thanks for all the help thus far, here is the combofix log file.
ComboFix 09-09-17.04 - HP_Owner 09/17/2009 20:57.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3191.2699 [GMT -4:00]
Running from: K:\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Owner\Application Data\Microsoft\profile.dat
c:\program files\meoqdr
c:\program files\meoqdr\cbtxsysguard.exe
c:\windows\Installer\5204cbe.msi
c:\windows\mark_32.dll
c:\windows\system32\drivers\ESQULdeyljapvucnrnpyrgquodtawysdhpwmp.sys
c:\windows\system32\ESQULvjejbodqjqviyoyjcvjdkamxeayxodtr.dll
c:\windows\system32\ESQULwoyopqfvtkxkphltirvbmadorxtgsvqm.dll
c:\windows\system32\ps2.bat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ESQULserv.sys
-------\Legacy_ESQULserv.sys
-------\Legacy_IPRIP
-------\Legacy_WINDOWS_MSI
-------\Service_Iprip
-------\Service_Windows MSI
-------\Service_ESQULserv.sys
((((((((((((((((((((((((( Files Created from 2009-08-18 to 2009-09-18 )))))))))))))))))))))))))))))))
.
2009-09-16 23:48 . 2009-09-16 23:48 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Sonic
2009-09-16 22:10 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-16 22:10 . 2009-09-16 22:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-16 22:10 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-16 21:26 . 2009-09-16 21:26 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-09-16 01:24 . 2004-08-04 07:00 18944 ----a-w- c:\windows\system32\simptcp.dll
2009-09-16 01:24 . 2004-08-04 07:00 18944 ----a-w- c:\windows\system32\dllcache\simptcp.dll
2009-09-16 01:24 . 2004-08-04 07:00 35328 ----a-w- c:\windows\system32\iprip.dll
2009-09-16 01:24 . 2004-08-04 07:00 35328 ----a-w- c:\windows\system32\dllcache\iprip.dll
2009-09-15 22:25 . 2009-09-15 22:25 -------- d-----w- c:\program files\Trend Micro
2009-09-14 23:42 . 2009-09-15 00:47 12032 ----a-w- c:\windows\system32\iehelper.dll.ren
2009-09-13 17:44 . 2009-09-14 16:22 -------- d-----w- C:\$AVG8.VAULT$
2009-09-13 17:35 . 2009-09-13 17:35 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-13 17:35 . 2009-09-13 17:35 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-13 17:35 . 2009-09-13 17:35 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-13 17:35 . 2009-09-13 17:35 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-13 17:35 . 2009-09-15 21:06 -------- d-----w- c:\windows\system32\drivers\Avg
2009-09-13 17:35 . 2009-09-13 17:35 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-09-13 17:35 . 2009-09-14 22:43 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-13 17:35 . 2009-09-13 17:35 -------- d-----w- c:\program files\AVG
2009-09-13 17:26 . 2009-09-13 17:26 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\AVG8
2009-09-13 17:20 . 2009-09-13 17:20 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-13 17:20 . 2009-09-13 17:20 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\SUPERAntiSpyware.com
2009-09-13 17:20 . 2009-09-13 17:20 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-11 23:19 . 2009-09-11 23:19 -------- d-----w- c:\program files\Common Files\LightScribe
2009-09-11 23:11 . 2009-09-11 23:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-11 21:30 . 2009-09-11 21:30 186880 ----a-w- c:\windows\system32\drivers\trlkprot.sys
2009-09-11 21:30 . 2009-09-11 21:30 -------- d-----w- c:\windows\trlrm
2009-09-11 21:30 . 2009-09-16 00:12 36 ---h--r- c:\windows\sued.dat
2009-09-11 21:30 . 2009-09-16 00:12 -------- d-----w- c:\program files\SpyWall
2009-09-09 23:09 . 2009-09-09 23:09 -------- d-----w- c:\program files\iPod
2009-09-09 23:08 . 2009-09-09 23:10 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-09 23:05 . 2009-09-09 23:06 -------- d-----w- c:\program files\QuickTime
2009-09-08 23:52 . 2009-09-08 23:52 -------- d-----w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2009-09-08 23:52 . 2009-09-08 23:52 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2009-09-06 00:13 . 2009-09-06 00:16 3012 ----a-w- C:\drmHeader.bin
2009-09-04 18:36 . 2009-09-04 19:13 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\tctemp
