Uipopuphidden has been showing up for about a year now. I'm not sure if it's tied to AT&T but I've never installed Freedom AV.
ComboFix 08-02.05.3 - Robert Smith 2008-02-06 16:48:05.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.251 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Robert Smith\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-06 to 2008-02-06 )))))))))))))))))))))))))))))))
.
2008-02-06 16:20 . 2008-02-06 16:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-06 16:20 . 2008-02-06 16:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-30 19:56 . 2004-08-03 23:00 260,272 --a------ C:\cmldr
2008-01-29 06:07 . 1999-12-17 09:13 86,016 --a------ C:\WINDOWS\unvise32.exe
2008-01-29 06:06 . 2008-01-29 06:07 <DIR> d-------- C:\Program Files\Master Tour Database
2008-01-27 20:22 . 2008-01-27 20:22 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-24 05:10 . 2008-01-24 05:10 <DIR> d-------- C:\Documents and Settings\Robert Smith\Application Data\Uniblue
2008-01-23 19:06 . 2008-01-23 19:07 <DIR> d-------- C:\Documents and Settings\Robert Smith\Application Data\PrevxCSI
2008-01-23 19:06 . 2008-01-23 19:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-13 19:52 . 2008-01-30 20:31 <DIR> d-------- C:\Documents and Settings\Robert Smith\Application Data\LimeWire
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-05 22:02 --------- d-----w C:\Program Files\QuickTime
2008-02-03 07:15 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-02-03 07:15 --------- d-----w C:\Program Files\iTunes
2008-01-29 02:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-29 02:13 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-29 00:57 --------- d-----w C:\Program Files\iPod
2008-01-28 02:50 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-27 13:58 --------- d-----w C:\Program Files\HiJack This
2008-01-24 00:39 --------- d-----w C:\Program Files\Windows Installer Clean Up
2008-01-02 01:30 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\AT&T
2008-01-02 01:25 --------- d-----w C:\Program Files\Common Files\Scanner
2008-01-02 01:18 --------- d-----w C:\Program Files\Common Files\Authentium
2008-01-02 01:17 --------- d-----w C:\Program Files\Raxco
2008-01-02 01:17 --------- d-----w C:\Program Files\CA
2008-01-02 01:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Raxco
2008-01-02 01:16 --------- d-----w C:\Program Files\AT&T
2008-01-02 01:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\AT&T
2008-01-02 01:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-01 23:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2007-12-31 01:36 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
2007-12-30 20:11 77,891 ----a-w C:\WINDOWS\system32\USRmlnkA.exe
2007-12-30 20:02 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\Yahoo!
2007-12-30 20:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-29 14:18 --------- d-----w C:\Program Files\ATT
2007-12-29 03:57 --------- d-----w C:\Program Files\Yahoo!
2007-12-26 13:52 --------- d-----w C:\Program Files\AC3Filter
2007-12-26 13:18 --------- d-----w C:\Program Files\ahead
2007-12-26 13:13 --------- d-----w C:\Program Files\Common Files\Nero
2007-12-25 13:16 --------- d-----w C:\Program Files\Common Files\Voyetra
2007-12-22 15:48 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\Canon
2007-12-22 15:22 --------- d-----w C:\Program Files\Canon
2007-12-22 15:18 --------- d-----w C:\Program Files\Common Files\NewSoft
2007-12-22 15:17 --------- d-----w C:\Program Files\Common Files\ScanSoft Shared
2007-12-22 15:17 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-22 15:17 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\ScanSoft
2007-12-22 15:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ScanSoft
2007-12-22 15:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-12-22 15:16 --------- d-----w C:\Program Files\ScanSoft
2007-12-22 15:15 --------- d-----w C:\Program Files\Common Files\CANON
2007-12-22 15:12 --------- d--h--w C:\Documents and Settings\All Users\Application Data\CanonBJ
2007-12-22 15:11 --------- d--h--w C:\Program Files\CanonBJ
2007-12-20 10:54 --------- d-----w C:\Program Files\OfficeUpdate11
