 vnccom;vnccom;C:\WINDOWS\system32\Drivers\vnccom.SYS [2005-03-03 00:14]
R2 XWMSMFP1;XWMSPAC;C:\WINDOWS\system32\Drivers\XWMSPAC.SYS [2001-10-09 14:10]
R2 XWMSMFP2;XWMSPRO;C:\WINDOWS\system32\Drivers\XWMSPRO.SYS [2001-10-09 14:10]
R3 vncdrv;vncdrv;C:\WINDOWS\system32\DRIVERS\vncdrv.sys [2005-03-03 00:14]
S3 19038;19038;C:\WINDOWS\system32\19038.sys [2008-01-12 10:36]
S3 DCamUSBGrandTek;ScopeCam PC Camera.;C:\WINDOWS\system32\Drivers\scopex1.SYS [2001-08-05 21:13]
S3 GT891x;ScopeCam DSC;C:\WINDOWS\system32\Drivers\scopex0.SYS [2001-11-04 19:11]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-24 08:00:01 C:\WINDOWS\Tasks\AntiSpyware Scheduled Scan.job"
- C:\Program Files\AntiSpywareApp\AntiSpyware.ex
- C:\Program Files\AntiSpywareApp
"2008-01-15 06:21:47 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2007-01-17 15:26:22 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-01-24 23:50:34 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-24 10:51:29 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-25 00:05:01 C:\WINDOWS\Tasks\User_Feed_Synchronization-{503F54EC-EF06-471C-8137-8B2899BCECE2}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-24 19:04:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-24 19:07:10
ComboFix-quarantined-files.txt 2008-01-25 00:07:08
ComboFix2.txt 2008-01-23 23:32:01
.
2008-01-08 21:57:55 --- E O F ---