First of all the answers to your two questions in your last post:
1. To my knowledge I did not open that port deliberately, unless I did so in the process of installing a program.
2. The system is running a lot faster and smoother now. Thanks a lot!
Here is the Combofix log you requested:
ComboFix 09-07-07.A2 - DBP 07/13/2009 10:53.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.308 [GMT -7:00]
Running from: c:\documents and settings\DBP\Desktop\system\ComboFix.exe
Command switches used :: c:\documents and settings\DBP\Desktop\system\CFScript.txt
FILE ::
"c:\program files\MSN Gaming Zone\rteje.html"
"c:\windows2\Fonts\zia03376"
"c:\windows2\system32\winsckdo.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows2\Fonts\zia03376
.
((((((((((((((((((((((((( Files Created from 2009-06-13 to 2009-07-13 )))))))))))))))))))))))))))))))
.
2009-07-08 02:30 . 2009-07-08 02:30 410984 ----a-w- c:\windows2\system32\deploytk.dll
2009-07-04 02:52 . 2009-07-04 02:52 84832 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-07-04 02:52 . 2009-07-13 01:13 1630560 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-06-30 04:41 . 2009-06-30 04:41 -------- d-sh--w- c:\documents and settings\Administrator.MARKETING\IETldCache
2009-06-30 01:08 . 2009-06-30 01:08 314712 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-06-30 01:08 . 2009-07-13 01:13 25440 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-06-30 01:08 . 2009-06-30 01:08 169312 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-06-30 01:07 . 2009-06-30 01:07 348496 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-06-30 01:07 . 2009-06-30 01:07 298336 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-06-30 01:05 . 2009-06-30 01:05 246128 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-30 01:04 . 2009-06-30 01:04 40288 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-30 01:04 . 2009-06-30 01:04 85352 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-06-30 01:04 . 2009-06-30 01:04 664424 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-06-30 01:03 . 2009-06-30 01:03 563064 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-06-30 01:03 . 2009-06-30 01:03 566632 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-06-30 01:02 . 2009-07-13 01:11 2353480 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-06-30 01:01 . 2009-06-30 01:01 629072 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-06-30 01:00 . 2009-06-30 01:00 520024 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-06-30 01:00 . 2009-06-30 01:00 1029456 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-30 00:13 . 2009-06-30 00:13 -------- d-----w- c:\program files\Trend Micro
2009-06-30 00:10 . 2009-06-30 00:10 -------- d-----w- c:\program files\ERUNT
2009-06-27 18:06 . 2009-06-27 18:09 -------- d--h--w- c:\windows2\msdownld.tmp
2009-06-27 18:06 . 2009-06-27 18:06 -------- d-----w- c:\windows2\Logs
2009-06-20 15:22 . 2009-07-07 02:22 -------- d-----w- c:\program files\XZAKTFrontFXTools1
2009-06-16 02:56 . 2009-06-16 02:56 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache
2009-06-15 02:46 . 2009-06-15 00:56 15688 ----a-w- c:\windows2\system32\lsdelete.exe
2009-06-15 00:56 . 2009-06-15 00:54 64160 ----a-w- c:\windows2\system32\drivers\Lbd.sys
2009-06-15 00:56 . 2009-06-15 00:56 15688 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-15 00:54 . 2009-06-15 00:54 64160 ----a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-15 00:45 . 2009-06-15 00:45 -------- dc-h--w- c:\documents and settings\All Users.WINDOWS2\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-15 00:45 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users.WINDOWS2\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-15 00:45 . 2009-06-15 00:45 -------- d-----w- c:\program files\Lavasoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-13 02:56 . 2009-02-26 18:58 -------- d-----w- c:\program files\My Journal
2009-07-09 04:02 . 2005-10-20 22:12 852048 ----a-w- c:\documents and settings\DBP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-08 02:29 . 2005-10-21 20:06 -------- d-----w- c:\program files\Java
2009-07-01 05:02 . 2007-08-21 18:28 524288 ----a-w- c:\windows2\system32\Busy_Wait.exe
2009-06-30 05:13 . 2009-03-23 08:36 -------- d-----w- c:\program files\Bonjour
2009-06-28 00:43 . 2006-09-02 21:34 -------- d-----w- c:\program files\UIU
2009-06-27 23:52 . 2006-02-27 19:14 -------- d-----w- c:\program files\WhatsRunning
2009-06-20 15:20 . 2006-05-25 16:27 -------- d-----w- c:\program files\XZAKT FrontFX Tools+ 2
2009-06-15 00:45 . 2007-07-04 08:51 -------- d-----w- c:\documents and settings\All Users.WINDOWS2\Application Data\Lavasoft
2009-06-12 00:16 . 2006-03-24 00:48 -------- d-----w- c:\documents and settings\DBP\Application Data\Xara
2009-06-12 00:16 . 2006-04-26 19:33 -------- d-----w- c:\program files\HTML Password Lock
2009-06-12 00:16 . 2009-04-25 21:04 -------- d-----w- c:\program files\Xara
2009-06-12 00:15 . 2009-05-26 23:44 -------- dc-h--w- c:\documents and settings\All Users.WINDOWS2\Application Data\{CDF61231-6AD7-4969-B4DD-9E6C0F51DD5E}
2009-06-12 00:15 . 2008-03-17 16:28 -------- d-----w- c:\program files\Bible Explorer 4
2009-06-12 00:15 . 2009-06-12 00:15 -------- d-----w- c:\program files\Common Files\WORDsearch
2009-06-12 00:15 . 2009-06-12 00:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS2\Application Data\wsc
2009-06-12 00:15 . 2009-06-12 00:15 -------- d-----w- c:\documents and settings\DBP\Application Data\EBookSys
2009-06-12 00:14 . 2009-03-23 08:33 -------- d-----w- c:\program files\Common Files\Apple
2009-06-12 00:14 . 2005-09-14 02:15 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-12 00:13 . 2004-12-10 22:50 -------- d-----w- c:\program files\Common Files\Macromedia
2009-06-12 00:13 . 2005-11-03 21:58 -------- d-----w- c:\program files\Opera
2009-06-12 00:13 . 2005-10-24 19:32 -------- d-----w- c:\program files\Macromedia
2009-06-12 00:10 . 2009-05-09 05:24 -------- d-----w- c:\program files\Lame for Audacity
2009-06-11 23:54 . 2008-08-29 03:02 -------- d-----w- c:\program files\SourceTec
2009-06-11 23:54 . 2008-08-29 03:02 -------- d-----w- c:\program files\Common Files\SourceTec
2009-06-11 23:52 . 2006-03-07 17:12 -------- d-----w- c:\program files\CoffeeCup Software
2009-05-23 01:21 . 2009-04-30 21:15 -------- d-----w- c:\documents and settings\DBP\Application Data\Move Networks
2009-05-22 05:44 . 2004-12-03 08:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-15 06:12 . 2009-05-15 06:12 45056 ----a-r- c:\documents and settings\DBP\Application Data\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe
2009-05-09 02:43 . 2009-05-09 02:45 38208 ----a-w- c:\documents and settings\DBP\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-05-02 23:04 . 2009-05-02 23:04 34062 ----a-w- c:\documents and settings\DBP\Application Data\Move Networks\ie_bin\Uninst.exe
2009-05-01 05:31 . 2009-05-01 05:31 295606 ----a-r- c:\documents and settings\DBP\Application Data\Microsoft\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\SC_Reader.exe
2009-04-29 21:37 . 2009-04-29 21:37 21035 ----a-w- c:\windows2\system32\drivers\AegisP.sys
2008-02-27 08:05 . 2008-02-27 08:06 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-08-21 18:28 . 2007-08-21 18:28 491 ----a-w- c:\program files\UnInst.log
.
