Here is the contents of Combofix.txt. There seems to be an issue because when it restarted, the windows start menu bar doesn't show up. Here's the log:
ComboFix 09-09-08.09 - user 09/09/2009 12:23.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.615 [GMT -4:00]
Running from: c:\documents and settings\user\Desktop\firefox1.exe
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\user\LOCALS~1\Temp\csrss.exe
c:\docume~1\user\LOCALS~1\Temp\lsass.exe
c:\docume~1\user\LOCALS~1\Temp\services.exe
c:\docume~1\user\LOCALS~1\Temp\svchost.exe
c:\docume~1\user\LOCALS~1\Temp\taskmgr.exe
c:\documents and settings\user\Application Data\inst.exe
c:\documents and settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\program files\Common Files\stem32~1
c:\program files\dobe~1
c:\program files\Internet Explorer\2.exe
c:\windows\Installer\5aea6.msp
c:\windows\Installer\8b546.msp
c:\windows\mcroso~1
c:\windows\msliveupdate.exe
c:\windows\system32\18467.exe
c:\windows\system32\41.exe
c:\windows\system32\AVR09.exe
c:\windows\system32\cdpasiwy.ini
c:\windows\system32\config\systemprofile\Desktop\Advanced Virus Remover.lnk
c:\windows\system32\config\systemprofile\Start Menu\Advanced Virus Remover.lnk
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
c:\windows\system32\drivers\smss.exe
c:\windows\system32\drivers\UACd.sys
c:\windows\system32\drivers\vsfoceekywxnst.sys
c:\windows\system32\drivers\vsfoceumnthemd.sys
c:\windows\system32\erywovul.ini
c:\windows\system32\gykajdte.ini
c:\windows\system32\jfuhxxvy.ini
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lyufdqfg.ini
c:\windows\system32\mrdwyfxa.ini
c:\windows\system32\msconfig.exe
c:\windows\system32\mtmbfccl.ini
c:\windows\system32\nnnmp.bak1
c:\windows\system32\nnnmp.bak2
c:\windows\system32\nnnmp.tmp
c:\windows\system32\pdcpfdcd.ini
c:\windows\system32\peesfrfe.ini
c:\windows\system32\pjiecwph.ini
c:\windows\system32\pwitvone.ini
c:\windows\system32\qnnnoark.ini
c:\windows\system32\rocemppn.ini
c:\windows\system32\sdra64.exe
c:\windows\system32\smfkgpko.ini
c:\windows\system32\tajf83ikdmf.dll
c:\windows\system32\vsfocejwxnrjec.dat
c:\windows\system32\vsfoceqxyymsbp.dll
c:\windows\system32\vsfocergiltpuw.dat
c:\windows\system32\vsfoceugpxsxpa.dll
c:\windows\system32\vsfocexssvpwpa.dll
c:\windows\system32\wcosfmav.ini
c:\windows\system32\winhelper.dll
c:\windows\system32\winupdate.exe
c:\windows\system32\ykndfdow.ini
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\logevent.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_vsfoceuxtoqxrx
-------\Legacy_vsfoceuxtoqxrx
-------\Legacy_MSCONTROLSERVICE
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-08-09 to 2009-09-09 )))))))))))))))))))))))))))))))
.
2009-09-08 07:38 . 2009-09-08 07:38 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-09-08 06:48 . 2009-09-08 06:49 -------- d-----w- C:\ARK
2009-09-08 00:53 . 2009-09-08 00:53 -------- d-----w- c:\program files\Trend Micro
2009-09-07 22:49 . 2009-09-07 22:49 -------- d-----w- c:\program files\Enigma Software Group
2009-09-07 22:08 . 2009-09-07 22:08 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Mozilla
2009-09-03 21:36 . 2005-04-25 02:43 13225 ----a-w- c:\windows\system32\drivers\Razerlow.sys
2009-09-03 21:33 . 2009-09-03 21:47 -------- d-----w- c:\documents and settings\user\Application Data\Uniblue
2009-09-03 21:33 . 2009-09-03 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-08-21 08:49 . 2009-08-21 08:49 -------- d-----w- c:\documents and settings\user\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-08-21 08:46 . 2009-08-21 11:27 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-19 10:44 . 2009-03-19 20:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-08-19 10:44 . 2008-04-17 16:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-08-19 10:44 . 2009-08-19 10:44 -------- d-----w- c:\program files\iPod
2009-08-19 10:44 . 2009-08-19 10:44 -------- d-----w- c:\program files\iTunes
2009-08-19 10:44 . 2009-08-19 10:44 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-19 10:43 . 2009-08-19 10:44 -------- d-----w- c:\program files\QuickTime
2009-08-19 10:42 . 2009-08-19 10:42 -------- d-----w- c:\program files\Apple Software Update
2009-08-19 10:42 . 2009-07-09 16:16 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-17 07:55 . 2006-05-24 03:48 24576 ----a-w- c:\windows\system32\StkAUSD.dll
2009-08-17 07:08 . 2009-08-17 23:12 -------- d-----w- c:\program files\abgx360
2009-08-14 00:29 . 2009-08-14 00:29 -------- d-----w- c:\program files\ImgBurn
2009-08-13 21:08 . 2009-08-13 21:08 -------- d-----w- c:\documents and settings\user\Application Data\Malwarebytes
2009-08-13 21:08 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-13 21:08 . 2009-08-13 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-13 21:08 . 2009-08-13 21:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-13 21:08 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-11 21:10 . 2009-08-12 04:46 -------- d-----w- c:\program files\FlashGet
