okay, got the combofix here...but avast activated itself after the reboot so dont know if it interfered with the results.
and on a side-note, ive never seen so many "a virus has been detected" notifications in my life. possibly because my computer actually gets treat with an once of respect
Ive noticed hes got both Limwire and Vuze installed, so im going to get rid of them as well.
ComboFix 09-03-10.03 - lee hill 2009-03-11 22:18:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.223.48 [GMT 0:00]
Running from: c:\documents and settings\lee hill\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090205-1] *On-access scanning disabled* (Outdated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\lee hill\Application Data\
02000000ac1ccf51530C.manifest
c:\documents and settings\lee hill\Application Data\
02000000ac1ccf51530O.manifest
c:\documents and settings\lee hill\Application Data\
02000000ac1ccf51530P.manifest
c:\documents and settings\lee hill\Application Data\
02000000ac1ccf51530S.manifest
c:\windows\GnuHashes.ini
c:\windows\system32\__c002BF04.dat
c:\windows\system32\__c004517.dat
c:\windows\system32\__c0051131.dat
c:\windows\system32\__c005DE3A.dat
c:\windows\system32\__c0063031.dat
c:\windows\system32\__c0078A84.dat
c:\windows\system32\__c007EB2.dat
c:\windows\system32\__c00A5190.dat
c:\windows\system32\__c00B93BF.dat
c:\windows\system32\__c00EA361.dat
c:\windows\system32\__c00FF684.dat
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\pthreadGC2.dll
C:\xcrashdump.dat
.
((((((((((((((((((((((((( Files Created from 2009-02-11 to 2009-03-11 )))))))))))))))))))))))))))))))
.
2009-03-11 22:28 . 2009-03-11 22:28 0 --a------ c:\windows\system32\2.tmp
2009-03-11 21:31 . 2009-03-11 21:31 <DIR> d-------- c:\program files\Alwil Software
2009-03-11 21:31 . 2003-03-18 20:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2009-03-11 21:17 . 2009-03-11 22:28 <DIR> d--hs---- c:\windows\system32\NetworkService32
2009-03-10 19:16 . 2009-03-10 19:16 <DIR> d-------- c:\program files\Trend Micro
2009-03-08 09:54 . 2009-03-08 09:54 374,272 --ahs---- c:\windows\system32\35.tmp
2009-03-07 13:54 . 2009-03-07 13:54 374,272 --ahs---- c:\windows\system32\33.tmp
2009-03-06 17:54 . 2009-03-06 17:54 374,272 --ahs---- c:\windows\system32\22.tmp
2009-03-01 12:45 . 2009-03-01 12:45 135,680 --a------ c:\windows\umezudan.dll
2009-03-01 12:33 . 2009-03-01 12:33 43,520 --a------ c:\windows\Pzolukog.dll
2009-02-28 19:48 . 2009-02-28 19:48 374,272 --ahs---- c:\windows\system32\10.tmp
2009-02-28 19:47 . 2009-02-28 19:47 135,168 --a------ c:\windows\system32\ifxcardm32.dll
2009-02-28 18:28 . 2008-01-01 08:00 499,712 --a------ c:\windows\system32\msvcp71.dll
2009-02-28 18:28 . 2008-01-01 08:00 348,160 --a------ c:\windows\system32\msvcr71.dll
2009-02-28 18:28 . 2008-01-02 03:12 7,680 --a------ c:\windows\system32\ff_vfw.dll
2009-02-28 18:28 . 2008-01-02 03:12 6,144 --a------ c:\windows\system32\ff_acm.acm
2009-02-28 18:28 . 2008-01-01 08:00 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2009-02-28 18:18 . 2009-02-28 18:29 <DIR> d-------- c:\program files\ffdshow
2009-02-27 22:15 . 2009-02-27 22:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-02-27 22:13 . 2009-02-27 22:13 <DIR> d-------- c:\program files\Messenger Plus! Live
2009-02-27 22:04 . 2009-02-07 02:08 55,152 --a------ c:\windows\system32\drivers\fssfltr_tdi.sys
2009-02-25 06:49 . 2008-06-17 19:02 8,461,312 -----c--- c:\windows\system32\dllcache\shell32.dll
2009-02-22 20:15 . 2009-02-22 20:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Azureus
2009-02-22 20:14 . 2009-03-09 11:30 <DIR> d-------- c:\documents and settings\lee hill\Application Data\Azureus
2009-02-22 20:11 . 2009-02-28 09:00 <DIR> d-------- c:\program files\Vuze
2009-02-22 19:54 . 2009-02-22 19:55 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-02-22 19:54 . 2009-02-22 21:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-22 19:34 . 2009-03-04 00:23 <DIR> d-------- c:\documents and settings\lee hill\Application Data\LimeWire
2009-02-22 19:33 . 2009-02-22 19:34 <DIR> d-------- c:\program files\LimeWire
2009-02-20 10:49 . 2008-05-09 10:53 512,000 -----c--- c:\windows\system32\dllcache\jscript.dll
2009-02-20 10:49 . 2008-05-09 10:53 430,080 -----c--- c:\windows\system32\dllcache\vbscript.dll
