Here is Combo log:
ComboFix 08-07-13.6 - Ken 2008-07-13 17:03:55.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.2030 [GMT -5:00]
Running from: C:\Users\Ken\Desktop\ComboFix.exe
Command switches used :: C:\Users\Ken\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\Windows\System32\drivers\lsissass.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\tn3
C:\Windows\system32\drivers\core.cache.dsk
C:\Windows\System32\drivers\lsissass.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_LSISSASS
-------\Service_lsissass
((((((((((((((((((((((((( Files Created from 2008-06-13 to 2008-07-13 )))))))))))))))))))))))))))))))
.
2008-07-12 19:12 . 2008-07-12 19:12 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-12 17:52 . 2008-07-12 17:52 <DIR> d-------- C:\Users\Ken\AppData\Roaming\Malwarebytes
2008-07-12 17:52 . 2008-07-12 17:52 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-07-12 17:52 . 2008-07-12 17:52 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-07-12 17:52 . 2008-07-12 17:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-12 17:52 . 2008-07-07 17:35 34,296 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-07-12 17:52 . 2008-07-07 17:35 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
2008-07-11 23:18 . 2008-04-26 03:25 3,600,952 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-07-11 23:18 . 2008-04-26 03:25 3,549,240 --a------ C:\Windows\System32\ntoskrnl.exe
2008-07-11 23:18 . 2008-04-26 03:26 891,448 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-07-11 23:18 . 2008-04-11 22:32 784,896 --a------ C:\Windows\System32\rpcrt4.dll
2008-07-11 23:18 . 2008-05-09 22:35 564,736 --a------ C:\Windows\System32\emdmgmt.dll
2008-07-11 23:18 . 2008-04-04 20:21 72,192 --a------ C:\Windows\System32\drivers\pacer.sys
2008-07-11 23:18 . 2008-04-04 22:34 15,360 --a------ C:\Windows\System32\pacerprf.dll
2008-07-11 23:12 . 2008-06-25 20:45 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
2008-07-11 23:12 . 2008-06-25 20:45 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
2008-07-11 23:11 . 2008-06-25 22:29 801,280 --a------ C:\Windows\System32\NaturalLanguage6.dll
2008-07-11 23:08 . 2008-05-08 16:59 430,080 --a------ C:\Windows\System32\vbscript.dll
2008-07-11 23:08 . 2008-05-08 16:59 180,224 --a------ C:\Windows\System32\scrobj.dll
2008-07-11 23:08 . 2008-05-08 16:59 172,032 --a------ C:\Windows\System32\scrrun.dll
2008-07-11 23:08 . 2008-05-08 16:59 155,648 --a------ C:\Windows\System32\wscript.exe
2008-07-11 23:08 . 2008-05-08 16:58 135,168 --a------ C:\Windows\System32\wshom.ocx
2008-07-11 23:08 . 2008-05-08 16:58 135,168 --a------ C:\Windows\System32\cscript.exe
2008-07-11 23:08 . 2008-05-08 16:59 90,112 --a------ C:\Windows\System32\wshext.dll
2008-07-10 22:03 . 2008-07-10 22:03 <DIR> d-------- C:\Users\Ken\AppData\Roaming\Comodo
2008-07-10 22:03 . 2008-07-10 22:56 <DIR> d-------- C:\Users\All Users\comodo
2008-07-10 22:03 . 2008-07-10 22:56 <DIR> d-------- C:\ProgramData\comodo
2008-07-10 22:03 . 2008-07-10 22:03 <DIR> d-------- C:\Program Files\COMODO
2008-07-10 22:03 . 2008-07-10 22:03 143,104 --a------ C:\Windows\System32\guard32.dll
2008-07-10 22:03 . 2008-07-10 22:03 85,008 --a------ C:\Windows\System32\drivers\cmdguard.sys
2008-07-10 22:03 . 2008-07-10 22:03 25,104 --a------ C:\Windows\System32\drivers\cmdhlp.sys
2008-07-06 21:50 . 2008-07-13 15:25 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-06 21:20 . 2008-07-12 17:44 <DIR> d-------- C:\Windows\System32\drivers\Avg
2008-07-06 21:20 . 2008-07-06 21:20 <DIR> d-------- C:\Users\All Users\avg8
2008-07-06 21:20 . 2008-07-06 21:20 <DIR> d-------- C:\ProgramData\avg8
2008-07-06 21:20 . 2008-07-06 21:20 <DIR> d-------- C:\Program Files\AVG
2008-07-06 21:20 . 2008-07-08 17:21 96,520 --a------ C:\Windows\System32\drivers\avgldx86.sys
2008-07-06 21:20 . 2008-07-06 21:20 10,520 --a------ C:\Windows\System32\avgrsstx.dll.old
2008-07-06 21:20 . 2008-07-08 17:21 10,520 --a------ C:\Windows\System32\avgrsstx.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-12 08:00 --------- d-----w C:\Program Files\Windows Mail
2008-07-11 01:44 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-07-11 01:25 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-30 23:41 --------- d-----w C:\Users\Ken\AppData\Roaming\Azureus
2008-06-25 12:34 --------- d-----w C:\ProgramData\Roxio
2008-06-25 11:48 --------- d-----w C:\Program Files\Free Windows Registry Cleaner
2008-06-20 01:57 --------- d-----w C:\ProgramData\WildTangent
2008-06-17 05:43 --------- d-----w C:\Program Files\Azureus
2008-06-17 03:37 --------- d-----w C:\Program Files\Blubster
2008-06-16 02:48 --------- d-----w C:\Users\Ken\AppData\Roaming\Vso
2008-06-05 01:38 --------- d-----w C:\Users\Ken\AppData\Roaming\Move Networks
2008-06-03 03:22 3,532 ----a-w C:\drmHeader.bin
2008-05-24 21:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-24 21:50 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-24 17:32 --------- d-----w C:\Users\Ken\AppData\Roaming\ESET
2008-05-24 17:31 --------- d-----w C:\ProgramData\ESET
2008-05-24 17:31 --------- d-----w C:\Program Files\ESET
2008-05-24 02:29 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-14 01:56 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-05-02 13:22 174 --sha-w C:\Program Files\desktop.ini