2009-09-04 18:34 . 2001-08-18 02:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-09-04 18:34 . 2004-08-04 04:56 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-09-04 16:31 . 2009-09-04 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-09-04 16:30 . 2009-09-11 14:26 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Azureus
2009-09-04 15:15 . 2009-09-04 15:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2009-09-04 15:02 . 2007-04-18 12:51 2113536 ----a-w- c:\windows\system32\python25.dll
2009-09-04 15:01 . 2009-09-04 16:09 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\ESRI
2009-09-04 14:50 . 2009-09-04 18:12 -------- d-----w- c:\program files\Common Files\ESRI
2009-09-04 14:49 . 2009-09-04 15:02 -------- d-----w- C:\Python25
2009-08-30 15:59 . 2009-08-30 15:59 -------- d-----w- c:\documents and settings\All Users\Application Data\espionServerData
2009-08-30 15:56 . 2009-08-30 15:56 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-08-30 15:55 . 2009-08-30 15:55 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-08-30 15:17 . 2009-09-04 18:18 -------- d-----w- C:\flexlm
2009-08-30 15:17 . 2009-08-30 15:17 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-08-30 15:14 . 2009-08-30 15:14 -------- d-----w- c:\program files\SafeNet Sentinel
2009-08-30 15:14 . 2009-08-30 15:14 -------- d-----w- c:\program files\Common Files\SafeNet Sentinel
2009-08-29 22:09 . 2009-08-30 12:01 -------- d-----w- c:\program files\uTorrent Ultra Accelerator
2009-08-29 21:21 . 2009-08-29 21:21 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\WinZip
2009-08-29 21:20 . 2009-08-29 21:22 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-08-29 20:48 . 2009-08-29 20:48 -------- d-----w- c:\windows\system32\LogFiles
2009-08-29 20:37 . 2009-08-29 20:37 -------- d-----w- c:\program files\PFPortChecker
2009-08-29 14:20 . 2009-08-29 15:22 -------- d-----w- c:\program files\PFConfig
2009-08-28 23:08 . 2009-08-28 23:08 -------- d--h--w- c:\windows\PIF
2009-08-28 22:03 . 2009-08-28 22:04 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Temp
2009-08-28 22:03 . 2009-08-28 22:03 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-08-28 22:03 . 2009-08-29 20:54 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Google
2009-08-28 22:03 . 2009-08-29 20:54 -------- d-----w- c:\program files\Google
2009-08-28 21:56 . 2009-08-28 21:56 -------- d-----w- c:\program files\Google Earth Pro 4.2
2009-08-28 21:56 . 2009-08-28 21:56 -------- d-----w- c:\windows\Google Earth Pro 4.2
2009-08-28 19:58 . 2009-08-28 19:58 -------- d-----w- c:\program files\Common Files\Corel
2009-08-28 19:58 . 2009-08-28 19:58 -------- d-----w- c:\program files\Corel
2009-08-28 19:40 . 2009-09-09 23:34 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Corel
2009-08-28 19:40 . 2009-09-09 23:34 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-28 19:40 . 2009-08-28 19:59 88 --sh--r- c:\windows\system32\B930CA19A1.sys
2009-08-28 19:39 . 2009-08-28 19:59 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Corel
2009-08-28 19:39 . 2009-08-28 19:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Corel
2009-08-25 01:17 . 2009-08-25 01:17 -------- d-----w- c:\program files\LightScribe
2009-08-25 00:55 . 2009-08-25 00:55 -------- d-----w- c:\program files\SymNetDrv
2009-08-23 21:37 . 2009-08-25 01:29 -------- d-----w- C:\Temp
2009-08-23 21:37 . 2008-05-20 09:59 1570816 ----a-w- c:\temp\TSDNWIN.exe
2009-08-23 21:37 . 2008-05-08 17:58 1048576 ----a-w- c:\temp\autorun.bin
2009-08-23 20:45 . 2009-08-23 20:45 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\WinBatch
2009-08-23 20:27 . 2009-08-23 20:27 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Motive
2009-08-23 20:16 . 2009-08-23 20:16 -------- d-----w- c:\program files\LightScribe Diagnostic Utility
2009-08-23 15:28 . 2006-03-17 18:49 368640 ----a-w- c:\windows\system32\TwnLib4.dll
2009-08-23 15:28 . 2006-03-17 15:45 802816 ----a-w- c:\windows\system32\imagXRA7.dll
2009-08-23 15:28 . 2006-03-17 15:45 258048 ----a-w- c:\windows\system32\imagXR7.dll