------- Sigcheck -------
[7] 2004-08-12 13:30 14336 8F078AE4ED187AAABC0A305146DE6716 c:\windows2\$NtServicePackUninstall$\svchost.exe
[7] 2008-02-12 09:29 14336 0C54D685CFA1D5054F59F08ADAF71248 c:\windows2\ServicePackFiles\i386\svchost.exe
[7] 2008-02-12 09:29 14336 0C54D685CFA1D5054F59F08ADAF71248 c:\windows2\system32\svchost.exe
[7] 2008-02-12 09:29 14336 0C54D685CFA1D5054F59F08ADAF71248 c:\windows2\system32\dllcache\cache\svchost.exe
[-] 2005-03-02 18:19 577024 1800F293BCCC8EDE8A70E12B88D80036 c:\windows2\$hf_mig$\KB890859\SP2QFE\user32.dll
[-] 2007-03-08 15:48 578048 7AA4F6C00405DFC4B70ED4214E7D687B c:\windows2\$hf_mig$\KB925902\SP2QFE\user32.dll
[-] 2007-03-08 15:36 577536 B409909F6E2E8A7067076ED748ABF1E7 c:\windows2\$NtServicePackUninstall$\user32.dll
[7] 2004-08-12 13:31 577024 C72661F8552ACE7C5C85E16A3CF505C4 c:\windows2\$NtUninstallKB890859$\user32.dll
[-] 2005-03-02 18:09 577024 DE2DB164BBB35DB061AF0997E4499054 c:\windows2\$NtUninstallKB925902$\user32.dll
[7] 2008-02-12 09:29 578560 7E02D28A2BDB710887815C41189014C1 c:\windows2\ServicePackFiles\i386\user32.dll
[7] 2008-02-12 09:29 578560 7E02D28A2BDB710887815C41189014C1 c:\windows2\system32\user32.dll
[7] 2008-02-12 09:29 578560 7E02D28A2BDB710887815C41189014C1 c:\windows2\system32\dllcache\cache\user32.dll
[7] 2004-08-12 13:34 82944 2ED0B7F12A60F90092081C50FA0EC2B2 c:\windows2\$NtServicePackUninstall$\ws2_32.dll
[7] 2008-02-12 09:29 82432 96163A36BFB5D8D66190FA6066A4A84C c:\windows2\ServicePackFiles\i386\ws2_32.dll
[7] 2008-02-12 09:29 82432 96163A36BFB5D8D66190FA6066A4A84C c:\windows2\system32\ws2_32.dll
[7] 2008-02-12 09:29 82432 96163A36BFB5D8D66190FA6066A4A84C c:\windows2\system32\dllcache\cache\ws2_32.dll
[-] 2005-09-02 23:53 660480 97A6FD7CAFD688CF2C78939EBAF0CD0C c:\windows2\$hf_mig$\KB896688\SP2QFE\wininet.dll
[-] 2005-10-21 03:38 661504 AF785C4947676A7FC1673FDC5C8D0B5B c:\windows2\$hf_mig$\KB905915\SP2QFE\wininet.dll
[-] 2006-03-04 03:58 663552 C0845ECBF4F9164E618EE381B79C9032 c:\windows2\$hf_mig$\KB912812\SP2QFE\wininet.dll
[-] 2006-05-10 05:25 663552 D94CFFDB53E7AC867438E2DFD50E7CBC c:\windows2\$hf_mig$\KB916281\SP2QFE\wininet.dll
[-] 2006-06-23 11:25 664576 64CE26DB72810B30F7855EA51E1DF836 c:\windows2\$hf_mig$\KB918899\SP2QFE\wininet.dll
[7] 2007-10-10 23:47 825344 0E5D918F87EFA7D2424D66B499C7EB04 c:\windows2\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
[7] 2007-12-07 02:01 825344 B5B411BB229AE6EAD7652A32ED47BFB9 c:\windows2\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
[-] 2006-05-10 05:23 658432 38AB7A56F566D9AAAD31812494944824 c:\windows2\$NtUninstallKB918899_0$\wininet.dll
[7] 2004-08-12 13:33 656384 C0823FC5469663BA63E7DB88F9919D70 c:\windows2\ie7\wininet.dll
[7] 2007-08-14 02:54 818688 A4A0FC92358F39538A6494C42EF99FE9 c:\windows2\ie7updates\KB942615-IE7\wininet.dll
[7] 2007-10-10 23:56 824832 30C1E0F34AD2972C72A01DB5C74AB065 c:\windows2\ie7updates\KB944533-IE7\wininet.dll
[7] 2007-12-07 02:21 824832 806D274C9A6C3AAEA5EAE8E4AF841E04 c:\windows2\ie8\wininet.dll
[7] 2008-02-12 09:29 666112 C1B4A43D78C9A0B2EC403E0D6F1A11BB c:\windows2\ServicePackFiles\i386\wininet.dll
[-] 2007-06-26 14:09 658944 184E47C8F7B331025E6DC92740DB188F c:\windows2\SoftwareDistribution\Download\00f4dcdbcc87699e75212b885cb6bebf\sp2gdr\wininet.dll
[-] 2007-06-26 14:35 665600 E1A3DD68B5380B360A7310A64D9BB188 c:\windows2\SoftwareDistribution\Download\00f4dcdbcc87699e75212b885cb6bebf\sp2qfe\wininet.dll
[-] 2007-08-20 10:04 824832 774435E499D8E9643EC961A6103C361F c:\windows2\SoftwareDistribution\Download\66b48c5a53c8af1f3beb636379e3da1e\sp2gdr\wininet.dll
[-] 2007-08-20 10:02 825344 357D54BF94FE9D6D8505A96B5C2A3BCA c:\windows2\SoftwareDistribution\Download\66b48c5a53c8af1f3beb636379e3da1e\sp2qfe\wininet.dll
[-] 2007-08-22 13:12 658944 1901AD51DA8BE9F8B38D5D526E5D1788 c:\windows2\SoftwareDistribution\Download\730e45fefcdf343b61704b89c95d7cca\sp2gdr\wininet.dll
