Again, thanks for the help.
ComboFix 08-01-23.2 - Compaq_Owner 2008-01-25 19:15:05.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.124 [GMT -8:00]
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Compaq_Owner\Desktop\CFscript.txt
* Created a new restore point
FILE
C:\WINDOWS\xxywwx.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\alot
C:\Program Files\alot\alotUninst.exe
C:\Program Files\alot\bin\alot.dll
C:\WINDOWS\xxywwx.dll
.
---- Previous Run -------
.
C:\Documents and Settings\Compaq_Owner\Application Data\tmp99.tmp.exe
C:\Documents and Settings\Compaq_Owner\Application Data\tmp9A.tmp.exe
C:\Documents and Settings\Compaq_Owner\Application Data\tmp9B.tmp.exe
C:\Documents and Settings\Compaq_Owner\Application Data\tmpA1.tmp.exe
C:\Documents and Settings\Steven\Application Data\tmp134.tmp.exe
C:\Documents and Settings\Steven\Application Data\tmp136.tmp.exe
C:\Documents and Settings\Steven\Application Data\tmp9D.tmp.exe
C:\Documents and Settings\Steven\Application Data\tmp9E.tmp.exe
C:\Documents and Settings\Steven\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Steven\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Steven\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\Terry\Application Data\tmp139.tmp.exe
C:\Documents and Settings\Terry\Application Data\tmp140.tmp.exe
C:\Documents and Settings\Terry\Application Data\tmp142.tmp.exe
C:\Documents and Settings\Terry\Application Data\tmp2.tmp.exe
C:\Documents and Settings\Terry\Application Data\tmp3.tmp.exe
C:\Documents and Settings\Terry\Application Data\tmp99.tmp.exe
C:\Documents and Settings\Terry\Application Data\tmp9A.tmp.exe
C:\Documents and Settings\Terry\Application Data\tmp9C.tmp.exe
C:\Documents and Settings\Terry\Application Data\tmp9D.tmp.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\conf.dat
C:\WINDOWS\system32\dmserve.dll
C:\WINDOWS\system32\drivers\fraevufm.dat
C:\WINDOWS\system32\tmp136.tmp.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_KIJCEBRG
-------\kijcebrg
((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.
2008-01-23 19:03 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-19 20:04 . 2008-01-19 20:04 <DIR> d-------- C:\Program Files\CCleaner
2008-01-19 14:55 . 2008-01-19 14:55 <DIR> d-------- C:\Program Files\IObit
2008-01-19 14:54 . 2007-01-18 04:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-01-19 14:52 . 2007-05-30 04:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-31 06:17 --------- d-----w C:\Program Files\Melody Assistant
2007-12-16 22:03 --------- d-----w C:\Program Files\CONEXANT
2007-12-15 16:37 --------- d-----w C:\Program Files\Utilities
2007-12-13 03:07 --------- d-----w C:\Program Files\Java
2007-12-13 03:07 --------- d-----w C:\Program Files\Common Files\Java
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-12-03 04:38 --------- d-----w C:\Program Files\eMusic Download Manager
2007-11-28 03:49 --------- d-----w C:\Program Files\MSXML 6.0
2007-11-28 03:48 --------- d-----w C:\Program Files\MSXML 4.0
2007-11-28 02:58 --------- d-----w C:\Program Files\Verizon
2007-11-28 02:58 --------- d-----w C:\Program Files\Common Files\SupportSoft
2007-11-28 02:55 --------- d-----w C:\Program Files\Common Files\Motive
2007-11-14 07:26 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 01:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 01:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2005-05-12 14:36 12,288 -c--a-w C:\WINDOWS\Fonts\RandFont.dll
2006-05-07 01:49 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( snapshot@2008-01-23_19.18.18.17 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-24 03:04:33 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-26 03:14:40 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-24 03:04:34 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-26 03:14:40 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-24 03:04:34 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-26 03:14:40 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-24 03:04:34 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-26 03:14:40 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-24 03:04:34 5,324,800 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
+ 2008-01-26 03:14:40 5,332,992 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
- 2008-01-24 03:04:34 176,128 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-26 03:14:40 176,128 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-26 02:39:00 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_504.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]
C:\Documents and Settings\Scott\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2006-07-31 09:12:35 225280]
PowerReg Scheduler.exe [2006-06-22 17:11:14 189952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2005-09-20 08:26]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-25 19:19:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.