i did follow your post.. i just didn't post them in order.. however, if there was something wrong with what i did, i did it again.. here's my rerun..
ComboFix 08-05-21.3 - martin 2008-05-27 16:57:54.4 - NTFSx86
Running from: C:\Documents and Settings\martin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\martin\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Program Files\Firefox Setup 2.0.0.3.exe
C:\WINDOWS\system32\hjltfqgi.dll
C:\WINDOWS\system32\rqRIxyyx.dll.vir
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\web\related.htm
.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.
2008-05-24 20:29 . 2008-05-24 20:29 0 --a------ C:\WINDOWS\BM1fd74f42.xml
2008-05-24 16:34 . 2008-05-24 16:34 <DIR> d-------- C:\VundoFix Backups
2008-05-24 16:15 . 2008-05-24 16:15 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-23 22:06 . 2008-05-23 22:15 <DIR> d-------- C:\Program Files\ESET
2008-05-23 22:06 . 2008-05-23 22:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-05-23 21:31 . 2008-05-23 21:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-05-23 21:30 . 2008-05-23 21:30 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-05-22 09:22 . 2008-05-22 09:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-16 08:56 . 2008-05-16 08:56 <DIR> d-------- C:\Program Files\WinFF
2008-05-16 08:56 . 1999-01-01 03:34 <DIR> d-------- C:\Documents and Settings\martin\Application Data\WinFF
2008-05-09 22:19 . 2008-05-09 22:19 <DIR> d-------- C:\Program Files\YouTube Downloader
2008-05-06 11:38 . 2004-03-09 09:58 646,656 --a------ C:\WINDOWS\system32\sxs.dll
2008-05-06 11:38 . 2004-03-09 09:58 646,656 --a--c--- C:\WINDOWS\system32\dllcache\sxs.dll
2008-05-06 11:37 . 2008-05-06 11:37 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-05-06 11:33 . 2008-05-06 11:34 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-06 11:20 . 2008-05-06 11:41 <DIR> d--h-c--- C:\WINDOWS\$xpsp1hfm$
2008-05-05 23:32 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-05 23:32 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-23 13:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-22 07:04 --------- d-----w C:\Documents and Settings\martin\Application Data\uTorrent
2008-05-10 06:34 --------- d-----w C:\Documents and Settings\martin\Application Data\U3
2008-04-27 17:21 --------- d-----w C:\Documents and Settings\martin\Application Data\Image Zone Express
2008-04-27 11:41 --------- d-----w C:\Program Files\LimeWire
2008-04-24 18:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVG7
2008-04-24 11:54 --------- d-----w C:\Program Files\Trend Micro
2008-04-22 04:17 --------- d-----w C:\Program Files\Kaspersky Lab
2008-04-22 02:01 --------- d-----w C:\Documents and Settings\martin\Application Data\AVG7
2008-04-17 02:27 --------- d-----w C:\Program Files\Yahoo!
2007-12-14 20:58 784 -c--a-w C:\Documents and Settings\martin\Application Data\mpauth.dat
2007-11-06 07:51 348 ----a-w C:\Documents and Settings\martin\.cb_layout.bin
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((( snapshot@2008-05-24_20.25.47.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-24 12:10:55 2,048 -cs-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-27 09:03:14 2,048 -cs-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
R1 epfwtdir;epfwtdir;C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R3 cwbmidi_device;Crystal WDM MPU-401 UART Driver;C:\WINDOWS\System32\drivers\cwbmidi.sys [2001-08-17 12:19]
R3 cwbwdm_device;Crystal WDM Audio Codec Driver;C:\WINDOWS\System32\drivers\cwbwdm.sys [2001-08-17 12:19]
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\System32\DRIVERS\NtApm.sys [2001-08-17 21:47]
S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\System32\DRIVERS\V0090Vid.sys [2005-04-14 09:00]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-27 17:03:53
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\HPZipm12.exe
.
**************************************************************************
.
