ComboFix is below..................................
.......
ComboFix 08-11-21.05 - Kris Maurer 2008-11-22 11:07:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.172 [GMT -5:00]
Running from: c:\documents and settings\Kris Maurer\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\sks~1
c:\windows\system32\bszip.dll
c:\windows\system32\config\systemprofile\Application Data\rhcahvj0ej77
c:\windows\system32\fnts~1
c:\windows\system32\fnts~1\F?nts\
c:\windows\system32\wnsapiicomsv.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-22 to 2008-11-22 )))))))))))))))))))))))))))))))
.
2008-11-21 21:35 . 2008-11-21 21:35 <DIR> d-------- c:\windows\system32\scripting
2008-11-21 21:35 . 2008-11-21 21:35 <DIR> d-------- c:\windows\system32\en
2008-11-21 21:35 . 2008-11-21 21:35 <DIR> d-------- c:\windows\system32\bits
2008-11-21 21:35 . 2008-11-21 21:35 <DIR> d-------- c:\windows\l2schemas
2008-11-21 21:33 . 2008-11-21 21:36 <DIR> d-------- c:\windows\ServicePackFiles
2008-11-21 21:25 . 2008-11-21 21:25 <DIR> d-------- c:\windows\EHome
2008-11-21 21:22 . 2008-08-14 05:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-11-21 21:20 . 2008-04-13 19:12 712,704 --------- c:\windows\system32\windowscodecs.dll
2008-11-21 21:20 . 2008-04-13 19:12 346,112 --------- c:\windows\system32\windowscodecsext.dll
2008-11-21 21:20 . 2008-04-13 19:12 276,992 --------- c:\windows\system32\wmphoto.dll
2008-11-21 21:20 . 2008-04-13 19:12 69,120 --------- c:\windows\system32\wlanapi.dll
2008-11-21 21:18 . 2008-04-13 19:11 1,888,992 --------- c:\windows\system32\ati3duag.dll
2008-11-21 21:17 . 2008-06-13 06:05 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-11-21 21:08 . 2008-09-15 07:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-11-21 21:08 . 2008-09-08 05:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-11-21 20:57 . 2008-08-14 05:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-21 20:57 . 2008-08-14 05:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-21 20:57 . 2008-08-14 04:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-21 20:57 . 2008-08-14 04:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-21 20:56 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-21 20:54 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-21 20:54 . 2008-04-11 14:04 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-11-21 20:54 . 2008-10-15 11:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-11-21 20:54 . 2008-05-01 09:33 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-11-21 18:32 . 2008-11-21 18:32 <DIR> d-------- C:\VundoFix Backups
2008-11-20 22:36 . 2008-11-20 22:36 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-20 22:36 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-20 22:36 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-20 22:31 . 2008-11-20 22:31 <DIR> d-------- c:\program files\Trend Micro
2008-11-20 21:29 . 2008-11-20 21:29 <DIR> d-------- c:\documents and settings\Kris Maurer\Application Data\Malwarebytes
2008-11-20 21:29 . 2008-11-20 21:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-20 16:58 . 2008-11-20 16:58 <DIR> d-------- c:\documents and settings\Kris Maurer\DoctorWeb
2008-11-20 16:51 . 2005-02-15 15:02 163,840 --a------ c:\windows\system32\igfxres.dll
2008-11-20 16:43 . 2008-04-13 19:11 156,672 --a--c--- c:\windows\system32\dllcache\winzm.ime
2008-11-20 16:43 . 2008-04-13 19:11 156,672 --a--c--- c:\windows\system32\dllcache\winsp.ime
2008-11-20 16:43 . 2008-04-13 19:11 156,672 --a--c--- c:\windows\system32\dllcache\winpy.ime
2008-11-20 16:43 . 2008-04-13 19:11 65,536 --a--c--- c:\windows\system32\dllcache\winime.ime
2008-11-20 16:43 . 2004-08-12 09:10 28,288 --a--c--- c:\windows\system32\dllcache\xjis.nls
2008-11-20 16:41 . 2004-08-12 08:58 1,875,968 --a--c--- c:\windows\system32\dllcache\msir3jp.lex
2008-11-20 16:40 . 2008-04-13 19:09 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2008-11-20 16:39 . 2004-08-12 08:56 195,618 --a--c--- c:\windows\system32\dllcache\c_10002.nls
2008-11-20 16:36 . 2008-11-20 16:36 749 -rah----- c:\windows\WindowsShell.Manifest
2008-11-20 16:36 . 2008-11-20 16:36 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-11-20 16:36 . 2008-11-20 16:36 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-11-20 16:36 . 2008-11-20 16:36 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-11-20 16:36 . 2008-11-20 16:36 488 -rah----- c:\windows\system32\logonui.exe.manifest
2008-11-20 16:35 . 2004-08-12 08:58 16,384 --a--c--- c:\windows\system32\dllcache\isignup.exe
2008-11-20 16:22 . 2004-08-12 09:06 24,661 --a------ c:\windows\system32\spxcoins.dll
2008-11-20 16:22 . 2004-08-12 09:06 24,661 --a--c--- c:\windows\system32\dllcache\spxcoins.dll
2008-11-20 16:22 . 2004-08-12 08:58 13,312 --a------ c:\windows\system32\irclass.dll
2008-11-20 16:22 . 2004-08-12 08:58 13,312 --a--c--- c:\windows\system32\dllcache\irclass.dll
2008-11-20 16:21 . 2004-08-12 09:06 1,042,903 --a--c--- c:\windows\system32\dllcache\SP2.CAT
2008-11-20 16:21 . 2004-08-12 09:02 797,189 --a--c--- c:\windows\system32\dllcache\NT5IIS.CAT
