Thanks so much for helping me o ut. I think I did everything I was supposed to. Here's my logs.
ComboFix 07-08-30.3 - "Owner" 2007-09-04 20:18:15.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.123 [GMT -7:00]
((((((((((((((((((((((((( Files Created from 2007-08-05 to 2007-09-05 )))))))))))))))))))))))))))))))
2007-09-04 19:58 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-09-04 00:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-09-03 22:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion 2007-09-03 21:48 <DIR> d-------- C:\Program Files\CCleaner 2007-08-06 18:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games 2007-08-05 13:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-03 22:53 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\PlayFirst 2007-09-03 22:53 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst 2007-09-03 22:51 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Sandlot Games 2007-09-03 22:51 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games 2007-09-01 19:07 --------- d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP 2007-09-01 00:19 55592 --a------ C:\WINDOWS\system32\adssite-remove.exe 2007-08-14 21:17 --------- d-------- C:\Program Files\iPod 2007-08-13 22:38 --------- d-------- C:\Program Files\iTunes 2007-08-06 00:08 --------- d-------- C:\Program Files\Enigma Software Group 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll 2007-07-27 07:39 33511 --a------ C:\WINDOWS\system32\ninjaext-uninstall.exe 2007-07-24 19:47 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Google 2007-07-24 02:04 --------- d-------- C:\Program Files\Google 2007-07-23 21:28 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\SpinTop 2007-07-23 20:02 774144 --a------ C:\Program Files\RngInterstitial.dll 2007-07-23 20:02 --------- d-------- C:\Program Files\Real 2007-07-23 20:02 --------- d-------- C:\Program Files\Common Files\Real 2007-07-23 07:06 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google 2007-07-23 06:57 38232 --------- C:\WINDOWS\system32\imjbrd.dll 2007-07-23 06:54 39884 --a------ C:\WINDOWS\system32\gzmrot-uninst.exe 2007-07-22 21:31 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games 2007-07-19 21:38 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Gamelab 2007-07-17 20:00 --------- d-------- C:\Program Files\QuickTime 2007-07-13 07:46 61440 --a------ C:\WINDOWS\system32\gzmrotate.dll 2007-07-10 00:40 --------- d-------- C:\Program Files\Common Files\Apple 2007-07-10 00:40 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple 2007-06-25 23:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll 2007-06-19 06:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll 2007-06-13 03:23 1033216 --a------ C:\WINDOWS\explorer.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{36A91CEC-6C71-4758-B492-397BFC8E96A2}] 2007-07-13 07:46 61440 --a------ C:\WINDOWS\system32\gzmrotate.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64badabb-4464-451e-846d-5448ecda3859}] 2007-07-23 06:57 38232 --------- C:\WINDOWS\system32\imjbrd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E4283631-646D-48C3-BAC2-70E28BBC77D0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
C:\DOCUME~1\Owner\STARTM~1\Programs\Startup\ LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2006-02-16 14:55:37]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\°À] °À
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\imjbrd] imjbrd.dll 2007-07-23 06:57 38232 C:\WINDOWS\system32\imjbrd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=c:\windows\system32\ddabbxx.dll
[color=red]SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] @="Service"
R0 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys R1 ICsrvr;VPN Client Protocol;C:\WINDOWS\system32\DRIVERS\ICsrvr.sys R1 ICtdi;VPN Client TDI Driver;C:\WINDOWS\system32\DRIVERS\ictdi.sys R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys R3 ICvnic;VPN Client Virtual Adapter;C:\WINDOWS\system32\DRIVERS\ICvnic.sys R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS S2 ICService;VPN Client;C:\Program Files\VPN\VPN Client\icsrv.exe S3 CCCP106;D-Link CIF Webcam;C:\WINDOWS\system32\DRIVERS\cccp106.sys S3 ed3d0121-a0b8-4cb9-8f10-e00414d97307;ed3d0121-a0b8-4cb9-8f10-e00414d97307;\??\D:\CDS300\cds300.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D] AutoRun\command- D:\Install.exe
Contents of the 'Scheduled Tasks' folder 2007-09-04 05:28:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe 2007-09-05 03:10:12 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-09-04 20:21:42 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
**************************************************************************
Completion time: 2007-09-04 20:23:04 C:\ComboFix-quarantined-files.txt ... 2007-09-04 20:23 C:\ComboFix2.txt ... 2007-09-04 20:11
--- E O F ---
