I am not sure what I did wrong.... but I figured something was up so i ran CF again, and this time it ran like described in the guide.
Here is a C&P of the log it created:
ComboFix 08-03-14.4 - Admin 2008-03-16 20:26:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.647 [GMT -4:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Bailey\Application Data\CROSOF~1
C:\Documents and Settings\Bailey\Application Data\CROSOF~1.NET
C:\Documents and Settings\Bailey\Application Data\CURITY~1
C:\Documents and Settings\Bailey\Application Data\CURITY~1\s?oolsv.exe
C:\Documents and Settings\Bailey\Application Data\DOBE~1
C:\Documents and Settings\Bailey\Application Data\FNTS~1
C:\Documents and Settings\Bailey\Application Data\MANTEC~1
C:\Documents and Settings\Bailey\Application Data\SEMBLY~1
C:\Documents and Settings\Bailey\Application Data\STEM32~1
C:\Documents and Settings\Bailey\Application Data\WNSXS~1
C:\Documents and Settings\Bailey\My Documents\APPATC~1
C:\Documents and Settings\Bailey\My Documents\CROSOF~1.NET
C:\Documents and Settings\Bailey\My Documents\DOBE~1
C:\Documents and Settings\Bailey\My Documents\FNTS~1
C:\Documents and Settings\Bailey\My Documents\PPPATC~1
C:\Documents and Settings\Bailey\My Documents\SMANTE~1
C:\Program Files\asks~1
C:\Program Files\Common Files\{34572~1
C:\Program Files\Common Files\{84572~1
C:\Program Files\Common Files\crosof~1
C:\Program Files\Common Files\crosof~1.net
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\mbols~1
C:\Program Files\Common Files\mcroso~1.net
C:\Program Files\Common Files\scurit~1
C:\Program Files\Common Files\sembly~1
C:\Program Files\Common Files\smbols~1
C:\Program Files\Common Files\ssembl~1
C:\Program Files\Common Files\sstem~1
C:\Program Files\Common Files\tsks~1
C:\Program Files\Common Files\ymante~1
C:\Program Files\Common Files\ymbols~1
C:\Program Files\crosof~1
C:\Program Files\dobe~1
C:\Program Files\ecurit~1
C:\Program Files\fnts~1
C:\Program Files\JavaCore
C:\Program Files\JavaCore\JavaCore.exe
C:\Program Files\JavaCore\UnInstall.exe
C:\Program Files\NoDNS
C:\Program Files\outerinfo
C:\Program Files\ppatch~1
C:\Program Files\pppatc~1
C:\Program Files\pppatc~1\?ppPatch\
C:\Program Files\racle~1
C:\Program Files\sstem~1
C:\Program Files\sstem3~1
C:\Program Files\Temporary
C:\Program Files\tsks~1
C:\Program Files\tsks~1\T?sks\
C:\Program Files\ystem~1
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\temp\tn3
C:\WINDOWS\asks~1
C:\WINDOWS\asks~2
C:\WINDOWS\BM87641259.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\crosof~1
C:\WINDOWS\curity~1
C:\WINDOWS\dobe~1
C:\WINDOWS\dobe~2
C:\WINDOWS\ecurit~1
C:\WINDOWS\fnts~1
C:\WINDOWS\fnts~1\d?dplay.exe
C:\WINDOWS\icroso~1
C:\WINDOWS\pppatc~1
C:\WINDOWS\pskt.ini
C:\WINDOWS\smante~1
C:\WINDOWS\smbols~1
C:\WINDOWS\ssembl~1