2009-08-11 20:46 . 2009-08-11 20:46 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-08-10 17:36 . 2009-08-10 17:36 -------- d-----w- c:\program files\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-09 16:29 . 2008-12-25 23:39 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-09 16:19 . 2007-11-13 06:40 -------- d-----w- c:\documents and settings\user\Application Data\uTorrent
2009-09-09 16:12 . 2004-08-04 01:56 55808 ----a-w- c:\windows\system32\eventlog.dll
2009-09-09 09:48 . 2007-11-14 19:09 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-09-08 19:37 . 2009-04-04 03:27 -------- d-----w- c:\program files\PurgeIE
2009-09-08 03:56 . 2007-11-27 05:13 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-08 03:22 . 2008-01-02 05:16 -------- d-----w- c:\documents and settings\user\Application Data\U3
2009-09-05 11:18 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP6a43.tmp
2009-09-03 23:03 . 2007-11-22 08:11 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-03 22:52 . 2008-02-13 18:50 -------- d-----w- c:\program files\Magic Video Converter
2009-09-03 20:45 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP6ca4.tmp
2009-09-03 20:11 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP3633.tmp
2009-08-28 20:54 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP32f6.tmp
2009-08-23 21:51 . 2007-12-07 00:43 -------- d-----w- c:\program files\Google
2009-08-23 01:44 . 2008-11-15 20:19 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-23 01:44 . 2007-11-17 09:33 -------- d-----w- c:\program files\Java
2009-08-22 01:19 . 2007-12-20 13:43 -------- d-----w- c:\documents and settings\user\Application Data\dvdcss
2009-08-21 08:51 . 2007-11-13 07:51 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-19 11:05 . 2007-11-21 20:03 -------- d-----w- c:\documents and settings\user\Application Data\Apple Computer
2009-08-19 10:44 . 2007-11-16 21:23 -------- d-----w- c:\program files\Bonjour
2009-08-19 10:43 . 2007-12-09 03:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-18 02:43 . 2008-07-12 19:04 -------- d-----w- c:\documents and settings\user\Application Data\Skype
2009-08-18 02:42 . 2007-12-07 02:24 -------- d-----w- c:\documents and settings\user\Application Data\skypePM
2009-08-17 08:16 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP65cf.tmp
2009-08-17 07:29 . 2007-11-12 22:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-17 07:14 . 2007-12-13 14:15 -------- d-----w- c:\documents and settings\user\Application Data\Vso
2009-08-17 07:14 . 2009-08-17 07:14 81920 ----a-w- c:\documents and settings\user\Application Data\ezpinst.exe
2009-08-17 07:14 . 2007-12-13 14:15 47360 ----a-w- c:\documents and settings\user\Application Data\pcouffin.sys
2009-08-16 11:25 . 2007-11-20 20:50 -------- d-----w- c:\program files\HiDownload
2009-08-14 00:25 . 2007-12-13 14:15 -------- d-----w- c:\program files\VSO
2009-08-12 05:52 . 2007-12-10 05:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-12 04:43 . 2007-12-10 05:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-11 20:46 . 2008-09-14 17:30 -------- d-----w- c:\program files\TVUPlayer
2009-08-10 20:48 . 2009-04-02 19:11 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-07 14:12 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP6476.tmp
2009-08-07 01:51 . 2007-11-22 08:11 -------- d-----w- c:\documents and settings\user\Application Data\Sony
2009-08-07 01:51 . 2008-09-20 04:31 -------- d-----w- c:\program files\Sony Setup
2009-08-04 00:54 . 2009-08-04 00:54 -------- d-----w- c:\documents and settings\user\Application Data\acccore
2009-08-04 00:54 . 2009-08-04 00:53 -------- d-----w- c:\documents and settings\All Users\Application Data\acccore
2009-08-04 00:53 . 2009-08-04 00:52 -------- d-----w- c:\program files\AIM6
2009-08-03 23:54 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP72b0.tmp
2009-08-03 23:53 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP730d.tmp
2009-08-03 22:45 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP735b.tmp
2009-08-03 22:13 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP709c.tmp
2009-08-03 21:40 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP706f.tmp
2009-08-03 21:09 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP70da.tmp
2009-08-03 20:36 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP738b.tmp
2009-08-03 20:04 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP70ea.tmp
2009-08-03 19:31 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP702e.tmp
2009-08-03 18:58 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP706e.tmp
2009-08-03 18:27 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP706d.tmp
2009-08-03 18:26 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP733c.tmp
2009-08-03 17:53 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP6fd1.tmp
2009-08-03 17:21 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP6cf2.tmp
2009-08-03 16:48 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP6aa0.tmp
2009-08-03 16:16 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP6e88.tmp
2009-08-03 15:43 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP318f.tmp
2009-07-31 03:10 . 2009-01-03 05:34 -------- d-----w- c:\program files\mkv2vob
2009-07-31 02:38 . 2008-10-01 00:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg8
