Here you go:
FYI, I scanned the windows/system32 directory with ESET after ComboFix was done and it came up clean.
But I'll wait to hear from you before I do anything else.
Thanks.
ComboFix 09-07-01.04 - Eric 07/02/2009 7:58.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1535.984 [GMT -7:00]
Running from: c:\documents and settings\Eric\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Eric\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
file zipped: c:\windows\system32\Suspect_termsrv.dll.vir
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\182d0.msi
c:\windows\Installer\1c8ff3.msp
c:\windows\Installer\2afae.msp
c:\windows\Installer\546a46bf.msi
c:\windows\Installer\5a7d0.msp
c:\windows\Installer\d321f.msi
c:\windows\Installer\dca74.msi
.
--------------- FCopy ---------------
c:\windows\ServicePackFiles\i386\termsrv.dll --> c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))))))
.
2009-06-14 05:20 . 2009-06-14 05:20 -------- d-----w- c:\program files\iTunes
2009-06-14 05:20 . 2009-06-14 05:20 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-14 05:13 . 2009-06-05 18:42 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-14 05:09 . 2009-06-14 05:09 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-10 13:36 . 2009-06-10 13:36 -------- d-----w- c:\windows\SxsCaPendDel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 02:39 . 2005-03-29 04:29 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-06-18 08:00 . 2008-12-04 08:00 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 18:27 . 2008-11-29 21:59 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 18:27 . 2008-11-29 21:59 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-05 18:42 . 2007-12-25 17:28 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-07 15:44 . 2005-03-28 03:19 344064 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:31 . 2005-03-28 03:19 668160 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:31 . 2005-03-28 03:05 81920 ------w- c:\windows\system32\ieencode.dll
2009-04-23 05:30 . 2009-04-23 05:30 34062 ----a-w- c:\documents and settings\Eric\Application Data\Move Networks\ie_bin\Uninst.exe
2009-04-17 13:03 . 2008-02-04 03:48 3218 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2009-04-17 09:58 . 2005-03-28 04:19 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:11 . 2005-03-28 03:19 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2006-08-09 16:42 . 2007-02-06 03:31 3198976 ----a-w- c:\program files\ViewSonicregistration.exe
2003-08-27 21:19 . 2004-05-26 03:21 36963 ----a-r- c:\program files\Common Files\SM1updtr.dll
2008-12-20 05:22 . 2004-11-19 23:26 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-20 05:22 . 2004-11-19 23:25 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2005-07-16 12:41 . 2004-11-19 23:26 44153 ----a-w- c:\program files\mozilla firefox\components\inspector.dll
2008-12-20 05:22 . 2004-11-19 23:25 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-20 05:22 . 2006-12-25 02:17 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-20 05:22 . 2006-12-25 02:17 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2002-08-29 19:00 . 2002-08-29 19:00 94784 --sh--w- c:\windows\twain.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-30_14.10.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-11-14 23:38 . 2005-11-14 23:38 72192 c:\windows\Installer\faa10.msp
+ 2008-04-12 10:03 . 2008-04-12 10:03 86528 c:\windows\Installer\f6b36e5.msi
