That's all done, here's your logs.
As for the Illusion entry, i'm not going to hide my shame.. that's a lewd game i acquired a long time ago, i'm VERY sure this isn't malware. There haven't been any changes in it for a long time.
ComboFix 08-11-21.05 - Compaq_Administrator 2008-11-27 20:14:53.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.131 [GMT 0:00]
Running from: c:\documents and settings\[redacted]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Administrator\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\system32\hqpvhooc.dll
c:\windows\system32\qdseqydh.dll
c:\windows\system32\umaowcni.dll
c:\windows\system32\wqnnjbga.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\hqpvhooc.dll
c:\windows\system32\qdseqydh.dll
c:\windows\system32\umaowcni.dll
c:\windows\system32\wqnnjbga.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-27 to 2008-11-27 )))))))))))))))))))))))))))))))
.
2008-11-27 19:56 . 2008-11-27 19:56 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\AdobeUM
2008-11-27 19:55 . 2008-11-27 19:55 <DIR> d-------- c:\program files\Launchy
2008-11-27 19:55 . 2008-11-27 19:55 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\Launchy
2008-11-27 16:33 . 2008-11-27 16:33 <DIR> d-------- c:\program files\Start Killer
2008-11-27 08:35 . 2008-11-27 08:35 236 --a------ C:\sqmdata12.sqm
2008-11-27 08:35 . 2008-11-27 08:35 200 --a------ C:\sqmnoopt12.sqm
2008-11-23 09:59 . 2008-11-23 10:07 <DIR> d-------- c:\program files\Rainmeter
2008-11-22 14:05 . 2008-11-22 14:05 236 --a------ C:\sqmdata11.sqm
2008-11-22 14:05 . 2008-11-22 14:05 200 --a------ C:\sqmnoopt11.sqm
2008-11-22 13:12 . 2008-11-22 13:12 <DIR> d-------- c:\program files\EA Games
2008-11-22 13:12 . 2007-10-12 15:14 3,734,536 --a------ c:\windows\system32\d3dx9_36.dll
2008-11-22 13:12 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
2008-11-22 13:12 . 2007-10-12 15:14 1,374,232 --a------ c:\windows\system32\D3DCompiler_36.dll
2008-11-22 13:12 . 2007-05-16 16:45 1,124,720 --a------ c:\windows\system32\D3DCompiler_34.dll
2008-11-22 13:12 . 2007-10-02 09:56 444,776 --a------ c:\windows\system32\d3dx10_36.dll
2008-11-22 13:12 . 2007-05-16 16:45 443,752 --a------ c:\windows\system32\d3dx10_34.dll
2008-11-22 13:12 . 2007-10-22 03:39 267,272 --a------ c:\windows\system32\xactengine2_10.dll
2008-11-22 13:12 . 2007-07-20 00:57 267,112 --a------ c:\windows\system32\xactengine2_9.dll
2008-11-22 13:12 . 2007-06-20 20:46 266,088 --a------ c:\windows\system32\xactengine2_8.dll
2008-11-22 13:12 . 2007-10-22 03:37 17,928 --a------ c:\windows\system32\X3DAudio1_2.dll
2008-11-22 09:37 . 2008-11-22 09:37 236 --a------ C:\sqmdata10.sqm
2008-11-22 09:37 . 2008-11-22 09:37 200 --a------ C:\sqmnoopt10.sqm
2008-11-22 09:32 . 2008-11-22 09:32 236 --a------ C:\sqmdata09.sqm
2008-11-22 09:32 . 2008-11-22 09:32 200 --a------ C:\sqmnoopt09.sqm
2008-11-21 09:26 . 2008-11-21 09:26 236 --a------ C:\sqmdata08.sqm
2008-11-21 09:26 . 2008-11-21 09:26 200 --a------ C:\sqmnoopt08.sqm
2008-11-21 07:46 . 2008-11-21 07:46 236 --a------ C:\sqmdata07.sqm
2008-11-21 07:46 . 2008-11-21 07:46 200 --a------ C:\sqmnoopt07.sqm
2008-11-20 19:42 . 2008-11-20 19:42 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-20 19:42 . 2008-11-20 20:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-20 19:41 . 2008-11-20 19:41 <DIR> d-------- c:\program files\Ad-Aware
2008-11-20 19:41 . 2008-11-20 19:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-20 10:23 . 2008-11-20 10:23 <DIR> d---s---- c:\documents and settings\Kim\UserData
2008-11-19 22:04 . 2008-11-19 22:04 <DIR> d-------- c:\program files\Nero 9
2008-11-19 22:04 . 2008-11-19 22:04 <DIR> d-------- c:\program files\Common Files\Nero
2008-11-19 21:50 . 2008-11-19 21:50 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\Sonic
2008-11-19 21:50 . 2008-11-19 21:50 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\Leadertech
2008-11-18 21:19 . 2008-11-18 21:19 236 --a------ C:\sqmdata06.sqm
2008-11-18 21:19 . 2008-11-18 21:19 200 --a------ C:\sqmnoopt06.sqm
2008-11-18 14:29 . 2008-11-20 10:23 <DIR> d-------- c:\documents and settings\Kim\Tracing