2009-08-23 15:28 . 2009-08-23 15:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-08-23 15:28 . 2006-03-17 15:45 497296 ----a-w- c:\windows\system32\imagXpr7.dll
2009-08-23 15:28 . 2006-03-17 15:45 1757184 ----a-w- c:\windows\system32\imagX7.dll
2009-08-23 15:28 . 2009-08-23 15:28 -------- d-----w- c:\program files\Common Files\Nero
2009-08-23 15:21 . 2009-09-04 13:17 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\WinAVI
2009-08-23 15:21 . 2009-08-23 15:21 -------- d-----w- c:\program files\WinAVI Video Converter
2009-08-23 15:21 . 2006-10-26 23:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-08-23 15:18 . 2009-08-23 15:18 -------- d-----w- c:\program files\Microsoft.NET
2009-08-23 15:15 . 2009-08-23 15:15 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-08-23 15:14 . 2009-08-23 15:14 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Microsoft Help
2009-08-23 15:14 . 2009-08-23 15:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-22 21:28 . 2009-08-30 16:02 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Adobe
2009-08-22 21:28 . 2009-08-22 21:28 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\AdobeUM
2009-08-22 21:28 . 2009-08-30 15:55 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-22 19:30 . 2009-08-22 19:30 -------- d-----w- c:\program files\DvidPL
2009-08-22 07:05 . 2009-08-22 07:05 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-22 07:04 . 2009-08-22 07:04 -------- d-----w- c:\program files\MSBuild
2009-08-22 07:04 . 2009-08-22 07:04 -------- d-----w- c:\program files\Reference Assemblies
2009-08-22 07:04 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-22 07:04 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-22 07:04 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-22 07:04 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-22 07:04 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-22 07:04 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-22 07:04 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-22 07:04 . 2009-08-28 20:18 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-22 07:01 . 2009-08-22 07:01 -------- d-----w- c:\program files\MSXML 6.0
2009-08-21 10:53 . 2005-11-09 14:00 462848 ----a-w- c:\windows\system32\HHActiveX.dll
2009-08-21 10:53 . 2005-11-09 14:00 24576 ----a-w- c:\windows\system32\msxml3a.dll
2009-08-21 10:51 . 2009-08-21 10:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Droppix
2009-08-21 03:27 . 2009-08-23 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\LightScribe
2009-08-21 03:04 . 2009-08-21 03:04 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\MicroVision Applications
2009-08-21 01:51 . 2009-08-21 01:51 -------- d-----w- c:\program files\NCH Software
2009-08-21 01:30 . 2009-08-21 01:30 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-08-21 01:30 . 2009-08-21 01:30 -------- d-----w- c:\program files\NCH Swift Sound
2009-08-21 01:30 . 2009-08-21 01:30 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\NCH Swift Sound
2009-08-19 22:09 . 2009-09-13 17:02 1324 ----a-w- c:\windows\system32\d3d9caps.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-18 01:05 . 2009-08-15 16:12 12 ----a-w- c:\windows\bthservsdp.dat
2009-09-18 00:50 . 2009-08-18 01:50 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Skype
2009-09-18 00:39 . 2005-05-27 00:27 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-09-18 00:29 . 2009-08-18 01:52 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\skypePM
2009-09-16 23:01 . 2009-08-15 15:26 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-16 01:06 . 2009-08-15 17:58 -------- d-----w- c:\program files\Linksys
2009-09-16 00:57 . 2009-09-16 00:57 3 ----a-w- c:\program files\option.txt
2009-09-15 03:41 . 2009-08-15 05:08 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\uTorrent
2009-09-15 02:35 . 2009-08-15 04:57 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Apple Computer
2009-09-14 23:58 . 2005-05-27 00:15 -------- d-----w- c:\program files\Easy Internet signup
