Hey,
ComboFix log
ComboFix 08-03-09.1 - Melissa 2008-03-09 12:36:22.5 - FAT32x86
Running from: C:\Documents and Settings\Melissa\Desktop\ComboFix.exe
- Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.
2008-03-07 10:07 . 2008-03-07 10:07 d-------- C:\Program Files\XoftSpySE
2008-03-06 22:38 . 2008-03-06 22:38 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-06 22:30 . 2008-03-06 22:30 d-------- C:\Program Files\MSECACHE
2008-03-04 08:42 . 2008-03-05 01:16 65,536 --ah----- C:\WINDOWS\MEMORY.DMP
2008-02-17 13:17 . 2008-02-17 13:17 303 --a------ C:\WINDOWS\ST6UNST.001
2008-02-17 13:15 . 2008-02-17 13:15 303 --a------ C:\WINDOWS\ST6UNST.000
2008-02-17 12:48 . 2008-02-17 12:48 d-------- C:\downloads
2008-02-16 02:02 . 2008-02-23 00:14 48 --a------ C:\WINDOWS.prj
2008-02-15 12:49 . 2008-02-15 12:49 d-------- C:\Documents and Settings\Melissa\Application Data\PKWARE
2008-02-15 12:49 . 2008-02-15 12:49 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PKWARE
2008-02-15 12:42 . 2008-02-15 12:42 d-------- C:\Program Files\PKWARE
2008-02-15 12:42 . 2008-02-15 12:42 d-------- C:\Program Files\Common Files\PKWARE
2008-02-15 12:39 . 2008-02-15 12:39 d-------- C:\WINDOWS\Downloaded Installations
2008-02-12 02:44 . 1998-06-18 00:00 102,912 --a------ C:\WINDOWS\system32\Vb6stkit.dll
2008-02-12 02:44 . 1999-05-15 00:24 97,280 --a------ C:\WINDOWS\system32\vspell32.ocx
2008-02-12 02:44 . 1997-02-24 17:44 70,656 --a------ C:\WINDOWS\system32\vspell32.dll
2008-02-12 02:44 . 2008-02-23 00:15 466 --a------ C:\WINDOWS\pagebreeze.ini
2008-02-12 02:44 . 2008-02-12 02:44 44 --a------ C:\WINDOWS\formbreeze.ini
2008-02-12 02:43 . 2008-02-12 02:43 d-------- C:\Program Files\PageBreeze
2008-02-12 02:43 . 2005-01-24 12:39 503,808 --a------ C:\WINDOWS\system32\ChilkatFTPx.dll
2008-02-12 02:43 . 1998-06-24 00:00 369,696 --a------ C:\WINDOWS\system32\Comct332.ocx
2008-02-12 02:43 . 1998-11-18 11:40 89,600 --a------ C:\WINDOWS\system32\Leocx32.ocx
2008-02-12 02:43 . 1998-11-22 14:23 84,992 --a------ C:\WINDOWS\system32\Ledit32.dll
2008-02-12 02:03 . 2008-02-12 02:03 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-12 02:03 . 2008-02-12 02:03 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 01:20 --------- d-sh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-08 01:18 --------- d-----w C:\Program Files\Windows Live
2008-02-08 01:16 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
2008-01-31 15:51 --------- d-----w C:\Program Files\Alwil Software
2008-01-31 08:42 --------- d-----w C:\Program Files\Java
2008-01-31 08:42 --------- d-----w C:\Program Files\Common Files\Java
2008-01-31 08:10 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
2008-01-31 06:31 --------- d-----w C:\Program Files\SpywareGuard
2008-01-31 06:22 --------- d-----w C:\Program Files\SpywareBlaster
2008-01-31 06:09 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-01-25 09:49 34,360 ----a-w C:\WINDOWS\system32\drivers\sbapifs.sys
2008-01-25 08:29 --------- d-----w C:\Documents and Settings\Melissa\Application Data\Sunbelt Software
2008-01-24 00:21 --------- d-----w C:\Documents and Settings\Melissa\Application Data\SpywareBot
2008-01-21 05:25 --------- d-----w C:\Documents and Settings\Melissa\Application Data\iWinArcade
2008-01-21 05:23 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin Games
2008-01-21 05:21 --------- d-----w C:\Program Files\Google
2008-01-20 06:23 --------- d-----w C:\Documents and Settings\Melissa\Application Data\Nvu
2008-01-18 04:41 --------- d-----w C:\Program Files\iPod
2008-01-18 04:40 --------- d-----w C:\Program Files\iTunes
2008-01-18 04:33 --------- d-----w C:\Program Files\QuickTime
2008-01-09 21:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2002-10-14 18:15 1,618 ----a-w C:\Program Files\EULA.txt
2002-10-05 05:42 5,841 ----a-w C:\Program Files\readme.txt
2002-01-18 03:45 86,588 ----a-w C:\Program Files\ssnetlib.dll
2002-01-18 03:45 29,244 ----a-w C:\Program Files\ssmslpcn.dll
2002-01-18 03:45 29,244 ----a-w C:\Program Files\dbmslpcn.dll
.