2008-11-18 10:09 . 2008-11-18 10:09 200 --a------ C:\sqmnoopt05.sqm
2008-11-18 10:09 . 2008-11-18 10:09 200 --a------ C:\sqmdata05.sqm
2008-11-18 08:52 . 2006-09-01 12:57 <DIR> d-------- c:\documents and settings\Kim\WINDOWS
2008-11-18 08:52 . 2008-11-20 10:23 <DIR> d-------- c:\documents and settings\Kim
2008-11-17 22:29 . 2007-03-07 23:51 129,784 --a------ c:\windows\system32\pxafs.dll
2008-11-17 21:56 . 2008-11-24 19:16 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\SiteAdvisor
2008-11-17 21:56 . 2008-11-17 21:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-11-17 21:56 . 2008-11-17 21:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\McAfee
2008-11-17 21:39 . 2008-11-17 21:42 <DIR> d-------- c:\program files\foobar2000
2008-11-17 20:55 . 2008-11-17 20:56 <DIR> d-------- c:\windows\system32\FLIQLO dir
2008-11-17 20:55 . 2008-11-17 20:55 532,480 --a------ c:\windows\system32\FLIQLO.scr
2008-11-17 20:42 . 2008-11-27 16:59 <DIR> d-------- c:\program files\CD Art Display
2008-11-17 20:42 . 2003-01-27 14:27 94,208 --a------ c:\windows\system32\wmpuice.dll
2008-11-17 20:42 . 2008-08-24 21:33 69,632 --a------ c:\windows\cadSSaver.scr
2008-11-17 20:15 . 2008-11-27 19:58 <DIR> d-------- c:\program files\Avast4
2008-11-16 20:45 . 2008-11-16 20:45 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\CyberLink
2008-11-16 20:41 . 2008-11-16 20:42 <DIR> d-------- c:\program files\InterActual
2008-11-16 19:08 . 2008-11-16 19:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\Blizzard
2008-11-16 16:23 . 2008-11-16 16:23 <DIR> d-------- c:\program files\DVD Flick
2008-11-16 16:23 . 2008-11-16 17:06 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\DVD Flick
2008-11-16 16:23 . 2004-03-09 00:00 662,288 --a------ c:\windows\system32\mscomct2.ocx
2008-11-16 16:23 . 1998-06-24 00:00 164,144 --a------ c:\windows\system32\comct232.ocx
2008-11-16 16:23 . 2003-01-26 13:41 40,960 --a------ c:\windows\system32\ssubtmr6.dll
2008-11-16 16:23 . 2007-08-31 18:36 36,864 --a------ c:\windows\system32\trayicon_handler.ocx
2008-11-16 16:23 . 2008-08-31 13:27 28,672 --a------ c:\windows\system32\mousewheel.ocx
2008-11-16 16:12 . 2006-09-01 12:57 <DIR> d-------- c:\documents and settings\Guest\WINDOWS
2008-11-16 16:12 . 2008-11-16 16:12 <DIR> d-------- c:\documents and settings\Guest
2008-11-16 14:21 . 2008-11-16 14:21 <DIR> d-------- c:\documents and settings\All Users\Application Data\Last.fm
2008-11-16 14:19 . 2008-11-16 14:19 <DIR> d-------- c:\program files\Last.fm
2008-11-16 13:29 . 2008-11-16 13:29 <DIR> d-------- c:\program files\BootSkin
2008-11-16 13:29 . 2008-11-16 13:30 162,432 --a------ c:\windows\system32\drivers\vidstub.sys
2008-11-16 12:57 . 2008-11-16 12:57 <DIR> d-------- c:\program files\Logon Loader
2008-11-16 09:17 . 2008-11-16 09:17 <DIR> d-------- c:\program files\Common Files\Blizzard Entertainment
2008-11-16 09:11 . 2008-11-16 09:15 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\Otto
2008-11-16 09:11 . 2008-11-16 09:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Otto
2008-11-15 23:55 . 2008-11-15 23:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\SlySoft
2008-11-15 23:52 . 2008-11-15 23:52 <DIR> d-------- c:\program files\SlySoft
2008-11-15 23:44 . 2008-11-15 23:44 <DIR> d-------- c:\program files\Handbrake
2008-11-15 23:41 . 2008-11-15 23:41 236 --a------ C:\sqmdata04.sqm
2008-11-15 23:41 . 2008-11-15 23:41 200 --a------ C:\sqmnoopt04.sqm
2008-11-15 23:36 . 2008-11-15 23:36 <DIR> d-------- c:\windows\system32\XPSViewer
2008-11-15 23:36 . 2008-11-15 23:36 <DIR> d-------- c:\program files\Reference Assemblies
2008-11-15 23:36 . 2008-11-15 23:36 <DIR> d-------- c:\program files\MSBuild
2008-11-15 23:35 . 2008-07-06 12:06 1,676,288 --a------ c:\windows\system32\xpssvcs.dll
2008-11-15 23:35 . 2008-07-06 12:06 1,676,288 --a------ c:\windows\system32\dllcache\xpssvcs.dll
2008-11-15 23:35 . 2008-07-06 10:50 597,504 --a------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2008-11-15 23:35 . 2008-07-06 12:06 575,488 --a------ c:\windows\system32\xpsshhdr.dll