[-] 2007-08-22 12:55 665600 A1BC17EB3758D73C3938B2318820F5B4 c:\windows2\SoftwareDistribution\Download\730e45fefcdf343b61704b89c95d7cca\sp2qfe\wininet.dll
[7] 2007-10-10 23:56 824832 30C1E0F34AD2972C72A01DB5C74AB065 c:\windows2\SoftwareDistribution\Download\e3709fbfd9557a7d083f543d51d38612\SP2GDR\wininet.dll
[7] 2007-10-10 23:47 825344 0E5D918F87EFA7D2424D66B499C7EB04 c:\windows2\SoftwareDistribution\Download\e3709fbfd9557a7d083f543d51d38612\SP2QFE\wininet.dll
[-] 2007-10-11 06:13 659456 2005AD86A22AEE68E21EE59F9CCB77F2 c:\windows2\SoftwareDistribution\Download\fa58243222bcfe35e5467668df396003\sp2gdr\wininet.dll
[-] 2007-10-11 05:57 666112 80D660A49E0D118144423099B2A9F5DA c:\windows2\SoftwareDistribution\Download\fa58243222bcfe35e5467668df396003\sp2qfe\wininet.dll
[-] 2007-06-27 14:34 823808 8068CBB58FE60CC95AEB2CFF70178208 c:\windows2\SoftwareDistribution\Download\fbd74e253a9131770d5798b356214bc9\sp2gdr\wininet.dll
[-] 2007-06-27 14:40 824320 D6ED5E042C5207553E7F5E842918137F c:\windows2\SoftwareDistribution\Download\fbd74e253a9131770d5798b356214bc9\sp2qfe\wininet.dll
[7] 2009-03-08 11:34 914944 6CE32F7778061CCC5814D5E0F282D369 c:\windows2\system32\wininet.dll
[7] 2009-03-08 11:34 914944 6CE32F7778061CCC5814D5E0F282D369 c:\windows2\system32\dllcache\wininet.dll
[7] 2009-03-08 11:34 914944 6CE32F7778061CCC5814D5E0F282D369 c:\windows2\system32\dllcache\cache\wininet.dll
[-] 2005-05-25 19:07 359936 63FDFEA54EB53DE2D863EE454937CE1E c:\windows2\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2006-01-13 17:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows2\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows2\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows2\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows2\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-12 13:30 359040 9F4B36614A0FC234525BA224957DE55C c:\windows2\$NtUninstallKB941644$\tcpip.sys
[7] 2008-02-12 04:50 361344 AD075303568EC3B139CEC4C22BAAECD1 c:\windows2\ServicePackFiles\i386\tcpip.sys
[-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows2\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
[-] 2006-01-13 01:13 340480 8C101C9C566E2384AF28EF7C1DE4A36E c:\windows2\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP1QFE\tcpip.sys
[-] 2006-01-13 02:28 359808 583E063FDC888CA30D05C2724B0D7EF4 c:\windows2\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP2GDR\tcpip.sys
[-] 2006-01-13 17:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows2\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP2QFE\tcpip.sys
[7] 2008-02-12 04:50 361344 AD075303568EC3B139CEC4C22BAAECD1 c:\windows2\system32\dllcache\cache\tcpip.sys
[7] 2008-02-12 04:50 361344 AD075303568EC3B139CEC4C22BAAECD1 c:\windows2\system32\drivers\tcpip.sys
[7] 2004-08-12 13:33 502272 01C3346C241652F43AED8E2149881BFE c:\windows2\$NtServicePackUninstall$\winlogon.exe
[7] 2008-02-12 09:29 507904 57021A062C8E266C0A2A636450364B43 c:\windows2\ServicePackFiles\i386\winlogon.exe
[7] 2008-02-12 09:29 507904 57021A062C8E266C0A2A636450364B43 c:\windows2\system32\winlogon.exe
[7] 2008-02-12 09:29 507904 57021A062C8E266C0A2A636450364B43 c:\windows2\system32\dllcache\cache\winlogon.exe
[7] 2004-08-12 13:24 182912 558635D3AF1C7546D26067D5D9B6959E c:\windows2\$NtServicePackUninstall$\ndis.sys
[7] 2008-02-12 04:50 182656 104EFCE994264E4B36C1B6F5A846EB60 c:\windows2\ServicePackFiles\i386\ndis.sys
[7] 2008-02-12 04:50 182656 104EFCE994264E4B36C1B6F5A846EB60 c:\windows2\system32\dllcache\cache\ndis.sys
[7] 2008-02-12 04:50 182656 104EFCE994264E4B36C1B6F5A846EB60 c:\windows2\system32\drivers\ndis.sys
[7] 2004-08-12 13:20 29056 4448006B6BC60E6C027932CFC38D6855 c:\windows2\$NtServicePackUninstall$\ip6fw.sys
[7] 2008-02-11 21:44 36608 C0E5E466FC2C126429728060B5CD92D9 c:\windows2\ServicePackFiles\i386\ip6fw.sys
[7] 2008-02-11 21:44 36608 C0E5E466FC2C126429728060B5CD92D9 c:\windows2\system32\dllcache\cache\ip6fw.sys
