I will do all that you said on your last post. Here is the results of the last Combofix you asked me to run. I’m going to runn DSS then go through your list of things to do from your last post.
ComboFix 08-01-09.2 - Sandy Rudy 2008-01-08 20:00:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1571 [GMT -7:00]
Running from: C:\Install\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-09 to 2008-01-09 )))))))))))))))))))))))))))))))
.
2008-01-08 19:14 . 2008-01-08 19:14 d-------- C:\Deckard
2008-01-08 18:05 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-07 22:07 . 2008-01-07 22:07 2,126 --a------ C:\WINDOWS\system32\wpa.dbl
2008-01-07 19:07 . 2008-01-07 22:48 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-01 16:29 . 2008-01-01 16:29 d-------- C:\VundoFix Backups
2007-12-28 20:53 . 2008-01-01 19:54 356,352 --a------ C:\Documents and Settings\Sandy Rudy\cwshredder.dll
2007-12-26 20:22 . 2005-09-15 03:15 860,160 -ra------ C:\WINDOWS\system32\mcs_dec2.ax
2007-12-26 20:22 . 2005-08-22 04:11 700,416 -ra------ C:\WINDOWS\system32\mcs_cor1.dll
2007-12-26 20:22 . 2005-11-08 22:05 282,624 -ra------ C:\WINDOWS\Uninstall.exe
2007-12-26 20:22 . 2005-09-15 01:16 249,856 -ra------ C:\WINDOWS\system32\mcs_cor2.dll
2007-12-26 20:22 . 2005-08-22 04:12 147,456 -ra------ C:\WINDOWS\system32\mcs_vfw.dll
2007-12-26 20:22 . 2005-11-03 16:29 72,832 -ra------ C:\WINDOWS\system32\drivers\CamAvb.sys
2007-12-26 20:22 . 2005-12-16 01:53 58,624 -ra------ C:\WINDOWS\system32\drivers\CamAv.sys
2007-12-26 20:22 . 2004-12-28 03:19 57,344 -ra------ C:\WINDOWS\HAJEInstall.dll
2007-12-26 20:22 . 2005-07-19 17:23 11,648 -ra------ C:\WINDOWS\system32\drivers\CamFlt.sys
2007-12-26 20:22 . 2005-08-22 04:13 4,385 -ra------ C:\WINDOWS\system32\install.inf
2007-12-23 17:32 . 2007-12-23 17:32 d-------- C:\Program Files\InterMute
2007-12-23 17:32 . 2007-12-23 17:32 2,158 --a------ C:\WINDOWS\system32\ssmute.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 02:17 --------- d-----w C:\Program Files\Trend Micro
2007-12-27 03:24 --------- d-----w C:\Program Files\QuickTime
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-30 04:42 --------- d-----w C:\Program Files\MySpace
2007-11-30 04:42 --------- d-----w C:\Documents and Settings\Sandy Rudy\Application Data\MySpace
2007-11-14 07:26 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-13 03:35 --------- d-----w C:\Program Files\Dl_cats
2007-10-30 09:55 3,065,856 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:35 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 00:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 00:40 222,720 ------w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 05:57 96,256 ------w C:\WINDOWS\system32\dllcache\inseng.dll
2007-10-11 05:57 666,112 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-11 05:57 617,984 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-11 05:57 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-11 05:57 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-11 05:57 474,112 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-10-11 05:57 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-11 05:57 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-10-11 05:57 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-10-11 05:57 251,904 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-10-11 05:57 205,824 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-11 05:57 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-11 05:57 151,040 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-10-11 05:57 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-11 05:57 1,498,112 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-10-11 05:57 1,054,208 ------w C:\WINDOWS\system32\dllcache\danim.dll
2007-10-11 05:57 1,024,000 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2007-10-10 10:48 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2005-11-03 23:29 72,832 ----a-r C:\WINDOWS\inf\CamAvb.sys
2007-01-09 02:02 88 --sh–r C:\WINDOWS\system32\BB92974E4C.sys
2007-01-09 02:03 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-01-08_18.13.31.62 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-09 02:43:02 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_2b8.dat
- 2008-01-09 02:42:54 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_7dc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ModemOnHold”=“C:\Program Files\NetWaiting\netWaiting.exe” [2003-09-10 01:24 20480]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-10 04:00 15360]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 09:24 1694208]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-08-14 15:31 68856]
“SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe” [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ehTray”=“C:\WINDOWS\ehome\ehtray.exe” [2005-09-29 13:01 67584]
“igfxtray”=“C:\WINDOWS\system32\igfxtray.exe” [2005-12-13 22:44 98304]
“igfxhkcmd”=“C:\WINDOWS\system32\hkcmd.exe” [2005-12-13 22:41 77824]
“igfxpers”=“C:\WINDOWS\system32\igfxpers.exe” [2005-12-13 22:45 118784]
“IntelZeroConfig”=“C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe” [2006-05-01 08:28 667718]
“IntelWireless”=“C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” [2006-05-01 08:28 602182]
“SigmatelSysTrayApp”=“stsystra.exe” [2006-03-24 22:30 282624 C:\WINDOWS\stsystra.exe]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2006-03-08 17:48 761947]
“dla”=“C:\WINDOWS\system32\dla\tfswctrl.exe” [2004-12-06 00:05 127035]
“ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe” [2004-07-27 15:50 221184]
“ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [2004-07-27 15:50 81920]
“Google Desktop Search”=“C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” [2007-01-01 08:05 236544]
“PCMService”=“C:\Program Files\Dell\MediaDirect\PCMService.exe” [2006-08-22 14:32 184320]
“Device Detector”=“DevDetect.exe”
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-01-01 08:03 98304]
“dlcimon.exe”=“C:\Program Files\Dell AIO Printer 946\dlcimon.exe” [2006-02-14 02:26 430080]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [2001-07-09 10:50 155648]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 06:00 79224]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 21:07:32]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\SpySub.exe [2007-12-23 17:32:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“InstallVisualStyle”= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
“InstallTheme”= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{FA010552-4A27-4cb1-A1BB-3E2D697F1639}”= c:\Program Files\InterMute\SpySubtract\sshook.dll [2007-12-23 17:32 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
R3 dlci_device;dlci_device;C:\WINDOWS\system32\dlcicoms.exe [2006-05-11 14:22]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-08 20:02:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
.
Completion time: 2008-01-08 20:03:29
ComboFix-quarantined-files.txt 2008-01-09 03:03:20
ComboFix2.txt 2008-01-09 01:13:46