+ 2009-05-16 14:43 . 2009-05-16 14:43 24064 c:\windows\Installer\964907a9.msi
+ 2009-03-24 22:22 . 2009-03-24 22:22 78848 c:\windows\Installer\4f74b89a.msp
+ 2009-03-20 02:35 . 2009-03-20 02:35 18944 c:\windows\Installer\4f74b88d.msp
+ 2009-03-20 02:35 . 2009-03-20 02:35 18944 c:\windows\Installer\4f74b885.msp
+ 2009-02-27 04:08 . 2009-02-27 04:08 19456 c:\windows\Installer\2cd21f14.msp
+ 2009-03-06 03:06 . 2009-03-06 03:06 20992 c:\windows\Installer\2cd21efa.msi
+ 2009-03-06 03:06 . 2009-03-06 03:06 52736 c:\windows\Installer\2cd21ef6.msi
+ 2009-03-06 03:05 . 2009-03-06 03:05 60928 c:\windows\Installer\2cd21ef2.msi
+ 2009-03-06 03:05 . 2009-03-06 03:05 32256 c:\windows\Installer\2cd21eee.msi
+ 2009-03-06 03:02 . 2009-03-06 03:02 22528 c:\windows\Installer\2cd21ee3.msi
+ 2003-01-19 03:54 . 2003-01-19 03:54 89600 c:\windows\Installer\15cee8.msi
+ 2005-03-28 03:19 . 2004-08-04 06:56 295424 c:\windows\system32\dllcache\termsrv.dll
+ 2006-06-12 22:15 . 2006-06-12 22:15 323584 c:\windows\Installer\faa26.msp
+ 2004-08-25 15:47 . 2004-08-25 15:47 134656 c:\windows\Installer\fa9fb.msp
+ 2004-03-10 16:01 . 2004-03-10 16:01 812544 c:\windows\Installer\fa961.msp
+ 2007-11-07 22:07 . 2007-11-07 22:07 999936 c:\windows\Installer\f6b36ee.msp
+ 2007-11-07 21:56 . 2007-11-07 21:56 553472 c:\windows\Installer\f6b36eb.msp
+ 2007-11-07 21:58 . 2007-11-07 21:58 908800 c:\windows\Installer\f6b36e7.msp
+ 2007-11-07 21:54 . 2007-11-07 21:54 507392 c:\windows\Installer\f6b36e6.msp
+ 2006-02-04 05:19 . 2006-02-04 05:19 625664 c:\windows\Installer\d782fac.msi
+ 2006-10-01 16:46 . 2006-10-01 16:46 213504 c:\windows\Installer\ae861.msi
+ 2006-03-04 23:31 . 2006-03-04 23:31 192000 c:\windows\Installer\9dbaec1.msi
+ 2003-05-11 04:24 . 2003-05-11 04:24 306176 c:\windows\Installer\9a6c643f.msi
+ 2009-02-10 15:50 . 2009-02-10 15:50 536576 c:\windows\Installer\654892c9.msp
+ 2008-11-12 10:00 . 2008-11-12 10:00 432640 c:\windows\Installer\5ce27907.msi
+ 2007-08-18 13:45 . 2007-08-18 13:45 431104 c:\windows\Installer\4ff50bb.msi
+ 2006-11-05 00:11 . 2006-11-05 00:11 531456 c:\windows\Installer\42f84fbc.msi
+ 2008-07-23 06:20 . 2008-07-23 06:20 110592 c:\windows\Installer\3f269b4.msp
+ 2008-01-24 17:04 . 2008-01-24 17:04 678400 c:\windows\Installer\3f26960.msp
+ 2008-11-24 03:29 . 2008-11-24 03:29 355328 c:\windows\Installer\3c615f3e.msi
+ 2005-11-18 02:48 . 2005-11-18 02:48 434688 c:\windows\Installer\39ac19b1.msi
+ 2005-11-20 06:39 . 2005-11-20 06:40 537600 c:\windows\Installer\3693c03.msi
+ 2009-02-27 04:08 . 2009-02-27 04:08 316928 c:\windows\Installer\2cd21f27.msp
+ 2009-02-13 02:09 . 2009-02-13 02:09 141312 c:\windows\Installer\2cd21f0a.msp
+ 2009-03-06 03:06 . 2009-03-06 03:06 201728 c:\windows\Installer\2cd21efe.msi
+ 2007-07-12 04:29 . 2007-07-12 04:29 190464 c:\windows\Installer\27f1db9.msi
+ 2008-01-13 15:41 . 2008-01-13 15:41 691200 c:\windows\Installer\25c7fea.msi
+ 2007-05-02 14:50 . 2007-05-02 14:50 101376 c:\windows\Installer\242fb152.msi
+ 2008-11-29 23:39 . 2008-11-29 23:39 853504 c:\windows\Installer\2373c1.msi
+ 2006-11-19 14:00 . 2006-11-19 14:00 428544 c:\windows\Installer\203dc55.msi
+ 2006-11-25 02:59 . 2006-11-25 02:59 294912 c:\windows\Installer\1954613b.msi
+ 2006-10-01 23:29 . 2006-10-01 23:29 729600 c:\windows\Installer\17c4a32.msi
+ 2009-04-20 21:59 . 2009-04-20 21:59 219648 c:\windows\Installer\16a34173.msp
+ 2003-01-19 01:54 . 2003-01-19 01:54 264704 c:\windows\Installer\13046.msi