2007-12-20 10:54 --------- d-----w C:\Program Files\MP3Downloading
2007-12-20 10:54 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2007-12-20 10:54 --------- d-----w C:\Program Files\Hewlett-Packard
2007-12-20 10:53 --------- d-----w C:\Program Files\Lexmark Fax Solutions
2007-12-20 10:53 --------- d-----w C:\Program Files\Common Files\AVSMedia
2007-12-20 10:53 --------- d-----w C:\Program Files\Apple Software Update
2007-12-20 10:53 --------- d-----w C:\Program Files\androidnews
2007-12-20 10:53 --------- d-----w C:\Program Files\Amazing DVD Player
2007-12-13 03:10 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\FaxCtr
2007-12-13 02:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\FaxCtr
2007-12-13 02:11 32,123 ----a-w C:\WINDOWS\PaperPortSave.reg
2007-12-13 02:11 --------- d-----w C:\Program Files\TweakNow RegCleaner Std
2007-12-13 02:09 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-12-13 01:56 --------- d-----w C:\Program Files\ATI Technologies
2007-12-12 11:42 --------- d-----w C:\Program Files\PrimaScan
2007-12-12 11:42 --------- d-----w C:\Program Files\Common Files\Panasonic
2007-11-24 18:28 654,920 ----a-w C:\mtinst.exe
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2004-12-16 18:50 8,273 ----a-w C:\Program Files\snylcd55.cat
2004-12-12 18:38 2,824 ----a-w C:\Program Files\HS75P_65.icm
2004-12-12 18:36 2,824 ----a-w C:\Program Files\HS75P_93.icm
2004-12-10 02:49 1,636 ----a-w C:\Program Files\SnyLCD55.inf
2004-05-19 15:16 20,854 ----a-w C:\Program Files\README-E.RTF
2002-02-17 22:52 8,584,973 ----a-w C:\Documents and Settings\Robert Smith\pcc2knt_76_1436.exe
2007-08-24 03:14 21,382,176 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-24 03:14 980,000 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-30 19:36 15360]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"-FreedomNeedsReboot"="C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 16:09 13552]
"AT&T Internet Security Suite"="C:\Program Files\AT&T\AT&T Internet Security Suite\RPS.exe" [2007-06-28 16:09 310000]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-29 10:10 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-30 19:36 267064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-05-29 19:34 5419008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"HydarVisionViewport"=viewport.exe
"BJCFD"=C:\Program Files\BroadJump\Client Foundation\CFD.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"DeviceDiscovery"=C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
"HPDJ Taskbar Utility"=C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
"USRpdA"=C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
R0 amdagpxp;AMD NB AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\amdagpxp.sys [2001-12-11 14:52]
R2 ppsio2;PPDevice;C:\WINDOWS\system32\drivers\ppsio2.sys [1999-04-01 18:16]
R3 MN130;Microsoft(R) PCI Adapter MN-130;C:\WINDOWS\system32\DRIVERS\MN130-51.sys [2002-05-29 12:25]
R3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys [2001-12-15 22:42]
R3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys [2001-12-16 03:27]
S2 IcRecUsb;IC Recorder Driver;C:\WINDOWS\system32\Drivers\IcRecUsb.sys [2001-10-01 22:37]
S3 Amps2prt;PS/2 Port Wheel Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\Amps2prt.sys [2000-11-03 20:37]
S3 cirrus;cirrus;C:\WINDOWS\system32\DRIVERS\cirrus.sys [2001-08-17 07:57]
S3 NUVision;NUVision II Video Service;C:\WINDOWS\system32\DRIVERS\nuvvid2.sys [2001-10-28 15:34]
S3 Radialpoint Security Services;AT&T Internet Security Suite;C:\WINDOWS\system32\dllhost.exe [2004-08-04 01:56]
S3 USR7900;U.S. Robotics 10/100 PCI NIC TX;C:\WINDOWS\system32\DRIVERS\USR7900.SYS [2001-12-03 09:41]
S3 USRpdA;U.S. Robotics 56K PCI Faxmodem Driver;C:\WINDOWS\system32\DRIVERS\USRpdA.sys [2001-08-17 15:28]
S3 vtdg46xx;vtdg46xx;C:\PROGRA~1\TURTLE~1\SANTAC~1\CONTRO~1\vtdg46xx.sys [2001-12-13 18:42]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-06 16:51:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-06 16:52:44
ComboFix-quarantined-files.txt 2008-02-06 22:52:17
ComboFix2.txt 2008-02-05 22:05:04
.