[7] 2008-02-11 21:44 36608 C0E5E466FC2C126429728060B5CD92D9 c:\windows2\system32\drivers\ip6fw.sys
[-] 2005-03-02 00:36 2056832 D8ABA3EAB509627E707A3B14F00FBB6B c:\windows2\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
[-] 2006-12-19 16:12 2059392 BA4B97C00A437C1CC3DA365D93EE1E9D c:\windows2\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
[-] 2007-02-28 09:15 2059392 4D3DBDCCBF97F5BA1E74F322B155C3BA c:\windows2\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
[-] 2007-02-28 08:38 2057600 515D30E2C90A3665A2739309334C9283 c:\windows2\$NtServicePackUninstall$\ntkrnlpa.exe
[7] 2004-08-12 13:29 2056832 947FB1D86D14AFCFFDB54BF837EC25D0 c:\windows2\$NtUninstallKB890859$\ntkrnlpa.exe
[-] 2005-03-02 00:34 2056832 81013F36B21C7F72CF784CC6731E0002 c:\windows2\$NtUninstallKB931784$\ntkrnlpa.exe
[7] 2008-02-11 21:35 2065792 0C1C830277A60A348184337BE389EF7A c:\windows2\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2006-12-19 12:55 2057600 1D659BFB788ED2BA45075624B748D249 c:\windows2\SoftwareDistribution\Download\3211116c3ab1e0da28f96fd6d81ebbaa\sp2gdr\ntkrnlpa.exe
[7] 2008-02-11 21:35 2065792 0C1C830277A60A348184337BE389EF7A c:\windows2\system32\ntkrnlpa.exe
[7] 2008-02-11 21:35 2065792 0C1C830277A60A348184337BE389EF7A c:\windows2\system32\dllcache\cache\ntkrnlpa.exe
[-] 2005-03-02 01:04 2179456 28187802B7C368C0D3AEF7D4C382AABB c:\windows2\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
[-] 2006-12-19 16:51 2182016 CEF243F6DEFD20BE4ADDE26C7ECACB54 c:\windows2\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
[-] 2007-02-28 09:55 2182144 5A5C8DB4AA962C714C8371FBDF189FC9 c:\windows2\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
[-] 2007-02-28 09:10 2180352 582A8DBAA58C3B1F176EB2817DAEE77C c:\windows2\$NtServicePackUninstall$\ntoskrnl.exe
[7] 2004-08-12 13:25 2180992 CE218BC7088681FAA06633E218596CA7 c:\windows2\$NtUninstallKB890859$\ntoskrnl.exe
[-] 2005-03-02 00:59 2179328 4D4CF2C14550A4B7718E94A6E581856E c:\windows2\$NtUninstallKB931784$\ntoskrnl.exe
[7] 2008-02-11 22:34 2188928 BB94D7DBE41EB844B68D83B7FA6BC20B c:\windows2\ServicePackFiles\i386\ntoskrnl.exe
[-] 2006-12-19 14:17 2180352 8F0DEAB1F81FB83F9C5995853CE48B9F c:\windows2\SoftwareDistribution\Download\3211116c3ab1e0da28f96fd6d81ebbaa\sp2gdr\ntoskrnl.exe
[7] 2008-02-11 22:34 2188928 BB94D7DBE41EB844B68D83B7FA6BC20B c:\windows2\system32\ntoskrnl.exe
[7] 2008-02-11 22:34 2188928 BB94D7DBE41EB844B68D83B7FA6BC20B c:\windows2\system32\dllcache\cache\ntoskrnl.exe
[7] 2008-02-12 09:29 1033728 CB7C9E2BA846DA0AFABD19DE6B6F2006 c:\windows2\explorer.exe
[-] 2007-06-13 11:26 1033216 7712DF0CDDE3A5AC89843E61CD5B3658 c:\windows2\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 10:23 1033216 97BD6515465659FF8F3B7BE375B2EA87 c:\windows2\$NtServicePackUninstall$\explorer.exe
[7] 2004-08-12 13:19 1032192 A0732187050030AE399B241436565E64 c:\windows2\$NtUninstallKB938828$\explorer.exe
[7] 2008-02-12 09:29 1033728 CB7C9E2BA846DA0AFABD19DE6B6F2006 c:\windows2\ServicePackFiles\i386\explorer.exe
[7] 2008-02-12 09:29 1033728 CB7C9E2BA846DA0AFABD19DE6B6F2006 c:\windows2\system32\dllcache\cache\explorer.exe
[7] 2004-08-12 13:28 108032 C6CE6EEC82F187615D1002BB3BB50ED4 c:\windows2\$NtServicePackUninstall$\services.exe
[7] 2008-02-12 09:29 108544 3BF0DF2D99EE82B08C1E76B72FA562C7 c:\windows2\ServicePackFiles\i386\services.exe
[7] 2008-02-12 09:29 108544 3BF0DF2D99EE82B08C1E76B72FA562C7 c:\windows2\system32\services.exe
[7] 2008-02-12 09:29 108544 3BF0DF2D99EE82B08C1E76B72FA562C7 c:\windows2\system32\dllcache\cache\services.exe
[7] 2004-08-12 13:21 13312 84885F9B82F4D55C6146EBF6065D75D2 c:\windows2\$NtServicePackUninstall$\lsass.exe
[7] 2008-02-12 09:29 13312 70885577298B92939F3B7AF54D5F8943 c:\windows2\ServicePackFiles\i386\lsass.exe
[7] 2008-02-12 09:29 13312 70885577298B92939F3B7AF54D5F8943 c:\windows2\system32\lsass.exe
[7] 2008-02-12 09:29 13312 70885577298B92939F3B7AF54D5F8943 c:\windows2\system32\dllcache\cache\lsass.exe