ComboFix 07-08-30.3 - "Owner" 2007-09-04 20:18:15.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.123 [GMT -7:00]
((((((((((((((((((((((((( Files Created from 2007-08-05 to 2007-09-05 )))))))))))))))))))))))))))))))
2007-09-04 19:58 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-09-04 00:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-09-03 22:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion 2007-09-03 21:48 <DIR> d-------- C:\Program Files\CCleaner 2007-08-06 18:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games 2007-08-05 13:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-03 22:53 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\PlayFirst 2007-09-03 22:53 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst 2007-09-03 22:51 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Sandlot Games 2007-09-03 22:51 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games 2007-09-01 19:07 --------- d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP 2007-09-01 00:19 55592 --a------ C:\WINDOWS\system32\adssite-remove.exe 2007-08-14 21:17 --------- d-------- C:\Program Files\iPod 2007-08-13 22:38 --------- d-------- C:\Program Files\iTunes 2007-08-06 00:08 --------- d-------- C:\Program Files\Enigma Software Group 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll 2007-07-27 07:39 33511 --a------ C:\WINDOWS\system32\ninjaext-uninstall.exe 2007-07-24 19:47 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Google 2007-07-24 02:04 --------- d-------- C:\Program Files\Google 2007-07-23 21:28 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\SpinTop 2007-07-23 20:02 774144 --a------ C:\Program Files\RngInterstitial.dll 2007-07-23 20:02 --------- d-------- C:\Program Files\Real 2007-07-23 20:02 --------- d-------- C:\Program Files\Common Files\Real 2007-07-23 07:06 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google 2007-07-23 06:57 38232 --------- C:\WINDOWS\system32\imjbrd.dll 2007-07-23 06:54 39884 --a------ C:\WINDOWS\system32\gzmrot-uninst.exe 2007-07-22 21:31 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games 2007-07-19 21:38 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Gamelab 2007-07-17 20:00 --------- d-------- C:\Program Files\QuickTime 2007-07-13 07:46 61440 --a------ C:\WINDOWS\system32\gzmrotate.dll 2007-07-10 00:40 --------- d-------- C:\Program Files\Common Files\Apple 2007-07-10 00:40 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple 2007-06-25 23:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll 2007-06-19 06:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll 2007-06-13 03:23 1033216 --a------ C:\WINDOWS\explorer.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{36A91CEC-6C71-4758-B492-397BFC8E96A2}] 2007-07-13 07:46 61440 --a------ C:\WINDOWS\system32\gzmrotate.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64badabb-4464-451e-846d-5448ecda3859}] 2007-07-23 06:57 38232 --------- C:\WINDOWS\system32\imjbrd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E4283631-646D-48C3-BAC2-70E28BBC77D0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
C:\DOCUME~1\Owner\STARTM~1\Programs\Startup\ LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2006-02-16 14:55:37]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\°À] °À
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\imjbrd] imjbrd.dll 2007-07-23 06:57 38232 C:\WINDOWS\system32\imjbrd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=c:\windows\system32\ddabbxx.dll
[color=red]SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] @="Service"
R0 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys R1 ICsrvr;VPN Client Protocol;C:\WINDOWS\system32\DRIVERS\ICsrvr.sys R1 ICtdi;VPN Client TDI Driver;C:\WINDOWS\system32\DRIVERS\ictdi.sys R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys R3 ICvnic;VPN Client Virtual Adapter;C:\WINDOWS\system32\DRIVERS\ICvnic.sys R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS S2 ICService;VPN Client;C:\Program Files\VPN\VPN Client\icsrv.exe S3 CCCP106;D-Link CIF Webcam;C:\WINDOWS\system32\DRIVERS\cccp106.sys S3 ed3d0121-a0b8-4cb9-8f10-e00414d97307;ed3d0121-a0b8-4cb9-8f10-e00414d97307;\??\D:\CDS300\cds300.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D] AutoRun\command- D:\Install.exe
Contents of the 'Scheduled Tasks' folder 2007-09-04 05:28:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe 2007-09-05 03:10:12 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-09-04 20:21:42 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
**************************************************************************
Completion time: 2007-09-04 20:23:04 C:\ComboFix-quarantined-files.txt ... 2007-09-04 20:23 C:\ComboFix2.txt ... 2007-09-04 20:11
--- E O F ---
********************************* ROOTCHK-(22-08-07)-LOG, by ejvindh Tue 09/04/2007 20:15:41.73
The rootkits that are detected by this tool were not found.
