QUOTE(HKEd @ Apr 21 2008, 07:01 PM)

Hi Trogg...can you please rename HijackCheck.exe to Hcheck.exe. Some malware can hide from HijackThis if Hijack is in the file name.
Follow the instructions
here to use ComboFix. When done, post the ComboFix log (C:\Combofix.txt).
Hi Thanks
I used Combofix - bit scarey!!
Here is the log
ComboFix 08-04-20.5 - Derek 2008-04-22 19:54:56.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1485 [GMT 1:00]
Running from: C:\Documents and Settings\Derek\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Derek\Desktop\WinXP_EN_PRO_BF.EXE
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Derek\ResErrors.log
C:\Program Files\NetProject
C:\Program Files\NetProject\sbmdl.dll
C:\Program Files\NetProject\sbmntr.exe
C:\Program Files\NetProject\sbsm.exe
C:\Program Files\NetProject\scit.exe
C:\WINDOWS\search_res.txt
C:\WINDOWS\winhelp.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DHLP
((((((((((((((((((((((((( Files Created from 2008-03-22 to 2008-04-22 )))))))))))))))))))))))))))))))
.
2008-04-21 22:43 . 2008-04-22 20:02 <DIR> d-------- C:\VEXPLITE
2008-04-21 22:43 . 2008-03-17 19:23 39,808 --a------ C:\WINDOWS\system32\drivers\VIRAGTLT.SYS
2008-04-21 11:18 . 2008-04-21 15:31 <DIR> d-------- C:\Program Files\HiJackNew
2008-04-21 08:51 . 2008-04-21 08:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-21 07:58 . 2008-04-21 08:00 <DIR> d-------- C:\hijackthis
2008-04-21 07:49 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-04-21 07:49 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-04-21 07:46 . 2008-04-21 07:46 268 --ah----- C:\sqmdata19.sqm
2008-04-21 07:46 . 2008-04-21 07:46 244 --ah----- C:\sqmnoopt19.sqm
2008-04-20 22:26 . 2008-04-20 22:41 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-04-20 22:25 . 2008-04-20 22:26 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-20 18:00 . 2008-04-20 18:00 268 --ah----- C:\sqmdata18.sqm
2008-04-20 18:00 . 2008-04-20 18:00 244 --ah----- C:\sqmnoopt18.sqm
2008-04-20 17:40 . 2008-04-20 17:40 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-20 17:31 . 2008-04-20 22:44 <DIR> d-------- C:\Program Files\NoAdware5.0
2008-04-20 17:24 . 2008-04-20 17:24 35 --a------ C:\WINDOWS\system\cmicnfg.ini
2008-04-20 16:49 . 2008-04-20 16:49 268 --ah----- C:\sqmdata17.sqm
2008-04-20 16:49 . 2008-04-20 16:49 244 --ah----- C:\sqmnoopt17.sqm
2008-04-20 16:41 . 2008-04-20 16:41 <DIR> d--hs---- C:\WinSpyControl
2008-04-20 16:41 . 2008-04-20 16:41 <DIR> d-------- C:\Documents and Settings\Derek\Application Data\WinSpyControl
2008-04-20 16:41 . 2008-04-20 16:41 <DIR> dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
2008-04-20 10:18 . 2008-04-20 10:18 268 --ah----- C:\sqmdata16.sqm
2008-04-20 10:18 . 2008-04-20 10:18 244 --ah----- C:\sqmnoopt16.sqm
2008-04-20 09:52 . 2008-04-20 09:52 <DIR> d-------- C:\Program Files\InterMute
2008-04-20 09:44 . 2008-04-20 09:44 268 --ah----- C:\sqmdata15.sqm
2008-04-20 09:44 . 2008-04-20 09:44 244 --ah----- C:\sqmnoopt15.sqm