2008-11-15 23:35 . 2008-07-06 12:06 575,488 --a------ c:\windows\system32\dllcache\xpsshhdr.dll
2008-11-15 23:35 . 2008-07-06 12:06 117,760 --a------ c:\windows\system32\prntvpt.dll
2008-11-15 23:35 . 2008-07-06 12:06 89,088 --a------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
2008-11-15 23:33 . 2008-11-15 23:39 <DIR> d-------- c:\windows\NV32401520.TMP
2008-11-15 23:33 . 2008-11-20 19:39 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-15 23:33 . 2008-10-07 13:33 201,157 --a------ c:\windows\system32\nvapps.nvb
2008-11-15 23:31 . 2008-11-15 23:31 <DIR> d-------- c:\program files\MSXML 6.0
2008-11-15 23:31 . 2008-11-15 23:31 <DIR> d-------- C:\NVIDIA
2008-11-15 23:27 . 2008-11-15 23:27 <DIR> d-------- c:\program files\SystemRequirementsLab
2008-11-15 23:27 . 2008-11-15 23:27 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\SystemRequirementsLab
2008-11-15 23:26 . 2008-11-15 23:26 <DIR> d-------- c:\windows\Sun
2008-11-15 13:22 . 2008-11-15 13:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2008-11-15 13:12 . 2008-11-15 13:12 <DIR> d-------- c:\program files\Wacom
2008-11-15 13:12 . 2000-11-22 11:40 1,682,273 --a------ c:\windows\system32\TabCP-En.znc
2008-11-15 13:12 . 2000-11-29 17:25 856,064 --a------ c:\windows\system32\Tablet.cpl
2008-11-15 13:12 . 2000-11-29 20:49 450,560 --a------ c:\windows\system32\Tablet.exe
2008-11-15 13:12 . 2000-11-29 20:49 90,112 --a------ c:\windows\system32\Wintab32.dll
2008-11-15 13:12 . 1999-12-21 15:53 53,248 --a------ c:\windows\system32\TabUnst.dll
2008-11-15 13:12 . 2000-11-29 20:49 49,152 --a------ c:\windows\system32\TabHook.dll
2008-11-15 13:12 . 2000-10-20 10:51 24,320 --a------ c:\windows\system32\drivers\penclass.sys
2008-11-15 13:12 . 1999-05-07 09:12 15,744 --a------ c:\windows\system32\wintab.dll
2008-11-15 13:12 . 2008-11-27 15:48 296 --a------ c:\windows\system32\wacom.dat
2008-11-15 13:11 . 2000-01-05 14:14 36,864 --a------ c:\windows\system32\pencls32.dll
2008-11-15 11:27 . 2008-11-15 11:27 <DIR> d-------- c:\program files\Bonjour
2008-11-15 11:24 . 2008-11-15 11:24 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2008-11-15 11:23 . 2008-11-15 11:23 236 --a------ C:\sqmdata03.sqm
2008-11-15 11:23 . 2008-11-15 11:23 200 --a------ C:\sqmnoopt03.sqm
2008-11-14 09:32 . 2008-11-14 09:32 236 --a------ C:\sqmdata02.sqm
2008-11-14 09:32 . 2008-11-14 09:32 200 --a------ C:\sqmnoopt02.sqm
2008-11-13 23:59 . 2008-11-13 23:59 236 --a------ C:\sqmdata01.sqm
2008-11-13 23:59 . 2008-11-13 23:59 200 --a------ C:\sqmnoopt01.sqm
2008-11-11 17:22 . 2008-11-11 17:22 <DIR> d-------- c:\program files\simplemu
2008-11-10 22:41 . 2008-11-10 22:42 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\vlc
2008-11-10 22:41 . 2008-11-19 16:48 <DIR> d-------- c:\documents and settings\Compaq_Administrator\Application Data\dvdcss
2008-11-10 22:39 . 2008-11-10 22:39 <DIR> d-------- c:\program files\VideoLAN
2008-11-10 21:13 . 2008-06-10 02:32 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-10 18:03 . 2008-11-10 18:49 <DIR> d-------- C:\illusion
2008-11-10 17:57 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 11:30 --------- d-----w c:\program files\Common Files\Adobe
2008-11-13 23:57 --------- d-----w c:\program files\Symantec
2008-11-13 23:57 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-13 23:57 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-11-10 21:13 --------- d-----w c:\program files\Java
2008-11-06 11:32 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-06 11:20 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 15:07 99,904 ----a-w c:\windows\system32\drivers\AnyDVD.sys
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 16:57 332,800 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-09-30 16:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\dllcache\win32k.sys
2008-09-09 00:03 51,712 ----a-w c:\windows\system32\sirenacm.dll
2008-09-04 16:42 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ----a-w c:\windows\system32\dllcache\msxml3.dll
2008-08-29 20:06 1,350,664 ----a-w c:\windows\system32\msxml6.dll