********************************* ROOTCHK-LOG-end
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-09-04 20:15:42 Windows 5.1.2600 Service Pack 2 scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
hidden processes: 0 hidden files: 0
ComboFix 07-08-30.3 - "Owner" 2007-09-04 19:59:30.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.119 [GMT -7:00] * Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Owner\APPLIC~1\tmp1.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp107.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp109.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp113.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp115.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp11D.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp139.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp13E.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp161.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp167.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp16F.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp174.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp1A3.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp1AF.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp1E0.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp1E7.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp2.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp2A8.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp2AF.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp2CD.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp2D4.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp3.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp311.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp315.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp347.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp34F.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp3AE.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp3D5.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp3E4.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp3FA.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp4.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp42A.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp476.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp498.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp4AE.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp4B4.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp4C0.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp4EB.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp4F0.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp5.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp500.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp543.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp555.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp5DB.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp5FD.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp6.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp60F.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp637.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp66F.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp73.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp75.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp7A.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp7B0.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp7C.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp7F.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp84.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp86.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp94.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmp9E.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpA.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpA4.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpA6.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpA7.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpA8.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpAF.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpB1.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpB4.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpCC.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpE0.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpF.tmp.exe C:\DOCUME~1\Owner\APPLIC~1\tmpF1.tmp.exe C:\DOCUME~1\Owner\STARTM~1\Programs\Startup.\TA_Start.lnk C:\DOCUME~1\Owner\STARTM~1\Programs\Startup\ta_start.lnk C:\WINDOWS\system32\install.exe C:\WINDOWS\system32\msnav32.ax C:\WINDOWS\system32\nsd208.dll C:\WINDOWS\system32\tmp1.tmp.dll C:\WINDOWS\system32\tmp109.tmp.dll C:\WINDOWS\system32\tmp115.tmp.dll C:\WINDOWS\system32\tmp122.tmp.dll C:\WINDOWS\system32\tmp13E.tmp.dll C:\WINDOWS\system32\tmp167.tmp.dll C:\WINDOWS\system32\tmp174.tmp.dll C:\WINDOWS\system32\tmp1AF.tmp.dll C:\WINDOWS\system32\tmp1E7.tmp.dll C:\WINDOWS\system32\tmp2AF.tmp.dll C:\WINDOWS\system32\tmp2D4.tmp.dll C:\WINDOWS\system32\tmp315.tmp.dll C:\WINDOWS\system32\tmp34F.tmp.dll C:\WINDOWS\system32\tmp3B3.tmp.dll C:\WINDOWS\system32\tmp3D9.tmp.dll C:\WINDOWS\system32\tmp3E7.tmp.dll C:\WINDOWS\system32\tmp3FF.tmp.dll C:\WINDOWS\system32\tmp4.tmp.dll C:\WINDOWS\system32\tmp432.tmp.dll C:\WINDOWS\system32\tmp47E.tmp.dll C:\WINDOWS\system32\tmp49A.tmp.dll C:\WINDOWS\system32\tmp4B0.tmp.dll C:\WINDOWS\system32\tmp4BB.tmp.dll C:\WINDOWS\system32\tmp4C1.tmp.dll C:\WINDOWS\system32\tmp4EC.tmp.dll C:\WINDOWS\system32\tmp4EE.tmp.dll C:\WINDOWS\system32\tmp4F4.tmp.dll C:\WINDOWS\system32\tmp5.tmp.dll C:\WINDOWS\system32\tmp503.tmp.dll C:\WINDOWS\system32\tmp545.tmp.dll C:\WINDOWS\system32\tmp557.tmp.dll C:\WINDOWS\system32\tmp5DE.tmp.dll C:\WINDOWS\system32\tmp5FF.tmp.dll C:\WINDOWS\system32\tmp612.tmp.dll C:\WINDOWS\system32\tmp63A.tmp.dll C:\WINDOWS\system32\tmp671.tmp.dll C:\WINDOWS\system32\tmp75.tmp.dll C:\WINDOWS\system32\tmp7A.tmp.dll C:\WINDOWS\system32\tmp7B2.tmp.dll C:\WINDOWS\system32\tmp96.tmp.dll C:\WINDOWS\system32\tmp9E.tmp.dll C:\WINDOWS\system32\tmpA4.tmp.dll C:\WINDOWS\system32\tmpAF.tmp.dll C:\WINDOWS\system32\tmpB1.tmp.dll C:\WINDOWS\system32\tmpB4.tmp.dll C:\WINDOWS\system32\tmpE0.tmp.dll C:\WINDOWS\system32\tmpF.tmp.dll C:\WINDOWS\system32\winpfz32.sys C:\WINDOWS\system32\xpdx.sys C:\WINDOWS\system32\zxdnt3d.cfg
