QUOTE (Jesusfreak @ Aug 4 2009, 11:18 PM)

Hi!
I'm back and ready to run ComboFix but when I run it, it says it may be a tainted version. Can you give me the safest location for the file. It says I should download another copy before I run it.
Thanks
I found it...sorry. Here it is.
ComboFix 09-08-04.02 - Billy 08/04/2009 18:44.1.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2521 [GMT -5:00]
Running from: i:\documents and settings\Billy\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
i:\windows\system32\UACetjmukeshaxivrtnk.db
i:\windows\system32\UACpyqbitltmoiopjqga.dat
i:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_PCMSTUB
-------\Service_6to4
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-07-04 to 2009-08-04 )))))))))))))))))))))))))))))))
.
2009-07-29 20:26 . 2009-07-29 20:26 -------- d-----w- i:\program files\Trend Micro
2009-07-28 20:31 . 2009-07-03 17:09 594432 -c----w- i:\windows\system32\dllcache\msfeeds.dll
2009-07-28 20:31 . 2009-07-03 17:09 55296 -c----w- i:\windows\system32\dllcache\msfeedsbs.dll
2009-07-28 20:29 . 2009-07-28 20:29 -------- d-----w- i:\documents and settings\ADMIN\Application Data\Malwarebytes
2009-07-27 21:58 . 2009-07-29 00:21 15 ----a-w- i:\documents and settings\Billy\settings.dat
2009-07-27 00:43 . 2009-07-29 01:25 -------- d---a-w- i:\documents and settings\All Users\Application Data\TEMP
2009-07-25 21:09 . 2009-03-30 15:33 96104 ----a-w- i:\windows\system32\drivers\avipbb.sys
2009-07-25 21:09 . 2009-03-24 21:08 55640 ----a-w- i:\windows\system32\drivers\avgntflt.sys
2009-07-25 21:09 . 2009-02-13 17:29 22360 ----a-w- i:\windows\system32\drivers\avgntmgr.sys
2009-07-25 21:09 . 2009-02-13 17:17 45416 ----a-w- i:\windows\system32\drivers\avgntdd.sys
2009-07-25 21:09 . 2009-07-25 21:09 -------- d-----w- i:\program files\Avira
2009-07-25 21:09 . 2009-07-25 21:09 -------- d-----w- i:\documents and settings\All Users\Application Data\Avira
2009-07-25 13:33 . 2009-07-25 13:33 -------- d-----w- i:\documents and settings\ADMIN\Application Data\IObit
2009-07-25 13:24 . 2009-07-25 13:24 -------- d-sh--w- i:\documents and settings\ADMIN\PrivacIE
2009-07-24 22:00 . 2009-07-24 22:00 3775176 ----a-w- i:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-24 21:31 . 2001-08-23 12:00 4224 -c--a-w- i:\windows\system32\dllcache\beep.sys
2009-07-24 21:31 . 2001-08-23 12:00 4224 ----a-w- i:\windows\system32\drivers\beep.sys
2009-07-22 10:53 . 2009-07-25 22:51 -------- d-----w- i:\documents and settings\Billy\Application Data\IObit
2009-07-22 10:53 . 2009-07-22 10:53 -------- d-----w- i:\program files\IObit
2009-07-13 20:35 . 2009-07-13 20:35 -------- d-----w- i:\documents and settings\Billy\Application Data\Malwarebytes
2009-07-13 20:27 . 2009-07-13 20:27 3550592 ----a-w- I:\winlogon.exe.exe
2009-07-13 03:44 . 2009-07-13 03:44 3561752 ----a-w- I:\mbam-setup.exe
2009-07-13 03:06 . 2009-06-17 16:27 38160 ----a-w- i:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 03:06 . 2009-07-13 18:36 19096 ----a-w- i:\windows\system32\drivers\mbam.sys
2009-07-13 03:06 . 2009-07-13 03:06 -------- d-----w- i:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-13 03:02 . 2009-07-13 03:02 -------- d-----w- i:\program files\FileASSASSIN
2009-07-13 00:55 . 2009-07-03 14:49 15688 ----a-w- i:\windows\system32\lsdelete.exe
2009-07-13 00:13 . 2009-07-03 14:49 64160 ----a-w- i:\windows\system32\drivers\Lbd.sys
2009-07-13 00:13 . 2009-07-13 00:13 -------- dc-h--w- i:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-13 00:13 . 2009-07-08 17:28 2920112 -c--a-w- i:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-07-13 00:13 . 2009-07-13 00:13 -------- d-----w- i:\program files\Lavasoft
2009-07-13 00:13 . 2009-07-13 00:13 -------- d-----w- i:\documents and settings\All Users\Application Data\Lavasoft
2009-07-12 23:11 . 2009-07-12 23:11 -------- d-----w- i:\documents and settings\Billy\Application Data\Yahoo!