+ 2005-09-20 16:47 . 2005-04-04 09:07 982016 c:\windows\Downloaded Installations\{EA7763E4-20ED-43E2-AEFB-D81D1FC2ED59}\ISScript11.Msi
+ 2005-12-25 18:33 . 2005-04-04 09:07 982016 c:\windows\Downloaded Installations\{872653C6-5DDC-488B-B7C2-CF9E4D9335E5}\ISScript11.Msi
+ 2004-03-07 15:01 . 2004-03-07 15:01 633856 c:\windows\Downloaded Installations\{86EDCFC4-DC59-43FC-BE0A-30A14FC371AA}\isscript.msi
+ 2006-03-25 20:10 . 2005-04-04 08:07 982016 c:\windows\Downloaded Installations\{59C4F14F-7590-45FC-BE9F-A67AB3590709}\ISScript11.Msi
+ 2006-02-01 15:10 . 2005-04-04 08:07 982016 c:\windows\Downloaded Installations\{501BADCD-F8F7-44CB-AC3F-6ED25C1A28B5}\ISScript11.Msi
+ 2005-12-25 18:10 . 2005-04-04 09:07 982016 c:\windows\Downloaded Installations\{13616DE2-9795-4910-8C93-80D45AF09658}\ISScript11.Msi
+ 2005-03-28 03:19 . 2004-07-17 17:35 1326080 c:\windows\system32\webfldrs.msi
+ 2005-03-28 03:05 . 2004-07-17 17:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2007-01-19 01:14 . 2007-01-19 01:14 3463680 c:\windows\Microsoft.NET\Framework\v1.0.3705\Updates\M928367\M928367Uninstall.msp
+ 2006-08-14 23:54 . 2006-08-14 23:54 7709184 c:\windows\Installer\fa9e3.msp
+ 2006-09-12 21:51 . 2006-09-12 21:51 7611392 c:\windows\Installer\fa9cd.msp
+ 2006-09-28 18:08 . 2006-09-28 18:08 9573888 c:\windows\Installer\fa9b7.msp
+ 2006-02-27 23:31 . 2006-02-27 23:31 1269248 c:\windows\Installer\fa9a2.msp
+ 2006-03-28 22:37 . 2006-03-28 22:37 6956032 c:\windows\Installer\fa98d.msp
+ 2004-09-13 07:35 . 2004-09-13 07:35 1452544 c:\windows\Installer\fa93b.msp
+ 2006-02-22 16:41 . 2006-02-22 16:41 2815488 c:\windows\Installer\fa8e7.msp
+ 2006-07-10 18:21 . 2006-07-10 18:21 4104192 c:\windows\Installer\fa8ca.msp
+ 2006-09-18 23:51 . 2006-09-18 23:51 8415744 c:\windows\Installer\fa8b5.msp
+ 2006-01-28 04:44 . 2006-01-28 04:44 9495552 c:\windows\Installer\fa156db.msi
+ 2007-11-07 21:50 . 2007-11-07 21:50 6055936 c:\windows\Installer\f6b36ed.msp
+ 2007-11-07 22:00 . 2007-11-07 22:00 3407360 c:\windows\Installer\f6b36ec.msp
+ 2007-11-07 21:46 . 2007-11-07 21:46 3010560 c:\windows\Installer\f6b36ea.msp
+ 2007-11-07 22:02 . 2007-11-07 22:02 6473216 c:\windows\Installer\f6b36e9.msp
+ 2007-11-07 22:12 . 2007-11-07 22:12 2533376 c:\windows\Installer\f6b36e8.msp
+ 2007-01-31 02:19 . 2007-01-31 02:19 9472512 c:\windows\Installer\f2397f0.msi
+ 2009-02-22 21:13 . 2009-02-22 21:13 1659392 c:\windows\Installer\e6f7115.msi
+ 2008-09-04 22:52 . 2008-09-04 22:52 4337664 c:\windows\Installer\ddcf97c.msp
+ 2007-01-19 18:01 . 2007-01-19 18:01 8410624 c:\windows\Installer\dc20b5d.msp
+ 2007-01-08 20:31 . 2007-01-08 20:31 7611392 c:\windows\Installer\dc20b48.msp
+ 2006-08-30 00:50 . 2006-08-30 00:50 3210240 c:\windows\Installer\dc20b33.msp
+ 2004-03-07 14:56 . 2004-03-07 14:56 3868160 c:\windows\Installer\d856807.msi
+ 2008-12-02 14:08 . 2008-12-02 14:08 6267392 c:\windows\Installer\d006a0d.msi
+ 2008-12-02 04:03 . 2008-12-02 04:03 1430016 c:\windows\Installer\ad6a01a.msi
+ 2008-04-07 22:32 . 2008-04-07 22:32 8415232 c:\windows\Installer\9dd7f2e8.msp
+ 2008-03-31 23:35 . 2008-03-31 23:35 8309760 c:\windows\Installer\9dd7f2d3.msp
+ 2008-01-11 21:13 . 2008-01-11 21:13 5862912 c:\windows\Installer\989a6fc.msp
+ 2008-01-29 19:00 . 2008-01-29 19:00 7983104 c:\windows\Installer\989a6e6.msp
+ 2004-05-26 03:20 . 2004-05-26 03:20 1014272 c:\windows\Installer\9163a8d5.msi
+ 2009-05-01 06:02 . 2009-05-01 06:02 9628672 c:\windows\Installer\8af59dd4.msp
+ 2009-04-24 19:31 . 2009-04-24 19:31 1425920 c:\windows\Installer\8af59dbe.msp