2009-02-20 10:49 . 2008-05-09 10:53 180,224 -----c--- c:\windows\system32\dllcache\scrobj.dll
2009-02-20 10:49 . 2008-05-09 10:53 172,032 -----c--- c:\windows\system32\dllcache\scrrun.dll
2009-02-20 10:49 . 2008-05-08 11:24 155,648 -----c--- c:\windows\system32\dllcache\wscript.exe
2009-02-20 10:49 . 2008-05-09 08:45 135,168 -----c--- c:\windows\system32\dllcache\cscript.exe
2009-02-20 10:49 . 2008-05-09 10:53 90,112 -----c--- c:\windows\system32\dllcache\wshext.dll
2009-02-19 21:20 . 2009-02-19 21:20 <DIR> d-------- c:\windows\system32\scripting
2009-02-19 21:20 . 2009-02-19 21:20 <DIR> d-------- c:\windows\system32\bits
2009-02-19 21:20 . 2009-02-19 21:20 <DIR> d-------- c:\windows\l2schemas
2009-02-19 21:09 . 2009-02-19 21:23 <DIR> d-------- c:\windows\ServicePackFiles
2009-02-18 19:08 . 2009-02-26 16:22 <DIR> d-------- c:\program files\Microsoft Silverlight
2009-02-15 08:56 . 2008-04-14 00:12 276,992 --------- c:\windows\system32\wmphoto.dll
2009-02-15 08:54 . 2008-04-14 00:12 4,274,816 --------- c:\windows\system32\nv4_disp.dll
2009-02-15 08:53 . 2008-04-14 00:10 102,912 -----c--- c:\windows\system32\dllcache\dpcdll.dll
2009-02-15 08:53 . 2008-04-14 00:11 86,016 --------- c:\windows\system32\mdmxsdk.dll
2009-02-15 08:53 . 2008-04-14 00:11 61,440 --------- c:\windows\system32\kmsvc.dll
2009-02-15 08:53 . 2008-04-13 18:45 46,592 --------- c:\windows\system32\drivers\irbus.sys
2009-02-15 08:53 . 2008-04-14 00:11 37,376 --------- c:\windows\system32\l2gpstore.dll
2009-02-15 08:53 . 2008-04-14 00:09 24,064 -----c--- c:\windows\system32\dllcache\pidgen.dll
2009-02-15 08:53 . 2004-08-04 06:41 11,868 --------- c:\windows\system32\drivers\mdmxsdk.sys
2009-02-15 08:53 . 2008-04-14 00:12 10,752 --------- c:\windows\system32\smtpapi.dll
2009-02-15 08:53 . 2008-04-14 00:12 9,728 --------- c:\windows\system32\rwnh.dll
2009-02-15 08:53 . 2008-04-13 18:43 9,728 --------- c:\windows\system32\comsdupd.exe
2009-02-15 08:53 . 2007-06-21 05:52 974 --------- c:\windows\system32\pid.inf
2009-02-15 08:51 . 2008-04-13 18:36 44,928 --------- c:\windows\system32\drivers\agpcpq.sys
2009-02-15 08:51 . 2008-04-13 18:36 43,008 --------- c:\windows\system32\drivers\amdagp.sys
2009-02-15 08:51 . 2008-04-13 18:36 42,752 --------- c:\windows\system32\drivers\alim1541.sys
2009-02-15 08:51 . 2008-04-13 18:36 42,368 --------- c:\windows\system32\drivers\agp440.sys
2009-02-15 08:51 . 2008-04-14 00:11 4,255 --------- c:\windows\system32\drivers\adv01nt5.dll
2009-02-15 08:51 . 2008-04-14 00:11 3,967 --------- c:\windows\system32\drivers\adv02nt5.dll
2009-02-15 08:51 . 2008-04-14 00:11 3,775 --------- c:\windows\system32\drivers\adv11nt5.dll
2009-02-15 08:51 . 2008-04-14 00:11 3,711 --------- c:\windows\system32\drivers\adv09nt5.dll
2009-02-15 08:51 . 2008-04-14 00:11 3,647 --------- c:\windows\system32\drivers\adv07nt5.dll
2009-02-15 08:51 . 2008-04-14 00:11 3,615 --------- c:\windows\system32\drivers\adv05nt5.dll
2009-02-15 08:51 . 2008-04-14 00:11 3,135 --------- c:\windows\system32\drivers\adv08nt5.dll
2009-02-14 13:47 . 2009-03-11 22:29 <DIR> d-------- c:\documents and settings\lee hill\Tracing
2009-02-14 13:39 . 2009-02-14 13:39 <DIR> d-------- c:\program files\Microsoft
2009-02-14 13:36 . 2009-02-14 13:36 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-02-14 13:26 . 2009-02-14 13:26 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-02-11 22:25 . 2004-08-03 23:56 221,184 --a------ c:\windows\system32\wmpns.dll
2009-02-11 22:22 . 2009-02-11 22:22 <DIR> d-------- c:\windows\system32\LogFiles
2009-02-11 22:22 . 2009-02-11 22:23 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-02-11 04:47 . 2009-02-11 04:47 552 --a------ c:\windows\system32\d3d8caps.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 22:04 --------- d-----w c:\program files\Windows Live
2009-02-11 22:25 --------- d-----w c:\program files\Windows Media Connect 2
2009-02-05 15:55 --------- d-----w c:\program files\Microsoft Games
2009-02-04 23:13 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-25 00:03 --------- d-----w c:\program files\DivX
2009-01-16 03:48 --------- d-----w c:\documents and settings\All Users\Application Data\Alawar Stargaze
2009-01-16 03:47 --------- d-----w c:\program files\ReflexiveArcade
.
------- Sigcheck -------
2004-08-03 23:56 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\$NtServicePackUninstall$\svchost.exe