2009-09-11 19:35 . 2009-08-15 19:17 -------- d-----w- c:\program files\DivX
2009-09-11 19:34 . 2009-08-15 19:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-09-09 23:10 . 2009-08-15 01:21 -------- d-----w- c:\program files\iTunes
2009-09-09 23:09 . 2009-08-15 01:20 -------- d-----w- c:\program files\Common Files\Apple
2009-09-04 18:34 . 2009-08-15 01:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-09-04 15:53 . 2009-08-15 16:43 113888 ----a-w- c:\documents and settings\HP_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-04 15:34 . 2009-08-15 01:27 79016 ---ha-w- c:\windows\system32\mlfcache.dat
2009-08-25 01:29 . 2009-08-15 01:26 -------- d-----w- c:\program files\Safari
2009-08-25 00:57 . 2005-05-27 00:29 -------- d-----w- c:\program files\Norton Internet Security
2009-08-25 00:55 . 2005-05-27 00:27 -------- d-----w- c:\program files\Symantec
2009-08-18 01:52 . 2009-08-18 01:52 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-18 01:49 . 2009-08-18 01:49 -------- d-----w- c:\program files\Common Files\Skype
2009-08-18 01:49 . 2009-08-18 01:49 -------- d-----r- c:\program files\Skype
2009-08-18 01:49 . 2009-08-18 01:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-08-16 21:34 . 2009-08-16 21:33 26750 ----a-w- c:\windows\~DFA10.tmp
2009-08-16 17:49 . 2005-05-27 00:02 -------- d-----w- c:\program files\Microsoft Works
2009-08-16 17:17 . 2009-08-16 17:16 -------- d-----w- c:\program files\EasyDVDClone
2009-08-16 07:00 . 2009-08-16 07:00 -------- d-----w- c:\program files\MSXML 4.0
2009-08-15 21:37 . 2009-08-15 21:37 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\DivX
2009-08-15 19:20 . 2009-08-15 19:20 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\InterVideo
2009-08-15 19:11 . 2009-08-15 04:57 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Symantec
2009-08-15 18:12 . 2009-08-15 18:12 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Leadertech
2009-08-15 17:33 . 2009-08-15 17:26 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
2009-08-15 17:33 . 2009-08-15 17:33 -------- d-----w- c:\program files\EPSON
2009-08-15 16:57 . 2009-08-15 16:42 -------- d-----w- c:\program files\Wide Angle Software
2009-08-15 16:28 . 2009-08-15 16:28 -------- d-----w- c:\program files\Boilsoft Video Splitter
2009-08-15 16:25 . 2009-08-15 16:25 -------- d-----w- c:\program files\Boilsoft Video Joiner
2009-08-15 16:24 . 2009-08-15 16:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Movavi VideoSuite 5
2009-08-15 16:23 . 2009-08-15 16:23 -------- d-----w- c:\program files\Movavi VideoSuite 5
2009-08-15 16:11 . 2009-08-15 16:08 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2009-08-15 16:08 . 2009-08-15 16:08 50688 ----a-w- c:\windows\system32\wbhelp2.dll
2009-08-15 15:28 . 2009-08-15 15:28 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\dvdcss
2009-08-15 05:08 . 2009-08-15 05:08 -------- d-----w- c:\program files\uTorrent
2009-08-15 04:57 . 2009-08-15 04:57 1861 --sha-r- c:\windows\system32\drivers\103C_HP_CPC_PS583AA-ABA a1020n_YC_0Pavi_QMXF522_E52NAheBLU2_47_IGoldfish3_SASUSTeK Computer INC._V1.xx_B3.20_T050331_WXH2_L409_M3192_J1000_7Intel_8Pentium 4_93.06_#090815_N10EC8139_Z11C1048C_G80862582.MRK
2009-08-15 01:27 . 2009-08-15 01:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-15 01:27 . 2005-05-26 23:37 -------- d-----w- c:\program files\Java
2009-08-15 01:21 . 2009-08-15 01:21 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-15 01:21 . 2009-08-15 01:21 -------- d-----w- c:\program files\Bonjour
2009-06-26 21:21 . 2009-06-26 21:21 96256 ----a-w- c:\windows\VX3000.dll
2009-06-26 21:21 . 2009-06-26 21:21 671744 ----a-w- c:\windows\system32\LCCoin30.dll
2009-06-26 21:21 . 2009-06-26 21:21 1956352 ----a-w- c:\windows\system32\drivers\VX3000.sys
2009-06-26 21:21 . 2009-06-26 21:21 757248 ----a-w- c:\windows\vVX3000.exe
2009-06-26 21:21 . 2009-06-26 21:21 222720 ----a-w- c:\windows\vVX3000.dll
2009-06-26 21:21 . 2009-06-26 21:21 170496 ----a-w- c:\windows\system32\cVX3000.dll