2008-04-20 09:39 . 2008-04-20 09:39 <DIR> d-------- C:\WINDOWS\system32\892267
2008-04-20 09:38 . 2008-04-20 09:38 268 --ah----- C:\sqmdata14.sqm
2008-04-20 09:38 . 2008-04-20 09:38 244 --ah----- C:\sqmnoopt14.sqm
2008-04-11 16:40 . 2008-04-11 17:58 <DIR> d-------- C:\Program Files\livetvbar
2008-04-11 16:40 . 2008-04-13 22:30 <DIR> d-------- C:\Program Files\Conduit
2008-04-11 16:39 . 2008-04-11 16:40 <DIR> d-------- C:\Program Files\3B Software
2008-04-03 13:54 . 2008-04-03 13:54 <DIR> d-------- C:\sr
2008-03-31 23:01 . 2008-03-31 23:01 268 --ah----- C:\sqmdata13.sqm
2008-03-31 23:01 . 2008-03-31 23:01 244 --ah----- C:\sqmnoopt13.sqm
2008-03-30 13:02 . 2008-03-30 13:02 <DIR> d-------- C:\Program Files\Common Files\xing shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-21 14:39 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kontiki
2008-04-21 09:25 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-21 07:53 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-04-20 15:40 --------- d-----w C:\Documents and Settings\Derek\Application Data\Warez
2008-04-16 14:52 --------- d-----w C:\Documents and Settings\Derek\Application Data\Poser 7
2008-04-03 17:07 --------- d-----w C:\Documents and Settings\Derek\Application Data\Serif
2008-04-03 11:15 --------- d-----w C:\Program Files\Serif
2008-04-01 07:03 --------- d-----w C:\Program Files\Google
2008-03-30 12:02 --------- d-----w C:\Program Files\Common Files\Real
2008-03-25 16:19 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-17 21:20 --------- d-----w C:\Documents and Settings\Derek\Application Data\MSN6
2008-03-17 13:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-17 13:26 --------- d-----w C:\Program Files\D-Link
2008-03-16 17:35 1,434,161 ----a-w C:\f5d7632-4av1_uk_1.00.09.bin
2008-02-29 16:30 --------- d-----w C:\Documents and Settings\Derek\Application Data\MayaWebBrowser
2008-02-28 19:16 --------- d-----w C:\Program Files\iTunes
2008-02-28 19:16 --------- d-----w C:\Program Files\iPod
2008-02-28 19:15 --------- d-----w C:\Program Files\QuickTime
2007-12-13 10:38 108,424 ----a-w C:\Documents and Settings\Derek\Application Data\GDIPFONTCACHEV1.DAT
2007-03-27 14:55 3,735,552 ----a-w C:\Program Files\c4dxl720.w08
2005-02-25 12:07 6,156 ----a-w C:\Program Files\Readme_IN-MaleReviewSeriesOne.txt
2001-10-04 01:22 5,120,000 ----a-w C:\Program Files\c4dxl720.w10
2001-10-04 01:22 5,120,000 ----a-w C:\Program Files\c4dxl720.w05
2001-10-04 01:22 5,120,000 ----a-w C:\Program Files\c4dxl720.exe
2001-10-04 01:21 5,120,000 ----a-w C:\Program Files\c4dxl720.w06
2001-10-04 01:21 5,120,000 ----a-w C:\Program Files\c4dxl720.w03
2001-10-04 01:21 5,120,000 ----a-w C:\Program Files\c4dxl720.w02
2001-10-04 01:20 5,120,000 ----a-w C:\Program Files\c4dxl720.w07
2001-10-04 01:20 5,120,000 ----a-w C:\Program Files\c4dxl720.w04
2001-01-21 00:51 2,990 ----a-w C:\Program Files\license.txt
2007-10-03 18:27 88 --sh--r C:\WINDOWS\system32\C5FDA7815F.sys
.