2008-08-28 10:04 333,056 ----a-w c:\windows\system32\dllcache\srv.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\Guest\WINDOWS ----
---- Directory of c:\documents and settings\Kim\Tracing ----
2008-11-20 10:23 0 --a------ c:\documents and settings\Kim\Tracing\WindowsLiveMessenger-uccapi-0.uccapilog
---- Directory of c:\documents and settings\Kim\WINDOWS ----
((((((((((((((((((((((((((((( snapshot@2008-11-22_16.14.08.68 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-22 00:28:36 343,424 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-11-24 18:50:28 345,016 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-10-16 14:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 14:09:44 43,544 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
+ 2008-11-27 15:48:23 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_1d8.dat
+ 2008-11-27 16:06:51 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_784.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-09-09 3513344]
"Google Update"="c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-06 133104]
"RocketDock"="j:\rocketdock\RocketDock.exe" [2007-09-02 495616]
"Steam"="c:\program files\Steam\Steam.exe" [2008-11-08 1410296]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"ftutil2"="ftutil2.dll" [2004-06-07 c:\windows\system32\ftutil2.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 c:\windows\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 c:\windows\arpwrmsg.exe]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]
"PCDrProfiler"="" [BU]
c:\documents and settings\Guest\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-09-01 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-09-01 27136]
c:\documents and settings\Kim\Start Menu\Programs\Startup\
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-09-01 27136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Launchy.lnk - c:\program files\Launchy\Launchy.exe [2008-11-27 286720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\\windows\\resources\\LoginUI\\logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifgEtuu]
[BU]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.3.game"=
"c:\\Program Files\\Steam\\steamapps\\rpowton\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\rpowton\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-20 110160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-20 20560]
R3 ZY202_XP;ZyXEL 802.11g XG202 1211 Driver;c:\windows\system32\DRIVERS\WlanUZXP.sys [2008-11-06 437760]
S3 AFGMp50;AFGMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\AFGMp50.sys []
S3 AFGSp50;AFGSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\AFGSp50.sys []
S3 ZDCNDIS5;ZDCNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS []
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-27 20:17:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-27 20:18:41
ComboFix-quarantined-files.txt 2008-11-27 20:18:38
ComboFix2.txt 2008-11-22 16:14:41
Pre-Run: 86,129,291,264 bytes free
Post-Run: 86,116,220,928 bytes free
270 --- E O F --- 2008-11-16 21:01:22
HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:25:21, on 27/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ad-Aware\aawservice.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
J:\RocketDock\RocketDock.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Start Killer\StartKiller.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\7-Zip\7zFM.exe
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\kurry.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {25401087-D0F5-4157-B9C0-A6C4E261B021} - (no file)
O2 - BHO: (no name) - {4E007A5F-299F-44FC-8B6B-F06B61867A2E} - (no file)
O2 - BHO: (no name) - {70DFDC90-21D2-4DC4-B66D-D0430B6CC90D} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B2594244-C6CC-4EA9-B497-F15845196C9B} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [RocketDock] "J:\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: iifgEtuu - C:\WINDOWS\
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
--
End of file - 8432 bytes
Thanks for the help again