2009-06-26 16:18 . 2009-08-15 04:16 659456 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2009-08-15 04:12 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-25 08:44 . 2009-08-15 04:16 59392 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:44 . 2009-08-15 04:16 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:44 . 2009-08-15 04:16 168448 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:44 . 2009-08-15 04:15 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:44 . 2009-08-15 04:12 298496 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:44 . 2004-08-04 11:00 724480 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-22 11:34 . 2004-08-04 18:00 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-07-16 25604904]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-08-20 2363392]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-05-26 180269]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 58984]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"VX3000"="c:\windows\vVX3000.exe" [2009-06-26 757248]
"pdfFactory Pro Dispatcher v2"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [2007-01-29 507904]
"FinePrint Dispatcher v5"="c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" [2008-04-18 520192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2009-08-25 100056]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-13 2007832]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-03-18 61952]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-29 88363]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-10-13 77824]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2004-10-13 2742272]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-5 258048]
SpySubtract.lnk - c:\program files\InterMute\SpySubtract\sslaunch.exe [2005-5-26 73728]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2005-5-26 45056]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-13 17:35 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\docume~1\ALLUSE~1\APPLIC~1\SPYWAR~1\sp_rsdel.exe \??\c:\docume~1\ALLUSE~1\APPLIC~1\SPYWAR~1\sp_rsdel.dat
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\PFPortChecker\\PFPortChecker.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\trlrm\\RMHSvc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Safari\\Safari.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/13/2009 1:35 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/13/2009 1:35 PM 108552]
R1 trlkprot;Trlokom Application scan driver;c:\windows\system32\drivers\trlkprot.sys [9/11/2009 5:30 PM 186880]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [9/16/2008 12:03 PM 169312]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/13/2009 1:35 PM 297752]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/28/2009 6:03 PM 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-09-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-28 22:03]
2009-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-28 22:03]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{FA010552-4A27-4cb1-A1BB-3E2D697F1639} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-17 21:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(712)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(4980)
c:\docume~1\HP_Owner\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\msi.dll
c:\windows\system32\hnetcfg.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCPROXY.EXE
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Norton Internet Security\ISSVC.exe
c:\program files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PSIService.exe
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\snmp.exe
c:\windows\trlrm\RMHSvc.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Symantec Shared\Security Center\symwsc.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\InterMute\SpySubtract\SpySub.exe
.
**************************************************************************
.
Completion time: 2009-09-18 21:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-18 01:10
Pre-Run: 659,921,702,912 bytes free
Post-Run: 660,091,109,376 bytes free
379 --- E O F --- 2009-09-16 01:09