------- Sigcheck -------
2002-08-29 13:00 12800 0f7d9c87b0ce1fa520473119752c6f79 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2004-08-04 08:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2004-08-04 08:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
2005-03-02 19:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$hf_mig$\KB890859\SP2GDR\user32.dll
2005-03-02 19:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 16:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2005-03-02 19:20 561152 74202eb1bd67e8be9509e38c8d2234b0 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2004-08-04 08:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2002-08-29 13:00 560128 dd9269230c21ee8fb7fd3fccc3b1cfcb C:\WINDOWS\$NtUninstallKB890859_0$\user32.dll
2005-03-02 19:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2004-08-04 08:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\ServicePackFiles\i386\user32.dll
2007-03-08 16:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\user32.dll
2007-03-08 16:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\dllcache\user32.dll
2006-08-16 13:14 70656 7b6a08441a4f11320421599d7ecf8d41 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
2002-08-29 13:00 75264 8529c295df59b564d37a73b5629162b1 C:\WINDOWS\$NtUninstallKB914388_0$\ws2_32.dll
2006-05-19 13:15 70656 3748e0fc8c1b6ada49f98c8e69a4228c C:\WINDOWS\$NtUninstallKB922819_0$\ws2_32.dll
2004-08-04 08:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
2004-08-04 08:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2002-08-29 13:00 516608 2246d8d8f4714a2cedb21ab9b1849abb C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2004-08-04 08:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2004-08-04 08:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2002-08-29 13:00 167552 3b350e5a2a5e951453f3993275a4523a C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
2004-08-04 07:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\ServicePackFiles\i386\ndis.sys
2004-08-04 07:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 07:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2004-08-04 07:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-02 01:34 2056832 81013f36b21c7f72cf784cc6731e0002 C:\WINDOWS\$hf_mig$\KB890859\SP2GDR\ntkrnlpa.exe
2005-03-02 01:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 17:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 10:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2005-03-02 01:36 1955840 62c353c0449fd961ef7814973fc2fd30 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-04 06:58 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2002-08-29 13:00 1947904 0e8efb15746878a9b256e75267337233 C:\WINDOWS\$NtUninstallKB890859_0$\ntkrnlpa.exe
2005-03-02 01:34 2056832 81013f36b21c7f72cf784cc6731e0002 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 13:55 2057600 1d659bfb788ed2ba45075624b748d249 C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 09:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2004-08-04 06:58 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2007-02-28 09:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 09:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2005-03-02 01:59 2179328 4d4cf2c14550a4b7718e94a6e581856e C:\WINDOWS\$hf_mig$\KB890859\SP2GDR\ntoskrnl.exe
2005-03-02 02:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 17:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 10:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2005-03-02 02:33 2040832 a15a2ee0be2f71fc1752a05660b8ebdc C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-04 07:19 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2002-08-29 13:00 2042240 b9080d97dbd631aadf9128f7316958d2 C:\WINDOWS\$NtUninstallKB890859_0$\ntoskrnl.exe
2005-03-02 01:59 2179328 4d4cf2c14550a4b7718e94a6e581856e C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 15:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 10:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2004-08-04 07:19 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2007-02-28 10:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 10:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2007-06-13 11:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\explorer.exe
2007-06-13 12:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2002-08-29 13:00 1004032 a82b28bfc2e4455fe43022a498c0ef0a C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 08:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2004-08-04 08:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2007-06-13 11:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\system32\dllcache\explorer.exe
2002-08-29 13:00 13312 414de7cf9d3f19c3ea902f1bb38ec116 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2004-08-04 08:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2004-08-04 08:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"NvMediaCenter"="C:\WINDOWS\System32\NVMCTRAY.DLL" [2003-10-06 16:16 49152]
"RAMrocket"="C:\Program Files\Ascentive\RAMrocket2007\RAMrocket.exe" [2006-12-13 20:45 1122304]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 17:13 1207080]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:54 5674352]
