So lets begin with the Combofix log.
ComboFix 08-01-14.3 - Michael 2008-01-14 21:16:45.4 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.617 [GMT -6:00]
Running from: C:\Documents and Settings\Michael\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2007-12-15 to 2008-01-15 )))))))))))))))))))))))))))))))
.
2008-01-14 20:28 . 2008-01-14 20:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-14 10:00 . 2008-01-14 10:00 268 --ah----- C:\sqmdata17.sqm
2008-01-14 10:00 . 2008-01-14 10:00 244 --ah----- C:\sqmnoopt17.sqm
2008-01-14 03:01 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-14 03:00 . 2008-01-14 03:00 <DIR> d-------- C:\Program Files\Common Files\Java
2008-01-14 02:53 . 2008-01-14 02:56 <DIR> d-------- C:\Documents and Settings\Michael\.SunDownloadManager
2008-01-14 02:37 . 2008-01-14 02:37 268 --ah----- C:\sqmdata16.sqm
2008-01-14 02:37 . 2008-01-14 02:37 244 --ah----- C:\sqmnoopt16.sqm
2008-01-14 02:21 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-14 01:43 . 2008-01-14 02:04 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-14 01:43 . 2008-01-14 01:43 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-14 01:43 . 2008-01-14 01:43 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-14 01:43 . 2008-01-14 01:43 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-14 01:34 . 2008-01-14 01:45 <DIR> d-------- C:\Documents and Settings\Michael\.housecall6.6
2008-01-14 01:23 . 2008-01-14 01:23 <DIR> d-------- C:\VundoFix Backups
2008-01-14 01:11 . 2008-01-14 01:11 268 --ah----- C:\sqmdata15.sqm
2008-01-14 01:11 . 2008-01-14 01:11 244 --ah----- C:\sqmnoopt15.sqm
2008-01-14 00:39 . 2008-01-14 00:39 268 --ah----- C:\sqmdata14.sqm
2008-01-14 00:39 . 2008-01-14 00:39 244 --ah----- C:\sqmnoopt14.sqm
2008-01-14 00:37 . 2008-01-14 09:57 3,374,149 --a------ C:\WINDOWS\{00000002-00000000-00000002-00001102-00000002-80641102}.BAK
2008-01-14 00:04 . 2008-01-14 00:04 <DIR> d-------- C:\Program Files\CCleaner
2008-01-14 00:03 . 2008-01-14 01:13 <DIR> d-------- C:\Program Files\RogueRemover FREE
2008-01-13 23:51 . 2008-01-13 23:51 268 --ah----- C:\sqmdata13.sqm
2008-01-13 23:51 . 2008-01-13 23:51 244 --ah----- C:\sqmnoopt13.sqm
2008-01-13 22:00 . 2008-01-13 22:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\vlc
2008-01-13 20:57 . 2008-01-13 20:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-01-13 20:46 . 2008-01-13 20:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-13 20:33 . 2008-01-13 20:33 268 --ah----- C:\sqmdata12.sqm
2008-01-13 20:33 . 2008-01-13 20:33 244 --ah----- C:\sqmnoopt12.sqm
2008-01-13 20:29 . 2008-01-13 20:29 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-01-13 20:16 . 2008-01-13 20:16 268 --ah----- C:\sqmdata11.sqm
2008-01-13 20:16 . 2008-01-13 20:16 244 --ah----- C:\sqmnoopt11.sqm
2008-01-13 19:58 . 2008-01-13 19:58 268 --ah----- C:\sqmdata10.sqm
2008-01-13 19:58 . 2008-01-13 19:58 244 --ah----- C:\sqmnoopt10.sqm
2008-01-13 19:23 . 2008-01-14 16:13 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-01-13 19:23 . 2008-01-13 19:23 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\PC Tools
2008-01-13 19:23 . 2008-01-14 21:03 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-13 19:23 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-01-13 19:23 . 2007-10-04 17:10 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-13 19:23 . 2007-10-04 17:10 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-13 19:23 . 2007-10-04 17:10 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-13 19:23 . 2007-10-04 17:11 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-01-13 18:52 . 2008-01-13 18:52 268 --ah----- C:\sqmdata09.sqm
2008-01-13 18:52 . 2008-01-13 18:52 244 --ah----- C:\sqmnoopt09.sqm
2008-01-13 17:52 . 2008-01-14 00:17 3,954 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-13 17:36 . 2008-01-13 17:36 268 --ah----- C:\sqmdata08.sqm
2008-01-13 17:36 . 2008-01-13 17:36 244 --ah----- C:\sqmnoopt08.sqm
2008-01-13 16:25 . 2008-01-14 01:13 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-13 16:25 . 2008-01-14 01:13 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\SUPERAntiSpyware.com
2008-01-13 16:25 . 2008-01-13 16:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-13 16:06 . 2008-01-13 16:06 268 --ah----- C:\sqmdata07.sqm
2008-01-13 16:06 . 2008-01-13 16:06 244 --ah----- C:\sqmnoopt07.sqm
