here's a report combofix generated. is this what i was supposed to post?
ComboFix 08-03-17.1 - Eve 2008-03-17 17:36:01.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.855 [GMT -5:00]
Running from: C:\Documents and Settings\Eve\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-02-17 to 2008-03-17 )))))))))))))))))))))))))))))))
.
2008-03-17 16:50 . 2008-03-17 16:50 <DIR> d----c--- C:\WINDOWS\LastGood
2008-03-15 19:18 . 2008-03-15 19:18 <DIR> d----c--- C:\Program Files\Trend Micro
2008-03-15 18:29 . 2006-03-18 06:09 613,376 --a--c--- C:\WINDOWS\system32\XFlower.dll
2008-03-13 16:35 . 2008-03-13 16:35 <DIR> d----c--- C:\Program Files\Windows Sidebar
2008-03-13 16:35 . 2008-03-13 16:40 <DIR> d----c--- C:\Program Files\Norton AntiVirus
2008-03-13 16:35 . 2008-03-13 16:36 123,952 --a--c--- C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-13 16:35 . 2008-03-13 16:36 60,800 --a--c--- C:\WINDOWS\system32\S32EVNT1.DLL
2008-03-13 16:35 . 2008-03-13 16:36 10,563 --a--c--- C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-03-13 16:35 . 2008-03-13 16:36 805 --a--c--- C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-03-13 13:21 . 2008-03-13 13:21 <DIR> d----c--- C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2008-02-28 13:28 . 2005-07-19 23:05 135,168 --a--c--- C:\WINDOWS\system32\igfxres.dll
2008-02-28 13:27 . 2007-12-04 08:04 837,496 --a--c--- C:\WINDOWS\system32\aswBoot.exe
2008-02-28 13:27 . 2004-01-09 04:13 380,928 --a--c--- C:\WINDOWS\system32\actskin4.ocx
2008-02-28 13:27 . 2007-12-04 07:54 95,608 --a--c--- C:\WINDOWS\system32\AvastSS.scr
2008-02-28 13:21 . 2004-08-10 06:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-02-28 13:20 . 2004-08-10 06:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-02-28 13:19 . 2004-08-10 06:00 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-02-28 13:18 . 2008-02-28 13:18 316,640 --a--c--- C:\WINDOWS\WMSysPr9.prx
2008-02-28 13:18 . 2008-02-28 13:18 23,392 --a--c--- C:\WINDOWS\system32\nscompat.tlb
2008-02-28 13:18 . 2008-02-28 13:18 16,832 --a--c--- C:\WINDOWS\system32\amcompat.tlb
2008-02-28 13:18 . 2008-02-28 13:18 0 --a--c--- C:\WINDOWS\control.ini
2008-02-28 13:13 . 2008-02-28 13:13 749 -rah-c--- C:\WINDOWS\WindowsShell.Manifest
2008-02-28 13:13 . 2008-02-28 13:13 749 -rah-c--- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-02-28 13:13 . 2008-02-28 13:13 749 -rah-c--- C:\WINDOWS\system32\sapi.cpl.manifest
2008-02-28 13:13 . 2008-02-28 13:13 749 -rah-c--- C:\WINDOWS\system32\nwc.cpl.manifest
2008-02-28 13:13 . 2008-02-28 13:13 749 -rah-c--- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-02-28 13:13 . 2008-02-28 13:13 488 -rah-c--- C:\WINDOWS\system32\logonui.exe.manifest
2008-02-28 13:12 . 2004-08-10 06:00 188,416 --a--c--- C:\WINDOWS\system32\msh261.drv
2008-02-28 13:12 . 2004-08-10 06:00 118,784 --a--c--- C:\WINDOWS\system32\msg723.acm
2008-02-28 13:12 . 2004-08-10 06:00 48,680 ---hsc--- C:\WINDOWS\winnt256.bmp
2008-02-28 13:12 . 2004-08-10 06:00 48,680 ---hsc--- C:\WINDOWS\winnt.bmp
2008-02-28 13:12 . 2004-08-10 06:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-02-28 13:12 . 2004-08-10 06:00 2 --a--c--- C:\WINDOWS\system32\desktop.ini
2008-02-28 13:12 . 2004-08-10 06:00 2 --a--c--- C:\WINDOWS\desktop.ini
2008-02-28 13:07 . 2008-02-28 13:07 <DIR> d----c--- C:\WINDOWS\system32\FxsTmp
2008-02-28 13:07 . 2008-02-28 13:07 34,380 --a--c--- C:\WINDOWS\system32\emptyregdb.dat
2008-02-28 13:07 . 2008-02-28 13:07 37 --a--c--- C:\WINDOWS\vbaddin.ini
2008-02-28 13:07 . 2008-02-28 13:07 36 --a--c--- C:\WINDOWS\vb.ini
2008-02-28 13:05 . 2004-08-10 06:00 345,088 --a--c--- C:\WINDOWS\system32\hypertrm.dll
2008-02-28 12:55 . 2004-08-10 06:00 2,008,817 --a--c--- C:\WINDOWS\system32\dllcache\NT5.CAT
2008-02-28 12:54 . 2004-08-10 06:00 1,086,058 -ra--c--- C:\WINDOWS\SETD7.tmp
2008-02-28 12:54 . 2004-08-10 06:00 106,147 -ra--c--- C:\WINDOWS\SETD4.tmp
2008-02-28 12:54 . 2004-08-10 06:00 13,753 -ra--c--- C:\WINDOWS\SETE3.tmp
2008-02-28 07:49 . 2008-02-28 13:24 238 --a--c--- C:\WINDOWS\system32\$winnt$.inf
2008-02-24 20:33 . 2007-07-30 19:19 271,224 --a--c--- C:\WINDOWS\system32\mucltui.dll
2008-02-24 20:33 . 2007-07-30 19:19 30,072 --a--c--- C:\WINDOWS\system32\mucltui.dll.mui
