Here is the second combi-fix log:
ComboFix 09-08-04.03 - C. Harris 08/06/2009 12:37.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1555 [GMT -7:00]
Running from: I:\Combo-Fix.exe
Command switches used :: c:\documents and settings\C. Harris\Desktop\CFScript.txt.lnk
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\2765f.msp
c:\windows\Installer\4a247.msp
.
((((((((((((((((((((((((( Files Created from 2009-07-06 to 2009-08-06 )))))))))))))))))))))))))))))))
.
2009-08-02 20:22 . 2009-08-02 20:22 -------- d-----w- c:\program files\Trend Micro
2009-08-02 02:03 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-02 02:03 . 2009-08-04 01:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-02 02:03 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-31 21:17 . 2009-07-31 21:17 -------- d-----w- c:\program files\iiuoww
2009-07-31 17:53 . 2009-07-31 17:53 -------- d-----w- c:\program files\HTvid
2009-07-28 21:23 . 2009-07-30 21:32 -------- d-----w- c:\documents and settings\C. Harris\Application Data\Apple Computer
2009-07-28 21:22 . 2009-03-19 23:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-07-28 21:22 . 2008-04-17 19:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-07-28 21:22 . 2009-07-28 21:22 -------- d-----w- c:\program files\iPod
2009-07-28 21:22 . 2009-07-28 21:22 -------- d-----w- c:\program files\iTunes
2009-07-28 21:22 . 2009-07-28 21:22 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-28 21:22 . 2009-07-28 21:22 -------- d-----w- c:\program files\Bonjour
2009-07-28 21:21 . 2009-07-28 21:22 -------- d-----w- c:\program files\QuickTime
2009-07-28 21:21 . 2009-07-28 21:21 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Apple Computer
2009-07-28 21:21 . 2009-07-28 21:21 -------- d-----w- c:\documents and settings\C. Harris\Local Settings\Application Data\Apple
2009-07-28 21:21 . 2009-07-28 21:21 -------- d-----w- c:\program files\Apple Software Update
2009-07-28 21:20 . 2009-07-28 21:20 -------- d-----w- c:\program files\Common Files\Apple
2009-07-28 21:20 . 2009-07-28 21:20 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Apple
2009-07-28 21:20 . 2009-07-28 21:23 -------- d-----w- c:\documents and settings\C. Harris\Local Settings\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-05 01:22 . 2006-08-19 07:33 -------- d-----w- c:\documents and settings\C. Harris\Application Data\Petroglyph
2009-08-05 01:22 . 2005-06-23 16:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-05 01:22 . 2006-08-19 07:22 -------- d-----w- c:\program files\LucasArts
2009-08-05 01:06 . 2007-05-12 16:20 -------- d---a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-08-05 00:28 . 2009-05-26 22:38 -------- d-----w- c:\documents and settings\C. Harris\Application Data\Skype
2009-08-05 00:21 . 2008-11-24 01:48 -------- d-----w- c:\documents and settings\C. Harris\Application Data\skypePM
2009-07-22 20:10 . 2008-09-22 04:15 -------- d-----w- c:\documents and settings\C. Harris\Application Data\LimeWire
2009-07-12 07:33 . 2006-08-12 06:35 24032 ----a-w- c:\documents and settings\C. Harris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-06 04:21 . 2008-07-17 05:10 -------- d-----w- c:\program files\Common Files\Real
2009-07-06 04:20 . 2009-07-06 04:20 -------- d-----w- c:\program files\Common Files\xing shared
2009-07-06 04:20 . 2009-07-06 04:20 -------- d-----w- c:\program files\Real
2009-07-06 04:20 . 2003-03-19 05:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-07-06 04:20 . 2003-02-21 11:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-05 22:47 . 2007-02-22 22:19 -------- d-----w- c:\program files\SpeedFan
2009-06-30 23:39 . 2006-10-23 03:18 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-06-30 23:39 . 2006-10-23 03:18 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-06-30 23:39 . 2006-10-23 03:18 12067 ----atw- c:\windows\system32\SIntf16.dll
2009-06-26 16:50 . 2004-08-04 12:00 666624 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-16 14:36 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2004-08-04 12:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 03:50 . 2009-06-02 03:50 612 ----a-w- c:\windows\eReg.dat
2008-10-29 03:42 . 2008-10-29 03:42 109 --sha-w- c:\windows\system32\2351735403.dat
.