+ 2007-06-10 03:26 . 2007-06-10 03:26 3226112 c:\windows\Installer\80e84.msi
+ 2003-01-19 03:13 . 2003-01-19 03:13 2652672 c:\windows\Installer\7e69b.msi
+ 2008-10-28 22:59 . 2008-10-28 22:59 8413184 c:\windows\Installer\6b7506b.msp
+ 2008-10-20 17:18 . 2008-10-20 17:18 6474240 c:\windows\Installer\6b75041.msp
+ 2008-01-14 22:08 . 2008-01-14 22:08 8411136 c:\windows\Installer\6b5c91fb.msp
+ 2008-01-14 21:26 . 2008-01-14 21:26 4478464 c:\windows\Installer\6b5c91e6.msp
+ 2008-01-14 21:26 . 2008-01-14 21:26 8362496 c:\windows\Installer\6b5c91d1.msp
+ 2006-01-25 04:05 . 2006-01-25 04:05 8979968 c:\windows\Installer\617a0e0.msi
+ 2006-03-04 05:38 . 2006-03-04 05:38 4337664 c:\windows\Installer\6020b0c.msi
+ 2005-03-29 03:54 . 2005-03-29 03:54 1422848 c:\windows\Installer\5a7d8.msp
+ 2004-12-16 04:26 . 2004-12-16 04:26 5288448 c:\windows\Installer\5820eb1a.msi
+ 2006-04-19 02:59 . 2006-04-19 02:59 2331136 c:\windows\Installer\56faa9f7.msi
+ 2007-09-17 20:33 . 2007-09-17 20:33 8415232 c:\windows\Installer\5222f2a.msp
+ 2009-03-24 22:20 . 2009-03-24 22:20 3276800 c:\windows\Installer\4f74bae8.msp
+ 2009-03-20 02:32 . 2009-03-20 02:32 1007104 c:\windows\Installer\4f74ba37.msp
+ 2009-03-20 02:34 . 2009-03-20 02:34 1867264 c:\windows\Installer\4f74b908.msp
+ 2003-01-22 02:11 . 2003-01-22 02:11 3262464 c:\windows\Installer\4f35a88.msi
+ 2007-03-29 18:34 . 2007-03-29 18:34 8414208 c:\windows\Installer\4c59661a.msp
+ 2007-04-19 22:40 . 2007-04-19 22:40 7979008 c:\windows\Installer\4c596605.msp
+ 2004-02-14 05:00 . 2004-02-14 05:00 2270208 c:\windows\Installer\48a6778e.msi
+ 2004-02-14 04:57 . 2004-02-14 04:57 2358784 c:\windows\Installer\48a67789.msi
+ 2006-12-13 15:32 . 2006-12-13 15:32 5861376 c:\windows\Installer\4441875.msp
+ 2003-05-31 17:19 . 2003-05-31 17:19 4028928 c:\windows\Installer\43128aa.msi
+ 2008-06-30 21:34 . 2008-06-30 21:34 8416768 c:\windows\Installer\3f2699f.msp
+ 2008-05-06 17:30 . 2008-05-06 17:30 9577984 c:\windows\Installer\3f26975.msp
+ 2008-06-20 01:28 . 2008-06-20 01:28 1573376 c:\windows\Installer\3dc80dd7.msp
+ 2008-04-18 21:56 . 2008-04-18 21:56 6215680 c:\windows\Installer\3dc80dae.msp
+ 2007-07-21 20:26 . 2007-07-21 20:26 7574016 c:\windows\Installer\3dc80da3.msp
+ 2005-11-20 06:41 . 2005-11-20 06:41 1453568 c:\windows\Installer\3693c11.msi
+ 2005-11-20 06:40 . 2005-11-20 06:40 1868800 c:\windows\Installer\3693c0a.msi
+ 2005-11-20 06:39 . 2005-11-20 06:39 2892288 c:\windows\Installer\3693bf4.msi
+ 2005-11-20 06:37 . 2005-11-20 06:37 5091840 c:\windows\Installer\3693bed.msi
+ 2008-10-15 23:45 . 2008-10-15 23:45 2330624 c:\windows\Installer\2ea53e3.msi
+ 2009-02-27 04:04 . 2009-02-27 04:04 6777344 c:\windows\Installer\2cd223e8.msp
+ 2009-02-20 01:31 . 2009-02-20 01:31 4572160 c:\windows\Installer\2cd222b7.msp
+ 2009-02-28 08:55 . 2009-02-28 08:55 5142528 c:\windows\Installer\2cd22006.msp
+ 2009-03-06 03:03 . 2009-03-06 03:04 2335744 c:\windows\Installer\2cd21eea.msi
+ 2008-01-13 16:36 . 2008-01-13 16:36 1769984 c:\windows\Installer\28e3976.msi
+ 2008-01-13 16:35 . 2008-01-13 16:35 1767424 c:\windows\Installer\28e3968.msi
+ 2008-06-12 03:13 . 2008-06-12 03:13 7988224 c:\windows\Installer\288fda8d.msp
+ 2008-01-22 13:03 . 2008-01-22 13:03 1840640 c:\windows\Installer\283b43d.msi
+ 2008-01-22 13:02 . 2008-01-22 13:02 1768448 c:\windows\Installer\283b37f.msi
+ 2007-10-30 13:17 . 2007-10-30 13:17 6503936 c:\windows\Installer\2516acb.msp
+ 2007-07-11 10:00 . 2007-07-11 10:00 6743040 c:\windows\Installer\1c38c48a.msp