2008-01-09 11:23:59 --- E O F ---
ComboFix 08-02.05.3 - Robert Smith 2008-02-06 16:48:05.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.251 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Robert Smith\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-06 to 2008-02-06 )))))))))))))))))))))))))))))))
.
2008-02-06 16:20 . 2008-02-06 16:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-06 16:20 . 2008-02-06 16:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-30 19:56 . 2004-08-03 23:00 260,272 --a------ C:\cmldr
2008-01-29 06:07 . 1999-12-17 09:13 86,016 --a------ C:\WINDOWS\unvise32.exe
2008-01-29 06:06 . 2008-01-29 06:07 <DIR> d-------- C:\Program Files\Master Tour Database
2008-01-27 20:22 . 2008-01-27 20:22 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-24 05:10 . 2008-01-24 05:10 <DIR> d-------- C:\Documents and Settings\Robert Smith\Application Data\Uniblue
2008-01-23 19:06 . 2008-01-23 19:07 <DIR> d-------- C:\Documents and Settings\Robert Smith\Application Data\PrevxCSI
2008-01-23 19:06 . 2008-01-23 19:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-13 19:52 . 2008-01-30 20:31 <DIR> d-------- C:\Documents and Settings\Robert Smith\Application Data\LimeWire
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-05 22:02 --------- d-----w C:\Program Files\QuickTime
2008-02-03 07:15 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-02-03 07:15 --------- d-----w C:\Program Files\iTunes
2008-01-29 02:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-29 02:13 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-29 00:57 --------- d-----w C:\Program Files\iPod
2008-01-28 02:50 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-27 13:58 --------- d-----w C:\Program Files\HiJack This
2008-01-24 00:39 --------- d-----w C:\Program Files\Windows Installer Clean Up
2008-01-02 01:30 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\AT&T
2008-01-02 01:25 --------- d-----w C:\Program Files\Common Files\Scanner
2008-01-02 01:18 --------- d-----w C:\Program Files\Common Files\Authentium
2008-01-02 01:17 --------- d-----w C:\Program Files\Raxco
2008-01-02 01:17 --------- d-----w C:\Program Files\CA
2008-01-02 01:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Raxco
2008-01-02 01:16 --------- d-----w C:\Program Files\AT&T
2008-01-02 01:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\AT&T
2008-01-02 01:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-01 23:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2007-12-31 01:36 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
2007-12-30 20:11 77,891 ----a-w C:\WINDOWS\system32\USRmlnkA.exe
2007-12-30 20:02 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\Yahoo!
2007-12-30 20:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-29 14:18 --------- d-----w C:\Program Files\ATT
2007-12-29 03:57 --------- d-----w C:\Program Files\Yahoo!
2007-12-26 13:52 --------- d-----w C:\Program Files\AC3Filter
2007-12-26 13:18 --------- d-----w C:\Program Files\ahead
2007-12-26 13:13 --------- d-----w C:\Program Files\Common Files\Nero
2007-12-25 13:16 --------- d-----w C:\Program Files\Common Files\Voyetra
2007-12-22 15:48 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\Canon
2007-12-22 15:22 --------- d-----w C:\Program Files\Canon
2007-12-22 15:18 --------- d-----w C:\Program Files\Common Files\NewSoft
2007-12-22 15:17 --------- d-----w C:\Program Files\Common Files\ScanSoft Shared
2007-12-22 15:17 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-22 15:17 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\ScanSoft
2007-12-22 15:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ScanSoft
2007-12-22 15:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-12-22 15:16 --------- d-----w C:\Program Files\ScanSoft
2007-12-22 15:15 --------- d-----w C:\Program Files\Common Files\CANON
2007-12-22 15:12 --------- d--h--w C:\Documents and Settings\All Users\Application Data\CanonBJ
2007-12-22 15:11 --------- d--h--w C:\Program Files\CanonBJ
2007-12-20 10:54 --------- d-----w C:\Program Files\OfficeUpdate11
2007-12-20 10:54 --------- d-----w C:\Program Files\MP3Downloading
