And lastly, my Combo-Fix log:
ComboFix 09-10-10.01 - marc 10/10/2009 16:53.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.660 [GMT -4:00]
Running from: c:\documents and settings\marc\Desktop\Combo-Fix.exe
AV: CyberDefender Internet Security *On-access scanning enabled* (Updated) {51D57A40-BB00-4754-AEA1-30DF654182EB}
AV: Prevx 3.0 *On-access scanning enabled* (Updated) {D486329C-1488-4CEB-9CC8-D662B732D901}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((( Files Created from 2009-09-10 to 2009-10-10 )))))))))))))))))))))))))))))))
.
2009-10-10 19:14 . 2009-10-10 19:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-10 15:13 . 2009-10-10 15:13 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-10-10 15:13 . 2009-10-10 15:13 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-10-10 15:13 . 2009-10-10 15:13 -------- d-----w- c:\program files\Prevx
2009-10-10 15:13 . 2009-10-10 19:57 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-10-10 15:07 . 2009-10-10 15:07 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-10 15:07 . 2009-10-10 15:07 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-10 14:47 . 2008-04-14 00:12 135680 ----a-w- c:\windows\system32\Littlemonkey.exe
2009-10-10 14:28 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-10 14:28 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-10 02:37 . 2009-10-10 02:37 -------- d-----w- c:\program files\Trend Micro
2009-10-10 02:24 . 2009-10-10 02:24 -------- dc----w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-10-10 01:33 . 2009-10-10 01:33 -------- d-sh--w- c:\documents and settings\marc\IECompatCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-20 23:26 . 2008-12-18 17:52 -------- d-----w- c:\program files\AutoCAD 2008
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-18 00:00 . 2008-12-05 16:42 50200 ----a-w- c:\documents and settings\marc\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2007-08-18 16:31 . 2007-08-18 16:31 38912 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2007-08-18 16:31 . 2007-08-18 16:31 102471 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2007-08-18 16:31 . 2007-08-18 16:31 93848 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2007-08-18 16:31 . 2007-08-18 16:31 94208 ----a-w- c:\program files\mozilla firefox\plugins\mwmcli.dll
2009-07-10 17:37 . 2009-07-10 17:37 1011349 --sha-w- c:\windows\system32\kamideva.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\pixie.exe" [2009-09-10 1312080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-09-15 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-09-15 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-09-15 77824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-5-22 2756608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"drv"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\WLKEEPER.exe"=
"c:\\Program Files\\Prevx\\prevx.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\EvtEng.exe"=
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [10/10/2009 11:13 AM 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [10/10/2009 11:13 AM 27656]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [10/10/2009 11:13 AM 4368952]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.cnn.com/
FF - ProfilePath - c:\documents and settings\marc\Application Data\Mozilla\Firefox\Profiles\prv98ipr.default\
FF - prefs.js: browser.startup.homepage - www.cnn.com
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-MbWzdFPAP-EXL540 - E:\PdtGuide.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-10 16:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"="a"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(848)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\UTSCSI.EXE
c:\windows\system32\rundll32.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2009-10-10 17:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-10 21:01
Pre-Run: 71,059,283,968 bytes free
Post-Run: 71,118,860,288 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
134 --- E O F --- 2009-09-09 04:04