+ 2007-10-16 13:30 . 2007-10-16 13:30 7641088 c:\windows\Installer\19a2c1cf.msi
+ 2006-09-18 00:41 . 2006-09-18 00:41 1408000 c:\windows\Installer\17b9b0f0.msi
+ 2007-10-10 13:25 . 2007-10-10 13:25 3555328 c:\windows\Installer\16be4c.msi
+ 2009-05-04 14:46 . 2009-05-04 14:46 8299008 c:\windows\Installer\16a3415e.msp
+ 2009-04-24 19:30 . 2009-04-24 19:30 2583552 c:\windows\Installer\16a34153.msp
+ 2009-04-29 22:03 . 2009-04-29 22:03 8404992 c:\windows\Installer\16a34147.msp
+ 2006-03-01 21:15 . 2006-03-01 21:15 3255296 c:\windows\Installer\1466851f.msi
+ 2004-03-07 15:01 . 2004-03-07 15:01 5978112 c:\windows\Installer\142ef.msi
+ 2009-06-14 05:25 . 2009-06-14 05:25 2478080 c:\windows\Installer\13855d56.msi
+ 2009-06-14 05:22 . 2009-06-14 05:22 4074496 c:\windows\Installer\13855c82.msi
+ 2009-06-14 05:17 . 2009-06-14 05:17 1665024 c:\windows\Installer\13855959.msi
+ 2009-06-14 05:17 . 2009-06-14 05:17 8992256 c:\windows\Installer\13855913.msi
+ 2009-06-14 05:13 . 2009-06-14 05:14 3295232 c:\windows\Installer\1385567d.msi
+ 2006-03-29 18:44 . 2006-03-29 18:44 3563520 c:\windows\Installer\12902944.msi
+ 2008-01-13 03:59 . 2008-01-13 03:59 1785344 c:\windows\Installer\11d074b7.msi
+ 2008-01-13 03:59 . 2008-01-13 03:59 2435072 c:\windows\Installer\11d074af.msi
+ 2008-01-13 03:56 . 2008-01-13 03:56 2399744 c:\windows\Installer\11d074a7.msi
+ 2008-01-13 03:53 . 2008-01-13 03:53 2437632 c:\windows\Installer\11d0749e.msi
+ 2008-01-13 03:49 . 2008-01-13 03:49 2999808 c:\windows\Installer\11d07496.msi
+ 2008-01-13 03:43 . 2008-01-13 03:43 3240448 c:\windows\Installer\11d0748e.msi
+ 2008-01-13 03:36 . 2008-01-13 03:36 1888256 c:\windows\Installer\11d07486.msi
+ 2008-01-13 03:26 . 2008-01-13 03:26 1727488 c:\windows\Installer\11d0742f.msi
+ 2008-01-13 03:26 . 2008-01-13 03:26 1765888 c:\windows\Installer\11d0741a.msi
+ 2008-01-13 03:25 . 2008-01-13 03:25 1784832 c:\windows\Installer\11d07413.msi
+ 2008-01-13 03:25 . 2008-01-13 03:25 1723904 c:\windows\Installer\11d0740c.msi
+ 2008-01-13 03:25 . 2008-01-13 03:25 1763840 c:\windows\Installer\11d07405.msi
+ 2008-01-13 03:24 . 2008-01-13 03:24 1728000 c:\windows\Installer\11d073fc.msi
+ 2008-01-13 03:24 . 2008-01-13 03:24 1794560 c:\windows\Installer\11d073f5.msi
+ 2008-01-13 03:24 . 2008-01-13 03:24 1891840 c:\windows\Installer\11d073ee.msi
+ 2008-01-13 03:23 . 2008-01-13 03:23 2084864 c:\windows\Installer\11d073e6.msi
+ 2008-01-13 03:22 . 2008-01-13 03:22 1724928 c:\windows\Installer\11d073de.msi
+ 2008-01-13 03:21 . 2008-01-13 03:21 1885696 c:\windows\Installer\11d073d6.msi
+ 2008-01-13 03:21 . 2008-01-13 03:21 1786880 c:\windows\Installer\11d073cf.msi
+ 2008-01-13 03:21 . 2008-01-13 03:21 1765376 c:\windows\Installer\11d073c8.msi
+ 2008-01-13 03:20 . 2008-01-13 03:20 1733120 c:\windows\Installer\11d073c1.msi
+ 2008-01-13 03:20 . 2008-01-13 03:20 1722880 c:\windows\Installer\11d073ba.msi
+ 2008-01-13 03:20 . 2008-01-13 03:20 1723904 c:\windows\Installer\11d073b1.msi
+ 2008-01-13 03:19 . 2008-01-13 03:20 1722880 c:\windows\Installer\11d073a6.msi
+ 2008-01-13 03:19 . 2008-01-13 03:19 1751040 c:\windows\Installer\11d0739b.msi
+ 2008-01-13 03:19 . 2008-01-13 03:19 1768448 c:\windows\Installer\11d07394.msi
+ 2008-01-13 03:18 . 2008-01-13 03:18 1766400 c:\windows\Installer\11d07386.msi
+ 2008-01-13 03:17 . 2008-01-13 03:17 2166272 c:\windows\Installer\11d0737f.msi
+ 2008-01-13 03:15 . 2008-01-13 03:15 1722880 c:\windows\Installer\11d07378.msi
+ 2008-01-13 03:15 . 2008-01-13 03:15 1960960 c:\windows\Installer\11d07370.msi