------- Sigcheck -------
2002-10-25 12:00 12800 0f7d9c87b0ce1fa520473119752c6f79 C:\WINDOWS\system32\svchost.exe
2002-10-25 12:00 12800 0f7d9c87b0ce1fa520473119752c6f79 C:\WINDOWS\system32\dllcache\svchost.exe
2004-08-04 01:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\svchost.exe
2002-10-25 12:00 12800 0f7d9c87b0ce1fa520473119752c6f79 C:\WINDOWS$NtServicePackUninstall$\svchost.exe
2006-06-23 11:33 575488 7e7760c7f263ec7a740ee265b263f770 C:\WINDOWS\system32\wininet.dll
2006-06-23 11:33 575488 7e7760c7f263ec7a740ee265b263f770 C:\WINDOWS\system32\dllcache\wininet.dll
2004-08-04 01:56 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\wininet.dll
2002-10-25 12:00 599040 f3587750a7481dccbea13d473a0700be C:\WINDOWS$NtUninstallKB918899-IE6SP1-20060725.123917$\wininet.dll
2006-06-23 11:33 575488 7e7760c7f263ec7a740ee265b263f770 C:\WINDOWS$NtServicePackUninstall$\wininet.dll
2002-10-25 12:00 516608 2246d8d8f4714a2cedb21ab9b1849abb C:\WINDOWS\system32\winlogon.exe
2002-10-25 12:00 516608 2246d8d8f4714a2cedb21ab9b1849abb C:\WINDOWS\system32\dllcache\winlogon.exe
2004-08-04 01:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\winlogon.exe
2002-10-25 12:00 516608 2246d8d8f4714a2cedb21ab9b1849abb C:\WINDOWS$NtServicePackUninstall$\winlogon.exe
2002-10-25 12:00 167552 3b350e5a2a5e951453f3993275a4523a C:\WINDOWS\system32\drivers\ndis.sys
2002-10-25 12:00 167552 3b350e5a2a5e951453f3993275a4523a C:\WINDOWS\system32\dllcache\ndis.sys
2004-08-04 00:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\ndis.sys
2002-10-25 12:00 167552 3b350e5a2a5e951453f3993275a4523a C:\WINDOWS$NtServicePackUninstall$\ndis.sys
2002-10-25 12:00 1004032 a82b28bfc2e4455fe43022a498c0ef0a C:\WINDOWS\explorer.exe
2002-10-25 12:00 1004032 a82b28bfc2e4455fe43022a498c0ef0a C:\WINDOWS\system32\dllcache\explorer.exe
2004-08-04 01:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\explorer.exe
2002-10-25 12:00 1004032 a82b28bfc2e4455fe43022a498c0ef0a C:\WINDOWS$NtServicePackUninstall$\explorer.exe
.
((((((((((((((((((((((((((((( snapshot_2008-03-07_19.48.05.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-25 15:25:54 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-03-09 17:45:16 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-01-25 15:25:54 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-03-09 17:45:16 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-01-25 15:25:54 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-09 17:45:16 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-09 18:17:52 27,536 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
- 2008-03-08 05:22:14 16,384 ----a-w C:\WINDOWS\TEMP\Perflib_Perfdata_504.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11 132496]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 07:00 79224]
C:\Documents and Settings\Melissa\Start Menu\Programs\Startup
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“UpdatesDisableNotify”=dword:00000001
“AntiVirusDisableNotify”=dword:00000001
“AntiVirusOverride”=dword:00000001
“FirewallOverride”=dword:00000001
R3 banshee;banshee;C:\WINDOWS\System32\DRIVERS\banshee.sys [2001-08-17 12:48]
R3 USR1801;U.S. Robotics Faxmodem Driver 1801;C:\WINDOWS\System32\DRIVERS\USR1801.SYS [2001-08-17 13:28]
R3 w89c940;Winbond W89C940 PCI Ethernet Adapter Driver;C:\WINDOWS\System32\DRIVERS\w940nd.sys [2001-08-17 12:13]
S4 MSControlService;Microsoft cache control;C:\WINDOWS\System32\windows
.
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-09 12:39:51
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0