QUOTE (JSntgRvr @ Sep 3 2009, 01:22 PM)

Any progress?
Yes, here is the Combo-Fix log. Some of the newly created files were created by me..
ComboFix 09-09-03.02 - diMitris 09/03/2009 13:12.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1446 [GMT -7:00]
Running from: c:\documents and settings\diMitris\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\98737496.ini
c:\program files\driver
c:\program files\Mozilla Firefox\searchplugins\search.xml
c:\windows\Installer\21c23b2.msi
c:\windows\system32\Drivers\xaioejes.sys
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DRIVER
-------\Legacy_DRIVERDRV
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_ilto
((((((((((((((((((((((((( Files Created from 2009-08-03 to 2009-09-03 )))))))))))))))))))))))))))))))
.
2009-09-02 06:38 . 2009-09-02 06:59 -------- d-----w- C:\fdsa
2009-09-02 06:28 . 2009-09-02 06:29 -------- d-----w- c:\program files\Spyware Doctor
2009-09-02 06:28 . 2009-09-02 06:28 -------- d-----w- c:\documents and settings\diMitris\Application Data\PC Tools
2009-09-02 06:19 . 2009-09-02 06:19 -------- d-----w- c:\program files\Windows Live Safety Center
2009-09-01 20:28 . 2009-09-02 07:04 -------- d-----w- c:\program files\dimi
2009-09-01 20:18 . 2009-02-01 08:29 136382 ----a-w- c:\windows\system32\fr33.exe
2009-08-31 20:54 . 2009-08-31 22:04 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-31 19:49 . 2009-08-31 19:49 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-08-31 19:31 . 2009-08-31 19:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-31 19:03 . 2009-08-31 19:03 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-08-31 18:17 . 2009-08-31 18:17 -------- d-----w- c:\documents and settings\Administrator\Application Data\Lavasoft
2009-08-31 18:14 . 2009-09-02 06:43 -------- d--h--w- c:\windows\PIF
2009-08-31 10:07 . 2009-08-31 10:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-08-31 02:41 . 2009-08-31 02:41 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-12 23:04 . 2009-08-13 00:25 -------- d-----w- c:\documents and settings\diMitris\Local Settings\Application Data\ApplicationHistory
2009-08-07 22:28 . 2009-08-07 22:28 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-08-06 04:29 . 2009-08-06 04:29 -------- d-sh--w- c:\documents and settings\diMitris\IECompatCache
2009-08-06 04:29 . 2009-08-06 04:29 -------- d-sh--w- c:\documents and settings\diMitris\PrivacIE
2009-08-06 04:28 . 2009-08-06 04:28 -------- d-sh--w- c:\documents and settings\diMitris\IETldCache
2009-08-05 08:27 . 2009-08-05 08:27 687104 ----a-w- c:\windows\is-CTR59.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-03 20:50 . 2008-06-05 11:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-02 18:25 . 2008-06-05 12:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-09-02 18:00 . 2008-06-05 11:07 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-02 06:34 . 2008-11-24 05:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-01 21:41 . 2009-06-21 13:23 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-01 20:53 . 2008-11-24 10:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-31 18:55 . 2008-12-01 11:02 -------- d-----w- c:\program files\SpeedFan
2009-08-31 02:43 . 2008-06-05 12:41 -------- d-----w- c:\documents and settings\diMitris\Application Data\uTorrent
2009-08-31 02:43 . 2008-06-05 11:18 -------- d-----w- c:\program files\mIRC
2009-08-28 22:33 . 2008-08-22 22:28 -------- d-----w- c:\program files\Safari
2009-08-06 04:13 . 2008-06-08 05:10 56884 ---ha-w- c:\windows\system32\mlfcache.dat
2009-08-04 14:15 . 2008-06-05 08:17 70088 ----a-w- c:\documents and settings\diMitris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-03 20:36 . 2008-11-24 10:07 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 20:36 . 2008-11-24 10:07 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-02 18:58 . 2008-06-05 12:38 -------- d-----w- c:\documents and settings\diMitris\Application Data\Nero
2009-08-02 18:29 . 2009-07-30 19:54 -------- d-----w- c:\documents and settings\diMitris\Application Data\Publish Providers
2009-07-30 21:25 . 2009-07-30 18:52 -------- d-----w- c:\documents and settings\diMitris\Application Data\vlc
2009-07-30 20:06 . 2009-07-30 20:06 -------- d-----w- c:\program files\MagicDVDRipper
2009-07-30 19:54 . 2009-07-30 19:54 -------- d-----w- c:\documents and settings\diMitris\Application Data\Sony
2009-07-30 19:50 . 2009-07-30 19:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony
2009-07-30 19:50 . 2009-07-30 19:50 -------- d-----w- c:\program files\Sony
2009-07-30 19:48 . 2008-06-10 01:03 -------- d-----w- c:\program files\MSBuild
2009-07-30 19:46 . 2009-07-30 19:46 -------- d-----w- c:\program files\Reference Assemblies