+ 2008-01-13 00:58 . 2008-01-13 00:58 1786880 c:\windows\Installer\11d07369.msi
+ 2008-01-13 00:57 . 2008-01-13 00:57 1727488 c:\windows\Installer\11d0735a.msi
+ 2008-01-13 00:56 . 2008-01-13 00:56 2602496 c:\windows\Installer\11d07353.msi
+ 2008-01-13 00:50 . 2008-01-13 00:50 1733632 c:\windows\Installer\11d0734c.msi
+ 2008-01-13 00:49 . 2008-01-13 00:49 1736704 c:\windows\Installer\11d07345.msi
+ 2008-01-13 00:49 . 2008-01-13 00:49 1768448 c:\windows\Installer\11d0733e.msi
+ 2008-01-13 00:49 . 2008-01-13 00:49 1759744 c:\windows\Installer\11d07337.msi
+ 2008-01-13 00:48 . 2008-01-13 00:48 1833472 c:\windows\Installer\11d07330.msi
+ 2008-01-13 00:48 . 2008-01-13 00:48 1723392 c:\windows\Installer\11d07329.msi
+ 2008-01-13 00:48 . 2008-01-13 00:48 1833984 c:\windows\Installer\11d07322.msi
+ 2008-09-02 13:22 . 2008-09-02 13:22 1549312 c:\windows\Installer\11ad8a.msi
+ 2003-01-19 16:00 . 2003-01-19 16:00 4701184 c:\windows\Installer\112664.msi
+ 2004-03-07 15:18 . 2004-03-07 15:18 4068352 c:\windows\Installer\1102c9.msi
+ 2008-01-12 18:24 . 2008-01-12 18:24 1792512 c:\windows\Installer\10714e7b.msi
+ 2005-12-25 18:33 . 2005-10-18 20:01 9935872 c:\windows\Downloaded Installations\{872653C6-5DDC-488B-B7C2-CF9E4D9335E5}\iTunes.msi
+ 2007-02-06 03:38 . 2007-02-06 03:38 5667328 c:\windows\Downloaded Installations\{76F45A69-AA7A-4BC0-BD33-173F963DD2C2}\Multimedia Card Reader Driver.msi
+ 2006-03-25 20:10 . 2006-02-23 23:42 9934848 c:\windows\Downloaded Installations\{59C4F14F-7590-45FC-BE9F-A67AB3590709}\iTunes.msi
+ 2006-02-01 15:10 . 2005-12-21 18:57 9934848 c:\windows\Downloaded Installations\{501BADCD-F8F7-44CB-AC3F-6ED25C1A28B5}\iTunes.msi
+ 2005-12-25 18:10 . 2005-10-12 04:53 9932800 c:\windows\Downloaded Installations\{13616DE2-9795-4910-8C93-80D45AF09658}\iTunes.msi
+ 2005-03-29 04:19 . 2002-08-29 19:00 1325568 c:\windows\$NtServicePackUninstall$\webfldrs.msi
+ 2006-11-27 16:33 . 2006-11-27 16:33 17519104 c:\windows\Installer\fa976.msp
+ 2008-08-19 16:37 . 2008-08-19 16:37 17523712 c:\windows\Installer\ddcf991.msp
+ 2008-01-24 22:56 . 2008-01-24 22:56 13570560 c:\windows\Installer\989a712.msp
+ 2008-01-29 20:14 . 2008-01-29 20:14 17524224 c:\windows\Installer\989a6d1.msp
+ 2008-10-20 17:22 . 2008-10-20 17:22 11758592 c:\windows\Installer\6b75075.msp
+ 2008-10-29 02:17 . 2008-10-29 02:17 17520128 c:\windows\Installer\6b75056.msp
+ 2009-03-09 22:55 . 2009-03-09 22:55 17526272 c:\windows\Installer\654892de.msp
+ 2009-02-26 02:07 . 2009-02-26 02:07 11646464 c:\windows\Installer\654892b1.msp
+ 2006-03-04 05:41 . 2006-03-04 05:41 12388864 c:\windows\Installer\6020b0f.msi
+ 2005-09-25 18:46 . 2005-09-25 18:46 16084480 c:\windows\Installer\51a60b01.msp
+ 2007-04-19 21:15 . 2007-04-19 21:15 17519104 c:\windows\Installer\4c59662f.msp
+ 2006-12-05 16:25 . 2006-12-05 16:25 17520128 c:\windows\Installer\444184e.msp
+ 2007-10-15 06:33 . 2007-10-15 06:33 26646016 c:\windows\Installer\42ee97de.msp
+ 2008-06-20 22:30 . 2008-06-20 22:30 16733184 c:\windows\Installer\3f2698a.msp
+ 2008-08-11 18:51 . 2008-08-11 18:51 15916544 c:\windows\Installer\3dc80de1.msp
+ 2008-08-11 18:49 . 2008-08-11 18:49 22457344 c:\windows\Installer\3dc80dcc.msp
+ 2008-07-30 06:20 . 2008-07-30 06:20 11767296 c:\windows\Installer\3dc80dc2.msp
+ 2008-09-24 19:05 . 2008-09-24 19:05 16381440 c:\windows\Installer\3dc80db8.msp
+ 2008-01-13 15:32 . 2008-01-13 15:32 11395584 c:\windows\Installer\25c8009.msp