2008-04-14 00:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 c:\windows\ServicePackFiles\i386\svchost.exe
2008-04-14 00:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 c:\windows\system32\svchost.exe
2007-03-08 15:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$NtServicePackUninstall$\user32.dll
2006-12-18 19:35 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$NtUninstallKB925902$\user32.dll
2008-04-14 00:12 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\ServicePackFiles\i386\user32.dll
2008-04-14 00:12 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\system32\user32.dll
2004-08-03 23:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\$NtServicePackUninstall$\ws2_32.dll
2008-04-14 00:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\ServicePackFiles\i386\ws2_32.dll
2008-04-14 00:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\system32\ws2_32.dll
2008-08-20 05:30 666112 9af5f25124fbdc36e2b510729cba2674 c:\windows\$hf_mig$\KB956390\SP3GDR\wininet.dll
2008-08-20 04:58 666624 94418f53d2612c26dbadc04dafbc197c c:\windows\$hf_mig$\KB956390\SP3QFE\wininet.dll
2008-08-26 09:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
2008-10-16 01:00 666112 1576318bf08d28cc61d1278114ad8d5b c:\windows\$hf_mig$\KB958215\SP3GDR\wininet.dll
2008-10-16 01:04 667136 e8fce58a470999350f64c591557f9e42 c:\windows\$hf_mig$\KB958215\SP3QFE\wininet.dll
2008-10-16 20:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
2008-12-20 23:56 827904 044e0a4e9fe97c0fb9afe9c89e2a82e6 c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
2006-12-18 19:35 664576 231ef4179acabe486376b5ca893f1076 c:\windows\$NtUninstallKB956390$\wininet.dll
2008-08-20 05:33 667648 c91e3a6ef094202f6b5ca8960dfcf243 c:\windows\$NtUninstallKB958215$\wininet.dll
2008-10-16 10:20 667648 93c9d0a216498ee14eb9b26119bb95ee c:\windows\ie7\wininet.dll
2007-08-14 02:54 818688 a4a0fc92358f39538a6494c42ef99fe9 c:\windows\ie7updates\KB956390-IE7\wininet.dll
2008-08-26 07:24 826368 ef8eba98145bfa44e80d17a3b3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll
2008-10-16 20:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\ie7updates\KB961260-IE7\wininet.dll
2008-04-14 00:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\ServicePackFiles\i386\wininet.dll
2008-12-20 23:15 826368 a82935d32d0672e8ff4e91ae398e901c c:\windows\system32\wininet.dll
2008-12-20 23:15 826368 a82935d32d0672e8ff4e91ae398e901c c:\windows\system32\dllcache\wininet.dll
2008-06-20 11:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 11:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 10:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$NtServicePackUninstall$\tcpip.sys
2008-04-13 19:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys
2006-12-18 19:35 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 19:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\tcpip.sys
2008-06-20 11:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\system32\dllcache\tcpip.sys
2008-06-20 11:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\system32\drivers\tcpip.sys
2004-08-03 23:56 502272 01c3346c241652f43aed8e2149881bfe c:\windows\$NtServicePackUninstall$\winlogon.exe
2008-04-14 00:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\ServicePackFiles\i386\winlogon.exe
2008-04-14 00:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\system32\winlogon.exe
2004-08-03 22:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\$NtServicePackUninstall$\ndis.sys
2008-04-13 19:20 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
2008-04-13 19:20 182656 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys
2004-08-03 22:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 18:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\ServicePackFiles\i386\ip6fw.sys
2008-04-13 18:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\system32\drivers\ip6fw.sys
2008-04-14 00:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\explorer.exe
2007-06-13 11:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$NtServicePackUninstall$\explorer.exe
2006-12-18 19:33 1033216 42d32722b805d7df42d30487a0bcbd78 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-14 00:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\ServicePackFiles\i386\explorer.exe
2004-08-03 23:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\$NtServicePackUninstall$\services.exe
