Half right!
Please delete the copy of ComboFix that you have, and download the updated version from
HERE
Please run the new ComboFix.exe using the same instructions as before
(ie disable all security programs)
Post the log, and make sure you can access CPanel.
I've run combofix and can access CPanel.
However, although I can connect to the Internet through the Vodafone USB Modem on the VCMLite dialup connection, the Vodafone Mobile Connect Lite program doesn't appear in the Systray or in the Task Manager. The software is on the USB Modem (E

. It shows me my upload/download speeds and volume of data used etc.
I won't do a system restore until you tell me to. :laugh:
ComboFix 08-06-30.2 - John Slee 2008-07-01 15:16:48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.142 [GMT 1:00]
Running from: C:\Documents and Settings\John Slee.EPIPHANY\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\John Slee.EPIPHANY\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\Cache
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-06-01 to 2008-07-01 )))))))))))))))))))))))))))))))
.
2010-10-10 10:09 . 2010-10-10 10:09 <DIR> d-------- C:\Program Files\Realtek Sound Manager
2010-10-10 10:09 . 2008-01-29 11:49 <DIR> d-------- C:\Program Files\AvRack
2010-10-10 10:08 . 2008-01-29 11:49 <DIR> d-------- C:\Program Files\Realtek AC97
2008-06-30 14:19 . 2008-06-30 14:19 <DIR> d-------- C:\Program Files\Vodafone
2008-06-28 23:57 . 2008-06-30 14:19 <DIR> d-------- C:\Program Files\Vodafone(2)
2008-06-27 11:06 . 2008-06-27 11:06 <DIR> d-------- C:\Documents and Settings\John Slee.EPIPHANY\Application Data\Vodafone
2008-06-26 08:58 . 2008-06-30 14:22 <DIR> d-------- C:\RECYCLER(2)
2008-06-26 08:38 . 2008-06-30 14:17 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Vodafone
2008-06-24 14:37 . 2008-06-24 14:37 <DIR> d-------- C:\Documents and Settings\John Slee.EPIPHANY\Application Data\GlarySoft
2008-06-22 11:12 . 2003-06-25 16:05 266,360 --a------ C:\WINDOWS\system32\TweakUI.exe
2008-06-22 11:12 . 2002-06-21 15:09 160,217 --a------ C:\WINDOWS\system32\PowerToysLicense.rtf
2008-06-20 10:49 . 2008-06-20 10:49 <DIR> d-------- C:\Deckard
2008-06-19 16:16 . 2008-06-19 16:16 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-06-19 16:16 . 2008-06-19 16:16 <DIR> d-------- C:\WINDOWS\system32\en
2008-06-19 16:16 . 2008-06-19 16:16 <DIR> d-------- C:\WINDOWS\system32\bits
2008-06-19 16:16 . 2008-06-19 16:16 <DIR> d-------- C:\WINDOWS\l2schemas
2008-06-19 16:06 . 2008-06-19 16:17 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-06-19 12:44 . 2004-08-04 13:00 300,969 -----c--- C:\WINDOWS\system32\dllcache\viz.wmv
2008-06-19 12:43 . 2004-08-04 13:00 1,398 -----c--- C:\WINDOWS\system32\dllcache\taon.gif
2008-06-19 12:43 . 2004-08-04 13:00 1,380 -----c--- C:\WINDOWS\system32\dllcache\taonh.gif
2008-06-19 12:43 . 2004-08-04 13:00 1,380 -----c--- C:\WINDOWS\system32\dllcache\taoff.gif
2008-06-19 12:43 . 2004-08-04 13:00 1,367 -----c--- C:\WINDOWS\system32\dllcache\taoffh.gif
2008-06-19 12:41 . 2004-08-04 13:00 572,557 -----c--- C:\WINDOWS\system32\dllcache\rtuner.wmv
2008-06-19 12:41 . 2008-04-14 01:12 397,056 --------- C:\WINDOWS\system32\s3gnb.dll
2008-06-19 12:41 . 2008-04-14 01:12 290,304 --------- C:\WINDOWS\system32\rhttpaa.dll
2008-06-19 12:41 . 2004-08-03 22:29 166,912 --------- C:\WINDOWS\system32\drivers\s3gnbm.sys
2008-06-19 12:41 . 2008-04-13 18:28 66,725 -----c--- C:\WINDOWS\system32\dllcache\revert.wmz
2008-06-19 12:41 . 2008-04-14 01:12 32,768 --------- C:\WINDOWS\system32\setupn.exe
2008-06-19 12:41 . 2008-04-13 19:56 30,592 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2008-06-19 12:41 . 2008-04-13 19:40 10,240 --------- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-06-19 12:39 . 2008-04-14 01:12 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-06-19 12:39 . 2004-08-03 22:29 1,897,408 --------- C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-06-19 12:39 . 2004-08-04 13:00 375,519 -----c--- C:\WINDOWS\system32\dllcache\nuskin.wmv