[7] 2004-08-12 13:18 15360 24232996A38C0B0CF151C2140AE29FC8 c:\windows2\$NtServicePackUninstall$\ctfmon.exe
[7] 2008-02-12 09:29 15360 A3F00130A3177AF0A263AE640DFCFE4C c:\windows2\ServicePackFiles\i386\ctfmon.exe
[7] 2008-02-12 09:29 15360 A3F00130A3177AF0A263AE640DFCFE4C c:\windows2\system32\ctfmon.exe
[7] 2008-02-12 09:29 15360 A3F00130A3177AF0A263AE640DFCFE4C c:\windows2\system32\dllcache\cache\ctfmon.exe
[-] 2005-06-11 00:17 57856 AD3D9D191AEA7B5445FE1D82FFBB4788 c:\windows2\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2005-06-10 23:53 57856 DA81EC57ACD4CDC3D4C51CF3D409AF9F c:\windows2\$NtServicePackUninstall$\spoolsv.exe
[7] 2004-08-12 13:29 57856 7435B108B935E42EA92CA94F59C8E717 c:\windows2\$NtUninstallKB896423$\spoolsv.exe
[7] 2008-02-12 09:29 57856 8B7AF2E5DACFD5A6204FA276136D82CC c:\windows2\ServicePackFiles\i386\spoolsv.exe
[7] 2008-02-12 09:29 57856 8B7AF2E5DACFD5A6204FA276136D82CC c:\windows2\system32\spoolsv.exe
[7] 2008-02-12 09:29 57856 8B7AF2E5DACFD5A6204FA276136D82CC c:\windows2\system32\dllcache\cache\spoolsv.exe
[7] 2008-02-12 09:30 111104 811F9413EE81D3EBF0C7494A61A86393 c:\windows2\ServicePackFiles\i386\wuauclt.exe
[7] 2008-10-16 21:09 51224 E654B78D2F1D791B30D0ED9A8195EC22 c:\windows2\system32\wuauclt.exe
[7] 2008-10-16 21:09 51224 E654B78D2F1D791B30D0ED9A8195EC22 c:\windows2\system32\dllcache\wuauclt.exe
[7] 2008-10-16 21:09 51224 E654B78D2F1D791B30D0ED9A8195EC22 c:\windows2\system32\dllcache\cache\wuauclt.exe
[7] 2004-08-12 13:31 24576 39B1FFB03C2296323832ACBAE50D2AFF c:\windows2\$NtServicePackUninstall$\userinit.exe
[7] 2008-02-12 09:29 26112 E7FA45622EA5F16C9BC7379591262B25 c:\windows2\ServicePackFiles\i386\userinit.exe
[7] 2008-02-12 09:29 26112 E7FA45622EA5F16C9BC7379591262B25 c:\windows2\system32\userinit.exe
[7] 2008-02-12 09:29 26112 E7FA45622EA5F16C9BC7379591262B25 c:\windows2\system32\dllcache\cache\userinit.exe
[7] 2004-08-12 13:30 295424 B60C877D16D9C880B952FDA04ADF16E6 c:\windows2\$NtServicePackUninstall$\termsrv.dll
[7] 2008-02-12 09:29 295424 6BD9B61403E1A9B366FB46FD66464940 c:\windows2\ServicePackFiles\i386\termsrv.dll
[7] 2008-02-12 09:29 295424 6BD9B61403E1A9B366FB46FD66464940 c:\windows2\system32\termsrv.dll
[7] 2008-02-12 09:29 295424 6BD9B61403E1A9B366FB46FD66464940 c:\windows2\system32\dllcache\cache\termsrv.dll
[-] 1999-04-24 06:22 471040 375B0813980AE17DCC689E913AB9DD7B c:\windows2\KERNEL32.DLL
[-] 2006-07-05 10:57 985088 0FDD84928A5DDE2510761B7EC76CCEC9 c:\windows2\$hf_mig$\KB917422\SP2QFE\kernel32.dll
[-] 2007-04-16 16:07 986112 09F7CB3687F86EDAA4CA081F7AB66C03 c:\windows2\$hf_mig$\KB935839\SP2QFE\kernel32.dll
[-] 2007-04-16 15:52 984576 A01F9CA902A88F7CED06884174D6419D c:\windows2\$NtServicePackUninstall$\kernel32.dll
[7] 2004-08-12 13:20 983552 888190E31455FAD793312F8D087146EB c:\windows2\$NtUninstallKB935839$\kernel32.dll
[7] 2008-02-12 09:28 989696 25C5D3A94763B533BEDBED5C7ECE9734 c:\windows2\ServicePackFiles\i386\kernel32.dll
[-] 2006-07-05 10:55 984064 D8DB5397DE07577C1CB50BA6D23B3AD4 c:\windows2\SoftwareDistribution\Download\040e86cafc583a58922d9f353b3a41cf\sp2gdr\kernel32.dll
[7] 2008-02-12 09:28 989696 25C5D3A94763B533BEDBED5C7ECE9734 c:\windows2\system32\kernel32.dll
[7] 2008-02-12 09:28 989696 25C5D3A94763B533BEDBED5C7ECE9734 c:\windows2\system32\dllcache\cache\kernel32.dll
[7] 2004-08-12 13:26 17408 1B5F6923ABB450692E9FE0672C897AED c:\windows2\$NtServicePackUninstall$\powrprof.dll
[7] 2008-02-12 09:29 17408 FA18078DA0F79D1B32D1646431A79171 c:\windows2\ServicePackFiles\i386\powrprof.dll
[7] 2008-02-12 09:29 17408 FA18078DA0F79D1B32D1646431A79171 c:\windows2\system32\powrprof.dll
[7] 2008-02-12 09:29 17408 FA18078DA0F79D1B32D1646431A79171 c:\windows2\system32\dllcache\cache\powrprof.dll
[7] 2004-08-12 13:20 110080 87CA7CE6469577F059297B9D6556D66D c:\windows2\$NtServicePackUninstall$\imm32.dll
[7] 2008-02-12 09:28 110080 4368E21DAA2A7859B5B6D6F89C8DF99F c:\windows2\ServicePackFiles\i386\imm32.dll