C:\WINDOWS\sstem3~1
C:\WINDOWS\system32\c2
C:\WINDOWS\system32\c4
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\drivers\fsvgaa.sys
C:\WINDOWS\system32\enhsbbtn.dll
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\hwyvepim.dll
C:\WINDOWS\system32\icroso~1
C:\WINDOWS\system32\icroso~1.net
C:\WINDOWS\system32\iDlo01
C:\WINDOWS\system32\jmllm.ini
C:\WINDOWS\system32\jmllm.ini2
C:\WINDOWS\system32\jyiiyrtp.ini
C:\WINDOWS\system32\k8
C:\WINDOWS\system32\mantec~1
C:\WINDOWS\system32\mbols~1
C:\WINDOWS\System32\mllmj.dll
C:\WINDOWS\system32\nptqkigh.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\ppatch~1
C:\WINDOWS\system32\ptryiiyj.dll
C:\WINDOWS\system32\racle~1
C:\WINDOWS\system32\racle~2
C:\WINDOWS\system32\s7
C:\WINDOWS\system32\s7\gbsu011.exe
C:\WINDOWS\system32\sblnycuq.dll
C:\WINDOWS\system32\tsks~1
C:\WINDOWS\system32\uxtvqwqw.ini
C:\WINDOWS\system32\wnstssv.exe
C:\WINDOWS\system32\wnsxs~1
C:\WINDOWS\system32\wqwqvtxu.dll
C:\WINDOWS\system32\x3
C:\WINDOWS\system32\ystem~1
C:\WINDOWS\wnsxs~1
C:\WINDOWS\ymante~1
C:\WINDOWS\ymbols~1
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CMDSERVICE
-------\LEGACY_FSVGAA
-------\LEGACY_NETWORK_MONITOR
-------\fsvgaa
((((((((((((((((((((((((( Files Created from 2008-02-17 to 2008-03-17 )))))))))))))))))))))))))))))))
.
2008-03-14 06:13 . 2008-03-14 06:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-14 06:12 . 2008-03-14 06:12 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-14 06:00 . 2008-03-14 06:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-03-14 04:14 . 2008-03-14 04:14 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-14 04:14 . 2008-03-14 04:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-14 01:59 . 2008-03-16 20:29 4,406 --a------ C:\WINDOWS\system32\Config.MPF
2008-03-14 01:56 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-03-14 01:53 . 2008-02-06 09:51 171,400 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-03-14 01:53 . 2007-06-25 14:54 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-03-14 01:53 . 2007-06-25 10:57 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-03-14 01:53 . 2007-06-25 10:57 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-03-14 01:53 . 2007-06-25 10:57 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-03-14 01:52 . 2007-03-02 14:16 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-03-14 01:51 . 2008-03-14 01:52 <DIR> d-------- C:\Program Files\McAfee.com
2008-03-14 01:51 . 2008-03-14 02:01 <DIR> d-------- C:\Program Files\McAfee
2008-03-14 01:51 . 2008-03-14 01:56 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-03-14 01:16 . 2008-03-14 01:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-03-14 01:02 . 2008-03-14 01:02 <DIR> dr-h----- C:\Documents and Settings\Administrator\Application Data\yahoo!
