Sorry, here you go:
ComboFix 08-06-07.1 - Administrator 2008-06-07 19:07:38.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.183 [GMT -4:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\blphcll0j0eecl.scr
C:\WINDOWS\system32\lphcll0j0eecl.exe
C:\WINDOWS\system32\phcll0j0eecl.bmp
.
((((((((((((((((((((((((( Files Created from 2008-05-07 to 2008-06-07 )))))))))))))))))))))))))))))))
.
2008-06-04 13:12 . 2008-06-04 13:12 <DIR> d-------- C:\Deckard
2008-06-04 13:07 . 2008-06-04 13:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-04 13:02 . 2008-06-04 13:02 <DIR> d-------- C:\ie-spyad_zo
2008-06-04 13:01 . 2008-06-04 13:10 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-06-04 13:01 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-06-04 11:00 . 2008-06-04 11:00 <DIR> d-------- C:\Program Files\Panda Security
2008-06-03 16:52 . 2008-06-07 19:05 121 --a------ C:\WINDOWS\bdagent.INI
2008-06-03 16:48 . 2008-06-03 16:48 <DIR> d-------- C:\Program Files\BitDefender
2008-06-03 16:48 . 2008-06-03 16:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-06-03 16:48 . 2008-06-03 16:48 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Bitdefender
2008-06-03 16:46 . 2008-04-12 19:17 143,200 --a------ C:\bitdefender_antivirus.exe
2008-06-03 16:45 . 2008-06-03 16:48 <DIR> d-------- C:\Program Files\Common Files\BitDefender
2008-06-02 14:25 . 2008-06-02 14:25 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\shcjl0j0eecl
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-07 19:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-03 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-06-03 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-06-03 13:16 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVG7
2008-05-08 17:37 --------- d-----w C:\Program Files\LimeWire
2008-05-06 14:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-06 14:19 --------- d-----w C:\Program Files\Veoh Networks
2008-05-06 14:18 21,452,040 ----a-w C:\VeohSetup-3.9.3.1029.exe
2008-04-24 04:08 --------- d-----w C:\Program Files\Apple Software Update
2008-04-24 03:47 --------- d-----w C:\Program Files\iTunes
2008-04-24 03:46 --------- d-----w C:\Program Files\iPod
2008-04-24 03:45 --------- d-----w C:\Program Files\QuickTime
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- C:\bitdefender_antivirus.exe ----
Company: Microsoft Corporation
File Description: Win32 Cabinet Self-Extractor
File Version: 6.00.3790.0 (srv03_rtm.030324-2048)
Product Name: Microsoftr Windowsr Operating System
Copyright: c Microsoft Corporation. All rights reserved.
Original file name: WEXTRACT.EXE
MD5: 81b8759495b2010b890239667d2ca2b1
---- Directory of C:\Documents and Settings\Administrator\Application Data\shcjl0j0eecl ----
((((((((((((((((((((((((((((( snapshot@2008-06-07_16.45.08.80 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-07 20:31:56 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-07 22:59:38 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2003-08-20 20:24 151552]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-29 13:30 335872]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-08 16:31 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-08 16:27 126976]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 02:05 122939]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 04:23 75520]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2005-02-07 15:00 98304]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 15:46 61440]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-02-16 17:45 360448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"@"="" []
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Clean Access Agent.lnk - C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe [2007-01-30 01:09:24 1941584]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)
"NoAutoTrayNotify"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2004-04-26 09:04 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
---h----- 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2004-01-07 02:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"MDM"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"50001:TCP"= 50001:TCP:webroots
"50002:TCP"= 50002:TCP:webroots2
"8192:TCP"= 8192:TCP:Sophos
"8193:TCP"= 8193:TCP:sophos1
"8194:TCP"= 8194:TCP:sophos
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
S2 ousbehci;NEC PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ousbehci.sys [2003-08-01 07:45]
S3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 23:26]
S3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;C:\WINDOWS\system32\DRIVERS\ousb2hub.sys [2003-08-01 07:45]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c4f3f4e1-2c11-11d9-8305-806d6172696f}]
\Shell\AutoRun\command - D:\Programs\nu2menu\nu2menu.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-02 21:54:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-03 07:00:00 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.exe
- C:\Program Files\SpywareBot
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-07 19:09:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-06-07 19:12:13
ComboFix-quarantined-files.txt 2008-06-07 23:11:38
ComboFix2.txt 2008-06-07 20:46:08
Pre-Run: 25,698,553,856 bytes free
Post-Run: 25,684,561,920 bytes free
155 --- E O F --- 2008-05-29 00:01:44