2009-07-30 19:44 . 2009-07-30 19:44 -------- d-----w- c:\documents and settings\diMitris\Application Data\Sony Setup
2009-07-30 19:43 . 2009-07-30 19:43 -------- d-----w- c:\program files\Sony Setup
2009-07-30 18:45 . 2009-07-30 18:45 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-07-30 18:45 . 2009-07-30 18:45 -------- d-----w- c:\program files\DVD Shrink
2009-07-22 02:04 . 2009-07-22 02:04 -------- d-----w- c:\program files\iTunes
2009-07-22 02:04 . 2009-07-22 02:04 -------- d-----w- c:\program files\iPod
2009-07-22 02:04 . 2008-06-05 12:26 -------- d-----w- c:\program files\Common Files\Apple
2009-07-16 03:00 . 2008-06-05 12:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-07-14 01:17 . 2008-12-08 11:04 256 ----a-w- c:\windows\system32\pool.bin
2009-07-14 00:49 . 2008-12-02 08:42 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-07-03 17:09 . 2006-06-23 18:33 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-06-29 16:12 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-16 14:55 . 2002-08-29 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2002-08-29 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
.
------- Sigcheck -------
[7] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$hf_mig$\KB917953\SP2GDR\tcpip.sys
[7] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[7] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2006-04-20 11:38 340480 B8158E2A6112C0A5CA67BC158FC70218 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\ServicePackFiles\i386\TCPIP.SYS
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\tcpip.sys
[-] 2008-09-07 09:07 360320 1AB9333EC47BC064050A2BF554AE5A95 c:\windows\system32\dllcache\TCPIP.SYS
[-] 2008-09-07 09:07 360320 1AB9333EC47BC064050A2BF554AE5A95 c:\windows\system32\drivers\TCPIP.SYS
c:\windows\system32\drivers\beep.sys ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NVSvc"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"ecure"=2 (0x2)
"system"=2 (0x2)
"svchost1"=2 (0x2)
"Viewpoint Manager Service"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NMIndexingService"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"Microsoft Office Groove Audit Service"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Adobe Version Cue CS3"=3 (0x3)
"gusvc"=2 (0x2)
"npkcmsvc"=2 (0x2)
"Pml Driver HPH11"=3 (0x3)
"gupdate1c926668f519d20"=2 (0x2)
"CCALib8"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"Nero BackItUp Scheduler 4.0"=2 (0x2)
"idsvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Steam\\steamapps\\pan@love-stations.com\\counter-strike\\hl.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Launcher.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Steam\\steamapps\\common\\fear2spdemo\\FEAR2SPDemo.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
S0 tclondrv;tclondrv;c:\windows\system32\DRIVERS\tclondrv.sys --> c:\windows\system32\DRIVERS\tclondrv.sys [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 ALLOW-IO;ALLOW-IO;\??\e:\allow-io.sys --> e:\ALLOW-IO.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [6/5/2009 1:05 PM 16640]
S4 ecure;FireDaemon Service: ecure;c:\windows\Temp\FireDaemon.EXE --> c:\windows\Temp\FireDaemon.EXE [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [9/1/2009 11:28 PM 337800]
S4 svchost1;FireDaemon Service: svchost1;c:\windows\Temp\FireDaemon.EXE --> c:\windows\Temp\FireDaemon.EXE [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com/
mSearchMigratedDefaultURL = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local;<local>
mSearchURL = hxxp://www.google.com/
TCP: {B7619692-AF55-4DF1-A88A-452471927EC3} = 209.18.47.61,209.18.47.62
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\documents and settings\diMitris\Application Data\Mozilla\Firefox\Profiles\471cks97.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - HiddenExtension: XUL Cache: {07433DDA-DFFF-4454-AB97-518CC05CCEE6} - c:\documents and settings\diMitris\Local Settings\Application Data\{07433DDA-DFFF-4454-AB97-518CC05CCEE6}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-03 13:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1659004503-287218729-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:82,48,19,f2,0f,77,82,fc,1c,59,cf,cd,53,f0,20,6c,72,c3,91,78,23,ef,71,
4c,a2,d3,fd,21,bb,28,e1,6b,77,31,40,af,ac,dd,6a,d1,f6,66,a2,36,94,39,8e,26,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(268)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-03 13:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-03 20:57
Pre-Run: 468,960,309,248 bytes free
Post-Run: 468,830,306,304 bytes free
266 --- E O F --- 2008-10-24 10:00