here is the combofix log
ComboFix 09-11-19.06 - Compaq_Owner 11/20/2009 11:25.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.247 [GMT -5:00]
Running from: c:\documents and settings\Compaq_Owner.HOMEPC\desktop\clean.exe
Command switches used :: /killall
AV: avast! antivirus 4.8.1356 [VPS 091120-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\pciide.sys
c:\windows\system32\AOLDial.dll . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2009-10-20 to 2009-11-20 )))))))))))))))))))))))))))))))
.
2009-11-18 14:57 . 2009-11-18 14:57 160272 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-11-18 14:57 . 2009-11-18 14:57 -------- d-----w- c:\documents and settings\Compaq_Owner.HOMEPC\log
2009-11-18 14:55 . 2009-11-18 14:55 -------- d-sh--w- c:\documents and settings\Compaq_Owner.HOMEPC\PrivacIE
2009-11-16 14:03 . 2009-11-16 14:03 -------- d-----w- c:\documents and settings\Administrator.HOMEPC\Application Data\Malwarebytes
2009-11-16 13:57 . 2009-11-16 13:57 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-11-16 13:53 . 2009-11-16 16:18 -------- d-----w- c:\documents and settings\Compaq_Owner.HOMEPC\Local Settings\Application Data\qytpue
2009-11-10 20:25 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-10 20:25 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-10 20:25 . 2009-11-10 20:25 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-10 17:35 . 2009-11-10 17:35 -------- d-----w- c:\program files\Common Files\McAfee
2009-11-10 17:35 . 2009-11-10 23:06 -------- d-----w- c:\program files\McAfee
2009-11-10 16:11 . 2009-09-15 11:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-10 16:11 . 2009-09-15 11:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-10 16:11 . 2009-09-15 11:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-10 16:11 . 2009-09-15 11:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-10 16:11 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-10 16:11 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-10 16:11 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-10 16:11 . 2009-09-15 11:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-10 16:11 . 2009-09-15 11:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-06 09:36 . 2009-11-06 09:36 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-11-06 01:12 . 2009-11-06 01:12 -------- d-sh--w- c:\documents and settings\Compaq_Owner.HOMEPC\IETldCache
2009-11-06 01:04 . 2009-11-06 01:04 -------- d-----w- c:\program files\LSI SoftModem
2009-11-06 01:04 . 2009-10-02 04:44 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-11-06 01:03 . 2009-11-06 13:49 -------- d-----w- c:\windows\ie8updates
2009-11-06 01:01 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-11-06 01:01 . 2009-08-29 08:08 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-06 01:01 . 2009-08-29 08:08 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-11-06 01:01 . 2009-08-29 08:08 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-11-06 01:01 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-06 01:01 . 2009-08-29 08:08 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-11-06 00:59 . 2009-11-06 01:01 -------- dc-h--w- c:\windows\ie8
2009-11-06 00:44 . 2009-11-06 00:44 -------- d-----w- c:\windows\system32\XPSViewer
2009-11-06 00:43 . 2009-11-06 00:43 -------- d-----w- c:\program files\Reference Assemblies
2009-11-06 00:43 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-11-06 00:43 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-11-06 00:43 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-11-06 00:43 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-11-06 00:43 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-11-06 00:43 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-11-06 00:43 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-11-06 00:43 . 2009-11-06 00:43 -------- d-----w- C:\b8c5031fb3359c0f2b
2009-11-06 00:23 . 2009-11-06 00:21 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-06 00:21 . 2009-11-06 00:21 152576 ----a-w- c:\documents and settings\Compaq_Owner.HOMEPC\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-05 22:54 . 2005-06-06 15:29 110592 ----a-w- c:\documents and settings\Compaq_Owner.HOMEPC\Application Data\U3\temp\cleanup.exe
2009-11-05 22:42 . 2009-11-05 22:54 -------- d-----w- c:\documents and settings\Compaq_Owner.HOMEPC\Application Data\U3
2009-11-02 20:18 . 2009-11-02 20:18 -------- d-----w- c:\documents and settings\Compaq_Owner.HOMEPC\Local Settings\Application Data\Fisher-Price
2009-11-02 00:00 . 2009-11-02 00:00 -------- d-----w- c:\documents and settings\Compaq_Owner.HOMEPC\Application Data\InstallShield
2009-11-01 23:56 . 2009-11-01 23:56 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-10-29 20:30 . 2009-10-29 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-29 20:19 . 2009-10-29 20:19 -------- d-----w- c:\documents and settings\Compaq_Owner.HOMEPC\Local Settings\Application Data\Apple
2009-10-29 20:17 . 2009-11-06 20:05 -------- dc----w- c:\windows\system32\DRVSTORE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-19 16:11 . 2009-09-04 22:58 158 ----a-w- c:\documents and settings\Compaq_Owner.HOMEPC\Application Data\wklnhst.dat
2009-11-17 15:07 . 2007-10-17 20:14 -------- d-----w- c:\program files\HOTALBUMMyBOX