[7] 2008-02-12 09:28 110080 4368E21DAA2A7859B5B6D6F89C8DF99F c:\windows2\system32\imm32.dll
[7] 2008-02-12 09:28 110080 4368E21DAA2A7859B5B6D6F89C8DF99F c:\windows2\system32\dllcache\cache\imm32.dll
[7] 2004-08-12 13:28 1580544 30A609E00BD1D4FFC49D6B5A432BE7F2 c:\windows2\$NtServicePackUninstall$\sfcfiles.dll
[7] 2008-02-12 09:29 1614848 1F7A2A5C1416FA73469216BFCCDA9395 c:\windows2\ServicePackFiles\i386\sfcfiles.dll
[7] 2008-02-12 09:29 1614848 1F7A2A5C1416FA73469216BFCCDA9395 c:\windows2\system32\sfcfiles.dll
[7] 2008-02-12 09:29 1614848 1F7A2A5C1416FA73469216BFCCDA9395 c:\windows2\system32\dllcache\cache\sfcfiles.dll
[7] 2004-08-12 13:17 167936 9C3C12975C97119412802B181FBEEFFE c:\windows2\$NtServicePackUninstall$\appmgmts.dll
[7] 2008-02-12 09:28 167936 A4DDB52FE0846A7F90C79CE9C655AD0A c:\windows2\ServicePackFiles\i386\appmgmts.dll
[7] 2008-02-12 09:28 167936 A4DDB52FE0846A7F90C79CE9C655AD0A c:\windows2\system32\appmgmts.dll
[7] 2008-02-12 09:28 167936 A4DDB52FE0846A7F90C79CE9C655AD0A c:\windows2\system32\dllcache\cache\appmgmts.dll
[7] 2004-08-12 13:20 24576 EBDEE8A2EE5393890A1ACEE971C4C246 c:\windows2\$NtServicePackUninstall$\kbdclass.sys
[7] 2008-02-11 21:42 24576 6946E7C9B6ACB20CDDAC1F12E08FEB58 c:\windows2\ServicePackFiles\i386\kbdclass.sys
[7] 2008-02-11 21:42 24576 6946E7C9B6ACB20CDDAC1F12E08FEB58 c:\windows2\system32\dllcache\cache\kbdclass.sys
[7] 2008-02-11 21:42 24576 6946E7C9B6ACB20CDDAC1F12E08FEB58 c:\windows2\system32\drivers\kbdclass.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-07-07_01.07.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-13 13:49 . 2009-07-13 13:49 16384 c:\windows2\temp\Perflib_Perfdata_728.dat
+ 2009-07-08 02:30 . 2009-07-08 02:30 148888 c:\windows2\system32\javaws.exe
+ 2009-07-08 02:30 . 2009-07-08 02:30 144792 c:\windows2\system32\javaw.exe
+ 2009-07-08 02:30 . 2009-07-08 02:30 144792 c:\windows2\system32\java.exe
+ 2009-07-10 00:59 . 2009-07-10 00:59 532480 c:\windows2\ERDNT\AutoBackup\7-9-2009\Users\00000002\UsrClass.dat
+ 2009-07-10 00:59 . 2005-10-20 19:02 163328 c:\windows2\ERDNT\AutoBackup\7-9-2009\ERDNT.EXE
+ 2009-07-09 01:40 . 2009-07-09 01:40 532480 c:\windows2\ERDNT\AutoBackup\7-8-2009\Users\00000002\UsrClass.dat
+ 2009-07-09 01:40 . 2005-10-20 19:02 163328 c:\windows2\ERDNT\AutoBackup\7-8-2009\ERDNT.EXE
+ 2009-07-07 13:20 . 2009-07-07 13:20 512000 c:\windows2\ERDNT\AutoBackup\7-7-2009\Users\00000002\UsrClass.dat
+ 2009-07-07 13:20 . 2005-10-20 19:02 163328 c:\windows2\ERDNT\AutoBackup\7-7-2009\ERDNT.EXE
+ 2009-07-13 13:51 . 2009-07-13 13:51 532480 c:\windows2\ERDNT\AutoBackup\7-13-2009\Users\00000002\UsrClass.dat
+ 2009-07-13 13:51 . 2005-10-20 19:02 163328 c:\windows2\ERDNT\AutoBackup\7-13-2009\ERDNT.EXE
+ 2009-07-12 13:10 . 2009-07-12 13:10 532480 c:\windows2\ERDNT\AutoBackup\7-12-2009\Users\00000002\UsrClass.dat
+ 2009-07-12 13:10 . 2005-10-20 19:02 163328 c:\windows2\ERDNT\AutoBackup\7-12-2009\ERDNT.EXE
+ 2009-07-11 13:47 . 2009-07-11 13:47 532480 c:\windows2\ERDNT\AutoBackup\7-11-2009\Users\00000002\UsrClass.dat
+ 2009-07-11 13:47 . 2005-10-20 19:02 163328 c:\windows2\ERDNT\AutoBackup\7-11-2009\ERDNT.EXE
+ 2009-07-10 13:31 . 2009-07-10 13:31 532480 c:\windows2\ERDNT\AutoBackup\7-10-2009\Users\00000002\UsrClass.dat
+ 2009-07-10 13:31 . 2005-10-20 19:02 163328 c:\windows2\ERDNT\AutoBackup\7-10-2009\ERDNT.EXE
+ 2005-10-20 13:53 . 2009-07-09 01:35 2211448 c:\windows2\system32\FNTCACHE.DAT
+ 2009-07-08 02:30 . 2009-07-08 02:30 1563648 c:\windows2\Installer\31018b.msi
+ 2009-07-10 00:59 . 2009-07-10 00:59 11935744 c:\windows2\ERDNT\AutoBackup\7-9-2009\Users\00000001\ntuser.dat
+ 2009-07-09 01:40 . 2009-07-09 01:40 11935744 c:\windows2\ERDNT\AutoBackup\7-8-2009\Users\00000001\ntuser.dat
+ 2009-07-07 13:20 . 2009-07-07 13:20 11935744 c:\windows2\ERDNT\AutoBackup\7-7-2009\Users\00000001\ntuser.dat
+ 2009-07-13 13:51 . 2009-07-13 13:51 11935744 c:\windows2\ERDNT\AutoBackup\7-13-2009\Users\00000001\ntuser.dat