2009-07-12 23:11 . 2009-07-25 17:38 -------- d-----w- i:\program files\Yahoo!
2009-07-12 23:06 . 2009-07-12 23:07 49492 ----a-w- I:\cc_20090712_180634.reg
2009-07-11 22:26 . 2009-07-12 22:28 -------- d-----w- i:\documents and settings\All Users\Application Data\4545
2009-07-11 22:25 . 2009-07-11 22:25 -------- d-sh--w- i:\windows\system32\config\systemprofile\IETldCache
2009-07-11 15:03 . 2009-07-11 15:04 -------- d-----w- i:\documents and settings\Billy\Local Settings\Application Data\Temp
2009-07-11 15:03 . 2009-07-11 15:03 -------- d-----w- i:\documents and settings\Billy\Local Settings\Application Data\Deployment
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-04 23:10 . 2009-04-11 03:27 -------- d-----w- i:\program files\Microsoft Silverlight
2009-07-25 16:26 . 2009-03-31 01:22 -------- d-----w- i:\documents and settings\Billy\Application Data\LimeWire
2009-07-25 13:12 . 2009-07-25 13:12 12720 ----a-w- i:\documents and settings\ADMIN\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-25 13:12 . 2009-07-25 13:12 -------- d-----w- i:\documents and settings\ADMIN\Application Data\Logitech
2009-07-25 13:12 . 2009-07-25 13:12 -------- d-----w- i:\documents and settings\ADMIN\Application Data\ATI
2009-07-19 12:40 . 2009-03-31 01:28 -------- d-----w- i:\documents and settings\All Users\Application Data\avg8
2009-07-17 13:49 . 2009-03-31 01:28 335752 ----a-w- i:\windows\system32\drivers\avgldx86.sys
2009-07-07 22:30 . 2009-03-27 21:39 12720 ----a-w- i:\documents and settings\Billy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-05 15:04 . 2009-07-05 15:04 0 ----a-w- i:\windows\Infob.dat
2009-07-05 15:04 . 2009-07-05 15:04 0 ----a-w- i:\windows\Infoa.dat
2009-07-05 15:04 . 2009-07-05 14:34 -------- d-----w- i:\program files\Free MKV Video2Dvd
2009-07-05 14:12 . 2009-04-06 01:06 -------- d-----w- i:\documents and settings\All Users\Application Data\Apple Computer
2009-07-05 14:06 . 2009-07-05 14:06 -------- d-----w- i:\program files\Sonic Foundry
2009-07-05 14:06 . 2009-07-05 14:06 -------- d-----w- i:\program files\Pure Motion
2009-07-05 14:06 . 2009-07-05 14:06 -------- d-----w- i:\program files\DebugMode
2009-07-03 17:09 . 2008-04-14 10:42 915456 ----a-w- i:\windows\system32\wininet.dll
2009-06-24 20:51 . 2009-03-31 01:28 11952 ----a-w- i:\windows\system32\avgrsstx.dll
2009-06-24 20:51 . 2009-03-31 01:28 27784 ----a-w- i:\windows\system32\drivers\avgmfx86.sys
2009-06-19 14:56 . 2009-06-19 14:56 -------- d-----w- i:\documents and settings\Billy\Application Data\x3watch
2009-06-16 14:36 . 2008-04-14 10:42 119808 ----a-w- i:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2008-04-14 10:41 81920 ----a-w- i:\windows\system32\fontsub.dll
2009-06-15 03:26 . 2009-03-28 07:26 -------- d-----w- i:\documents and settings\Billy\Application Data\AdobeUM
2009-06-03 19:09 . 2008-04-14 10:42 1291264 ----a-w- i:\windows\system32\quartz.dll
2009-06-01 14:29 . 2009-06-01 14:29 12328 ----a-w- i:\documents and settings\Florence\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-25 18:06 . 2009-05-25 18:06 79872 ----a-w- i:\documents and settings\Billy\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
2009-05-25 18:06 . 2009-05-25 18:06 349184 ----a-w- i:\documents and settings\Billy\Application Data\SanDisk\Sansa Updater\SansaUpdaterInstall.exe
2009-05-25 18:06 . 2009-05-25 18:06 541696 ----a-w- i:\documents and settings\Billy\Application Data\SanDisk\Sansa Updater\SansaUpdater.exe
2009-05-07 15:32 . 2008-04-14 10:41 345600 ----a-w- i:\windows\system32\localspl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SansaDispatch"="i:\documents and settings\Billy\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-05-25 79872]
"Nero PhotoShow Media Manager"="i:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-05-10 249856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="i:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-17 139264]
"ccleaner"="i:\program files\CCleaner\CCleaner.exe" [2009-06-25 1578736]
