UPDATE
I think this is what you wanted.
ComboFix 07-12-12.3 - ofoor 2007-12-21 15:13:24.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.101 [GMT -8:00]
Running from: C:\Documents and Settings\ofoor\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\ofoor\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\SYSTEM32\ppqss.bak1
C:\WINDOWS\SYSTEM32\ppqss.bak2
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\SYSTEM32\ppqss.bak1
C:\WINDOWS\SYSTEM32\ppqss.bak2
.
((((((((((((((((((((((((( Files Created from 2007-11-21 to 2007-12-21 )))))))))))))))))))))))))))))))
.
2007-12-07 23:03 . 2007-12-07 23:03 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-12-06 02:41 . 2007-08-20 02:04 6,058,496 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2007-12-06 02:41 . 2007-04-17 01:32 2,455,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2007-12-06 02:41 . 2007-03-07 21:10 991,232 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2007-12-06 02:41 . 2007-08-20 02:04 459,264 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2007-12-06 02:41 . 2007-08-20 02:04 383,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2007-12-06 02:41 . 2007-08-20 02:04 267,776 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2007-12-06 02:41 . 2007-08-20 02:04 63,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2007-12-06 02:41 . 2007-08-20 02:04 52,224 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2007-12-06 02:41 . 2007-08-17 02:20 13,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-12-06 02:28 . 2007-12-06 02:30 <DIR> d-------- C:\de4829dd77365fae207638b3625e35
2007-12-06 02:00 . 2007-12-06 02:00 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-06 01:59 . 2007-12-06 01:59 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-04 11:49 . 2007-12-04 11:49 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-12-04 11:49 . 2007-12-04 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-04 10:53 . 2007-12-04 10:53 <DIR> d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-21 23:18 4,147,232 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-20 23:32 48,020 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-13 14:45 1,368,052 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-06 11:17 --------- d-----w C:\Program Files\Yahoo!
2007-12-06 11:17 --------- d-----w C:\Program Files\Common Files\Scanner
2007-12-06 11:17 --------- d-----w C:\Documents and Settings\ofoor\Application Data\Yahoo!
2007-12-06 11:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-06 11:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-20 21:31 --------- d-----w C:\Program Files\Lavasoft
2007-11-20 21:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-20 21:27 --------- d-----w C:\Documents and Settings\ofoor\Application Data\Lavasoft
2007-11-20 21:24 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-19 20:33 --------- d-----w C:\Program Files\The Cleaner Free
2007-11-19 18:54 5,376 ----a-w C:\WINDOWS\system32\drivers\MS1000.sys
2007-11-16 18:27 --------- d-----w C:\Program Files\RogueRemover FREE
2007-11-15 18:14 --------- d-----w C:\Documents and Settings\ofoor\Application Data\AVG7
2007-11-14 21:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2007-11-14 21:55 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-14 20:19 9,216 ----a-w C:\WINDOWS\SYSTEM32\avgwlntf.dll
2007-11-14 20:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-14 18:32 82,432 ----a-w C:\WINDOWS\SYSTEM32\msxml4r.dll
2007-11-14 18:32 44,544 ----a-w C:\WINDOWS\SYSTEM32\msxml4a.dll
2007-11-14 18:32 --------- d-----w C:\Program Files\RealVNC
2007-11-14 18:23 --------- d-----w C:\Program Files\Tektegrity
2007-11-11 02:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-11-11 01:47 --------- d-----w C:\Program Files\iolo
2007-11-07 21:26 --------- d-----w C:\Documents and Settings\ofoor\Application Data\U3
2007-11-07 18:10 117 ----a-w C:\Documents and Settings\ofoor\mit.bat
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2005-03-10 18:20 561,152 -c--a-w C:\Documents and Settings\ofoor\chatlnk.exe
.