2008-06-19 12:39 . 2004-08-03 22:41 180,360 --------- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2008-06-19 12:39 . 2008-04-14 01:12 144,384 --------- C:\WINDOWS\system32\onex.dll
2008-06-19 12:38 . 2008-04-14 01:12 176,640 --------- C:\WINDOWS\system32\napstat.exe
2008-06-19 12:38 . 2004-07-17 11:35 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2008-06-19 12:38 . 2004-08-04 13:00 22,060 -----c--- C:\WINDOWS\system32\dllcache\npds.zip
2008-06-19 12:38 . 2004-08-04 13:00 403 -----c--- C:\WINDOWS\system32\dllcache\npdrmv2.zip
2008-06-19 12:36 . 2008-04-14 01:10 294,912 -----c--- C:\WINDOWS\system32\dllcache\msaud32.acm
2008-06-19 12:35 . 2008-04-14 01:11 397,312 --------- C:\WINDOWS\system32\mmcex.dll
2008-06-19 12:35 . 2008-04-14 01:11 184,320 --------- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-06-19 12:35 . 2008-04-14 01:11 106,496 --------- C:\WINDOWS\system32\mmcfxcommon.dll
2008-06-19 12:35 . 2004-08-04 13:00 97,117 -----c--- C:\WINDOWS\system32\dllcache\mplayer2.hlp
2008-06-19 12:35 . 2008-04-14 01:12 33,792 --------- C:\WINDOWS\system32\mmcperf.exe
2008-06-19 12:35 . 2004-08-04 13:00 18,286 -----c--- C:\WINDOWS\system32\dllcache\mplayer2.inf
2008-06-19 12:35 . 2004-08-04 13:00 2,778 -----c--- C:\WINDOWS\system32\dllcache\mplogoh.gif
2008-06-19 12:35 . 2004-08-04 13:00 2,545 -----c--- C:\WINDOWS\system32\dllcache\mplogo.gif
2008-06-19 12:35 . 2004-08-04 13:00 1,885 -----c--- C:\WINDOWS\system32\dllcache\mplayer2.cnt
2008-06-19 12:34 . 2004-08-04 13:00 457,607 -----c--- C:\WINDOWS\system32\dllcache\mdlib.wmv
2008-06-19 12:34 . 2008-04-14 01:11 86,016 --------- C:\WINDOWS\system32\mdmxsdk.dll
2008-06-19 12:34 . 2004-08-03 22:41 11,868 --------- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-06-19 12:33 . 2008-04-14 01:09 290,816 -----c--- C:\WINDOWS\system32\dllcache\l3codeca.acm
2008-06-19 12:33 . 2008-04-14 01:11 37,376 --------- C:\WINDOWS\system32\l2gpstore.dll
2008-06-19 12:32 . 2008-04-14 01:11 61,440 --------- C:\WINDOWS\system32\kmsvc.dll
2008-06-19 12:32 . 2008-04-14 01:09 6,144 --------- C:\WINDOWS\system32\kbdpash.dll
2008-06-19 12:32 . 2008-04-14 01:09 6,144 --------- C:\WINDOWS\system32\kbdnepr.dll
2008-06-19 12:32 . 2008-04-14 01:09 6,144 --------- C:\WINDOWS\system32\kbdiultn.dll
2008-06-19 12:32 . 2008-04-14 01:09 6,144 --------- C:\WINDOWS\system32\kbdbhc.dll
2008-06-19 12:30 . 2007-06-21 06:52 974 --------- C:\WINDOWS\system32\pid.inf
2008-06-19 12:29 . 2008-04-13 19:45 46,592 --------- C:\WINDOWS\system32\drivers\irbus.sys
2008-06-19 12:29 . 2008-04-13 19:43 9,728 --------- C:\WINDOWS\system32\comsdupd.exe
2008-06-19 12:27 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-06-19 12:27 . 2004-08-03 22:41 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2008-06-19 12:27 . 2004-08-03 22:41 220,032 --------- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2008-06-19 12:27 . 2008-04-13 19:36 46,464 --------- C:\WINDOWS\system32\drivers\gagp30kx.sys
2008-06-19 12:27 . 2008-04-14 01:11 32,285 --------- C:\WINDOWS\system32\hsfcisp2.dll
2008-06-19 12:27 . 2008-04-13 19:46 25,600 --------- C:\WINDOWS\system32\drivers\hidbth.sys
2008-06-19 12:27 . 2008-04-13 19:45 19,200 --------- C:\WINDOWS\system32\drivers\hidir.sys
2008-06-19 12:25 . 2008-04-14 01:11 650,752 --------- C:\WINDOWS\system32\dot3ui.dll
2008-06-19 12:24 . 2008-04-14 01:11 233,472 --------- C:\WINDOWS\system32\azroles.dll
2008-06-19 12:24 . 2008-04-13 19:46 36,480 --------- C:\WINDOWS\system32\drivers\bthprint.sys
2008-06-19 12:24 . 2008-04-14 01:11 25,471 --------- C:\WINDOWS\system32\drivers\atv04nt5.dll
2008-06-19 12:24 . 2008-04-14 01:11 21,183 --------- C:\WINDOWS\system32\drivers\atv01nt5.dll
2008-06-19 12:24 . 2008-04-14 01:11 17,279 --------- C:\WINDOWS\system32\drivers\atv10nt5.dll
2008-06-19 12:24 . 2008-04-14 01:11 15,423 --------- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2008-06-19 12:24 . 2008-04-14 01:11 14,143 --------- C:\WINDOWS\system32\drivers\atv06nt5.dll