2008-03-14 00:44 . 2007-12-06 22:21 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-14 00:44 . 2007-06-30 23:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-14 00:44 . 2007-06-30 23:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-14 00:44 . 2007-12-06 22:21 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-14 00:44 . 2007-12-06 22:21 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-14 00:44 . 2007-12-06 22:21 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-14 00:44 . 2007-12-06 22:21 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-14 00:44 . 2007-12-06 22:21 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-14 00:44 . 2007-12-06 07:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-14 00:40 . 2007-08-13 19:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-03-14 00:18 . 2007-07-09 09:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-03-13 23:45 . 2008-03-14 00:58 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-03-13 23:29 . 2004-08-04 03:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-03-13 23:27 . 2008-03-13 23:27 <DIR> d-------- C:\WINDOWS\provisioning
2008-03-13 23:27 . 2008-03-13 23:27 <DIR> d-------- C:\WINDOWS\peernet
2008-03-13 23:26 . 2008-03-13 23:26 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-03-13 23:22 . 2006-09-06 18:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-13 23:20 . 2008-03-13 23:20 <DIR> d-------- C:\WINDOWS\EHome
2008-03-13 23:17 . 2004-08-04 01:56 11,776 --a------ C:\WINDOWS\system32\spnpinst.exe
2008-03-13 23:17 . 2004-08-02 15:20 7,208 --a------ C:\WINDOWS\system32\secupd.sig
2008-03-13 23:17 . 2004-08-02 15:20 4,569 --a------ C:\WINDOWS\system32\secupd.dat
2008-03-13 23:06 . 2008-03-13 23:06 215 --a------ C:\WINDOWS\system32\MRT.INI
2008-03-13 23:02 . 2004-08-04 03:56 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2008-03-13 23:02 . 2004-08-04 03:56 331,264 --a------ C:\WINDOWS\system32\ipnathlp.dll
2008-03-13 23:02 . 2004-08-04 03:56 265,728 --a------ C:\WINDOWS\system32\h323.tsp
2008-03-13 23:02 . 2004-08-04 03:56 77,312 --a------ C:\WINDOWS\system32\browser.dll
2008-03-13 23:02 . 2007-03-08 11:36 40,960 --a------ C:\WINDOWS\system32\mf3216.dll
2008-03-13 22:56 . 2004-08-04 03:56 239,104 --a------ C:\WINDOWS\system32\srrstr.dll
2008-03-13 22:52 . 2008-03-13 23:01 <DIR> d--h-c--- C:\WINDOWS\$xpsp1hfm$
2008-03-13 22:52 . 2008-03-13 22:52 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-03-13 22:52 . 2004-01-10 01:11 26,112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe
2008-03-13 22:44 . 2008-03-13 22:44 <DIR> d-------- C:\WINDOWS\system32\bits
2008-03-08 00:02 . 2008-03-08 00:02 <DIR> d--hs---- C:\Documents and Settings\Administrator\UserData
2008-03-08 00:02 . 2004-08-04 03:56 438,784 --a------ C:\WINDOWS\system32\xpob2res.dll
2008-03-08 00:02 . 2004-08-04 03:56 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2008-03-08 00:02 . 2004-08-04 03:56 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-03-08 00:02 . 2004-08-04 03:56 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2008-03-08 00:02 . 2004-08-04 03:56 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2008-03-07 23:04 . 2008-03-07 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Citrix
2008-03-07 23:01 . 2008-03-07 23:01 61,224 --a------ C:\Documents and Settings\Bailey\GoToAssistDownloadHelper.exe
2008-03-07 22:05 . 2008-03-13 23:58 20,480 --a------ C:\WINDOWS\quit.exe
2008-03-07 22:01 . 2008-03-07 22:01 <DIR> d-------- C:\WINDOWS\McAfee.com
2008-03-07 21:41 . 2008-03-14 01:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-03-07 21:41 . 2008-03-14 21:08 2,430 --a------ C:\WINDOWS\WinInit.Ini
2008-03-05 22:34 . 2008-03-07 10:37 0 --ahs---- C:\Documents and Settings\Bailey\Application Data\
0047cf333f146ee683017927e4c506bb6ccc0fb8840ba1e2bc.dat
2008-03-05 19:56 . 2008-03-05 19:54 13,824 --a------ C:\Documents and Settings\Bailey\Application Data\evjhv.exe
2008-03-05 19:54 . 2008-03-05 19:54 13,824 --a------ C:\2107xg.exe
2008-03-05 19:50 . 2008-03-14 03:30 <DIR> d--hs---- C:\WINDOWS\U2hpcGxleTI
2008-03-05 19:50 . 2008-03-14 05:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-05 19:49 . 2008-03-05 19:50 167,545 --------- C:\WINDOWS\system32\drivers\core.cache.dsk
2008-03-05 19:45 . 2008-03-05 19:45 <DIR> d-------- C:\WINDOWS\Sun
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-14 10:14 --------- d-----w C:\Program Files\Lavasoft
2008-03-14 10:14 --------- d-----w C:\Documents and Settings\Bailey\Application Data\Lavasoft
2008-03-14 09:03 --------- d-----w C:\Program Files\Sync Manager