((((((((((((((((((((((((((((( snapshot_2007-12-06_23.48.15.26 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-27 11:58:11 140,288 ----a-w C:\WINDOWS\catchme.exe
+ 2007-12-10 03:04:27 142,336 ----a-w C:\WINDOWS\catchme.exe
+ 2004-08-04 07:56:43 25,088 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mslbui.dll
+ 2004-08-04 07:56:46 43,520 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wbemsvc.dll
- 2007-11-14 20:19:29 3,968 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\avgclean.sys
+ 2007-12-20 15:02:14 10,760 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\avgclean.sys
- 2007-11-14 20:38:19 19,904 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys
+ 2007-12-20 15:01:54 26,952 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys
+ 2006-12-04 22:37:58 1,317,648 ----a-w C:\WINDOWS\SYSTEM32\msxml6.dll
+ 2006-10-05 12:31:10 79,872 ----a-w C:\WINDOWS\SYSTEM32\msxml6r.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 06:59]
"System Mechanic Popup Stopper"="C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe" [2004-10-26 15:39]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:56 C:\WINDOWS\SYSTEM32\rundll32.exe]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 17:12]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-12 22:01]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 10:35]
"ADUserMon"="C:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 15:39]
"Iomega Drive Icons"="C:\Program Files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 13:30]
"Deskup"="C:\Program Files\Iomega\DriveIcons\deskup.exe" [2002-07-16 09:55]
"StatusClient 2.6"="C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2005-04-08 10:18]
"TomcatStartup 2.5"="C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2004-05-20 10:37]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe" [2005-03-13 19:21]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-04-14 23:11]
"Kaseya Agent Service Helper"="c:\Program Files\Tektegrity\Client\Agent\KaUsrTsk.exe" [2007-06-04 20:04]
C:\Documents and Settings\jeff.BILLING_01\Start Menu\Programs\Startup\
Shortcut to MAP F.lnk - C:\MAP F.BAT [2004-04-30 15:55:03]
C:\Documents and Settings\ofoor\Start Menu\Programs\Startup\
LaunchU3.exe.lnk - C:\Documents and Settings\ofoor\Application Data\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe [2006-11-26 12:37:21]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - C:\WINDOWS\Installer\{D25122BC-A60E-4663-B602-B01718F12044}\Icon3E5562ED7.ico [2006-08-01 15:04:19]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-11-14 12:19 9216 C:\WINDOWS\SYSTEM32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
RUNDLL32.exe C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll,cdaEngineMain
R2 KaseyaAgent;TekTegrity Agent;"c:\Program Files\Tektegrity\Client\Agent\AgentMon.exe" -s
R2 KaseyaAVService;Kaseya Security Service;"c:\Program Files\Tektegrity\Client\Agent\KasAVSrv.exe" -s
S3 MS1000;MS1000;C:\WINDOWS\system32\DRIVERS\MS1000.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a432314-4ca7-11db-bf3f-000cf1e4889b}]
\Shell\AutoRun\command - E:\LaunchU3.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-21 15:18:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\System32\NavLogon.dll
.
Completion time: 2007-12-21 15:20:28
C:\ComboFix2.txt ... 2007-12-21 14:42
C:\ComboFix3.txt ... 2007-12-14 15:13
.
2007-11-14 17:21:55 --- E O F ---
I think this is what you wanted.
ComboFix 07-12-12.3 - ofoor 2007-12-21 15:13:24.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.101 [GMT -8:00]
Running from: C:\Documents and Settings\ofoor\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\ofoor\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\SYSTEM32\ppqss.bak1
C:\WINDOWS\SYSTEM32\ppqss.bak2
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\SYSTEM32\ppqss.bak1
C:\WINDOWS\SYSTEM32\ppqss.bak2
.
((((((((((((((((((((((((( Files Created from 2007-11-21 to 2007-12-21 )))))))))))))))))))))))))))))))
.
2007-12-07 23:03 . 2007-12-07 23:03 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-12-06 02:41 . 2007-08-20 02:04 6,058,496 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2007-12-06 02:41 . 2007-04-17 01:32 2,455,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2007-12-06 02:41 . 2007-03-07 21:10 991,232 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2007-12-06 02:41 . 2007-08-20 02:04 459,264 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2007-12-06 02:41 . 2007-08-20 02:04 383,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2007-12-06 02:41 . 2007-08-20 02:04 267,776 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2007-12-06 02:41 . 2007-08-20 02:04 63,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2007-12-06 02:41 . 2007-08-20 02:04 52,224 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2007-12-06 02:41 . 2007-08-17 02:20 13,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-12-06 02:28 . 2007-12-06 02:30 <DIR> d-------- C:\de4829dd77365fae207638b3625e35
2007-12-06 02:00 . 2007-12-06 02:00 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-12-06 01:59 . 2007-12-06 01:59 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-04 11:49 . 2007-12-04 11:49 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-12-04 11:49 . 2007-12-04 11:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-04 10:53 . 2007-12-04 10:53 <DIR> d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-21 23:18 4,147,232 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-20 23:32 48,020 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-13 14:45 1,368,052 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-06 11:17 --------- d-----w C:\Program Files\Yahoo!
2007-12-06 11:17 --------- d-----w C:\Program Files\Common Files\Scanner
2007-12-06 11:17 --------- d-----w C:\Documents and Settings\ofoor\Application Data\Yahoo!