2008-06-19 12:24 . 2008-04-14 01:11 11,359 --------- C:\WINDOWS\system32\drivers\atv02nt5.dll
2008-06-19 12:24 . 2008-04-14 01:11 7,168 --------- C:\WINDOWS\system32\bitsprx4.dll
2008-06-19 12:24 . 2004-08-04 13:00 999 -----c--- C:\WINDOWS\system32\dllcache\bktrh.gif
2008-06-19 12:22 . 2008-04-14 01:11 136,192 --------- C:\WINDOWS\system32\aaclient.dll
2008-06-19 12:22 . 2008-04-14 01:11 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2008-06-19 12:22 . 2008-04-14 01:11 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2008-06-19 12:22 . 2008-04-14 01:11 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2008-06-19 12:22 . 2008-04-14 01:11 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2008-06-19 12:22 . 2008-04-14 01:11 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2008-06-19 12:22 . 2008-04-14 01:11 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2008-06-19 12:22 . 2008-04-14 01:11 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll
2008-06-19 01:43 . 2008-06-19 01:43 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-19 01:43 . 2008-06-19 01:43 <DIR> d-------- C:\Documents and Settings\John Slee.EPIPHANY\Application Data\SUPERAntiSpyware.com
2008-06-19 01:43 . 2008-06-19 01:43 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-06-18 23:49 . 2008-06-18 23:49 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-18 12:40 . 2008-06-18 14:02 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-06-18 12:26 . 2008-06-19 01:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-18 11:16 . 2008-06-30 14:19 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-18 11:16 . 2008-06-30 14:19 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-06-18 09:54 . 2008-06-18 09:54 <DIR> d-------- C:\Program Files\RogueRemover FREE
2008-06-17 18:52 . 2005-02-03 18:58 425,984 --a------ C:\WINDOWS\system32\GeoCodec.dll
2008-06-17 18:52 . 2005-02-03 18:58 425,984 -ra------ C:\WINDOWS\GeoCodec.dll
2008-06-17 18:52 . 2001-05-04 12:05 413,760 --a------ C:\WINDOWS\mpg4c32.dll
2008-06-17 18:52 . 2005-03-08 17:02 92,105 --a------ C:\WINDOWS\Stable_7000.xml
2008-06-17 18:52 . 2003-12-02 10:03 12,045 --a------ C:\WINDOWS\buzzer.wav
2008-06-16 16:42 . 2008-06-16 16:42 <DIR> d-------- C:\Program Files\MozBackup
2008-06-13 13:46 . 2008-06-13 12:05 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-13 13:46 . 2008-05-08 15:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-13 02:51 . 2008-06-13 21:10 765 --a------ C:\camerades.inf
2008-06-13 01:21 . 2008-04-13 19:46 85,248 --a------ C:\WINDOWS\system32\drivers\nabtsfec.sys
2008-06-13 01:21 . 2008-04-13 19:46 19,200 --a------ C:\WINDOWS\system32\drivers\wstcodec.sys
2008-06-13 01:21 . 2008-04-13 19:46 17,024 --a------ C:\WINDOWS\system32\drivers\ccdecode.sys
2008-06-13 01:21 . 2008-04-14 01:12 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-06-13 01:21 . 2008-04-13 19:46 15,232 --a------ C:\WINDOWS\system32\drivers\streamip.sys
2008-06-13 01:21 . 2008-04-13 19:46 11,136 --a------ C:\WINDOWS\system32\drivers\slip.sys
2008-06-13 01:21 . 2008-04-13 19:46 10,880 --a------ C:\WINDOWS\system32\drivers\ndisip.sys
2008-06-13 01:21 . 2008-04-13 19:39 5,504 --a------ C:\WINDOWS\system32\drivers\mstee.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-01 14:27 --------- d-----w C:\Documents and Settings\John Slee.EPIPHANY\Application Data\OpenOffice.org2
2008-07-01 14:25 1,893 ----a-w C:\WINDOWS\bcmwltrytmp.reg
2008-07-01 13:49 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-07-01 10:29 --------- d-----w C:\Program Files\Google
2008-07-01 07:29 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-06-30 14:12 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-06-26 07:38 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-20 12:03 --------- d-----w C:\Program Files\Java