2008-01-13 14:40 . 2008-01-13 14:40 86,144 --a------ C:\WINDOWS\system32\drivers\fipss.sys
2008-01-10 14:58 . 2008-01-10 14:58 268 --ah----- C:\sqmdata06.sqm
2008-01-10 14:58 . 2008-01-10 14:58 244 --ah----- C:\sqmnoopt06.sqm
2008-01-08 01:20 . 2008-01-08 01:20 91 --a------ C:\WINDOWS\EMSDll.INI
2008-01-01 16:26 . 2008-01-01 16:26 <DIR> d-------- C:\Program Files\iTunes
2008-01-01 16:26 . 2008-01-01 16:26 <DIR> d-------- C:\Program Files\iPod
2008-01-01 16:25 . 2008-01-01 16:25 <DIR> d-------- C:\Program Files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-14 23:54 --------- d-----w C:\Documents and Settings\Michael\Application Data\tor
2008-01-14 19:32 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-14 16:31 --------- d-----w C:\Documents and Settings\Michael\Application Data\Vidalia
2008-01-14 16:01 --------- d-----w C:\Documents and Settings\Michael\Application Data\OpenOffice.org2
2008-01-14 09:01 --------- d-----w C:\Program Files\Java
2008-01-14 07:15 --------- d-----w C:\Program Files\SpywareBlaster
2008-01-14 07:13 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-14 06:31 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2008-01-14 06:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-14 01:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-13 21:12 --------- d-----w C:\Documents and Settings\Michael\Application Data\.gaim
2008-01-13 20:57 --------- d-----w C:\Documents and Settings\Michael\Application Data\Azureus
2008-01-13 20:37 --------- d-----w C:\Program Files\Azureus
2008-01-09 22:57 --------- d-----w C:\Program Files\eMule
2007-12-14 01:51 --------- d-----w C:\Documents and Settings\Michael\Application Data\CoreFTP
2007-12-06 06:57 --------- d-----w C:\Documents and Settings\Michael\Application Data\Skype
2007-11-24 23:11 --------- d-----w C:\Program Files\Ventrilo
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2005-12-30 21:32 54,855 ----a-w C:\Program Files\tor-bundle-uninstall.exe
2005-12-20 22:31 26,657 ----a-w C:\Program Files\BUNDLE_LICENSE
2006-04-25 17:51 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-01-14_ 2.42.36.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-11-10 19:27:06 49,248 ----a-w C:\WINDOWS\system32\java.exe
+ 2007-12-14 06:57:22 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2005-11-10 19:27:16 49,250 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2007-12-14 06:57:24 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2005-11-10 21:03:54 127,078 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2007-12-14 07:59:16 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TorCP"="C:\Program Files\TorCP\torcp.exe" [ ]
"DriveCrypt Startup"="C:\Program Files\DriveCrypt\DriveCrypt.exe" [2004-05-30 03:29 2711552]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 21:49 4662776]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"Vidalia"="C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe" [2007-08-26 00:02 11852288]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32 58984]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-03-06 14:53 100048]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 14:29 7561216]
"nwiz"="nwiz.exe" [2006-03-09 14:29 1519616 C:\WINDOWS\system32\nwiz.exe]
"Acronis True Image Monitor"="C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe" [2005-12-31 00:45 417838]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2005-12-31 00:45 61440]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 19:56 24576 C:\WINDOWS\system32\CTHELPER.EXE]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 03:00 28672]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 14:29 86016]
"MXOBG"="C:\WINDOWS\MXOALDR.EXE" [2006-08-06 13:51 94208]
"\\PAUL\EPSON Stylus Photo R300 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.exe" [2003-06-04 04:00 99840]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 01:36 81920]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-26 20:53 180269]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27 1065288]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 18:04 5562368]
C:\Documents and Settings\Michael\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2005-12-14 19:01:20]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\palmOne\Hotsync.exe [2004-06-09 16:27:34]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-12 19:01:04]
