Good, that Symantec error didn't pop up this time. Here is the log.
ComboFix 08-09-19.04 - HP_Administrator 2008-09-19 17:51:44.2 - NTFSx86
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.
2008-09-19 17:33 . 2008-09-19 17:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-09-19 16:18 . 2008-09-19 16:18 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-19 15:52 . 2008-09-19 16:40 <DIR> d-------- C:\SDFix
2008-09-19 10:28 . 2008-09-19 10:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-19 10:10 . 2008-09-19 10:10 <DIR> d-------- C:\Program Files\Malwarebytes Anti-Malware
2008-09-19 10:10 . 2008-09-19 10:10 <DIR> d-------- C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
2008-09-19 10:10 . 2008-09-19 10:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-19 10:10 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-19 10:10 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-19 09:57 . 2008-09-19 09:57 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-19 01:32 . 2008-09-19 01:32 <DIR> d-------- C:\Program Files\CCleaner
2008-09-19 01:28 . 2008-09-19 16:46 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-18 23:27 . 2008-09-18 23:27 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-09-18 23:27 . 2008-09-18 23:27 917,504 --a------ C:\WINDOWS\system32\FLASH.OCX
2008-09-18 19:37 . 2008-09-18 21:07 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\AVGTOOLBAR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 22:01 --------- d-----w C:\Program Files\lx_cats
2008-09-19 19:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-19 04:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-09-19 00:18 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-13 17:54 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\NCH Swift Sound
2008-08-31 18:11 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-28 01:25 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\OpenOffice.org2
2008-08-17 02:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-08-15 22:40 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-15 22:39 --------- d-----w C:\Program Files\Common Files\Real
2008-08-15 21:17 --------- d-----w C:\Program Files\LimeWire
2008-08-13 02:08 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-08 02:48 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-08-04 16:04 --------- d-----w C:\Program Files\Lexmark Toolbar
2008-08-04 16:04 --------- d-----w C:\Program Files\Lexmark 2400 Series
2008-07-29 19:46 --------- d-----w C:\Program Files\QuickTime
2008-07-28 22:43 --------- d-----w C:\Program Files\Reference Assemblies
2008-07-28 22:43 --------- d-----w C:\Program Files\MSBuild
2008-07-23 03:53 26,926 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2007-12-13 21:07 21,321,008 -c--a-w C:\Program Files\QuickTimeInstaller.exe
2007-09-20 21:39 31 -c--a-w C:\Documents and Settings\HP_Administrator\b289484.dll
2007-09-20 21:39 30 -c--a-w C:\Documents and Settings\HP_Administrator\p289484.dll
2007-07-04 01:54 785,160 -c--a-w C:\Program Files\WindowsMediaPlayer10.exe
2007-04-26 00:17 0 -c-h--w C:\Program Files\AppUpdate.log
2007-04-04 23:56 6,372 -c--a-w C:\Program Files\Uninst.isu
2006-04-22 22:43 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
2005-12-29 22:58 251 -c--a-w C:\Program Files\wt3d.ini
2001-11-08 05:49 405,504 -c--a-w C:\Program Files\SStylerProDemo.exe
2001-11-08 03:04 163,840 -c--a-w C:\Program Files\AdvCtrl.dll
2001-11-08 03:02 40,960 -c--a-w C:\Program Files\AdvDlg.dll
2001-11-08 02:58 135,168 -c--a-w C:\Program Files\CDib24.dll
2001-10-02 06:01 51 ----a-w C:\Program Files\Mail.url
2001-10-02 06:01 50 ----a-w C:\Program Files\Web.url
2001-10-01 18:14 3,858 -c--a-w C:\Program Files\read.me
2001-10-01 17:32 2,019 -c--a-w C:\Program Files\license.txt
.
((((((((((((((((((((((((((((( snapshot@2008-09-19_15.29.30.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 20:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-09-19 20:18:25 6,823,936 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\ntuser.dat
+ 2008-09-19 20:18:25 1,392,640 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-09-19 20:18:23 6,823,936 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\ntuser.dat
+ 2008-09-19 20:18:23 1,392,640 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-10 253952]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 1277952]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-31 1235736]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696]
"lxcrmon.exe"="C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" [2006-03-06 286720]
"EzPrint"="C:\Program Files\Lexmark 2400 Series\ezprint.exe" [2006-02-07 98304]
"LXCRCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll" [2006-02-24 65536]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-15 185896]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 C:\WINDOWS\sm56hlpr.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra--c--- 2006-03-30 17:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-31 97928]
R3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-10 12672]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2008-02-21 19712]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [ ]
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2008-02-21 18304]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [ ]
.
Contents of the 'Scheduled Tasks' folder
2008-09-16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-19 17:59:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\hp\KBD\kbd.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-09-19 18:11:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 22:11:09
ComboFix2.txt 2008-09-19 19:29:55
Pre-Run: 176,555,810,816 bytes free
Post-Run: 176,572,583,936 bytes free
183 --- E O F --- 2008-09-19 13:44:40