2008-06-18 22:30 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-06-18 11:40 --------- d-----w C:\Program Files\Lavasoft
2008-06-18 09:39 --------- d-----w C:\Program Files\Email Marketing Pro 2008
2008-06-17 20:13 --------- d-----w C:\Program Files\QuickTime
2008-06-13 11:05 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 00:29 --------- d-----w C:\Program Files\WebCam
2008-05-26 06:37 --------- d-----w C:\Program Files\palmOne
2008-05-25 21:16 --------- d-----w C:\Documents and Settings\John Slee.EPIPHANY\Application Data\AVGTOOLBAR
2008-05-25 21:07 9,388 ----a-w C:\WINDOWS\system32\drivers\iaStor.PNF
2008-05-25 21:07 7,280 ----a-w C:\WINDOWS\system32\drivers\viamraid.PNF
2008-05-25 21:07 63,240 ----a-w C:\WINDOWS\system32\drivers\Si3112r.PNF
2008-05-25 21:07 6,984 ----a-w C:\WINDOWS\system32\drivers\SiSRaid.PNF
2008-05-25 21:07 12,432 ----a-w C:\WINDOWS\system32\drivers\adpu320.PNF
2008-05-25 21:07 12,204 ----a-w C:\WINDOWS\system32\drivers\nvraid.PNF
2008-05-25 21:07 10,828 ----a-w C:\WINDOWS\system32\drivers\iaAHCI.PNF
2008-05-22 11:14 --------- d-----w C:\Documents and Settings\John Slee.EPIPHANY\Application Data\GeoSetter
2008-05-22 08:24 --------- d-----w C:\Program Files\GeoSetter
2008-05-18 09:35 --------- d-----w C:\Program Files\orange3
2008-05-17 19:46 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-17 19:46 75,272 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-17 19:46 --------- d-----w C:\Program Files\AVG
2008-05-17 19:46 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2008-05-17 10:36 --------- d-----w C:\Program Files\Water Explorer
2008-05-15 23:01 --------- d-----w C:\Program Files\Gallery Remote
2008-05-15 22:22 --------- d-----w C:\Documents and Settings\John Slee.EPIPHANY\Application Data\PFrank
2008-05-15 22:09 --------- d-----w C:\Program Files\PFrank
2008-05-15 10:03 --------- d--h--w C:\Program Files\Zero G Registry
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-06 15:56 --------- d-----w C:\Documents and Settings\John Slee.EPIPHANY\Application Data\BITS
2008-04-14 00:12 69,120 ----a-w C:\WINDOWS\notepad.exe
2008-04-14 00:12 50,688 ----a-w C:\WINDOWS\twain_32.dll
2008-04-14 00:12 32,866 ------w C:\WINDOWS\slrundll.exe
2008-04-14 00:12 283,648 ----a-w C:\WINDOWS\winhlp32.exe
2008-04-14 00:12 146,432 ----a-w C:\WINDOWS\regedit.exe
2008-04-14 00:12 10,752 ----a-w C:\WINDOWS\hh.exe
2008-04-14 00:12 1,033,728 ----a-w C:\WINDOWS\explorer.exe
2008-04-14 00:11 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
2008-04-14 00:11 39,424 ------w C:\WINDOWS\AppPatch\acadproc.dll
2008-04-14 00:11 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
2008-04-14 00:11 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
2008-04-14 00:11 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
2008-04-14 00:11 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
2007-04-21 14:32 80 ----a-w C:\Program Files\serial.txt
2007-01-10 15:37 278,528 ----a-w C:\Program Files\Common Files\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 10:08 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 01:12 15360]
"ISUSPM"="C:\Documents and Settings\All Users.WINDOWS\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 16:41 222128]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSync2.exe" [2008-03-26 18:41 1232896]
"VMCL"="C:\Program Files\vodafone\vmclite\DongleEnumerator.exe" [2007-08-17 14:35 131072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-20 06:20 29744]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-11 10:35 185632]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 00:12 49152]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-17 20:46 1177368]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"VTTimer"="VTTimer.exe" [2005-03-08 04:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-11-01 05:15 163840 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 17:22 577536 C:\WINDOWS\soundman.exe]