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 21:56 --------- dc----w C:\Documents and Settings\Eve\Application Data\MailWasherPro
2008-03-15 18:06 --------- dc----w C:\Program Files\Common Files\Symantec Shared
2008-03-13 21:38 --------- dc----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-13 21:36 --------- dc----w C:\Program Files\Symantec
2008-03-13 20:38 --------- dc----w C:\Program Files\Spybot - Search & Destroy
2008-03-13 20:38 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-13 20:28 --------- dc----w C:\Documents and Settings\Eve\Application Data\Symantec
2008-03-13 20:27 --------- dc----w C:\Program Files\Azureus
2008-03-13 18:11 --------- dc----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-13 18:11 --------- dc----w C:\Documents and Settings\Eve\Application Data\SUPERAntiSpyware.com
2008-03-13 18:09 --------- dc----w C:\Program Files\CCleaner
2008-02-25 02:29 --------- dc----w C:\Documents and Settings\Eve\Application Data\Azureus
2008-02-08 23:29 --------- dc----w C:\Program Files\MSECACHE
2008-02-06 18:43 579,464 -c--a-w C:\WINDOWS\system32\SymNeti.dll
2008-02-06 18:43 31,408 -c--a-w C:\WINDOWS\system32\drivers\SymIM.sys
2008-02-06 18:43 207,240 -c--a-w C:\WINDOWS\system32\SymRedir.dll
2008-02-06 18:43 13,021 -c--a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2008-02-05 16:34 96,432 -c--a-w C:\WINDOWS\system32\drivers\symfw.sys
2008-02-05 16:34 41,008 -c--a-w C:\WINDOWS\system32\drivers\symndisv.sys
2008-02-05 16:34 38,576 -c--a-w C:\WINDOWS\system32\drivers\symids.sys
2008-02-05 16:34 37,424 -c--a-w C:\WINDOWS\system32\drivers\symndis.sys
2008-02-05 16:34 22,320 -c--a-w C:\WINDOWS\system32\drivers\symredrv.sys
2008-02-05 16:34 188,464 -c--a-w C:\WINDOWS\system32\drivers\symtdi.sys
2008-02-05 16:34 13,616 -c--a-w C:\WINDOWS\system32\drivers\symdns.sys
2008-02-05 16:34 1,612 -c--a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2008-02-04 17:27 1,430 -c--a-w C:\WINDOWS\system32\drivers\srtspl.inf
2008-02-04 17:27 1,421 -c--a-w C:\WINDOWS\system32\drivers\srtspx.inf
2008-02-04 17:27 1,415 -c--a-w C:\WINDOWS\system32\drivers\srtsp.inf
2008-02-01 19:55 10,549 -c--a-w C:\WINDOWS\system32\drivers\srtspx.cat
2008-02-01 19:55 10,549 -c--a-w C:\WINDOWS\system32\drivers\srtspl.cat
2008-02-01 19:55 10,545 -c--a-w C:\WINDOWS\system32\drivers\srtsp.cat
2008-02-01 06:02 --------- dc----w C:\Program Files\Soulseek
2008-01-31 22:51 43,696 -c--a-w C:\WINDOWS\system32\drivers\srtspx.sys
2008-01-31 22:51 317,616 -c--a-w C:\WINDOWS\system32\drivers\srtspl.sys
2008-01-31 22:51 279,088 -c--a-w C:\WINDOWS\system32\drivers\srtsp.sys
2008-01-31 22:04 --------- dc----w C:\Documents and Settings\All Users\Application Data\Creative
2008-01-31 22:03 --------- dc----w C:\Program Files\Dell
2008-01-30 02:22 --------- dc----w C:\Program Files\Motorola Phone Tools
2008-01-29 23:12 --------- dc----w C:\Program Files\SmitfraudFix
2008-01-29 23:09 --------- dc----w C:\Program Files\Flash
2008-01-29 23:09 --------- dc----w C:\Program Files\Comodo
2008-01-29 22:27 --------- dc----w C:\Program Files\FireTrust
2008-01-19 14:20 --------- dc----w C:\Program Files\itunes
2008-01-18 21:01 --------- dc----w C:\Program Files\iPod
2008-01-18 20:58 --------- dc----w C:\Program Files\QuickTime
2008-01-17 23:06 --------- dc----w C:\Program Files\SUPERAntiSpyware
2008-01-17 14:05 --------- dc----w C:\Program Files\Foxit Software
2008-01-17 13:51 --------- dc----w C:\Documents and Settings\All Users\Application Data\BOC425
2007-12-04 14:56 32 -c--a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2006-12-21 03:27 92,064 -c--a-w C:\Documents and Settings\Eve\mqdmmdm.sys
2006-12-21 03:27 9,232 -c--a-w C:\Documents and Settings\Eve\mqdmmdfl.sys
2006-12-21 03:27 79,328 -c--a-w C:\Documents and Settings\Eve\mqdmserd.sys
2006-12-21 03:27 66,656 -c--a-w C:\Documents and Settings\Eve\mqdmbus.sys
2006-12-21 03:27 6,208 -c--a-w C:\Documents and Settings\Eve\mqdmcmnt.sys
2006-12-21 03:27 5,936 -c--a-w C:\Documents and Settings\Eve\mqdmwhnt.sys
2006-12-21 03:27 4,048 -c--a-w C:\Documents and Settings\Eve\mqdmcr.sys
2006-12-21 03:27 25,600 -c--a-w C:\Documents and Settings\Eve\usbsermptxp.sys
