New Logs as Requested
well, got the scans and logs done, but something just wasntsnt allowing me to get back online. im now here and here are the logs u requested
ComboFix 08-05-12.1 - Dredog B 2008-05-13 3:33:15.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.133 [GMT -7:00]
Running from: F:\Documents and Settings\Dredog B\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\WINDOWS\pskt.ini
.
---- Previous Run -------
.
F:\Documents and Settings\Dredog B\Application Data\SSTEM3~1
F:\Documents and Settings\Dredog B\My Documents\APPATC~1
F:\Documents and Settings\LocalService\Application Data\ShoppingReport
F:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\Config.xml
F:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\db\Aliases.dbs
F:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\db\Sites.dbs
F:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
F:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\report\aggr_storage.xml
F:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\report\send_storage.xml
F:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
F:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility_Icons
F:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ico
F:\Program Files\QdrDrive
F:\Program Files\Temporary
F:\WINDOWS\cookies.ini
F:\WINDOWS\pskt.ini
F:\WINDOWS\RHJlZG9nIEQu\
F:\WINDOWS\RHJlZG9nIEQu\\asappsrv.dll
F:\WINDOWS\RHJlZG9nIEQu\\command.exe
F:\WINDOWS\RHJlZG9nIEQu\command.exe
F:\WINDOWS\system32\BegMoUvw.ini
F:\WINDOWS\system32\BegMoUvw.ini2
F:\WINDOWS\system32\dcsvvcys.ini
F:\WINDOWS\system32\drivers\ftdiskk.sys
F:\WINDOWS\system32\jaqjikux.ini
F:\WINDOWS\system32\mcrh.tmp
F:\WINDOWS\system32\pac.txt
F:\WINDOWS\system32\pqusstex.ini
F:\WINDOWS\system32\VFfgPqru.ini
F:\WINDOWS\system32\VFfgPqru.ini2
F:\WINDOWS\system32\WyFfNXyb.ini
F:\WINDOWS\system32\WyFfNXyb.ini2
F:\WINDOWS\system32\zxdnt3d.cfg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Service_cmdService
-------\Legacy_FTDISKK
-------\Service_ftdiskk
((((((((((((((((((((((((( Files Created from 2008-04-13 to 2008-05-13 )))))))))))))))))))))))))))))))
.
2008-05-13 03:11 . 2008-05-13 03:11 108,608 --a------ F:\WINDOWS\system32\mfockvws.dll
2008-05-13 03:10 . 2008-05-13 03:10 366,592 --a------ F:\WINDOWS\system32\urqPgfFV.dll
2008-05-13 00:16 . 2008-05-13 00:16 2,112 --a------ F:\WINDOWS\system32\mjbnpbpd.exe
2008-05-13 00:13 . 2008-05-13 00:13 116,800 --a------ F:\WINDOWS\system32\xjvlpesb.dll
2008-05-13 00:12 . 2008-05-13 00:12 95,296 --a------ F:\WINDOWS\system32\xukijqaj.dll
2008-05-13 00:11 . 2008-05-13 00:11 109,632 --a------ F:\WINDOWS\system32\thmgsnnb.dll
2008-05-13 00:10 . 2008-05-13 00:10 370,688 --a------ F:\WINDOWS\system32\wvUoMgeB.dll
2008-05-13 00:05 . 2008-05-13 00:05 <DIR> d-------- F:\Documents and Settings\LocalService\Application Data\Symantec
2008-05-13 00:04 . 2008-05-13 00:04 <DIR> d-------- F:\WINDOWS\system32\Kaspersky Lab
2008-05-13 00:04 . 2008-05-13 00:04 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-12 17:08 . 2008-05-12 23:06 534 ---hs---- F:\WINDOWS\system32\dcsvvcys.ini
2008-05-12 16:49 . 2007-11-23 13:13 <DIR> d-------- F:\SDFix
2008-05-12 16:48 . 2008-05-12 16:49 <DIR> d-------- F:\Program Files\Common Files\Wise Installation Wizard
2008-05-12 16:46 . 2008-05-12 16:46 <DIR> d-------- F:\Program Files\Trend Micro
2008-05-12 01:24 . 2008-05-12 14:12 698 --a------ F:\WINDOWS\wininit.ini
2008-05-11 23:58 . 2008-05-11 23:59 <DIR> d-------- F:\Program Files\Spybot - Search & Destroy
2008-05-11 23:56 . 2008-05-11 23:55 691,545 --a------ F:\WINDOWS\unins000.exe
2008-05-11 23:56 . 2008-05-11 23:56 2,553 --a------ F:\WINDOWS\unins000.dat
2008-05-11 23:49 . 2008-05-12 10:09 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-11 22:11 . 2008-05-11 22:11 <DIR> d-------- F:\Program Files\SymNetDrv
2008-05-11 22:04 . 2008-05-11 22:04 <DIR> d-------- F:\Documents and Settings\NetworkService\Application Data\Yahoo!