2008-05-02 12:58 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-05-02 12:58 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-05-02 12:32 47,560 ----a-w C:\Windows\System32\SPReview.exe
2008-05-02 12:32 152,576 ----a-w C:\Windows\System32\SPWizUI.dll
2008-04-26 08:08 1,314,816 ----a-w C:\Windows\System32\quartz.dll
2008-04-25 04:35 826,880 ----a-w C:\Windows\System32\wininet.dll
2008-04-23 04:42 428,544 ----a-w C:\Windows\System32\EncDec.dll
2008-04-23 04:42 293,376 ----a-w C:\Windows\System32\psisdecd.dll
2008-01-03 23:54 47,360 ----a-w C:\Users\Ken\AppData\Roaming\pcouffin.sys
2007-10-31 04:15 420 ----a-w C:\Users\Ken\AppData\Roaming\wklnhst.dat
2007-05-25 03:05 1,163,592 ----a-w C:\Users\Ken\install_flash_player.exe
2008-01-21 13:24 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-01-21 13:24 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
2008-01-06 20:31 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-01-06 20:31 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-01-06 20:31 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2007-09-02 19:26 22 --sha-w C:\Windows\SMINST\HPCD.sys
2008-02-01 05:37 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-07-13_15.54.45.74 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-13 20:49:54 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-07-13 22:11:13 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2005-10-21 01:02:28 163,328 ----a-w C:\Windows\erdnt\subs\ERDNT.EXE
- 2008-07-13 20:50:22 1,310,720 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-07-13 22:24:26 1,310,720 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
- 2008-07-13 20:50:22 1,310,720 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-07-13 22:24:28 1,310,720 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
- 2008-07-13 19:14:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-07-13 21:58:02 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-07-13 19:14:50 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-13 21:58:02 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-07-13 19:14:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-07-13 21:58:02 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-07-13 19:19:33 108,894 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-07-13 22:16:14 108,894 ----a-w C:\Windows\System32\perfc009.dat
- 2008-07-13 19:19:33 630,928 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-07-13 22:16:14 630,928 ----a-w C:\Windows\System32\perfh009.dat
- 2008-07-13 19:17:05 87,308 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-07-13 20:51:56 87,450 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-07-13 19:17:04 52,260 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-07-13 20:51:48 52,554 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-18 23:33 1233920]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-18 23:33 125952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 23:33 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-04-19 18:11 151552]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 06:28 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 06:28 8497696]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-08 17:21 1232152]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-07-10 22:03 1655552]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll C:\Windows\system32\guard32.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\Windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Connections.lnk]
backup=C:\Windows\pss\HP Connections.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCUTRAYICON]
FactoryMode [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero PhotoShow Media Manager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
--a------ 2006-08-14 01:07 102400 C:\Program Files\Roxio\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-05-08 16:24 54840 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
--a------ 2006-11-16 17:59 1480296 C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 2006-09-28 08:42 65536 c:\hp\support\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-02-16 20:15 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 13:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
--a------ 2006-12-08 10:16 65536 C:\hp\KBD\KbdStub.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-09-12 06:28 81920 C:\Windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 11:56 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
--a------ 2006-07-31 09:00 1116920 C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2006-08-10 12:10 221184 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management]
--a------ 2006-11-02 04:45 215552 C:\Windows\WindowsMobile\wmdSync.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-18 23:33 202240 C:\Program Files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{6E6A127A-0B43-4E56-8825-E2B3164F5BC0}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{BD383BD3-E6C8-4976-9397-C1937F40170F}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{C1819F0B-FF69-4093-AC3E-334153611C8E}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{A7013299-4886-43D0-A152-E4F8C42E372B}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{5D378F73-CF2A-42A5-8F87-96A6EE31A1E5}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{C30651B3-C136-488C-8C66-9A1A3140B937}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{A25263A1-2CDF-45DE-A8BF-897BDDCFA182}"= TCP:9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{0C06651B-F13E-4112-BF36-A7B656CAFA54}"= TCP:1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{B9A7B8B9-36F7-485C-8414-940D5A37D5D7}"= C:\Program Files\HP Connections\6811507\Program\HP Connections:HP Connections