+ 2004-01-30 09:21 . 2004-01-30 09:21 15605132 c:\windows\Installer\2447b321.msp
+ 2005-03-28 02:39 . 2005-03-28 02:39 10723328 c:\windows\Installer\1c9047.msp
+ 2007-07-24 22:11 . 2007-07-24 22:11 17521152 c:\windows\Installer\1c5b0eec.msp
+ 2007-06-14 20:47 . 2007-06-14 20:47 17512448 c:\windows\Installer\1c4adb18.msp
+ 2009-05-06 01:06 . 2009-05-06 01:06 17515008 c:\windows\Installer\16a34188.msp
+ 2007-06-15 09:29 . 2007-06-15 09:29 37983232 c:\windows\Installer\11d0747c.msp
+ 2008-01-13 03:35 . 2008-01-13 03:35 10476544 c:\windows\Installer\11d0747b.msi
+ 2005-09-20 16:47 . 2005-09-04 03:26 10065408 c:\windows\Downloaded Installations\{EA7763E4-20ED-43E2-AEFB-D81D1FC2ED59}\iTunes.msi
+ 2004-05-26 03:39 . 2004-05-26 03:51 19479040 c:\windows\Downloaded Installations\{E83562AD-CFFD-4E8B-841F-6B60B5AC2496}\iTunes.msi
+ 2005-06-28 22:21 . 2005-06-28 22:21 21069312 c:\windows\Downloaded Installations\{A89EB61A-717D-4E9B-BB70-7626DF2EB947}\iTunes.msi
+ 2006-03-04 23:30 . 2006-03-04 23:30 21676544 c:\windows\Downloaded Installations\{88C3AC3E-241E-087C-B9E7-A81E0034E964}\merge65_win32_2172.msi
+ 2004-03-07 15:01 . 2004-03-07 15:01 15179776 c:\windows\Downloaded Installations\{86EDCFC4-DC59-43FC-BE0A-30A14FC371AA}\Palm VersaMail(tm).msi
+ 2006-01-25 04:04 . 2006-01-25 04:04 33979904 c:\windows\Downloaded Installations\{00C2E789-F948-4BE1-8167-6E6447DC4CE2}\iPod for Windows 2006-01-10.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-06 68856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS Probe"="c:\program files\ASUS\Probe\AsusProb.exe" [2002-12-06 617984]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2003-12-13 33792]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2003-05-15 114688]
"SM1BG"="c:\windows\SM1BG.EXE" [2003-08-27 94208]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-10 28672]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2003-05-15 163840]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-08-23 196608]
"CXMon"="c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-08-10 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_12\bin\jusched.exe" [2007-05-02 75520]
"HPHmon03"="c:\windows\system32\hphmon03.exe" [2001-08-23 311296]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-22 1191936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-11 39792]
"Acrobat Assistant 8.0"="e:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-11 624248]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"egui"="f:\program files\ESET\ESET Smart Security\egui.exe" [2008-08-18 1447168]
"PWRISOVM.EXE"="f:\program files\PowerISO\PWRISOVM.EXE" [2008-11-02 167936]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"Malwarebytes' Anti-Malware"="f:\malware\Malware\mbamgui.exe" [2009-06-17 414992]
"WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2008-12-02 364544]
c:\documents and settings\Eric\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\Palm\HOTSYNC.EXE [2003-9-25 299008]
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-8 98304]
WD Anywhere Backup Launcher.lnk - c:\documents and settings\Eric\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe [2008-12-2 17542]
MagicDisc.lnk - f:\program files\MagicDisc\MagicDisc.exe [2008-12-11 575488]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Dataviz Messenger.lnk - c:\windows\DvzCommon\DvzMsgr.exe [2003-7-1 24576]
Quicken Scheduled Updates.lnk - c:\program files\Quicken\bagent.exe [2003-10-2 57344]
Monitor Apache Servers.lnk - c:\program files\Apache Group\Apache2\bin\ApacheMonitor.exe [2006-7-27 41042]