2008-05-11 19:01 . 2008-05-11 19:01 4,608 --a------ F:\WINDOWS\system32\drivers\symlcbrd.sys
2008-05-11 19:00 . 2008-05-11 19:15 <DIR> d-------- F:\Documents and Settings\Dredog B\Application Data\Symantec
2008-05-11 19:00 . 2006-09-15 22:52 124,016 --a------ F:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-11 19:00 . 2006-09-15 22:52 91,904 --a------ F:\WINDOWS\system32\S32EVNT1.DLL
2008-05-11 18:59 . 2008-05-11 22:12 <DIR> d-------- F:\Program Files\Symantec
2008-05-11 18:59 . 2008-05-11 23:40 <DIR> d-------- F:\Program Files\Common Files\Symantec Shared
2008-05-11 18:59 . 2008-05-11 19:14 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Symantec
2008-05-11 13:48 . 2008-05-11 13:48 2,048 --a------ F:\WINDOWS\system32\jceundkf.exe
2008-05-11 13:43 . 2008-05-11 13:44 109,056 --a------ F:\WINDOWS\system32\rrfyejig.dll
2008-05-11 00:36 . 2008-05-13 02:56 1,024 --ah----- F:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-11 00:28 . 2008-05-11 00:28 9,662 --a------ F:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-05-10 16:12 . 2008-05-10 16:12 9,662 --a------ F:\WINDOWS\system32\pinkip.ico
2008-05-10 11:18 . 2008-05-10 11:18 2,048 --a------ F:\WINDOWS\system32\cskwkkad.exe
2008-05-10 11:15 . 2008-05-10 17:53 1,505,387 --ahs---- F:\WINDOWS\system32\pqusstex(2).ini
2008-05-10 11:12 . 2008-05-10 11:12 116,736 --a------ F:\WINDOWS\system32\kxaqtyyv.dll
2008-05-10 11:10 . 2008-05-10 11:10 110,080 --a------ F:\WINDOWS\system32\nffinghs.dll
2008-05-10 11:10 . 2008-05-10 11:10 110,080 --a------ F:\WINDOWS\system32\nffinghs(2).dll
2008-05-10 11:10 . 2008-05-13 03:20 109,807 --a------ F:\WINDOWS\BMcb788b9d.xml
2008-05-10 05:37 . 2008-05-10 05:37 13,942 --a------ F:\WINDOWS\system32\iphone-011.ico
2008-05-10 01:37 . 2008-05-10 01:37 9,662 --a------ F:\WINDOWS\system32\vaio3-011.ico
2008-05-09 23:13 . 2008-05-09 23:13 <DIR> d-------- F:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-05-09 21:36 . 2008-05-11 22:41 860 --a------ F:\WINDOWS\system32\winpfz33.sys
2008-05-09 21:35 . 2008-05-09 21:35 401,972 --a------ F:\WINDOWS\system32\g33.exe
2008-05-09 21:35 . 2008-05-09 21:35 28,672 --a------ F:\WINDOWS\system32\rqRJYrPG.dll
2008-05-09 21:34 . 2008-05-12 00:54 <DIR> d-------- F:\WINDOWS\system32\vdTMP
2008-05-09 21:34 . 2008-05-09 21:34 <DIR> d-------- F:\WINDOWS\system32\hNF
2008-05-09 21:34 . 2008-05-12 00:01 <DIR> d-------- F:\WINDOWS\system32\din3
2008-05-09 21:34 . 2008-05-12 00:01 <DIR> d-------- F:\WINDOWS\system32\dFrnx05