+ 2009-07-12 13:10 . 2009-07-12 13:10 11935744 c:\windows2\ERDNT\AutoBackup\7-12-2009\Users\00000001\ntuser.dat
+ 2009-07-11 13:47 . 2009-07-11 13:47 11935744 c:\windows2\ERDNT\AutoBackup\7-11-2009\Users\00000001\ntuser.dat
+ 2009-07-10 13:31 . 2009-07-10 13:31 11935744 c:\windows2\ERDNT\AutoBackup\7-10-2009\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-06 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-08 148888]
c:\documents and settings\DBP\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2004-12-10 45056]
c:\documents and settings\All Users.WINDOWS2\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 2326528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SDhelper"=2 (0x2)
"ADSService"=2 (0x2)
"ElnkFWPPService"=3 (0x3)
"cmdService"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"Symantec Core LC"=2 (0x2)
"Pml Driver HPZ12"=3 (0x3)
"ose"=3 (0x3)
"NetSvc"=2 (0x2)
"MDM"=2 (0x2)
"Macromedia Licensing Service"=2 (0x2)
"LiveUpdate"=3 (0x3)
"gusvc"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Adobe LM Service"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\America Online 9.0b\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1157172737\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\1157172737\\EE\\aim6.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\WINDOWS2\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS2\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\msncall.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1157172737\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:*

isabled:EarthLink UHP Modem Support
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\windows2\system32\drivers\Lbd.sys [6/14/2009 5:56 PM 64160]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows2\system32\drivers\EAPPkt.sys [10/9/2007 1:13 PM 38144]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/17/2008 10:34 PM 24652]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows2\system32\drivers\wg111v3.sys [12/28/2007 3:02 PM 287232]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 1029456]
S3 acfva;acfva;c:\windows2\system32\drivers\acfva.sys [9/2/2006 2:34 PM 28445]
S3 ADSFilter;ADSFilter - (Aluria Filter Driver);c:\windows2\system32\DRIVERS\ADSFilter.sys --> c:\windows2\system32\DRIVERS\ADSFilter.sys [?]
S3 BW2NDIS5;BW2NDIS5;c:\windows2\system32\Drivers\BW2NDIS5.sys --> c:\windows2\system32\Drivers\BW2NDIS5.sys [?]
S3 WlanUIG;2Wire 802.11g USB Driver;c:\windows2\system32\drivers\WlanUIG.sys [1/13/2007 5:05 PM 347648]
S4 Stuffit Archive Name Service;Stuffit Archive Name Service;c:\program files\Smith Micro\StuffIt11\ArcNameService.exe [7/18/2007 3:26 PM 157000]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows2\system32\rundll32.exe" "c:\windows2\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-13 c:\windows2\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 01:03]
.
- - - - ORPHANS REMOVED - - - -
BHO-{8B2A62D8-E333-42C1-955B-DC5278F9FF4D} - (no file)
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyServer = 192.168.0.5:8080
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*
http://www.yahoo.com
IE: Display All Images with Full Quality - c:\program files\NetZero\qsacc\appres.dll/228
IE: Display Image with Full Quality - c:\program files\NetZero\qsacc\appres.dll/227
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: att.net
Trusted Zone: microsoft.com\office
Trusted Zone: sbcglobal.net
Trusted Zone: yahoo.com
TCP: {F9CDFA58-BAA3-4C29-BD94-83FBB681E11B} = 207.69.188.185,207.69.188.186
Handler: ezpp - {810403FA-E82E-11D5-8AAB-0010A404A3DE} - c:\windows2\system32\EZTOOL~1.DLL
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS2/Java/classes/xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-13 11:08
Windows 5.1.2600 Service Pack 3, v.3311 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(628)
c:\windows2\system32\igfxdev.dll
.
