PCB,
Sorry I had to eat dinner and Windows did somethings that had to be restarted three times. Here's the Combofix txt.
omboFix 09-08-22.06 - Colin L. Williams 08/23/2009 16:01.1.1 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.382 [GMT -4:00]
Running from: c:\documents and settings\Colin L. Williams\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Colin L. Williams\Local Settings\Temporary Internet Files\13050b8a.bmp
c:\documents and settings\Colin L. Williams\Local Settings\Temporary Internet Files\35050aec.bmp
c:\documents and settings\Colin L. Williams\Local Settings\Temporary Internet Files\index.dat
c:\windows\Fonts\Wphv07nb.ttf
c:\windows\Installer\9e14d.msp
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\ESQULtacxivdjbvxtevxfqpatsqtgekpkpjtv.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\ESQULalqeaxvmtkiqennbsmpmfwmiqqkerjke.dll
c:\windows\system32\ESQULpphyfppbnrjrfwsinwbmerjponqickir.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ESQULserv.sys
-------\Legacy_ESQULserv.sys
-------\Service_ESQULserv.sys
((((((((((((((((((((((((( Files Created from 2009-07-23 to 2009-08-23 )))))))))))))))))))))))))))))))
.
2009-08-23 15:43 . 2009-08-23 16:24 -------- d-----w- c:\program files\Malwarebytes'Anti-Malware
2009-08-22 22:48 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 22:48 . 2009-08-22 22:48 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-08-22 22:48 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-20 22:14 . 2009-08-20 22:14 -------- d-----w- c:\program files\Trend Micro
2009-08-20 21:38 . 2009-08-20 21:38 -------- d-----w- C:\ERDNT
2009-08-20 21:37 . 2009-08-20 21:37 -------- d-----w- c:\windows\ERUNT
2009-08-20 21:37 . 2009-08-20 21:38 -------- d-----w- C:\!FixIEDef
2009-08-19 01:05 . 2009-08-19 01:05 -------- d-----w- c:\documents and settings\Colin L. Williams\Application Data\Bin
2009-08-19 00:57 . 2009-08-19 00:57 137 ----a-w- c:\windows\tsiwinfile.dat
2009-08-19 00:57 . 2009-08-19 00:57 -------- d-----w- c:\windows\AntiSpy
2009-08-19 00:47 . 2009-08-19 00:47 -------- d-----w- c:\program files\Ashampoo
2009-08-19 00:43 . 2009-08-19 00:54 -------- d-----w- c:\program files\Defender Pro
2009-08-12 21:10 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-06 21:13 . 2009-08-18 20:22 -------- d-----w- c:\program files\Carbonite
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-23 18:47 . 2008-12-11 02:46 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Google Updater
2009-08-23 01:21 . 2009-06-13 20:48 -------- d-----w- c:\program files\Bonjour
2009-08-22 21:35 . 2005-03-04 20:21 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-20 21:01 . 2007-11-28 00:04 -------- d-----w- c:\program files\Google
2009-08-19 20:52 . 2005-03-06 05:21 71624 ----a-w- c:\documents and settings\Colin L. Williams\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-18 22:53 . 2009-06-13 18:18 -------- d-----w- c:\documents and settings\Colin L. Williams\Application Data\LimeWire
2009-08-18 21:40 . 2005-03-04 15:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-06 21:12 . 2005-03-11 02:06 -------- d-----w- c:\program files\Java
2009-08-05 09:01 . 2003-07-16 20:37 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-25 09:23 . 2008-11-28 14:38 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2003-07-16 20:24 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 07:56 286208 ------w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2004-12-08 00:37 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2003-07-16 20:25 17408 ------w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2003-07-16 20:47 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2003-07-16 20:28 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2003-07-16 20:47 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2003-07-16 20:24 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2005-03-04 06:19 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2003-07-16 20:52 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-05 15:42 . 2009-06-13 20:57 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 15:42 . 2009-01-19 17:30 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-03 19:09 . 2003-07-16 20:42 1291264 ----a-w- c:\windows\system32\quartz.dll
2005-04-06 01:43 . 2005-04-06 01:43 336644 ------w- c:\program files\ClnBBear.zip
2005-04-05 14:31 . 2005-04-05 14:31 381959 ------w- c:\program files\ClnAbot.zip
2005-03-28 23:00 . 2005-03-28 23:00 21848504 ------w- c:\program files\iTunesSetup.exe
2005-03-07 13:56 . 2005-03-07 13:56 4424776 ------w- c:\program files\EZAntivirus.exe
2005-03-04 19:59 . 2005-03-04 19:59 2636408 ----a-w- c:\program files\aawsepersonal.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-11 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-11-08 294912]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-05-03 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-05-03 610304]
"Omnipage"="c:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 49152]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-12 196608]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-05 28672]
"BCMSMMSG"="BCMSMMSG.exe" - c:\windows\BCMSMMSG.exe [2003-08-29 122880]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
c:\documents and settings\Colin L. Williams\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2006-7-27 225280]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
NkvMon.exe.lnk - c:\program files\Nikon\NkView6\NkvMon.exe [2005-3-4 237568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\ScanSoft\\OmniPageSE\\EregEng\\NAVBrowser.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
S2 icservice;icservice;c:\program files\Aladdin Systems\Internet Cleanup\icserv.exe [4/14/2003 2:35 PM 32768]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-23 16:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(512)
c:\windows\system32\WININET.dll
.
Completion time: 2009-08-23 16:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-23 20:46
Pre-Run: 14,290,604,032 bytes free
Post-Run: 14,247,251,968 bytes free
153 --- E O F --- 2009-08-12 21:50