2008-05-09 21:34 . 2008-05-12 00:57 <DIR> d-------- F:\WINDOWS\system32\2033b
2008-05-09 21:34 . 2008-05-09 21:34 28,672 --a------ F:\WINDOWS\system32\iiffExyW.dll
2008-05-04 10:28 . 2008-05-04 10:29 <DIR> d-------- F:\Documents and Settings\Dredog B\Application Data\ArcSoft
2008-05-04 10:19 . 1995-07-31 13:44 212,480 --a------ F:\WINDOWS\PCDLIB32.DLL
2008-04-19 01:35 . 2008-04-19 01:35 <DIR> d-------- F:\WINDOWS\system32\Crystal
2008-04-19 01:35 . 2000-06-13 00:00 1,046,288 --a------ F:\WINDOWS\system32\msjet35.dll
2008-04-19 01:35 . 1999-03-29 13:23 595,968 --a------ F:\WINDOWS\system32\RESIZER.DLL
2008-04-19 01:35 . 1997-01-14 01:00 519,680 --a------ F:\WINDOWS\system32\DBGrid32.ocx
2008-04-19 01:35 . 2000-12-06 00:00 209,608 --a------ F:\WINDOWS\system32\TabCtl32.ocx
2008-04-19 01:35 . 1998-06-24 01:00 200,496 --a------ F:\WINDOWS\system32\DBList32.ocx
2008-04-19 01:35 . 1995-10-11 01:00 133,904 --a------ F:\WINDOWS\system32\Mfcans32.dll
2008-04-19 01:35 . 1997-12-08 01:00 123,664 --a------ F:\WINDOWS\system32\msjint35.dll
2008-04-19 01:35 . 1998-06-18 01:00 89,360 --a------ F:\WINDOWS\system32\Vb5db.dll
2008-04-19 01:35 . 1997-12-08 01:00 24,848 --a------ F:\WINDOWS\system32\msjter35.dll
2008-04-18 20:29 . 2008-05-10 16:56 51 --a------ F:\WINDOWS\system32\ver13399.dll
2008-04-18 20:28 . 2003-02-27 10:54 1,048,576 --a------ F:\WINDOWS\system32\tdbg8.ocx
2008-04-18 20:28 . 1997-07-11 00:00 368,912 --a------ F:\WINDOWS\system32\vbar332.dll
2008-04-18 20:28 . 2001-03-13 14:49 140,288 --a------ F:\WINDOWS\system32\COMDLG32.OCX
2008-04-14 01:35 . 2008-05-10 21:43 <DIR> d-------- F:\Documents and Settings\Dredog B\Incomplete
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-12 02:21 --------- d-----w F:\Program Files\PopCap Games
2008-05-11 00:46 --------- d-----w F:\Program Files\Dell Photo AIO Printer 964
2008-05-10 14:00 --------- d-----w F:\Program Files\Dl_cats
2008-05-04 17:34 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-04-14 10:16 --------- d-----w F:\Documents and Settings\Dredog B\Application Data\FrostWire
2008-04-14 02:39 --------- d-----w F:\Program Files\Common Files\LogiShrd
2008-04-13 09:05 --------- d-----w F:\Program Files\palmOne
2008-04-02 20:22 --------- d-----w F:\Documents and Settings\All Users\Application Data\Logitech
2008-03-26 03:53 --------- d-----w F:\Program Files\Common Files\InstallShield
2008-03-25 02:29 --------- d-----w F:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-25 02:26 --------- d-----w F:\Program Files\Yahoo!