2006-12-21 03:27 22,768 -c--a-w C:\Documents and Settings\Eve\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-03-13 16:37 116088 --a--c--- C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\Avast4\ALWILS~1\ashDisp.exe" [2007-12-04 08:00 79224]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 23:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 23:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 23:10 114688]
"SigmatelSysTrayApp"="stsystra.exe" []
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 04:04 59392]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 17:47 51048]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-02-06 22:49 718704]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-10 05:00 44544]
C:\Documents and Settings\Eve\Start Menu\Programs\Startup\
MailWasherPro.lnk - C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe [2008-01-29 17:27:41 5661184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\auto.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AutoRun.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\cross.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Discovery.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\guangd.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NAVSetup.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwProxy.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SDGames.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\servet.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ShuiNiu.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\sos.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\svch0st.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Systom.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TNT.Exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TxoMoU.Exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UFO.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Wsyscheck.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\XP.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\zxsweep.exe]
Debugger=C:\WINDOWS\system32\Flower.exe
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SAC-Desktop-Alert.lnk]
backup=C:\WINDOWS\pss\SAC-Desktop-Alert.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Eve^Start Menu^Programs^Startup^Norton Disk Doctor.LNK]
backup=C:\WINDOWS\pss\Norton Disk Doctor.LNKStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a--c--- 2007-04-27 16:17 50736 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BOC-425]
--a--c--- 2007-11-26 10:38 342272 C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
--a--c--- 2004-07-30 11:04 245760 C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--a--c--- 2005-02-23 16:19 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a--c--- 2004-08-10 04:04 59392 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX8400 Series]
--a--c--- 2007-02-15 06:00 179200 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
--a--c--- 2003-09-03 20:12 221184 C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a--c--- 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a--c--- 2004-07-27 16:50 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a--c--- 2008-01-15 03:22 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a--c--- 2007-01-19 11:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickCamPro.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2007-09-25 00:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a--c--- 2007-07-18 20:04 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\itunes\\iTunes.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
"%windir%\\system32\\sessmgr.exe"=
R2 NMSAccessU;NMSAccessU;C:\Program Files\iDumpPro\NMSAccessU.exe [2007-10-12 04:34]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-02-06 13:43]
S2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
S3 P0630VID;Creative WebCam Live!;C:\WINDOWS\system32\DRIVERS\P0630Vid.sys [2004-07-29 20:55]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-02-06 13:43]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-01 20:46:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-13 21:40:04 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Eve.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-17 17:38:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-17 17:39:30
.
2008-03-17 21:55:24 --- E O F ---