2007-12-06 11:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-06 11:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-20 21:31 --------- d-----w C:\Program Files\Lavasoft
2007-11-20 21:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-20 21:27 --------- d-----w C:\Documents and Settings\ofoor\Application Data\Lavasoft
2007-11-20 21:24 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-19 20:33 --------- d-----w C:\Program Files\The Cleaner Free
2007-11-19 18:54 5,376 ----a-w C:\WINDOWS\system32\drivers\MS1000.sys
2007-11-16 18:27 --------- d-----w C:\Program Files\RogueRemover FREE
2007-11-15 18:14 --------- d-----w C:\Documents and Settings\ofoor\Application Data\AVG7
2007-11-14 21:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2007-11-14 21:55 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-14 20:19 9,216 ----a-w C:\WINDOWS\SYSTEM32\avgwlntf.dll
2007-11-14 20:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-14 18:32 82,432 ----a-w C:\WINDOWS\SYSTEM32\msxml4r.dll
2007-11-14 18:32 44,544 ----a-w C:\WINDOWS\SYSTEM32\msxml4a.dll
2007-11-14 18:32 --------- d-----w C:\Program Files\RealVNC
2007-11-14 18:23 --------- d-----w C:\Program Files\Tektegrity
2007-11-11 02:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-11-11 01:47 --------- d-----w C:\Program Files\iolo
2007-11-07 21:26 --------- d-----w C:\Documents and Settings\ofoor\Application Data\U3
2007-11-07 18:10 117 ----a-w C:\Documents and Settings\ofoor\mit.bat
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2005-03-10 18:20 561,152 -c--a-w C:\Documents and Settings\ofoor\chatlnk.exe
.
((((((((((((((((((((((((((((( snapshot_2007-12-06_23.48.15.26 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-27 11:58:11 140,288 ----a-w C:\WINDOWS\catchme.exe
+ 2007-12-10 03:04:27 142,336 ----a-w C:\WINDOWS\catchme.exe
+ 2004-08-04 07:56:43 25,088 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mslbui.dll
+ 2004-08-04 07:56:46 43,520 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wbemsvc.dll
- 2007-11-14 20:19:29 3,968 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\avgclean.sys
+ 2007-12-20 15:02:14 10,760 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\avgclean.sys
- 2007-11-14 20:38:19 19,904 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys
+ 2007-12-20 15:01:54 26,952 ----a-w C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys
+ 2006-12-04 22:37:58 1,317,648 ----a-w C:\WINDOWS\SYSTEM32\msxml6.dll
+ 2006-10-05 12:31:10 79,872 ----a-w C:\WINDOWS\SYSTEM32\msxml6r.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 06:59]
"System Mechanic Popup Stopper"="C:\Program Files\iolo\System Mechanic 5\PopupStopper.exe" [2004-10-26 15:39]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:56 C:\WINDOWS\SYSTEM32\rundll32.exe]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 17:12]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-12 22:01]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 10:35]
"ADUserMon"="C:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 15:39]
"Iomega Drive Icons"="C:\Program Files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 13:30]
"Deskup"="C:\Program Files\Iomega\DriveIcons\deskup.exe" [2002-07-16 09:55]
"StatusClient 2.6"="C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2005-04-08 10:18]
"TomcatStartup 2.5"="C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2004-05-20 10:37]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe" [2005-03-13 19:21]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-04-14 23:11]
"Kaseya Agent Service Helper"="c:\Program Files\Tektegrity\Client\Agent\KaUsrTsk.exe" [2007-06-04 20:04]
C:\Documents and Settings\jeff.BILLING_01\Start Menu\Programs\Startup\
Shortcut to MAP F.lnk - C:\MAP F.BAT [2004-04-30 15:55:03]
C:\Documents and Settings\ofoor\Start Menu\Programs\Startup\
LaunchU3.exe.lnk - C:\Documents and Settings\ofoor\Application Data\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe [2006-11-26 12:37:21]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - C:\WINDOWS\Installer\{D25122BC-A60E-4663-B602-B01718F12044}\Icon3E5562ED7.ico [2006-08-01 15:04:19]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-11-14 12:19 9216 C:\WINDOWS\SYSTEM32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
RUNDLL32.exe C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll,cdaEngineMain
R2 KaseyaAgent;TekTegrity Agent;"c:\Program Files\Tektegrity\Client\Agent\AgentMon.exe" -s
R2 KaseyaAVService;Kaseya Security Service;"c:\Program Files\Tektegrity\Client\Agent\KasAVSrv.exe" -s
S3 MS1000;MS1000;C:\WINDOWS\system32\DRIVERS\MS1000.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a432314-4ca7-11db-bf3f-000cf1e4889b}]
\Shell\AutoRun\command - E:\LaunchU3.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-21 15:18:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\System32\NavLogon.dll
.
Completion time: 2007-12-21 15:20:28
C:\ComboFix2.txt ... 2007-12-21 14:42
C:\ComboFix3.txt ... 2007-12-14 15:13
.
2007-11-14 17:21:55 --- E O F ---