2008-03-19 09:47 1,845,248 ----a-w F:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w F:\WINDOWS\system32\win32k(4).sys
2008-03-19 09:47 1,845,248 ----a-w F:\WINDOWS\system32\win32k(3).sys
2008-03-19 09:47 1,845,248 ----a-w F:\WINDOWS\system32\win32k(2).sys
2008-03-02 01:36 3,591,680 ----a-w F:\WINDOWS\system32\mshtml(3).dll
2008-03-02 01:36 3,591,680 ----a-w F:\WINDOWS\system32\mshtml(2).dll
2008-03-01 13:06 826,368 ----a-w F:\WINDOWS\system32\wininet.dll
2008-03-01 13:06 826,368 ----a-w F:\WINDOWS\system32\wininet(2).dll
2008-03-01 13:06 6,066,176 ----a-w F:\WINDOWS\system32\ieframe(2).dll
2008-03-01 13:06 267,776 ----a-w F:\WINDOWS\system32\iertutil(2).dll
2008-03-01 13:06 214,528 ----a-w F:\WINDOWS\system32\dxtrans(3).dll
2008-03-01 13:06 214,528 ----a-w F:\WINDOWS\system32\dxtrans(2).dll
2008-03-01 13:06 105,984 ----a-w F:\WINDOWS\system32\url(2).dll
2008-03-01 13:06 1,159,680 ----a-w F:\WINDOWS\system32\urlmon(2).dll
2008-02-29 08:55 70,656 ----a-w F:\WINDOWS\system32\ie4uinit(3).exe
2008-02-29 08:55 70,656 ----a-w F:\WINDOWS\system32\ie4uinit(2).exe
2008-02-22 10:00 13,824 ----a-w F:\WINDOWS\system32\ieudinit(3).exe
2008-02-22 10:00 13,824 ----a-w F:\WINDOWS\system32\ieudinit(2).exe
2008-02-20 06:51 282,624 ----a-w F:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w F:\WINDOWS\system32\gdi32(2).dll
2008-02-20 05:32 45,568 ----a-w F:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w F:\WINDOWS\system32\dnsapi(3).dll
2008-02-20 05:32 148,992 ----a-w F:\WINDOWS\system32\dnsapi(2).dll
2007-06-27 06:10 317,440 ----a-w F:\WINDOWS\inf\unregmp2(3).exe
2007-06-27 06:10 317,440 ----a-w F:\WINDOWS\inf\unregmp2(2).exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-12_17.14.31.04 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-13 00:06:04 2,048 --s-a-w F:\WINDOWS\bootstat.dat
+ 2008-05-13 10:18:42 2,048 --s-a-w F:\WINDOWS\bootstat.dat
+ 2005-05-24 19:27:16 213,048 ----a-w F:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 22:47:20 94,208 ----a-w F:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 22:49:54 950,272 ----a-w F:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1382AB6D-F331-4C6F-A904-737794F22C8A}]
F:\WINDOWS\system32\byXNfFyW.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5966C112-0937-4AE0-891E-0B5EA04368CF}]
2008-05-13 00:10 370688 --a------ F:\WINDOWS\system32\wvUoMgeB.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8FD6C367-D41E-49A0-96E8-964277D2C481}]
2008-05-13 03:10 366592 --a------ F:\WINDOWS\system32\urqPgfFV.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A7E81B89-DF38-40C8-A767-6FBECB65B862}]
2008-05-09 21:34 28672 --a------ F:\WINDOWS\system32\iiffExyW.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="F:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLCJCATS"="F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll" [2005-08-15 13:40 73728]
"13151845"="F:\WINDOWS\system32\sycvvscd.dll" [ ]
"BMcb788b9d"="F:\WINDOWS\system32\mfockvws.dll" [2008-05-13 03:11 108608]
"ccApp"="F:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32 58984]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{A7E81B89-DF38-40C8-A767-6FBECB65B862}"= F:\WINDOWS\system32\iiffExyW.dll [2008-05-09 21:34 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iiffExyW]
iiffExyW.dll 2008-05-09 21:34 28672 F:\WINDOWS\system32\iiffExyW.dll
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^desktop(2)(2).ini]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop(2)(2).ini
backup=F:\WINDOWS\pss\desktop(2)(2).iniCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^desktop(2).ini]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop(2).ini
backup=F:\WINDOWS\pss\desktop(2).iniCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^desktop(3).ini]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop(3).ini
backup=F:\WINDOWS\pss\desktop(3).iniCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME(2).lnk]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME(2).lnk
backup=F:\WINDOWS\pss\HOTSYNCSHORTCUTNAME(2).lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME(3).lnk]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME(3).lnk
backup=F:\WINDOWS\pss\HOTSYNCSHORTCUTNAME(3).lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=F:\WINDOWS\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^Dredog B^Start Menu^Programs^Startup^Deewoo(2).lnk]
path=F:\Documents and Settings\Dredog B\Start Menu\Programs\Startup\Deewoo(2).lnk
backup=F:\WINDOWS\pss\Deewoo(2).lnkStartup
[HKLM\~\startupfolder\F:^Documents and Settings^Dredog B^Start Menu^Programs^Startup^Deewoo(3).lnk]