Completion time: 2008-05-27 17:08:25 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-27 09:08:12
ComboFix2.txt 2008-05-26 14:26:41
ComboFix3.txt 2008-05-26 14:03:16
ComboFix4.txt 2008-05-24 12:26:37
Pre-Run: 4,546,035,712 bytes free
Post-Run: 4,539,285,504 bytes free
91 --- E O F --- 2008-05-06 03:42:18
ComboFix 08-05-21.3 - martin 2008-05-27 16:57:54.4 - NTFSx86
Running from: C:\Documents and Settings\martin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\martin\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\Program Files\Firefox Setup 2.0.0.3.exe
C:\WINDOWS\system32\hjltfqgi.dll
C:\WINDOWS\system32\rqRIxyyx.dll.vir
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\web\related.htm
.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.
2008-05-24 20:29 . 2008-05-24 20:29 0 --a------ C:\WINDOWS\BM1fd74f42.xml
2008-05-24 16:34 . 2008-05-24 16:34 <DIR> d-------- C:\VundoFix Backups
2008-05-24 16:15 . 2008-05-24 16:15 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-23 22:06 . 2008-05-23 22:15 <DIR> d-------- C:\Program Files\ESET
2008-05-23 22:06 . 2008-05-23 22:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-05-23 21:31 . 2008-05-23 21:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-05-23 21:30 . 2008-05-23 21:30 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-05-22 09:22 . 2008-05-22 09:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-16 08:56 . 2008-05-16 08:56 <DIR> d-------- C:\Program Files\WinFF
2008-05-16 08:56 . 1999-01-01 03:34 <DIR> d-------- C:\Documents and Settings\martin\Application Data\WinFF
2008-05-09 22:19 . 2008-05-09 22:19 <DIR> d-------- C:\Program Files\YouTube Downloader
2008-05-06 11:38 . 2004-03-09 09:58 646,656 --a------ C:\WINDOWS\system32\sxs.dll
2008-05-06 11:38 . 2004-03-09 09:58 646,656 --a--c--- C:\WINDOWS\system32\dllcache\sxs.dll
2008-05-06 11:37 . 2008-05-06 11:37 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-05-06 11:33 . 2008-05-06 11:34 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-06 11:20 . 2008-05-06 11:41 <DIR> d--h-c--- C:\WINDOWS\$xpsp1hfm$
2008-05-05 23:32 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-05 23:32 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-23 13:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-22 07:04 --------- d-----w C:\Documents and Settings\martin\Application Data\uTorrent
2008-05-10 06:34 --------- d-----w C:\Documents and Settings\martin\Application Data\U3
2008-04-27 17:21 --------- d-----w C:\Documents and Settings\martin\Application Data\Image Zone Express
2008-04-27 11:41 --------- d-----w C:\Program Files\LimeWire
2008-04-24 18:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVG7
2008-04-24 11:54 --------- d-----w C:\Program Files\Trend Micro
2008-04-22 04:17 --------- d-----w C:\Program Files\Kaspersky Lab
2008-04-22 02:01 --------- d-----w C:\Documents and Settings\martin\Application Data\AVG7
2008-04-17 02:27 --------- d-----w C:\Program Files\Yahoo!
2007-12-14 20:58 784 -c--a-w C:\Documents and Settings\martin\Application Data\mpauth.dat
2007-11-06 07:51 348 ----a-w C:\Documents and Settings\martin\.cb_layout.bin
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((( snapshot@2008-05-24_20.25.47.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-24 12:10:55 2,048 -cs-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-27 09:03:14 2,048 -cs-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
R1 epfwtdir;epfwtdir;C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R3 cwbmidi_device;Crystal WDM MPU-401 UART Driver;C:\WINDOWS\System32\drivers\cwbmidi.sys [2001-08-17 12:19]
R3 cwbwdm_device;Crystal WDM Audio Codec Driver;C:\WINDOWS\System32\drivers\cwbwdm.sys [2001-08-17 12:19]
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\System32\DRIVERS\NtApm.sys [2001-08-17 21:47]
S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\System32\DRIVERS\V0090Vid.sys [2005-04-14 09:00]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-27 17:03:53
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\HPZipm12.exe
.
**************************************************************************
.
Completion time: 2008-05-27 17:08:25 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-27 09:08:12
ComboFix2.txt 2008-05-26 14:26:41
ComboFix3.txt 2008-05-26 14:03:16
ComboFix4.txt 2008-05-24 12:26:37
Pre-Run: 4,546,035,712 bytes free
Post-Run: 4,539,285,504 bytes free
91 --- E O F --- 2008-05-06 03:42:18