this is the results of combofix AFTER i ran CCleaner ( i did not do the register part of CCleaner. i did not get a response about wether or not i have to worry about the program deleting or adjusting something it shouldn't have.
ComboFix 07-10-20.6 - admin 2007-10-21 13:07:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.286 [GMT -5:00]
Running from: C:\Documents and Settings\admin\Desktop\FlashGet\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\info.txt
C:\WINDOWS\system32\LMIinit.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((( Files Created from 2007-09-21 to 2007-10-21 )))))))))))))))))))))))))))))))
.
2007-10-21 13:05 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-19 13:44 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-19 11:16 <DIR> d-------- C:\Program Files\Common Files\EZB Systems
2007-10-17 14:28 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2007-10-17 14:24 <DIR> d-------- C:\Program Files\Microsoft Works
2007-10-17 14:19 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-10-17 14:15 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2007-10-17 14:13 <DIR> dr-h----- C:\MSOCache
2007-10-17 14:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-17 13:49 <DIR> d-------- C:\Program Files\UltraISO
2007-10-17 13:31 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Nero
2007-10-17 13:29 <DIR> d-------- C:\Program Files\Common Files\Nero
2007-10-17 13:28 <DIR> d-------- C:\Program Files\Nero 8.0.3.0 Lite
2007-10-17 11:18 <DIR> d-------- C:\Program Files\WexTech
2007-10-17 11:18 <DIR> d-------- C:\Program Files\Common Files\WexTech Shared
2007-10-17 11:18 <DIR> d-------- C:\Program Files\Common Files\LHSPF
2007-10-17 11:18 111,616 --a------ C:\WINDOWS\system32\Ltih30tb.dll
2007-10-17 11:14 <DIR> d-------- C:\Program Files\Borland
2007-10-17 11:14 93,184 --------- C:\WINDOWS\system32\LTIH21TB.DLL
2007-10-17 11:13 <DIR> d-------- C:\Program Files\Corel
2007-10-17 11:13 1,213,440 --------- C:\WINDOWS\system32\opengl.dll
2007-10-17 11:13 315,904 --------- C:\WINDOWS\system32\glu.dll
2007-10-17 11:13 154,624 --------- C:\WINDOWS\system32\glut.dll
2007-10-17 10:55 <DIR> d-------- C:\WINDOWS\Corel
2007-10-10 08:13 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-04 16:05 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-10-04 16:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-04 14:28 <DIR> d-------- C:\Program Files\FlashGet
2007-10-03 10:34 <DIR> d-------- C:\Program Files\TerraGo Technologies
2007-10-03 10:34 <DIR> d-------- C:\Program Files\Common Files\TerraGo
2007-10-03 10:34 54,784 --a------ C:\WINDOWS\system32\mgc32.dll
2007-09-28 14:40 <DIR> d-------- C:\Program Files\CCleaner
2007-09-28 11:52 <DIR> d-------- C:\Documents and Settings\admin\Contacts
2007-09-28 11:50 <DIR> d-------- C:\Program Files\MSN Messenger
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-21 18:15 5,444,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-21 18:13 73,964 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-21 13:22 --------- d-----w C:\Program Files\LogMeIn
2007-10-17 19:48 --------- d-----w C:\Program Files\Palm
2007-10-17 19:23 --------- d-----w C:\Program Files\MSBuild
2007-10-12 14:13 98,520 ----a-w C:\Documents and Settings\admin\Application Data\GDIPFONTCACHEV1.DAT
2007-10-04 21:05 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-03 15:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-01 20:20 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0
2007-09-18 19:59 --------- d-----w C:\Program Files\Chapura
2007-09-18 19:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2007-09-18 19:54 --------- d-----w C:\Documents and Settings\admin\Application Data\OfficeUpdate12
2007-09-14 19:49 --------- d-----w C:\Documents and Settings\admin\Application Data\Apple Computer
2007-09-14 19:34 --------- d-----w C:\Program Files\iTunes
2007-09-14 19:33 --------- d-----w C:\Program Files\QuickTime
2007-09-14 19:33 --------- d-----w C:\Program Files\iPod
2007-09-14 19:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-09-14 19:31 --------- d-----w C:\Program Files\Apple Software Update
2007-09-14 19:30 --------- d-----w C:\Program Files\Common Files\Apple
2007-09-14 19:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-14 13:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2007-09-13 21:49 --------- d-----w C:\Documents and Settings\admin\Application Data\Leadertech