2009-11-10 17:35 . 2009-09-02 12:57 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-07 01:46 . 2009-08-25 22:55 34008 ----a-w- c:\documents and settings\Compaq_Owner.HOMEPC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-06 20:06 . 2004-10-20 14:46 -------- d-----w- c:\program files\iTunes
2009-11-06 20:05 . 2004-10-20 14:46 -------- d-----w- c:\program files\iPod
2009-11-06 00:44 . 2009-04-11 21:54 -------- d-----w- c:\program files\MSBuild
2009-11-06 00:21 . 2004-10-20 13:39 -------- d-----w- c:\program files\Java
2009-11-02 00:00 . 2009-07-16 20:36 -------- d-----w- c:\program files\Fisher-Price
2009-10-30 00:29 . 2007-06-29 17:47 -------- d-----w- c:\program files\Common Files\Apple
2009-10-30 00:17 . 2009-08-25 22:17 -------- d-----w- c:\documents and settings\Compaq_Owner.HOMEPC\Application Data\Apple Computer
2009-10-29 20:26 . 2008-04-04 19:47 -------- d-----w- c:\program files\Bonjour
2009-10-29 20:26 . 2004-10-20 14:46 -------- d-----w- c:\program files\QuickTime
2009-10-29 20:18 . 2007-05-19 18:41 -------- d-----w- c:\program files\Apple Software Update
2009-10-08 19:57 . 2008-07-30 00:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 19:57 . 2004-12-02 17:19 220160 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 19:56 . 2004-12-02 17:19 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2009-09-16 14:22 . 2009-09-02 13:59 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 14:22 . 2009-09-02 13:59 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 14:22 . 2009-09-02 13:59 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 14:22 . 2009-07-08 17:44 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 14:22 . 2009-09-02 13:57 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-11 14:18 . 2004-12-02 17:18 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-12-02 17:18 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 17:36 . 2004-10-20 13:12 82435 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-09-01 17:34 . 2009-09-01 17:34 69632 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\msxmlwrapper.dll
2009-08-29 08:08 . 2004-12-02 17:20 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 12:07 . 2009-08-27 12:07 15172 ----a-w- c:\windows\system32\drivers\PzWDM.sys
2009-08-26 08:00 . 2004-12-02 17:19 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 23:08 . 2009-08-25 22:17 142 ----a-w- c:\documents and settings\Compaq_Owner.HOMEPC\Local Settings\Application Data\fusioncache.dat
2009-08-23 15:12 . 2009-04-11 20:10 117760 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2008-03-08 20:47 . 2008-03-08 20:47 0 ----a-w- c:\program files\temp01
2005-05-19 18:51 . 2005-05-19 18:51 774144 ----a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-10-20 180269]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-21 155648]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-12-18 118784]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-13 98304]
"MBBalloon"="c:\program files\HOTALBUMMyBOX\MBBalloon.exe" [2006-12-15 787096]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"eligmini"="c:\program files\Fisher-Price\Easy-Link internet launch pad\Easy-Link internet launch pad.exe" [2008-09-03 487424]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-18 196608]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-08 53248]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2004-09-24 49152]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-30 88363]
c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
Compaq Organize.lnk - c:\program files\Hewlett-Packard\Compaq Organize\bin\displayAgent.exe [2004-10-21 36864]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-2-27 809488]
MediaChecker.lnk - c:\program files\HOTALBUMMyBOX\MediaChecker.exe [2006-12-15 913560]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-2-5 54512]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [8/27/2009 7:07 AM 15172]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11/10/2009 11:11 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/10/2009 11:11 AM 20560]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [11/10/2009 12:35 PM 92296]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CLASSPNP_2
*Deregistered* - CLASSPNP_2
.
Contents of the 'Scheduled Tasks' folder
2009-11-16 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 22:50]
2009-11-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Compaq_Owner.HOMEPC\Application Data\Mozilla\Firefox\Profiles\a2xiqs09.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPcol305.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-LSI Soft Modem - c:\windows\agrsmdel
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-20 12:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x84F5D170]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf772df28
\Driver\ACPI -> ACPI.sys @ 0xf76a0cb8
\Driver\atapi -> atapi.sys @ 0xf7658852
IoDeviceObjectType -> ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xf7529bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7536a21
SendHandler -> NDIS.sys @ 0xf751487b
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(720)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3300)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-11-20 12:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-20 17:17
Pre-Run: 135,565,180,928 bytes free
Post-Run: 135,530,807,296 bytes free
- - End Of File - - 8BC4037F2C0FA0BEC6DEF4DD89113BE9