2008-04-14 00:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\ServicePackFiles\i386\services.exe
2008-04-14 00:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\system32\services.exe
2004-08-03 23:56 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\$NtServicePackUninstall$\lsass.exe
2008-04-14 00:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\ServicePackFiles\i386\lsass.exe
2008-04-14 00:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\system32\lsass.exe
2004-08-03 23:56 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\$NtServicePackUninstall$\ctfmon.exe
2008-04-14 00:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-14 00:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\system32\ctfmon.exe
2006-12-18 19:35 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$NtServicePackUninstall$\spoolsv.exe
2008-04-14 00:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-14 00:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b c:\windows\system32\spoolsv.exe
2004-08-03 23:56 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\$NtServicePackUninstall$\userinit.exe
2008-04-14 00:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-14 00:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\system32\userinit.exe
2006-12-18 19:35 295424 c29a5286e64d97385178452d5f307b98 c:\windows\$NtServicePackUninstall$\termsrv.dll
2008-04-14 00:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\ServicePackFiles\i386\termsrv.dll
2008-04-14 00:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\system32\termsrv.dll
2007-04-16 16:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$NtServicePackUninstall$\kernel32.dll
2006-12-18 19:33 985600 16f21882c96ee0136a92e867da94215c c:\windows\$NtUninstallKB935839$\kernel32.dll
2008-04-14 00:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\ServicePackFiles\i386\kernel32.dll
2008-04-14 00:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\system32\kernel32.dll
2004-08-03 23:56 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\$NtServicePackUninstall$\powrprof.dll
2008-04-14 00:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\ServicePackFiles\i386\powrprof.dll
2008-04-14 00:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\system32\powrprof.dll
2004-08-03 23:56 110080 87ca7ce6469577f059297b9d6556d66d c:\windows\$NtServicePackUninstall$\imm32.dll
2008-04-14 00:11 110080 0da85218e92526972a821587e6a8bf8f c:\windows\ServicePackFiles\i386\imm32.dll
2008-04-14 00:11 110080 0da85218e92526972a821587e6a8bf8f c:\windows\system32\imm32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-07 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-07 136600]
"Qbemirozili"="c:\windows\Pzolukog.dll" [2009-03-01 43520]
"Rcarosita"="c:\windows\umezudan.dll" [2009-03-01 135680]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"C-Media Mixer"="Mixer.exe" [2002-10-16 c:\windows\mixer.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\30e0e646530]
2009-02-28 19:47 135168 c:\windows\system32\ifxcardm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\ifxcardm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-03-11 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-03-11 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-02-27 55152]
S3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [2009-02-02 31872]
--- Other Services/Drivers In Memory ---
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - helpsvc
*Deregistered* - HTTPFilter
*Deregistered* - ImapiService
*Deregistered* - JavaQuickStarterService
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - NWCWorkstation
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SLService
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
Notify-__c0063031 - c:\windows\system32\__c0063031.dat
Notify-__c00889E9 - c:\windows\system32\__c00889E9.dat
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-11 22:30:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\windows\System32\ifxcardm32.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\WgaTray.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-03-11 22:40:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-11 22:39:55
Pre-Run: 47,534,796,800 bytes free
Post-Run: 47,475,150,848 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
322