2007-09-12 21:53 --------- d-----w C:\Documents and Settings\admin\Application Data\Autodesk
2007-09-12 21:44 --------- d-----w C:\Program Files\Revit Architecture 2008
2007-09-12 21:44 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2007-09-12 21:28 --------- d-----w C:\Program Files\SonicWallES
2007-09-12 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-09-12 21:28 --------- d-----w C:\Documents and Settings\admin\Application Data\MailFrontier
2007-09-12 20:45 --------- d-----w C:\Program Files\Reference Assemblies
2007-09-12 20:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2007-09-12 20:28 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-09-12 20:28 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2007-09-12 20:28 --------- d-----w C:\Program Files\Motorola Phone Tools
2007-09-12 20:27 --------- d-----w C:\Program Files\Common Files\Motorola Shared
2007-09-12 20:22 --------- d-----w C:\Program Files\Avanquest update
2007-09-12 20:22 --------- d-----w C:\Documents and Settings\admin\Application Data\InstallShield
2007-09-12 20:02 92,064 ----a-w C:\Documents and Settings\admin\mqdmmdm.sys
2007-09-12 20:02 9,232 ----a-w C:\Documents and Settings\admin\mqdmmdfl.sys
2007-09-12 20:02 79,328 ----a-w C:\Documents and Settings\admin\mqdmserd.sys
2007-09-12 20:02 66,656 ----a-w C:\Documents and Settings\admin\mqdmbus.sys
2007-09-12 20:02 6,208 ----a-w C:\Documents and Settings\admin\mqdmcmnt.sys
2007-09-12 20:02 5,936 ----a-w C:\Documents and Settings\admin\mqdmwhnt.sys
2007-09-12 20:02 4,048 ----a-w C:\Documents and Settings\admin\mqdmcr.sys
2007-09-12 20:02 25,600 ----a-w C:\WINDOWS\system32\drivers\usbsermptxp.sys
2007-09-12 20:02 25,600 ----a-w C:\Documents and Settings\admin\usbsermptxp.sys
2007-09-12 20:02 22,768 ----a-w C:\Documents and Settings\admin\usbsermpt.sys
2007-09-12 20:02 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-09-12 20:00 --------- d-----w C:\Documents and Settings\admin\Application Data\MSN6
2007-09-12 13:49 --------- d-----w C:\Program Files\MSXML 6.0
2007-09-12 13:43 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-09-11 20:48 --------- d-----w C:\Program Files\AutoCAD 2007
2007-09-11 20:48 --------- d-----w C:\Program Files\AnswerWorks 4.0
2007-09-11 20:34 --------- d-----w C:\Program Files\AutoCAD 2008
2007-09-11 20:23 --------- d-----w C:\Program Files\Autodesk
2007-09-11 19:18 --------- d-----w C:\Program Files\Common Files\Caere
2007-09-11 19:13 --------- d-----w C:\Program Files\Wine Country Gift Baskets
2007-09-06 21:14 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2007-08-15 16:45 524,288 ----a-w C:\WINDOWS\opuc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-03-27 03:34 C:\WINDOWS\SOUNDMAN.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2005-03-08 06:42]
"Cmaudio"="cmicnfg.cpl" []
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 16:55]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 23:24]
"QuickBooksDB"="C:\Program Files\Intuit\QuickBooks Enterprise Solutions 5.0\QBDBMgrN.exe" [2005-10-20 10:54]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2007-10-04 16:04:43]
Adobe Acrobat Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 00:01:50]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe [2006-03-05 07:43:54]
R1 ATMhelpr;ATMhelpr;C:\WINDOWS\system32\drivers\ATMhelpr.sys
R1 ISODrive;ISO DVD/CD-ROM Device Driver;\??\C:\Program Files\UltraISO\drivers\ISODrive.sys
R2 LMIInfo;LogMeIn Kernel Information Provider;\??\C:\Program Files\LogMeIn\x86\RaInfo.sys
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys
R3 lmimirr;lmimirr;C:\WINDOWS\system32\DRIVERS\lmimirr.sys
S3 4mmdat;4mmdat;C:\WINDOWS\system32\DRIVERS\4mmdat.sys
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys
S3 qic157;qic157;C:\WINDOWS\system32\DRIVERS\qic157.sys
S3 usbsermptxp;Motorola USB Modem Driver for MPT XP;C:\WINDOWS\system32\DRIVERS\usbsermptxp.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{36a91826-5af4-11dc-95ab-000fea13711f}]
AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-10-21 05:00:00 C:\WINDOWS\Tasks\back-up.job"
- C:\WINDOWS\system32\ntbackup.exe
"2007-10-20 02:34:00 C:\WINDOWS\Tasks\BACKUP.job"
- C:\WINDOWS\system32\ntbackup.exe
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-21 13:15:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-21 13:19:13 - machine was rebooted
.
--- E O F ---