Completion time: 2009-07-13 11:23
ComboFix-quarantined-files.txt 2009-07-13 18:21
ComboFix2.txt 2009-07-08 01:16
ComboFix3.txt 2009-07-07 01:20
Pre-Run: 24,548,556,800 bytes free
Post-Run: 24,787,316,736 bytes free
387 --- E O F --- 2009-06-11 22:47
And here is the most recent dds log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by DBP at 11:24:45.45 on Mon 07/13/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.231 [GMT -7:00]
============== Running Processes ===============
C:\WINDOWS2\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS2\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS2\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS2\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS2\system32\wscntfy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS2\system32\notepad.exe
C:\WINDOWS2\explorer.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\DBP\Desktop\system\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyServer = 192.168.0.5:8080
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*
http://www.yahoo.com
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: X1IEHook Class: {52706ef7-d7a2-49ad-a615-e903858cf284} - c:\program files\netzero\qsacc\X1IEBHO.dll
BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows2\system32\dla\tfswshx.dll
BHO: WsftpBrowserHelper Class: {601ed020-fb6c-11d3-87d8-0050da59922b} - c:\program files\ipswitch\ws_ftp pro\wsbho2k0.dll
BHO: {8B2A62D8-E333-42C1-955B-DC5278F9FF4D} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: ZeroBar: {f5735c15-1fb2-41fe-ba12-242757e69dde} - c:\program files\netzero\toolbar.dll
TB: ZeroBar: {f0f8ecbe-d460-4b34-b007-56a92e8f84a7} - c:\program files\netzero\Toolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\dbp\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\dbp\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
StartupFolder: c:\docume~1\alluse~2.win\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe
IE: Display All Images with Full Quality - c:\program files\netzero\qsacc\appres.dll/228
IE: Display Image with Full Quality - c:\program files\netzero\qsacc\appres.dll/227
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: att.net
Trusted Zone: microsoft.com\office
Trusted Zone: sbcglobal.net
Trusted Zone: yahoo.com
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS2/Java/classes/xmldso.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {F9CDFA58-BAA3-4C29-BD94-83FBB681E11B} = 207.69.188.185,207.69.188.186
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: ezpp - {810403FA-E82E-11D5-8AAB-0010A404A3DE} - c:\windows2\system32\EZTOOL~1.DLL
Handler: junomsg - {C4D10830-379D-11d4-9B2D-00C04F1579A5} - c:\program files\juno\bin\jmsgpph.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows2\system32\WPDShServiceObj.dll
STS: IE Component Categories cache daemon: {553858a7-4922-4e7e-b1c1-97140c1c16ef} - c:\windows2\system32\ieframe.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows2\system32\drivers\Lbd.sys [2009-6-14 64160]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows2\system32\drivers\EAPPkt.sys [2007-10-9 38144]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-6-17 24652]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows2\system32\drivers\wg111v3.sys [2007-12-28 287232]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
S3 acfva;acfva;c:\windows2\system32\drivers\acfva.sys [2006-9-2 28445]
S3 ADSFilter;ADSFilter - (Aluria Filter Driver);c:\windows2\system32\drivers\adsfilter.sys --> c:\windows2\system32\drivers\ADSFilter.sys [?]
S3 BW2NDIS5;BW2NDIS5;c:\windows2\system32\drivers\bw2ndis5.sys --> c:\windows2\system32\drivers\BW2NDIS5.sys [?]
S3 WlanUIG;2Wire 802.11g USB Driver;c:\windows2\system32\drivers\WlanUIG.sys [2007-1-13 347648]
S4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-9 108648]
S4 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\CCPWDSVC.EXE [2004-12-13 79520]
S4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-9 108648]
S4 Stuffit Archive Name Service;Stuffit Archive Name Service;c:\program files\smith micro\stuffit11\ArcNameService.exe [2007-7-18 157000]
S4 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-8-18 1251720]
=============== Created Last 30 ================
2009-07-13 10:52 155,136 a------- c:\windows2\PEV.exe
2009-07-07 19:30 410,984 a------- c:\windows2\system32\deploytk.dll
2009-07-07 19:30 73,728 a------- c:\windows2\system32\javacpl.cpl
2009-07-06 18:17 <DIR> -cd----- c:\windows2\system32\dllcache\cache
2009-07-06 17:16 <DIR> a-dshr-- C:\cmdcons
2009-07-06 17:11 161,792 a------- c:\windows2\SWREG.exe
2009-07-06 17:11 98,816 a------- c:\windows2\sed.exe
2009-06-29 17:13 <DIR> --d----- c:\program files\Trend Micro
2009-06-27 11:06 <DIR> --d-h--- c:\windows2\msdownld.tmp
2009-06-27 11:06 <DIR> --d----- c:\windows2\Logs
2009-06-20 08:22 <DIR> --d----- c:\program files\XZAKTFrontFXTools1
2009-06-14 19:46 15,688 a------- c:\windows2\system32\lsdelete.exe
2009-06-14 17:56 64,160 a------- c:\windows2\system32\drivers\Lbd.sys
2009-06-14 17:45 <DIR> -cd-h--- c:\docume~1\alluse~2.win\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 17:45 <DIR> --d----- c:\program files\Lavasoft
==================== Find3M ====================
2009-06-30 22:02 524,288 a------- c:\windows2\system32\Busy_Wait.exe
2008-03-30 08:45 2,400,784 a------- c:\documents and settings\dbp\WLinstaller.exe
2008-03-04 11:10 724,984 a------- c:\documents and settings\dbp\gotomypc_437.exe
2008-02-27 01:05 774,144 a------- c:\program files\RngInterstitial.dll
2007-12-28 15:02 287,232 a------- c:\windows2\inf\wg111v3\wg111v3.sys
2007-12-28 14:59 342,528 a------- c:\windows2\inf\wg111v3\vista64\wg111v3.sys
2007-11-27 17:53 63,488 a------- c:\windows2\inf\wg111v3\SetDrv64.exe
2007-11-27 17:52 32,768 a------- c:\windows2\inf\wg111v3\SetDrv.exe
2007-08-21 14:10 3,902,784 a------- c:\documents and settings\dbp\gosetup.exe
2007-08-21 11:28 491 a------- c:\program files\UnInst.log
2007-01-25 21:28 722,176 a------- c:\documents and settings\dbp\gotomypc_428.exe
2007-01-20 10:01 563,712 a------- c:\documents and settings\dbp\gotomypc_370.exe
2006-12-15 11:30 315,392 a------- c:\windows2\inf\wg111v3\InstallDriver.exe
2006-12-15 11:30 212,992 a------- c:\windows2\inf\wg111v3\CopyWHQLDriver.exe
2006-12-15 11:30 98,304 a------- c:\windows2\inf\wg111v3\UScanM.exe
2006-12-15 11:30 20,480 a------- c:\windows2\inf\wg111v3\RTWUPath.exe
2006-12-15 11:30 19,968 a------- c:\windows2\inf\wg111v3\RTWREFU.EXE
2006-02-07 12:36 563,712 a------- c:\documents and settings\dbp\370_gotomypc.exe
2005-11-22 10:40 483,401 a------- c:\documents and settings\dbp\314_gotomypc.exe
2008-02-26 06:36 32,768 a--sh--- c:\windows2\system32\config\systemprofile\local settings\history\history.ie5\mshist012008022620080227\index.dat
============= FINISH: 11:24:55.67 ===============
Thanks for all your help.
Doug