"SMSERIAL"="sm56hlpr.exe" [2005-11-10 05:44 557056 C:\WINDOWS\sm56hlpr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 01:12 15360]
C:\Documents and Settings\John Slee.EPIPHANY\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [1/21/2008 3:41:28 PM 393216]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [10/26/2006 8:56:55 AM 113664]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [10/26/2006 12:24:59 AM 125624]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [5/12/2005 12:23:26 AM 282624]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [1/1/2007 12:22:03 PM 98304]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1/21/2000 9:15:54 AM 65588]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.mpg4"= C:\WINDOWS\mpg4c32.dll
"vidc.mpg2"= C:\WINDOWS\mpg4c32.dll
"vidc.mpg3"= C:\WINDOWS\mpg4c32.dll
"vidc.GEOX"= C:\WINDOWS\system32\GeoCodec.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-17 20:46]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-17 20:46]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-17 20:46]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-17 20:46]
R3 EKBfltr;ENE Keyboard Controller;C:\WINDOWS\system32\DRIVERS\EKBfltr.sys [2005-01-14 18:22]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-20 06:20]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2008-04-14 01:12]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2008-04-14 01:12]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2008-04-14 01:12]
S3 phil2vid;Philips USB VGA Camera;C:\WINDOWS\system32\DRIVERS\philcam2.sys [2001-08-17 14:04]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2008-04-14 01:12]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28e60155-ee01-11dc-8457-000d888eddaa}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28e60156-ee01-11dc-8457-000d888eddaa}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31a2c79a-f811-11dc-847f-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31a2c79b-f811-11dc-847f-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{36fa1034-ee72-11dc-8458-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{524a47c0-46a9-11dd-854a-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9c32ba74-f006-11dc-845d-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7cf184a-f064-11dc-8461-000d888eddaa}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7cf184b-f064-11dc-8461-000d888eddaa}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d51d1d4c-f872-11dc-8481-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d51d1d4d-f872-11dc-8481-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d60bb227-f6b6-11dc-847c-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d60bb228-f6b6-11dc-847c-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d60bb229-f6b6-11dc-847c-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d60bb22d-f6b6-11dc-847c-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d60bb22e-f6b6-11dc-847c-0014a59a0895}]
\Shell\AutoRun\command - E:\StartVMCLite.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-27 18:28:11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Picasa Media Detector - C:\Program Files\Picasa2\PicasaMediaDetector
HKLM-Run-Broadcom Wireless Manager UI - C:\WINDOWS\system32\WLTRAY
HKLM-Run-BluetoothAuthenticationAgent - bthprops.cpl,,BluetoothAuthenticationAgent
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-01 15:26:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"C:\Program Files\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\WLTRAY.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\wscntfy.exe
E:\PhoneConnectorVMC.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.bin
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-07-01 15:36:11 - machine was rebooted [John Slee]
ComboFix-quarantined-files.txt 2008-07-01 14:36:01
ComboFix2.txt 2008-06-25 14:18:09
Pre-Run: 8,872,251,392 bytes free
Post-Run: 8,876,593,152 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
371 --- E O F --- 2008-06-20 14:13:37