Privoxy.lnk - C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe [2006-11-20 08:30:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax 4.1.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax 4.1.lnk
backup=C:\WINDOWS\pss\eFax 4.1.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Michael^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Michael\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Michael^Start Menu^Programs^Startup^Peepbox.lnk]
path=C:\Documents and Settings\Michael\Start Menu\Programs\Startup\Peepbox.lnk
backup=C:\WINDOWS\pss\Peepbox.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-10-09 11:28 139264 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eFax 4.1]
--a------ 2005-12-16 17:59 107008 C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
--a------ 2003-07-25 13:15 536576 C:\Program Files\Eraser\eraser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeRAM XP]
--a------ 2006-03-22 23:13 1591808 C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gaim]
--a------ 2005-08-11 20:44 69793 C:\Program Files\Gaim\gaim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ]
--a------ 2005-11-15 12:12 473928 C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2006-10-31 08:50 190464 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\heart five nurb mix]
C:\Documents and Settings\All Users\Application Data\Blue Blah Heart Five\Dash Type.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Info Bash Intra Mix]
C:\Documents and Settings\All Users\Application Data\creative style mix blue\Amen vc save.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 12:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lesstransskipfilm]
C:\Documents and Settings\All Users\Application Data\sect memo less trans\lieseach.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
--a------ 2004-12-22 07:21 823296 C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 16:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Once win]
C:\DOCUME~1\Michael\APPLIC~1\BINTHA~1\delete real.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2007-02-09 16:00 25388584 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoftickPPP]
--a------ 2004-10-20 16:05 160256 C:\Program Files\Softick\PPP\Bin\PPPGate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
--a------ 2006-01-07 01:36 81920 C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-02-11 17:10 1269760 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-04-26 20:53 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 03:00 90112 C:\WINDOWS\UpdReg.EXE
R0 DCR;DCR;C:\WINDOWS\system32\Drivers\DCR.sys [2006-01-01 03:16]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 23:31]
S1 fipss;fipss;C:\WINDOWS\system32\drivers\fipss.sys [2008-01-13 14:40]
S2 DriveCryptService;DriveCrypt Service;C:\Program Files\DriveCrypt\DcrServ.exe [2006-01-01 03:16]
S2 lmgrd;Flexlm;"C:\OrCAD\OrCAD_10.5\IntelliCAD 4\LicenseManager\lmgrd.exe" []
S3 ICDUSB2;Sony IC Recorder (P);C:\WINDOWS\system32\Drivers\ICDUSB2.sys [2002-11-28 20:23]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2005-08-02 15:10]
S3 RioS10;RioS10 driver;C:\WINDOWS\system32\Drivers\RioS10.sys [2002-07-31 08:45]
S3 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2005-10-14 03:53]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" [2005-09-23 07:01]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\I]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-01-15 02:00:02 C:\WINDOWS\Tasks\AB99DF31918A5481.job"
- c:\docume~1\michael\applic~1\bintha~1\ELSECAMPSTORE.exe
"2008-01-08 21:43:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-12 03:38:13 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Michael.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-14 21:17:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"Acronis True Image Monitor"="\"C:\\Program Files\\Acronis\\TrueImage\\TrueImageMonitor.exe\""
"\\\\PAUL\\EPSON Stylus Photo R300 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2F1.EXE /P37 \"\\\\PAUL\\EPSON Stylus Photo R300 Series\" /O6 \"USB001\" /M \"Stylus Photo R300\""
.
Completion time: 2008-01-14 21:18:21
ComboFix-quarantined-files.txt 2008-01-15 03:18:13
ComboFix2.txt 2008-01-15 03:14:48
ComboFix3.txt 2008-01-14 16:07:51
ComboFix4.txt 2008-01-14 08:44:00
.
2008-01-10 08:13:40 --- E O F ---