Hi Blade..this is the log..
ComboFix 10-06-10.03 - user 06/11/2010 10:50:06.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1980.1395 [GMT 8:00]
Running from: c:\documents and settings\user\Desktop\renamed.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\{5F229C11-5039-40E4-8537-6950BB1C9ECC}
C:\autorun.inf
c:\documents and settings\user\Templates\cache
c:\documents and settings\user\Templates\cache\$RECYCLE.BIN\{5F229C11-5039-40E4-8537-6950BB1C9ECC}\desktop.ini
c:\documents and settings\user\Templates\cache\$RECYCLE.BIN\{5F229C11-5039-40E4-8537-6950BB1C9ECC}\NF2.exe
c:\documents and settings\user\Templates\cache\$RECYCLE.BIN\{5F229C11-5039-40E4-8537-6950BB1C9ECC}\rcmd.ini
c:\documents and settings\user\Templates\cache\$RECYCLE.BIN\{5F229C11-5039-40E4-8537-6950BB1C9ECC}\RemoteINF.exe
c:\documents and settings\user\Templates\cache\$RECYCLE.BIN\{5F229C11-5039-40E4-8537-6950BB1C9ECC}\temp.db
c:\documents and settings\user\Templates\cache\$RECYCLE.BIN\{5F229C11-5039-40E4-8537-6950BB1C9ECC}\tmp.db
c:\documents and settings\user\Templates\cache\desktop.ini
d:\$recycle.bin\{5F229C11-5039-40E4-8537-6950BB1C9ECC}
D:\autorun.inf
c:\windows\system32\midimap.dll . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2010-05-11 to 2010-06-11 )))))))))))))))))))))))))))))))
.
2010-06-02 04:12 . 2007-07-27 15:11 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-06-02 03:45 . 2009-10-13 10:30 270336 -c----w- c:\windows\system32\dllcache\oakley.dll
2010-06-02 03:45 . 2009-11-27 16:07 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll
2010-06-02 03:45 . 2009-11-27 16:07 28672 -c----w- c:\windows\system32\dllcache\msvidc32.dll
2010-06-02 03:45 . 2009-11-27 16:07 84992 -c----w- c:\windows\system32\dllcache\avifil32.dll
2010-06-02 03:45 . 2009-11-27 16:07 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll
2010-06-02 03:45 . 2009-11-27 16:07 11264 -c----w- c:\windows\system32\dllcache\msrle32.dll
2010-06-02 03:44 . 2010-01-29 15:01 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-06-02 03:44 . 2009-12-16 18:43 343040 -c----w- c:\windows\system32\dllcache\mspaint.exe
2010-06-02 03:44 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2010-06-02 03:44 . 2009-09-11 14:13 136704 -c----w- c:\windows\system32\dllcache\msv1_0.dll
2010-06-02 03:44 . 2009-06-25 08:41 56832 -c----w- c:\windows\system32\dllcache\secur32.dll
2010-06-02 03:44 . 2009-06-25 08:41 54272 -c----w- c:\windows\system32\dllcache\wdigest.dll
2010-06-02 03:44 . 2009-06-25 08:41 147456 -c----w- c:\windows\system32\dllcache\schannel.dll
2010-06-02 03:44 . 2009-06-25 08:41 301568 -c----w- c:\windows\system32\dllcache\kerberos.dll
2010-06-02 03:44 . 2009-06-24 10:28 92928 -c----w- c:\windows\system32\dllcache\ksecdd.sys
2010-06-02 03:43 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-06-02 03:43 . 2010-02-16 14:08 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-06-02 03:43 . 2010-02-16 13:25 2066816 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-06-02 03:43 . 2010-02-16 13:25 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-06-02 03:42 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-06-02 03:41 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-06-02 03:38 . 2009-10-15 16:39 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-06-02 03:38 . 2009-10-15 16:39 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-06-02 03:38 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-06-02 03:33 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-06-02 03:32 . 2009-07-31 04:35 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2010-06-02 03:29 . 2009-08-13 15:16 512000 -c----w- c:\windows\system32\dllcache\jscript.dll
2010-06-02 03:25 . 2009-12-24 06:59 177664 -c----w- c:\windows\system32\dllcache\wintrust.dll
2010-06-02 03:25 . 2010-01-13 14:01 86016 -c----w- c:\windows\system32\dllcache\cabview.dll
2010-06-02 03:23 . 2010-06-02 03:23 -------- d-----w- c:\program files\ESET
2010-06-02 03:09 . 2009-08-06 11:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-06-02 03:03 . 2009-10-12 07:21 100736 ----a-w- c:\windows\system32\drivers\ewusbdev.sys
2010-06-02 03:03 . 2010-06-02 03:08 -------- d-----w- c:\program files\Celcom Broadband Manager
2010-05-26 05:03 . 2010-05-26 05:04 63488 ----a-w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-05-26 05:03 . 2010-05-26 05:03 52224 ----a-w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-05-26 05:03 . 2010-05-26 05:04 117760 ----a-w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-05-26 05:03 . 2010-05-26 05:03 -------- d-----w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com
2010-05-26 05:03 . 2010-05-26 05:03 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-05-26 05:03 . 2010-05-26 05:03 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-05-20 04:24 . 2010-05-20 04:24 -------- d-----w- c:\program files\Alwil Software