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE -------\DomainService -------\xpdx
((((((((((((((((((((((((( Files Created from 2007-08-05 to 2007-09-05 )))))))))))))))))))))))))))))))
2007-09-04 19:58 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-09-04 00:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-09-03 22:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion 2007-09-03 21:48 <DIR> d-------- C:\Program Files\CCleaner 2007-08-06 18:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SpinTop Games 2007-08-05 13:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-03 22:53 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\PlayFirst 2007-09-03 22:53 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst 2007-09-03 22:51 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Sandlot Games 2007-09-03 22:51 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games 2007-09-01 19:07 --------- d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP 2007-09-01 00:19 55592 --a------ C:\WINDOWS\system32\adssite-remove.exe 2007-08-14 21:17 --------- d-------- C:\Program Files\iPod 2007-08-13 22:38 --------- d-------- C:\Program Files\iTunes 2007-08-06 00:08 --------- d-------- C:\Program Files\Enigma Software Group 2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll 2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll 2007-07-27 07:39 33511 --a------ C:\WINDOWS\system32\ninjaext-uninstall.exe 2007-07-24 19:47 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Google 2007-07-24 02:04 --------- d-------- C:\Program Files\Google 2007-07-23 21:28 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\SpinTop 2007-07-23 20:02 774144 --a------ C:\Program Files\RngInterstitial.dll 2007-07-23 20:02 --------- d-------- C:\Program Files\Real 2007-07-23 20:02 --------- d-------- C:\Program Files\Common Files\Real 2007-07-23 07:06 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google 2007-07-23 06:57 38232 --------- C:\WINDOWS\system32\imjbrd.dll 2007-07-23 06:54 39884 --a------ C:\WINDOWS\system32\gzmrot-uninst.exe 2007-07-22 21:31 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Oberon Games 2007-07-19 21:38 --------- d-------- C:\DOCUME~1\Owner\APPLIC~1\Gamelab 2007-07-17 20:00 --------- d-------- C:\Program Files\QuickTime 2007-07-13 07:46 61440 --a------ C:\WINDOWS\system32\gzmrotate.dll 2007-07-10 00:40 --------- d-------- C:\Program Files\Common Files\Apple 2007-07-10 00:40 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple 2007-06-25 23:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll 2007-06-19 06:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll 2007-06-13 03:23 1033216 --a------ C:\WINDOWS\explorer.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{36A91CEC-6C71-4758-B492-397BFC8E96A2}] 2007-07-13 07:46 61440 --a------ C:\WINDOWS\system32\gzmrotate.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64badabb-4464-451e-846d-5448ecda3859}] 2007-07-23 06:57 38232 --------- C:\WINDOWS\system32\imjbrd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E4283631-646D-48C3-BAC2-70E28BBC77D0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
C:\DOCUME~1\Owner\STARTM~1\Programs\Startup\ LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2006-02-16 14:55:37]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\°À] °À
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\imjbrd] imjbrd.dll 2007-07-23 06:57 38232 C:\WINDOWS\system32\imjbrd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=c:\windows\system32\ddabbxx.dll
[color=red]SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.[/color]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs] @="Service"
R0 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys R1 ICsrvr;VPN Client Protocol;C:\WINDOWS\system32\DRIVERS\ICsrvr.sys R1 ICtdi;VPN Client TDI Driver;C:\WINDOWS\system32\DRIVERS\ictdi.sys R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys R3 ICvnic;VPN Client Virtual Adapter;C:\WINDOWS\system32\DRIVERS\ICvnic.sys R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS S2 ICService;VPN Client;C:\Program Files\VPN\VPN Client\icsrv.exe S3 CCCP106;D-Link CIF Webcam;C:\WINDOWS\system32\DRIVERS\cccp106.sys S3 ed3d0121-a0b8-4cb9-8f10-e00414d97307;ed3d0121-a0b8-4cb9-8f10-e00414d97307;\??\D:\CDS300\cds300.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D] AutoRun\command- D:\Install.exe
Contents of the 'Scheduled Tasks' folder 2007-09-04 05:28:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe 2007-09-05 03:10:12 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-09-04 20:07:27 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
**************************************************************************
Completion time: 2007-09-04 20:11:04 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-09-04 20:11
--- E O F ---
|