2008-11-20 16:21 . 2004-08-12 08:59 399,645 --a--c--- c:\windows\system32\dllcache\MAPIMIG.CAT
2008-11-20 16:21 . 2004-08-12 09:01 37,484 --a--c--- c:\windows\system32\dllcache\MW770.CAT
2008-11-20 16:21 . 2004-08-12 08:57 13,472 --a--c--- c:\windows\system32\dllcache\HPCRDP.CAT
2008-11-20 16:21 . 2004-08-12 08:57 8,574 --a--c--- c:\windows\system32\dllcache\IASNT4.CAT
2008-11-20 16:21 . 2004-08-12 09:11 7,710 --a--c--- c:\windows\system32\dllcache\OEMBIOS.CAT
2008-11-20 16:21 . 2004-08-12 09:09 7,334 --a--c--- c:\windows\system32\dllcache\wmerrenu.cat
2008-11-20 11:08 . 2008-11-20 11:08 <DIR> d-------- c:\windows\dell
2008-11-20 11:08 . 2008-11-20 21:18 527,921,152 --a------ c:\windows\MEMORY.DMP
2008-11-20 10:15 . 2008-11-20 12:15 <DIR> d-------- c:\program files\CleanUp!
2008-11-19 15:53 . 2008-11-19 15:53 <DIR> d-------- c:\documents and settings\Administrator\Application Data\InstallShield
2008-11-14 16:56 . 2008-11-20 22:49 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-14 16:53 . 2008-11-20 16:25 4,128 --a------ C:\INFCACHE.1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-22 15:50 1,786 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-11-21 23:28 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-15 03:55 --------- d-----w c:\program files\Common Files\Scanner
2008-11-15 02:38 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-28 07:46 74,752 ----a-w c:\windows\system32\msw3prt.dll
2008-08-28 07:46 104,960 ----a-w c:\windows\system32\win32spl.dll
2008-05-04 00:04 56 --sh--r c:\windows\system32\42F52BF3EA.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"qvfcez"="c:\program files\??sks\javaw.exe" [?]
"pjjcaml"="c:\program files\??sks\alg.exe" [?]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-31 68856]
"isuspm"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"dellsupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2007-03-07 1773568]
"sunjavaupdatesched"="c:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975]
"realtray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-10-07 26112]
"quicktime task"="c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-07-13 169264]
"ituneshelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-09-25 229952]
"isusscheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"isuspm startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
"intelwireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-02-15 155648]
"hotkeyscmds"="c:\windows\system32\hkcmd.exe" [2005-02-15 126976]
"dvdlauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"dell quickset"="c:\program files\Dell\QuickSet\quickset.exe" [2005-03-04 606208]
"apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"act! preloader"="c:\program files\ACT\ACT for Windows\Act8.exe" [2006-04-05 1015808]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-10-07 24576]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 16:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Yahoo! Autosync.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Yahoo! Autosync.lnk
backup=c:\windows\pss\Yahoo! Autosync.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msmsgs]
--------- 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pcmservice]
--a------ 2004-04-11 20:15 290816 c:\program files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\picasa media detector]
--a------ 2008-02-25 20:23 443968 c:\program files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RoxWatch9"=2 (0x2)
"RoxLiveShare9"=2 (0x2)
"Roxio Upnp Server 9"=2 (0x2)
"Roxio UPnP Renderer 9"=3 (0x3)
"MSK80Service"=2 (0x2)
"MpfService"=2 (0x2)
"McSysmon"=3 (0x3)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\ACT\\ACT for Windows\\Act8.exe"=
"%windir%\\system32\\sessmgr.exe"=
R2 Maxtor Sync Service;Maxtor Service;"c:\program files\Maxtor\Sync\SyncServices.exe" [2007-07-13 156976]
R2 MSSQL$ACT7;MSSQL$ACT7;c:\program files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe -sACT7 []
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-11-02 24652]
S1 8a0dfb28;8a0dfb28;c:\windows\system32\drivers\8a0dfb28.sys []
S3 SQLAgent$ACT7;SQLAgent$ACT7;c:\program files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE -i ACT7 []
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-08-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2008-07-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe []
2007-10-18 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-sen - c:\windows\system32\FNTS~1\wucrtupd.exe
HKCU-Run-aim6 - (no file)
HKLM-Run-siteadvisor - c:\program files\SiteAdvisor\6261\SiteAdv.exe
MSConfigStartUp-mcagent_exe - c:\program files\McAfee.com\Agent\mcagent.exe
MSConfigStartUp-roxwatchtray - c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-22 11:08:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-22 11:10:43
ComboFix-quarantined-files.txt 2008-11-22 16:10:01
Pre-Run: 17,878,667,264 bytes free
Post-Run: 17,858,400,256 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
217 --- E O F --- 2008-11-22 15:03:41
Please let me know whats next....