WinZip Quick Pick.lnk - c:\program files\WinZip9\WZQKPICK.EXE [2006-10-10 118784]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\M:\0autocheck autochk *
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Palm\\HOTSYNC.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\SmartFTP\\SmartFTP.exe"=
"c:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"=
"e:\\Program Files\\Adobe\\Adobe Dreamweaver CS3\\Dreamweaver.exe"=
"f:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [8/27/2004 4:18 PM 97920]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [3/9/2008 6:29 PM 8576]
R2 afpa;afpa;c:\windows\system32\drivers\afpa.sys [5/10/2003 12:12 AM 106224]
R2 ekrn;Eset Service;f:\program files\ESET\ESET Smart Security\ekrn.exe [8/18/2008 1:25 PM 468224]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088]
R2 MBAMService;MBAMService;f:\malware\Malware\mbamservice.exe [11/29/2008 2:59 PM 195856]
R3 Dot4Usb HPH09

ot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [8/23/2001 3:24 AM 18864]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/29/2008 2:59 PM 19096]
R3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\drivers\urvpndrv.sys [11/3/2003 6:43 PM 28304]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys --> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S3 ASUSHWIO;ASUSHWIO;\??\c:\windows\System32\drivers\ASUSHWIO.sys --> c:\windows\System32\drivers\ASUSHWIO.sys [?]
S3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [8/23/2004 8:26 PM 10768]
.
Contents of the 'Scheduled Tasks' folder
2009-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]
2009-07-02 c:\windows\Tasks\Malwarebytes' Scheduled Update for Eric.job
- f:\malware\Malware\mbam.exe [2008-11-29 18:27]
2009-07-02 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Eric.job
- f:\malware\Malware\mbam.exe [2008-11-29 18:27]
2009-07-01 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-01 05:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig?sourceid=navclient&ie=UTF-8&hl=en
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mSearch Bar =
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append to existing PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {2D72C39D-53F6-4AEA-A9DB-1298429DA974} - hxxp://www.3dvista.com/downloads/viewer3dv.cab
DPF: {94837F90-A2CA-4A8A-9DA0-B5438EC563EA} - hxxp://install.wildtangent.com/cda/islandrally/ActiveLauncher/ActiveLauncherSetup.cab
DPF: {E66D35B8-E70D-42A6-B1F5-DB784CB92B15} - hxxps://remote.halw.com/vdesk/terminal/urvncx.cab#version=5400,0,50202,1
FF - ProfilePath - c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\xyeup4yl.Default User\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - plugin: c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\xyeup4yl.Default User\extensions\OberonGameHost@OberonGames.com\platform\WINNT_x86-msvc\plugins\npOberonGameHost.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-02 08:02
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL]
"ImagePath"="e:\web\xampp\mysql\bin\mysqld-nt --defaults-file=e:\web\xampp\mysql\bin\my.cnf mysql"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1224)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-07-02 8:04
ComboFix-quarantined-files.txt 2009-07-02 15:04
ComboFix2.txt 2009-07-01 14:58
ComboFix3.txt 2009-06-30 14:14
Pre-Run: 2,936,586,240 bytes free
Post-Run: 2,894,266,368 bytes free
430 --- E O F --- 2009-06-10 10:08
Upload was successful