2009-07-31 02:30 . 2009-07-31 02:30 -------- d-----w- c:\program files\AVG
2009-07-29 22:27 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP953b.tmp
2009-07-29 02:53 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP7f32.tmp
2009-07-29 02:21 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP7c06.tmp
2009-07-29 01:48 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP7724.tmp
2009-07-29 01:17 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP7474.tmp
2009-07-29 00:44 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP6dfc.tmp
2009-07-29 00:12 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP63da.tmp
2009-07-25 21:04 . 2008-06-15 17:44 98304 ----a-w- c:\windows\DUMP8a7d.tmp
2009-07-23 09:44 . 2009-07-23 09:44 -------- d-----w- c:\documents and settings\All Users\Application Data\GoBit Games
2009-07-23 09:43 . 2009-07-23 09:43 -------- d-----w- c:\program files\Burger Shop 2
2009-07-09 16:16 . 2007-12-09 03:19 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-29 10:52 . 2007-11-22 08:08 531160 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2007-11-15 04:00 . 2007-11-15 03:58 48 --sh--w- c:\windows\S821ED78A.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-11-25 2272192]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-05 1994480]
"mount.exe"="c:\program files\GiPo@Utilities\FileUtilities.3\mount.exe" [2008-04-11 374272]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-07-09 49968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-04 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-04 81920]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-08-03 419088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-23 149280]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-04-02 868352]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-02-26 16125440]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-10-04 1626112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-23 124928]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
MA111 Configuration Utility.lnk - c:\program files\NETGEAR\MA111v2 USB Adapter\MA111v2.exe [2004-5-28 421888]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\KeyHoleTV\\KeyHoleTV.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\River Past\\Video Cleaner Pro\\VideoCleaner.exe"=
"c:\\Program Files\\River Past\\Animated GIF Converter and Booster Pack\\VideoCleaner.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"49990:TCP"= 49990:TCP:utorrent
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/4/2009 2:49 PM 74480]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2/2/2009 3:23 AM 33792]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/13/2009 5:08 PM 19096]
R3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [9/3/2009 5:36 PM 13225]
S1 aswSP;avast! Self Protection; [x]
S2 acmlfwmmzdvruc;acmlfwmmzdvruc;\??\c:\windows\system32\drivers\yqbaxx.sys --> c:\windows\system32\drivers\yqbaxx.sys [?]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys --> c:\windows\system32\DRIVERS\aswFsBlk.sys [?]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/13/2009 5:08 PM 232720]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S2 Windowhelp;Windowhelp; [x]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys --> c:\windows\system32\drivers\ScreamingBAudio.sys [?]
NETSVCS REQUIRES REPAIRS - current entries shown
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
Schedule
Seclogon
SENS
Sharedaccess
SRService
Tapisrv
Themes
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
BITS
wuauserv
ShellHWDetection
WmdmPmSN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
Contents of the 'Scheduled Tasks' folder
2009-09-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-09-09 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
------- Supplementary Scan -------
.
uStart Page = www.google.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\7d2vl89o.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1690724&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://wfigs.proboards48.com/
FF - plugin: c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\7d2vl89o.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLC\npvlc.dll
.
- - - - ORPHANS REMOVED - - - -
BHO-{BF56A325-23F2-42AD-F4E4-00AAC39CAA53} - (no file)
HKCU-Run-Performance Center - c:\program files\Ascentive\Performance Center\APCMain.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
HKU-Default-Run-Advanced Virus Remover - c:\program files\AdvancedVirusRemover\PAVRM.exe
Notify-xvexqrmi - xvexqrmi.dll
AddRemove-KeyHoleTV - c:\program files\KeyHoleTV\uninstall.exe
AddRemove-Veetle TV Player - c:\windows\UninstVeetleTVPlayer.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-09 12:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(752)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\libusbd-nt.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\StkASv2K.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-09-09 12:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-09 16:38
Pre-Run: 123,384,991,744 bytes free
Post-Run: 123,687,645,184 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
387 --- E O F --- 2008-07-23 04:36