"1&1 EasyLogin"="C:\Program Files\1&1\1&1 EasyLogin\EasyLogin.exe" [2008-01-24 13:32 1545216]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"Easy-PrintToolBox"="C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.exe" [2004-01-14 02:10 409600]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe" [2004-04-06 11:28 172032]
"HPHUPD06"="C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 05:53 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 15:54 241664]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 05:42 659456]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"Acronis True Image Monitor"="C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe" [2007-04-16 18:49 419408]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-04-16 18:49 69632]
"FLMOFFICE4DMOUSE"="C:\Program Files\Belkin Office Keyboard\moffice.exe" [2007-06-11 18:28 958464]
"OFFICEKB"="C:\Program Files\Belkin Office Keyboard\kbdap32a.exe" [2007-06-11 18:28 385024]
"FLMK08KB"="C:\Program Files\Belkin Keyboard\KbdAp32A.exe" [2007-06-11 18:42 385024]
"Corel Photo Downloader"="C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe" [ ]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 12:23 1032640]
"Corel File Shell Monitor"="C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2007-10-30 20:52 16200]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-30 13:01 185896]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-10-06 16:16 5058560]
"VIRIT LITE MONITOR"="C:\VEXPLITE\MONLITE.EXE" [2008-03-20 19:31 245760]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\digital imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\digital imaging\bin\hpqthb08.exe [2006-02-10 07:56:20 73728]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
TabUserW.exe.lnk - C:\WINDOWS\system32\Wtablet\TabUserW.exe [2003-12-04 17:48:40 77824]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{db763ed8-100a-481b-8913-50a2f41dcdc3}"= C:\WINDOWS\system32\bubbj.dll [2008-04-18 13:02 13312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
"VIDC.TR20"= tr2032.dll
"vidc.vivo"= ivvideo.dll
"SENTINEL"= snti386.dll
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.mpegacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ahead\\ODD Toolkit\\ODDUpdate.exe"=
"C:\\Program Files\\HP\\digital imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\DEREk OLD G\\WSFTP\\WS_FTP95.EXE"=
"C:\\Program Files\\e frontier\\Poser 7\\Poser.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\kdx\\KHost.exe"=
"C:\\WINDOWS\\system32\\spoolsv.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Right Hemisphere\\Deep Paint 3D\\Deep3D.exe"=
"C:\\Program Files\\Right Hemisphere\\Deep UV\\DeepUV.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\C4D Studio Bundle v9.012\\C4D Client.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"F:\\Program Files\\Warez\\Warez.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 PenClass;Pen Class;C:\WINDOWS\system32\Drivers\penclass.sys [2001-04-09 14:45]
R0 VIRAGTLT;VIRAGTLT;C:\WINDOWS\system32\drivers\VIRAGTLT.SYS [2008-03-17 19:23]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 18:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 18:35]
R2 viritsvclite;Virit eXplorer Lite;C:\VEXPLITE\viritsvc.exe [2007-10-10 12:12]
R3 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\moufiltr.sys [2007-06-11 18:28]
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 07:01]
S2 gafwload;D-Link DSL-200 USB ADSL Loader;C:\WINDOWS\system32\DRIVERS\gafwload.sys [2002-03-22 11:01]
S3 USBAV191;Instant VideoXpress;C:\WINDOWS\system32\DRIVERS\USBAV191.SYS [2005-04-28 06:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##Server#server#SIS - Word Docs]
\Shell\AutoRun\command - POWERPNT.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\LaunchU3.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-16 19:56:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-21 10:50:00 C:\WINDOWS\Tasks\Backup.job"
- C:\WINDOWS\system32\ntbackup.exe“backup
"2008-04-21 13:00:00 C:\WINDOWS\Tasks\body a j.job"
- C:\WINDOWS\system32\ntbackup.exeybackup
"2008-04-22 19:04:01 C:\WINDOWS\Tasks\HP Usg Daily FY04.job"
- C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe
"2007-05-25 13:10:00 C:\WINDOWS\Tasks\sis bosy l to j.job"
- C:\WINDOWS\system32\ntbackup.execbackup
"2008-04-22 18:39:00 C:\WINDOWS\Tasks\sis.job"
- C:\WINDOWS\system32\ntbackup.exe¡backup
"2008-04-22 18:44:00 C:\WINDOWS\Tasks\SIS1.job"
- C:\WINDOWS\system32\ntbackup.exedbackup
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-22 20:01:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\defragActivityMonitor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Belkin Office Keyboard\mouse32a.dat
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\digital imaging\bin\hpqimzone.exe
C:\Program Files\HP\digital imaging\bin\hpqnrs08.exe
C:\Program Files\HP\digital imaging\bin\hpqste08.exe
C:\WINDOWS\system32\HPZipm12.exe
.
**************************************************************************
.
Completion time: 2008-04-22 20:09:59 - machine was rebooted [Derek]
ComboFix-quarantined-files.txt 2008-04-22 19:08:52
Pre-Run: 157,070,843,904 bytes free
Post-Run: 157,467,893,760 bytes free
WinXP_EN_PRO_BF.EXE
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
309 --- E O F --- 2008-04-21 16:44:47