2008-03-14 08:09 --------- d-----w C:\Program Files\Opera
2008-03-08 04:01 --------- d--h--w C:\Documents and Settings\Administrator\Application Data\Gtek
2008-02-28 21:38 --------- d-----w C:\Documents and Settings\Bailey\Application Data\LimeWire
2008-02-06 00:44 --------- d-----w C:\Program Files\MySpace
2008-02-06 00:44 --------- d-----w C:\Program Files\AIM
2008-02-06 00:44 --------- d-----w C:\Documents and Settings\Bailey\Application Data\Aim
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"Eecmlk"="C:\WINDOWS\F?nts\d?dplay.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2004-08-04 03:56 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmnkk]
pmnmnkk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvutttr]
wvutttr.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Bailey^Start Menu^Programs^Startup^Morpheus.lnk]
path=C:\Documents and Settings\Bailey\Start Menu\Programs\Startup\Morpheus.lnk
backup=C:\WINDOWS\pss\Morpheus.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Bailey^Start Menu^Programs^Startup^RABCO - Auto Update.lnk]
path=C:\Documents and Settings\Bailey\Start Menu\Programs\Startup\RABCO - Auto Update.lnk
backup=C:\WINDOWS\pss\RABCO - Auto Update.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\845721c5]
C:\WINDOWS\System32\ptryiiyj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-07-13 22:10 339968 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM87641259]
C:\WINDOWS\System32\nptqkigh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMon]
C:\WINDOWS\System32\CTF\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2006-08-28 22:57 395776 C:\Program Files\Dell Support\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ehss]
C:\PROGRA~1\PPPATC~1\tracert.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IESet]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ifbqnhk]
C:\Program Files\Common Files\?ssembly\t?skmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]
C:\Program Files\ipwins\ipwins.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-02-23 16:45 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JavaCore]
C:\Program Files\\JavaCore\\JavaCore.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Windows Adapter 5.1.3214]
--a------ 2008-03-05 19:54 13824 C:\Documents and Settings\Bailey\Application Data\evjhv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2004-06-18 01:24 53248 C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
--a------ 2004-06-18 01:24 131072 C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NoDNS]
C:\Program Files\\NoDNS\\NoDNS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nvcoi]
C:\Program Files\nvcoi\nvcoi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
--a------ 2005-02-25 20:28 212992 C:\PROGRA~1\Nero\data\xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Qbdopmwc]
C:\WINDOWS\?asks\?ervices.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Qqg]
C:\Documents and Settings\Bailey\Application Data\??curity\s?oolsv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-11-07 19:14 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2003-10-31 20:42 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ruiz]
C:\PROGRA~1\COMMON~1\ruiz\ruizm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu572.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6w]
C:\Documents and Settings\Bailey\Application Data\Microsoft\Windows\cicflxj.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2004-10-14 15:42 1404928 C:\Program Files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-10-12 04:10 49263 C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Agent]
C:\Program Files\Sync Manager\agent\syncagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uypbfqt]
C:\Program Files\Common Files\?ssembly\??anregw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebBuying]
C:\Program Files\Web Buying\v1.8.8\webbuying.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTouch]
C:\Documents and Settings\Bailey\Application Data\WinTouch\WinTouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-01-19 13:49 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zxxy]
C:\WINDOWS\system32\?dobe\l?gonui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"MDM"=2 (0x2)
"helpsvc"=2 (0x2)
"Browser"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-03-15 05:40:33 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-03-14 05:52:20 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-16 20:31:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-03-16 20:32:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-17 00:32:52
.
2008-03-14 02:45:16 --- E O F ---