path=F:\Documents and Settings\Dredog B\Start Menu\Programs\Startup\Deewoo(3).lnk
backup=F:\WINDOWS\pss\Deewoo(3).lnkStartup
[HKLM\~\startupfolder\F:^Documents and Settings^Dredog B^Start Menu^Programs^Startup^Deewoo.lnk]
path=F:\Documents and Settings\Dredog B\Start Menu\Programs\Startup\Deewoo.lnk
backup=F:\WINDOWS\pss\Deewoo.lnkStartup
[HKLM\~\startupfolder\F:^Documents and Settings^Dredog B^Start Menu^Programs^Startup^desktop(2)(2).ini]
path=F:\Documents and Settings\Dredog B\Start Menu\Programs\Startup\desktop(2)(2).ini
backup=F:\WINDOWS\pss\desktop(2)(2).iniStartup
[HKLM\~\startupfolder\F:^Documents and Settings^Dredog B^Start Menu^Programs^Startup^desktop(2).ini]
path=F:\Documents and Settings\Dredog B\Start Menu\Programs\Startup\desktop(2).ini
backup=F:\WINDOWS\pss\desktop(2).iniStartup
[HKLM\~\startupfolder\F:^Documents and Settings^Dredog B^Start Menu^Programs^Startup^desktop(3).ini]
path=F:\Documents and Settings\Dredog B\Start Menu\Programs\Startup\desktop(3).ini
backup=F:\WINDOWS\pss\desktop(3).iniStartup
[HKLM\~\startupfolder\F:^Documents and Settings^Dredog B^Start Menu^Programs^Startup^DW_Start(2).lnk]
path=F:\Documents and Settings\Dredog B\Start Menu\Programs\Startup\DW_Start(2).lnk
backup=F:\WINDOWS\pss\DW_Start(2).lnkStartup
[HKLM\~\startupfolder\F:^Documents and Settings^Dredog B^Start Menu^Programs^Startup^DW_Start(3).lnk]
path=F:\Documents and Settings\Dredog B\Start Menu\Programs\Startup\DW_Start(3).lnk
backup=F:\WINDOWS\pss\DW_Start(3).lnkStartup
[HKLM\~\startupfolder\F:^Documents and Settings^Dredog B^Start Menu^Programs^Startup^DW_Start.lnk]
path=F:\Documents and Settings\Dredog B\Start Menu\Programs\Startup\DW_Start.lnk
backup=F:\WINDOWS\pss\DW_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-03-09 12:09 63712 F:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 F:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMcb788b9d]
--a------ 2008-05-11 13:44 109056 F:\WINDOWS\system32\rrfyejig.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2007-01-09 17:32 58984 F:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlcjmon.exe]
--a------ 2005-09-30 10:51 430080 F:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
F:\WINDOWS\system32\scntskdm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JavaCore]
F:\Program Files\\JavaCore\\JavaCore.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kumz]
F:\PROGRA~1\COMMON~1\kumz\kumzm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
--a------ 2005-08-10 10:12 286720 F:\Program Files\Dell Photo AIO Printer 964\memcard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 09:24 1694208 F:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 F:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 F:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Svconr]
F:\Program Files\Svconr\Svconr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
--a------ 2008-05-11 22:11 100056 F:\PROGRA~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebSUpdater]
C:\Program Files\winvi\wupda.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinUpdater]
C:\Program Files\winvi\update.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-12-17 17:13 3810544 F:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{51-18-8E-EA-DW}]
F:\windows\system32\rwwnw64d.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"F:\\WINDOWS\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*

isabled

xpsp2res.dll,-22009
R2 zumbus;Zune Bus Enumerator Driver;F:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 18:39]
R3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);F:\WINDOWS\system32\drivers\ctlsb16.sys [2001-08-17 05:19]
S3 BrScnUsb;Brother USB Still Image driver;F:\WINDOWS\system32\Drivers\BrScnUsb.sys [2004-10-14 20:50]
S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;F:\WINDOWS\system32\Drivers\BrSerIf.sys [2006-01-18 06:44]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver;F:\WINDOWS\system32\Drivers\BrUsbSer.sys [2006-01-18 20:17]
S3 samhid;samhid;F:\WINDOWS\system32\drivers\samhid.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-05-12 02:20:30 F:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Dredog B.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-13 03:36:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: F:\WINDOWS\system32\winlogon.exe
-> F:\WINDOWS\system32\iiffExyW.dll
.
Completion time: 2008-05-13 3:40:53
ComboFix-quarantined-files.txt 2008-05-13 10:40:39
Pre-Run: 14,516,346,880 bytes free
Post-Run: 14,505,418,752 bytes free
320 --- E O F --- 2008-05-12 06:02:44