"{46440B8A-A209-434E-8581-A0B58E16FE10}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{704700B6-6661-48AB-B252-C1D31D8D530C}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{9E7AD0E6-394C-43EF-BF81-A51607F222FF}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{ED568ABF-128B-40DC-8018-5768683BC34C}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{9534223D-A4DC-456C-AC10-742B7DAAD796}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{9A6C01E9-FCED-4196-8168-8C10D62C7349}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{5EFED946-E209-4339-AEF6-65EB5095474E}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{8D15887E-978C-4B68-9346-960FBF941865}"= UDP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{7C95C464-4593-4061-9C73-72B7344264B2}"= TCP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{354BB3EE-AD5A-415A-BF09-4E56F56EF56E}"= UDP:990:LocalSubnet:LocalSubnet|IF={07A70FF6-B72E-413E-BCDD-26B25CD51323}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr

%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{F8215624-F651-464D-80B2-DFB4A346180B}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{BC1473FC-95DA-4D54-A2E1-A04A3BA8E969}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{5A14463C-496E-42AD-AFAF-F83AB40C2266}"= UDP:990:LocalSubnet:LocalSubnet|IF={07A70FF6-B72E-413E-BCDD-26B25CD51323}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr

%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{48279ACF-FC4A-4F83-8DBE-10F952F5C473}"= UDP:990:LocalSubnet:LocalSubnet|IF={07A70FF6-B72E-413E-BCDD-26B25CD51323}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr

%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{BFE23D80-B40E-46DF-A3CB-FCF4B4DEFB00}"= TCP:63138:Azureus
"TCP Query User{6522C80F-39A6-4EA6-8F19-581E938F6EDF}C:\\users\\ken\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= UDP:C:\users\ken\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe
"UDP Query User{2121E812-5292-405E-953F-1D8B63466853}C:\\users\\ken\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= TCP:C:\users\ken\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe
"TCP Query User{776B6005-4A03-4232-AD28-14728E0DDD25}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{F651C470-9718-435E-9CCD-B24FC3E3084D}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"TCP Query User{415DE8D8-F688-433C-803B-8D1985307300}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{F34B6587-EC75-4FA8-91FB-79FFD6596631}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{B439C075-8792-466E-AC40-E4A2364B14D5}C:\\program files\\itunes\\itunes.exe"= UDP:C:\program files\itunes\itunes.exe:iTunes
"UDP Query User{4421A75E-99FE-4A45-9907-3B0D8C10E8C5}C:\\program files\\itunes\\itunes.exe"= TCP:C:\program files\itunes\itunes.exe:iTunes
"{506C781B-A9CE-418D-9EFC-ED5C4D16AB8D}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{538FD763-EC3B-466B-851E-F5606B631FAB}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{62564FD6-89FF-43D0-9E13-D6E6451202BD}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-07-08 17:21]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys [2008-07-10 22:03]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys [2008-07-10 22:03]
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2006-08-01 20:06]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-08 17:21]
R2 DQLWinService;DQLWinService;C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-09-03 13:32]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 09:42]
R3 hcw18bda;Hauppauge WinTV 418 Driver;C:\Windows\system32\drivers\hcw18bda.sys [2007-04-18 16:30]
S2 IntelDHSvcConf;Intel DH Service;C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe [2006-05-10 12:13]
S3 GameConsoleService;GameConsoleService;C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe [2008-05-05 17:25]
S3 NetDirect;TAP-Win32 NetDirect Adapter;C:\Windows\system32\DRIVERS\NetDirect.sys [2007-06-07 07:29]
S3 VST_DPV;VST_DPV;C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 02:41]
S3 VSTHWBS2;VSTHWBS2;C:\Windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 02:41]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6c69b87-bfcd-11db-9c7b-806e6f6e6963}]
\shell\AutoRun\command - K:\WD_Windows_Tools\setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder
"2008-07-13 22:24:28 C:\Windows\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-06-05 08:21:52 C:\Windows\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-07-13 16:32:10 C:\Windows\Tasks\User_Feed_Synchronization-{FE738198-38AB-4249-894A-3551E61D8C19}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-13 17:24:36
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG8\avgwdsvc.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2008-07-13 17:27:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-13 22:27:15
ComboFix2.txt 2008-07-13 20:56:13
Pre-Run: 208,983,330,816 bytes free
Post-Run: 211,285,188,608 bytes free
311 --- E O F --- 2008-07-12 07:32:32