"Advanced SystemCare 3"="i:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-06-30 2329224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="i:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"StartCCC"="i:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"QuickTime Task"="i:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"NeroFilterCheck"="i:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LiveMonitor"="i:\program files\MSI\Live Update 3\LMonitor.exe" [2009-02-24 498688]
"InCD"="i:\program files\Nero\Nero 7\InCD\InCD.exe" [2006-11-10 1051648]
"AVG8_TRAY"="i:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-24 1948440]
"avgnt"="i:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"MSConfig"="i:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]
"RTHDCPL"="RTHDCPL.EXE" - i:\windows\RTHDCPL.exe [2008-07-03 16876032]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - i:\windows\KHALMNPR.Exe [2004-10-21 29696]
i:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - i:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Logitech SetPoint.lnk - i:\program files\Logitech\SetPoint\KEM.exe [2009-3-27 581632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-24 20:51 11952 ----a-w- i:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"i:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"i:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"j:\\Unreal Tournament 3\\Binaries\\UT3.exe"=
R0 Lbd;Lbd;i:\windows\system32\drivers\Lbd.sys [7/12/2009 7:13 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;i:\windows\system32\drivers\avgldx86.sys [3/30/2009 8:28 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;i:\windows\system32\drivers\avgtdix.sys [3/30/2009 8:28 PM 108552]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;i:\program files\Avira\AntiVir Desktop\sched.exe [7/25/2009 4:09 PM 108289]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;i:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;i:\windows\system32\drivers\AtiHdmi.sys [3/27/2009 9:54 PM 93184]
S2 bjftulks;bjftulks;i:\windows\system32\drivers\brrshma.sys --> i:\windows\system32\drivers\brrshma.sys [?]
S2 rayar;rayar;\??\i:\windows\system32\drivers\skvelixtl.sys --> i:\windows\system32\drivers\skvelixtl.sys [?]
S2 vkcyvsjbs;vkcyvsjbs;\??\i:\windows\system32\drivers\jkqtor.sys --> i:\windows\system32\drivers\jkqtor.sys [?]
S4 avg8wd;AVG Free8 WatchDog;i:\progra~1\AVG\AVG8\avgwdsvc.exe [3/30/2009 8:28 PM 298776]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"i:\windows\system32\rundll32.exe" "i:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-28 i:\windows\Tasks\Ad-Aware Update (Weekly).job
- i:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
2009-08-04 i:\windows\Tasks\WGASetup.job
- i:\windows\system32\KB905474\wgasetup.exe [2009-04-30 03:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
IE: Add to Google Photos Screensa&ver - i:\windows\system32\GPhotos.scr/200
DPF: Microsoft XML Parser for Java - file://i:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-04 18:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(768)
i:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2472)
i:\windows\system32\WININET.dll
i:\program files\Logitech\SetPoint\lgscroll.dll
i:\windows\system32\ieframe.dll
i:\windows\system32\webcheck.dll
i:\windows\system32\WPDShServiceObj.dll
i:\windows\system32\PortableDeviceTypes.dll
i:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
i:\windows\system32\ati2evxx.exe
i:\windows\system32\ati2evxx.exe
i:\program files\AVG\AVG8\avgrsx.exe
i:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
i:\program files\Avira\AntiVir Desktop\avguard.exe
i:\program files\Nero\Nero 7\InCD\InCDsrv.exe
i:\program files\Java\jre6\bin\jqs.exe
i:\program files\Common Files\LightScribe\LSSrvc.exe
i:\windows\system32\wbem\unsecapp.exe
i:\program files\Lavasoft\Ad-Aware\AAWTray.exe
i:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
i:\program files\AVG\AVG8\avgtray.exe
i:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
i:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
i:\program files\Logitech\SetPoint\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2009-08-04 18:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-04 23:49
Pre-Run: 94,835,458,048 bytes free
Post-Run: 94,961,287,168 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
i:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
210 --- E O F --- 2009-08-04 23:09