Had to install the Windows Recovery Console.
Here's the log:
ComboFix 08-12-20.05 - mom 2008-12-21 9:53:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.189 [GMT -6:00]
Running from: c:\documents and settings\mom\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Altnet
.
((((((((((((((((((((((((( Files Created from 2008-11-21 to 2008-12-21 )))))))))))))))))))))))))))))))
.
2008-12-21 09:40 . 2008-12-21 09:54 <DIR> d-------- c:\windows\system32\CatRoot_bak
2008-12-21 04:06 . 2008-12-21 04:06 <DIR> d-------- c:\program files\MSXML 4.0
2008-12-21 04:01 . 2008-12-21 04:01 <DIR> d-------- c:\program files\Trend Micro
2008-12-21 03:50 . 2008-10-16 14:38 6,066,176 --------- c:\windows\system32\dllcache\ieframe.dll
2008-12-21 03:50 . 2007-04-17 03:32 2,455,488 --------- c:\windows\system32\dllcache\ieapfltr.dat
2008-12-21 03:50 . 2007-03-07 23:10 991,232 --------- c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-21 03:50 . 2008-10-16 14:38 459,264 --------- c:\windows\system32\dllcache\msfeeds.dll
2008-12-21 03:50 . 2008-10-16 14:38 383,488 --------- c:\windows\system32\dllcache\ieapfltr.dll
2008-12-21 03:50 . 2008-08-28 04:04 333,056 --------- c:\windows\system32\dllcache\srv.sys
2008-12-21 03:50 . 2008-10-16 14:38 267,776 --------- c:\windows\system32\dllcache\iertutil.dll
2008-12-21 03:50 . 2008-10-16 14:38 63,488 --------- c:\windows\system32\dllcache\icardie.dll
2008-12-21 03:50 . 2008-10-16 14:38 52,224 --------- c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-21 03:50 . 2008-10-16 07:11 13,824 --------- c:\windows\system32\dllcache\ieudinit.exe
2008-12-21 03:45 . 2008-06-13 07:10 272,128 --------- c:\windows\system32\drivers\bthport.sys
2008-12-21 03:45 . 2008-06-13 07:10 272,128 --------- c:\windows\system32\dllcache\bthport.sys
2008-12-21 03:40 . 2008-08-14 03:51 138,368 --------- c:\windows\system32\dllcache\afd.sys
2008-12-21 03:39 . 2008-12-21 03:39 27 --a------ c:\windows\sssTbarV2.ini
2008-12-21 03:30 . 2008-09-15 05:57 1,846,016 --------- c:\windows\system32\dllcache\win32k.sys
2008-12-21 03:29 . 2008-08-14 04:00 2,180,352 --------- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-21 03:29 . 2008-08-14 03:58 2,136,064 --------- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-21 03:29 . 2008-08-14 03:22 2,057,728 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-21 03:29 . 2008-08-14 03:22 2,015,744 --------- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-21 03:19 . 2008-05-08 06:28 202,752 --------- c:\windows\system32\dllcache\rmcast.sys
2008-12-21 03:18 . 2008-04-11 12:50 683,520 --------- c:\windows\system32\dllcache\inetcomm.dll
2008-12-21 03:18 . 2008-10-24 05:10 453,632 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-21 03:18 . 2008-05-01 08:30 331,776 --------- c:\windows\system32\dllcache\msadce.dll
2008-12-21 03:17 . 2008-09-04 10:42 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2008-12-21 03:17 . 2008-10-15 10:57 332,800 --------- c:\windows\system32\dllcache\netapi32.dll
2008-12-21 03:17 . 2008-10-03 04:15 247,326 --------- c:\windows\system32\dllcache\strmdll.dll
2008-12-21 03:08 . 2008-12-21 03:08 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-21 03:08 . 2008-12-21 03:08 <DIR> d-------- c:\documents and settings\mom\Application Data\Malwarebytes
2008-12-21 03:08 . 2008-12-21 03:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-21 03:08 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-21 03:08 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-21 02:22 . 2008-12-21 03:13 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-21 02:22 . 2008-12-21 03:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-21 01:35 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-12-21 01:35 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-12-21 01:34 . 2008-10-16 14:09 31,768 --a------ c:\windows\system32\wucltui.dll.mui
2008-12-21 01:34 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuaucpl.cpl.mui
2008-12-21 01:34 . 2008-10-16 14:07 23,576 --a------ c:\windows\system32\wuapi.dll.mui
2008-12-21 01:34 . 2008-10-16 14:07 18,456 --a------ c:\windows\system32\wuaueng.dll.mui
2008-12-21 01:19 . 1999-04-13 00:00 1,046,288 --a------ c:\windows\system32\msjet35.dll
2008-12-21 01:19 . 1998-04-24 20:08 368,912 --a------ c:\windows\system32\vbar332.dll
2008-12-21 01:19 . 1998-04-24 19:40 252,176 --a------ c:\windows\system32\msrd2x35.dll
2008-12-21 01:19 . 1999-03-24 22:28 182,784 --a------ c:\windows\system32\ddao35.dll
2008-12-21 01:19 . 1998-04-24 19:40 123,664 --a------ c:\windows\system32\Msjint35.dll
2008-12-21 01:19 . 1998-04-24 19:40 24,848 --a------ c:\windows\system32\msjter35.dll
2008-12-21 01:17 . 2008-12-21 01:17 <DIR> d-------- c:\program files\Symantec
2008-12-21 01:17 . 2008-12-21 02:48 <DIR> d-------- c:\program files\Norton CleanSweep
2008-12-21 00:32 . 2008-12-21 00:32 73 --a------ c:\windows\st_affiliate.ini