2007-12-20 10:54 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2007-12-20 10:54 --------- d-----w C:\Program Files\Hewlett-Packard
2007-12-20 10:53 --------- d-----w C:\Program Files\Lexmark Fax Solutions
2007-12-20 10:53 --------- d-----w C:\Program Files\Common Files\AVSMedia
2007-12-20 10:53 --------- d-----w C:\Program Files\Apple Software Update
2007-12-20 10:53 --------- d-----w C:\Program Files\androidnews
2007-12-20 10:53 --------- d-----w C:\Program Files\Amazing DVD Player
2007-12-13 03:10 --------- d-----w C:\Documents and Settings\Robert Smith\Application Data\FaxCtr
2007-12-13 02:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\FaxCtr
2007-12-13 02:11 32,123 ----a-w C:\WINDOWS\PaperPortSave.reg
2007-12-13 02:11 --------- d-----w C:\Program Files\TweakNow RegCleaner Std
2007-12-13 02:09 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-12-13 01:56 --------- d-----w C:\Program Files\ATI Technologies
2007-12-12 11:42 --------- d-----w C:\Program Files\PrimaScan
2007-12-12 11:42 --------- d-----w C:\Program Files\Common Files\Panasonic
2007-11-24 18:28 654,920 ----a-w C:\mtinst.exe
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2004-12-16 18:50 8,273 ----a-w C:\Program Files\snylcd55.cat
2004-12-12 18:38 2,824 ----a-w C:\Program Files\HS75P_65.icm
2004-12-12 18:36 2,824 ----a-w C:\Program Files\HS75P_93.icm
2004-12-10 02:49 1,636 ----a-w C:\Program Files\SnyLCD55.inf
2004-05-19 15:16 20,854 ----a-w C:\Program Files\README-E.RTF
2002-02-17 22:52 8,584,973 ----a-w C:\Documents and Settings\Robert Smith\pcc2knt_76_1436.exe
2007-08-24 03:14 21,382,176 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-24 03:14 980,000 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-30 19:36 15360]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"-FreedomNeedsReboot"="C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 16:09 13552]
"AT&T Internet Security Suite"="C:\Program Files\AT&T\AT&T Internet Security Suite\RPS.exe" [2007-06-28 16:09 310000]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-29 10:10 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-30 19:36 267064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-05-29 19:34 5419008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"HydarVisionViewport"=viewport.exe
"BJCFD"=C:\Program Files\BroadJump\Client Foundation\CFD.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"DeviceDiscovery"=C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
"HPDJ Taskbar Utility"=C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
"USRpdA"=C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
R0 amdagpxp;AMD NB AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\amdagpxp.sys [2001-12-11 14:52]
R2 ppsio2;PPDevice;C:\WINDOWS\system32\drivers\ppsio2.sys [1999-04-01 18:16]
R3 MN130;Microsoft(R) PCI Adapter MN-130;C:\WINDOWS\system32\DRIVERS\MN130-51.sys [2002-05-29 12:25]
R3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys [2001-12-15 22:42]
R3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys [2001-12-16 03:27]
S2 IcRecUsb;IC Recorder Driver;C:\WINDOWS\system32\Drivers\IcRecUsb.sys [2001-10-01 22:37]
S3 Amps2prt;PS/2 Port Wheel Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\Amps2prt.sys [2000-11-03 20:37]
S3 cirrus;cirrus;C:\WINDOWS\system32\DRIVERS\cirrus.sys [2001-08-17 07:57]
S3 NUVision;NUVision II Video Service;C:\WINDOWS\system32\DRIVERS\nuvvid2.sys [2001-10-28 15:34]
S3 Radialpoint Security Services;AT&T Internet Security Suite;C:\WINDOWS\system32\dllhost.exe [2004-08-04 01:56]
S3 USR7900;U.S. Robotics 10/100 PCI NIC TX;C:\WINDOWS\system32\DRIVERS\USR7900.SYS [2001-12-03 09:41]
S3 USRpdA;U.S. Robotics 56K PCI Faxmodem Driver;C:\WINDOWS\system32\DRIVERS\USRpdA.sys [2001-08-17 15:28]
S3 vtdg46xx;vtdg46xx;C:\PROGRA~1\TURTLE~1\SANTAC~1\CONTRO~1\vtdg46xx.sys [2001-12-13 18:42]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-06 16:51:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-06 16:52:44
ComboFix-quarantined-files.txt 2008-02-06 22:52:17
ComboFix2.txt 2008-02-05 22:05:04
.
2008-01-09 11:23:59 --- E O F ---