(((((((((((((((((((((((((((((
SnapShot@2009-08-05_19.33.04 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-19 39408]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"SMSystemAnalyzer"="c:\program files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 557056]
"SetDefaultMIDI"="MIDIDef.exe" - c:\windows\MIDIDEF.EXE [2005-02-17 24576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-05-06 102490]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-05-06 708698]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-09 7561216]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 1443072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-06 198160]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"SystemGuardAlerter"="c:\program files\iolo\System Mechanic 6\SystemGuardAlerter.exe" [2006-12-20 386048]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"SetDefPrt"="c:\program files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-27 49152]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 622592]
"ACU"="c:\program files\Atheros\ACU.exe" [2006-03-26 335961]
"Ptipbmf"="ptipbmf.dll" - c:\windows\system32\ptipbmf.dll [2005-05-05 118784]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-08-13 61952]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-03-09 1519616]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2005-02-17 14848]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2005-05-06 2748928]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-05-06 77824]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Qualcomm\Eudora\EuShlExt.dll" [2005-11-14 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 06:34 24576 ----a-w- c:\program files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\program files\iolo\System Mechanic 6
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^C. Harris^Start Menu^Programs^Startup^Registration Ghost Recon Advanced Warfighter.LNK]
path=c:\documents and settings\C. Harris\Start Menu\Programs\Startup\Registration Ghost Recon Advanced Warfighter.LNK
backup=c:\windows\pss\Registration Ghost Recon Advanced Warfighter.LNKStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Sprint PCS v3 Utility Service"=2 (0x2)
"MpfService"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
"McTskshd.exe"=2 (0x2)
"McDetect.exe"=2 (0x2)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"AVG Anti-Spyware Guard"=2 (0x2)
"ProductivITService"=2 (0x2)
"PnkBstrA"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\MWL\\MWLSvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [3/13/2008 4:52 PM 33800]
R1 TeksKernel;TeksKernel;c:\windows\system32\drivers\TeksKernel.sys [7/8/2004 2:14 PM 9060]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [3/13/2008 4:49 PM 472320]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [12/14/2008 9:31 PM 596336]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [12/14/2008 9:31 PM 596336]
R2 viewer_service;SECTRA Viewer Update Service;c:\program files\Sectra\IDS5web\bin\viewer_service.exe [11/12/2007 7:05 PM 24628]
R3 Slazldrv;SmartLink AMR_PCI Driver;c:\windows\system32\drivers\SLDRV\slazldrv.sys [5/5/2005 6:33 PM 230448]
S3 1012NDS5;1012NDS5 NDIS Protocol Driver;c:\windows\system32\1012NDS5.sys [3/11/2003 3:33 PM 15872]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [1/13/2009 9:19 PM 33752]
S4 ProductivITService;ProductivIT Service;c:\program files\AlienAutopsy\TEKS_Service.exe [7/8/2004 2:22 PM 77824]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
.
------- Supplementary Scan -------
.
uSearch Page =
hxxp://www.google.comuStart Page =
hxxp://www.cnn.com/uSearch Bar =
hxxp://www.google.com/iemStart Page =
hxxp://www.cnn.com/uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&xport to Microsoft Excel
IE: Open using &Advanced JPEG Compressor - c:\program files\Advanced JPEG Compressor\ajcieex.htm
DPF: {7C705EA9-3C3B-4F3A-B1AA-2184CDFAE4D0} -
hxxp://www.offsiteimagemanagement.com/IDS5web/install/Setup.exeDPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} -
file://d:\cdviewer\CdViewer.cab.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-06 12:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
"ImagePath"="\??\c:\documents and settings\C. Harris\Desktop\GetThermal_for_SAGER
[1].CLEVO.KAPOK\winio.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WINIO]
"ImagePath"="\??\c:\documents and settings\C. Harris\Desktop\GetThermal_for_SAGER
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3740775528-3358379298-2972928916-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
@SACL=
[HKEY_USERS\S-1-5-21-3740775528-3358379298-2972928916-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a6,11,e5,54,e3,56,1f,51,48,57,d6,ec,34,d2,aa,b5,14,f2,ca,83,7e,a0,80,
f5,90,52,ad,c9,0a,10,31,32,12,51,91,19,77,ca,a9,25,98,12,b4,c4,4e,6c,f2,14,\
"??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1016)
c:\program files\AlienGUIse\fastload.dll
c:\program files\iolo\Common\Lib\sguard.dll
- - - - - - - > 'lsass.exe'(1072)
c:\program files\iolo\Common\Lib\sguard.dll
- - - - - - - > 'csrss.exe'(992)
c:\program files\iolo\Common\Lib\sguard.dll
.
Completion time: 2009-08-06 12:44
ComboFix-quarantined-files.txt 2009-08-06 19:44
ComboFix2.txt 2009-08-05 19:39
Pre-Run: 56,425,750,528 bytes free
Post-Run: 56,376,803,328 bytes free
206 --- E O F --- 2009-08-06 19:30