The first script that you gave me gave me a log of the files deleted, but I tried it with the edited script and I don't think it mentions the files deleted (I unfortunately lost the earlier log though...)
ComboFix 09-04-22.02 - Wenngee 04/21/2009 22:49.4 - NTFSx86
Running from: c:\documents and settings\Wenngee\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Wenngee\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((( Files Created from 2009-03-22 to 2009-04-22 )))))))))))))))))))))))))))))))
.
2009-04-21 22:26 . 2009-04-21 23:02 -------- d-----w C:\32788R22FWJFW.0.tmp
2009-04-14 23:40 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-14 23:39 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-14 23:39 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-14 23:39 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-14 23:39 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-14 23:39 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 23:39 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-14 23:39 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-14 23:39 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-14 23:35 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-14 23:35 . 2009-03-27 06:58 1203922 -c----w c:\windows\system32\dllcache\sysmain.sdb
2009-04-14 23:35 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-03-31 22:57 . 2009-03-31 22:57 -------- d-----w c:\windows\system32\scripting
2009-03-31 22:57 . 2009-03-31 22:57 -------- d-----w c:\windows\l2schemas
2009-03-31 22:57 . 2009-03-31 22:57 -------- d-----w c:\windows\system32\en
2009-03-31 22:57 . 2009-03-31 22:57 -------- d-----w c:\windows\system32\bits
2009-03-31 22:42 . 2009-03-31 22:59 -------- d-----w c:\windows\ServicePackFiles
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-22 02:57 . 2006-08-09 01:07 16822 ----a-w c:\windows\system32\tablet.dat
2009-04-21 22:06 . 2007-06-22 20:20 -------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2009-04-21 22:03 . 2005-09-06 20:49 -------- d-----w c:\program files\McAfee.com
2009-04-21 21:16 . 2005-03-31 19:52 -------- d-----w c:\program files\Java
2009-04-21 19:57 . 2008-05-13 03:08 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-21 19:57 . 2008-05-13 03:08 325128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-21 19:56 . 2008-05-13 03:08 107272 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-19 21:27 . 2005-09-23 21:59 30744 ----a-w c:\documents and settings\Wenngee\Application Data\wklnhst.dat
2009-04-19 01:55 . 2006-12-08 23:12 -------- d-----w c:\program files\Furcadia
2009-04-18 02:59 . 2008-05-23 04:22 268 ---ha-w C:\sqmdata05.sqm
2009-04-18 02:59 . 2008-05-23 04:22 244 ---ha-w C:\sqmnoopt05.sqm
2009-04-17 04:45 . 2008-05-22 05:34 268 ---ha-w C:\sqmdata04.sqm
2009-04-17 04:45 . 2008-05-22 05:34 244 ---ha-w C:\sqmnoopt04.sqm
2009-04-13 01:33 . 2009-04-13 01:21 -------- d-----w c:\program files\Blockland
2009-04-06 21:22 . 2008-05-13 03:07 -------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-04-01 03:40 . 2008-05-21 04:24 268 ---ha-w C:\sqmdata03.sqm
2009-04-01 03:40 . 2008-05-21 04:24 244 ---ha-w C:\sqmnoopt03.sqm
2009-03-31 23:16 . 2005-03-31 02:49 326711 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-31 22:31 . 2005-03-31 01:29 250048 --sha-r C:\ntldr
2009-03-17 00:06 . 2005-09-07 00:12 80064 -c--a-w c:\documents and settings\Wenngee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-08 02:44 . 2009-03-08 02:44 -------- d-----w c:\program files\Netflix
2009-03-06 14:22 . 2005-03-31 01:29 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:53 . 2009-03-03 00:53 -------- d-----w c:\documents and settings\Wenngee\Application Data\OpenOffice.org
2009-03-03 00:37 . 2009-03-03 00:37 -------- d-----w c:\program files\JRE
2009-03-03 00:37 . 2009-03-03 00:36 -------- d-----w c:\program files\OpenOffice.org 3
2009-03-03 00:18 . 2005-03-31 01:29 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2005-03-31 01:29 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2005-03-31 01:29 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2005-03-31 01:29 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2005-03-31 01:29 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2005-03-31 01:29 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2005-03-31 01:29 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-07 23:02 . 2004-08-03 22:59 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2005-03-31 01:29 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2005-03-31 01:29 2189056 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2005-03-31 01:29 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2005-03-31 01:29 56832 ----a-w c:\windows\system32\secur32.dll
2008-06-30 22:23 . 2008-08-29 22:22 32 ----a-r c:\documents and settings\All Users\hash.dat
2005-09-20 22:59 . 2005-09-20 22:59 130 -c--a-w c:\documents and settings\Wenngee\Local Settings\Application Data\fusioncache.dat
2005-09-06 18:46 . 2005-03-31 20:35 67144 -c----w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
1999-07-07 00:00 . 1999-07-07 00:00 6 -csh--r c:\windows\@@desktop.dat
2008-04-14 00:12 . 2005-03-31 01:29 1384479 --sh--r c:\windows\system32\msvbvm60.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-31 50480]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-10-08 155648]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-08 114688]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-01-15 184320]
"HKSERV.EXE"="c:\program files\Sony\HotKey Utility\HKserv.exe" [2004-10-17 122880]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-01-14 151552]
"WCULauncher"="c:\program files\Sony\SmartWi Connection Utility\WCULauncher.exe" [2005-03-16 15360]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"SmartWiConnectionUtility"="c:\program files\Sony\SmartWi Connection Utility\SmartWi.exe" [2005-03-16 618496]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-01-25 81920]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-21 1601304]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-9-24 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2006-8-8 114688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-21 19:57 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R3 SEMWModem;Sony Ericsson SEMWModem;c:\windows\system32\DRIVERS\GCXX.sys [2005-01-03 114944]
R3 SEMWWNIC;Sony Ericsson SEMWWNIC;c:\windows\system32\DRIVERS\GCXXNet.sys [2005-01-03 53248]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-21 325128]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-21 107272]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-04-21 903960]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-21 298264]
S3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\DRIVERS\SonyPI.sys [2003-06-19 71961]
.
Contents of the 'Scheduled Tasks' folder
2009-04-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}uInternet Connection Wizard,ShellNext =
hxxp://www.sony.com/vaiopeopleuInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {0CBF6FB5-68EA-406D-882A-AB3B5984D988} -
hxxps://hotspot.pccwwifi.com/vpn/wlvpndialer.ocxFF - ProfilePath - c:\documents and settings\Wenngee\Application Data\Mozilla\Firefox\Profiles\4qqjxhya.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - comcast.net
FF - prefs.js: keyword.URL -
hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=108&ei=utf-8&yahoo_domain=search.yahoo.com&p=FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Wenngee\Application Data\Mozilla\Firefox\Profiles\4qqjxhya.default\extensions\flashplugin@idm\platform\WINNT\plugins\npidmdcp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
FF - user.js: browser.sessionstore.resume_from_crash - false
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-21 22:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1908)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\rundll32.exe
c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\Tablet.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\windows\system32\fxssvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
c:\windows\system32\igfxext.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Sony\HotKey Utility\HKWnd.exe
.
**************************************************************************
.
Completion time: 2009-04-22 23:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-22 03:06
ComboFix2.txt 2009-04-22 01:06
ComboFix3.txt 2009-04-21 23:38
ComboFix4.txt 2009-04-21 23:29
Pre-Run: 5,330,464,768 bytes free
Post-Run: 5,644,845,056 bytes free
217 --- E O F --- 2009-04-21 19:51