2010-05-20 03:55 . 2010-05-20 03:55 -------- d-----w- c:\documents and settings\user\Application Data\Malwarebytes
2010-05-20 03:55 . 2009-01-14 08:11 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-20 03:55 . 2009-01-14 08:11 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-20 03:55 . 2010-05-20 03:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-20 03:55 . 2010-05-20 03:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-11 02:43 . 2010-03-23 14:04 -------- d-----w- c:\program files\WinFlip
2010-06-08 10:02 . 2010-05-02 12:49 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-02 04:15 . 2010-03-23 14:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-11 13:41 . 2010-03-22 20:18 -------- d-----w- c:\program files\Mobile Partner
2010-04-22 04:42 . 2010-03-25 11:04 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-04-22 04:38 . 2010-04-22 04:38 1924976 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2010-04-22 04:21 . 2010-04-22 04:21 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-22 04:16 . 2010-03-27 17:14 -------- d-----w- c:\documents and settings\user\Application Data\CBS Interactive
2010-03-27 06:51 . 2010-03-23 14:07 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-23 14:35 . 2010-03-23 14:21 68848 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-23 14:19 . 2010-03-23 14:19 0 ----a-w- c:\windows\nsreg.dat
2010-03-23 14:05 . 2010-03-23 14:05 21640 ----a-w- c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[-] 2009-07-16 . 3D1ABDC3009D6B7CA7F9E66769C126CA . 568832 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2009-07-16 . EA032FC150B9C6276C98EB3DED3B75C6 . 652800 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2009-07-16 . 8C578971B2F1A27B961A99CE5D2EFD7D . 3378176 . . [6.00.2900.5803] . . c:\windows\system32\mshtml.dll
[-] 2009-07-16 . 99C1ACB1B8F0F2CECC56515E502B5120 . 575488 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2009-07-16 . CC2883E0A1EBBBAAE185D811720C66B3 . 757248 . . [6.00.2900.5803] . . c:\windows\system32\wininet.dll
[-] 2009-07-16 . E382F43EEAB770932F2727B65BD888B4 . 1723904 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2009-07-16 . CBF5945651C96E471B3A004BBDC36864 . 37376 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UberIcon"="c:\program files\UberIcon\UberIcon Manager.exe" [2007-08-17 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-25 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-25 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-25 136192]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"WINFLIP"="c:\program files\WinFlip\WinFlip.exe" [2008-05-21 483328]
"VisualTooltip"="c:\program files\Utilities\VisualTooltip\VisualToolTip.exe" [2007-04-25 956928]
"DriveSpace"="c:\program files\Drive Space Indicator\DrvSpace.exe" [2009-04-18 417761]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-01-14 399504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"UberIcon"="c:\program files\UberIcon\UberIcon Manager.exe" [2007-08-17 159744]
c:\documents and settings\user\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-27 98632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoShellSearchButto"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/18/2010 2:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/11/2010 2:41 AM 67656]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5/20/2010 11:55 AM 170640]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [5/11/2010 9:41 PM 114432]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [6/2/2010 11:03 AM 100736]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/20/2010 11:55 AM 15504]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 8:49 PM 227232]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: {3FD77C3D-775C-45ED-8DB2-44DB52584C55} = 203.82.64.145 203.82.64.129
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\bdlsfim7.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.bramjnet.com/vb/
FF - prefs.js: network.proxy.ftp - :8181
FF - prefs.js: network.proxy.gopher - :8181
FF - prefs.js: network.proxy.http - :8181
FF - prefs.js: network.proxy.socks - :8181
FF - prefs.js: network.proxy.ssl - :8181
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-11 10:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
@=""
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
@=""
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
@=""
"Installed"="1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(884)
c:\windows\system32\SETUPAPI.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(940)
c:\windows\system32\wdigest.dll
c:\windows\system32\setupapi.dll
.
Completion time: 2010-06-11 10:53:16
ComboFix-quarantined-files.txt 2010-06-11 02:53
Pre-Run: 94,428,663,808 bytes free
Post-Run: 94,485,004,288 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /NOEXECUTE=OPTIN /FASTDETECT
- - End Of File - - 81808DF858D022E56D3567D35EC50156