2008-12-18 18:56 . 2008-12-18 18:56 24,064 --a------ C:\Welcome letter SCI220 12-18 Angele Smith.doc
2008-12-18 18:35 . 2008-12-18 18:35 33,792 --a------ C:\Calendar [12 18 08 thru 01 29 09] new Angela Smith.doc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 07:22 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-21 07:19 --------- d-----w c:\documents and settings\mom\Application Data\Symantec
2008-12-21 06:11 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-13 06:40 3,593,216 ------w c:\windows\system32\dllcache\mshtml.dll
2008-11-19 02:55 64 ----a-w c:\documents and settings\mom\Application Data\wklnhst.dat
2008-11-19 02:49 --------- d-----w c:\documents and settings\mom\Application Data\Template
2008-11-04 00:23 --------- d-----w c:\documents and settings\mom\Application Data\U3
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 13:01 283,648 ------w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 20:12 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 20:12 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 20:07 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 13:11 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-15 07:06 633,632 ------w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:15 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 22:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-06-09 03:32 952 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-12-13 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-12-13 126976]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2005-02-08 159744]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 794624]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-09-07 213054]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-02 106496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-06-02 267048]
"AGRSMMSG"="AGRSMMSG.exe" [2004-08-24 c:\windows\AGRSMMSG.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Java\\jre1.5.0_02\\bin\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d7e258e-998f-11dd-b03e-0012f09a3bb2}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f763ce35-9f00-11dd-b040-0012f09a3bb2}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2008-12-21 c:\windows\Tasks\At1.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At10.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At11.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At12.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At13.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At14.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At15.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At16.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At17.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At18.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-21 c:\windows\Tasks\At19.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-21 c:\windows\Tasks\At2.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At20.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At21.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At22.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At23.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At24.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-21 c:\windows\Tasks\At3.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-21 c:\windows\Tasks\At4.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-21 c:\windows\Tasks\At5.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At6.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At7.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At8.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\At9.job
- c:\windows\system32\7P3M54Rh.exe []
2008-12-20 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Caldwell.job
- c:\progra~1\NORTON~1\Navw32.exe []
2008-12-21 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 15:21]
2008-06-26 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 15:21]
2008-12-21 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2001-08-17 07:47]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-IS CfgWiz - c:\program files\Norton Internet Security\cfgwiz.exe
HKLM-Run-URLLSTCK.exe - c:\program files\Norton Internet Security\UrlLstCk.exe
HKLM-Run-SSC_UserPrompt - c:\program files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
HKLM-Run-ChangeResolution - c:\hp\bin\ChangeResolution.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-21 09:56:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????1?3?0?8??????? ???B???????????????B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-21 9:57:12
ComboFix-quarantined-files.txt 2008-12-21 15:56:51
Pre-Run: 46,827,335,680 bytes free
Post-Run: 47,421,272,064 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
251 --- E O F --- 2008-12-21 10:11:54