Just to let you know, I had to remove my Malawarebytes because my icon wasn't there so I couldn't disable it.
ComboFix 11-07-11.02 - Administrator 07/11/2011 10:06:01.1.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.246.133 [GMT -4:00]
Running from: c:\documents and settings\Administrator.CULVERHOUSE\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\VDPLtsHLVdsd.exe
c:\documents and settings\Owner\Application Data\6339077DDBD6B58811114A339A45E7EE
c:\documents and settings\Owner\Application Data\6339077DDBD6B58811114A339A45E7EE\enemies-names.txt
c:\documents and settings\Owner\Application Data\6339077DDBD6B58811114A339A45E7EE\local.ini
c:\documents and settings\Owner\Application Data\6339077DDBD6B58811114A339A45E7EE\lsrslt.ini
c:\documents and settings\Owner\Application Data\6339077DDBD6B58811114A339A45E7EE\tplsis70t.exe
c:\documents and settings\Owner\Application Data\Adobe\plugs
c:\documents and settings\Owner\Application Data\Adobe\shed
c:\documents and settings\Owner\Application Data\PriceGong\Data\wlu.txt
c:\documents and settings\Owner\g2mdlhlpx.exe
c:\documents and settings\Owner\Local Settings\Application Data\{DBD1E57D-81F0-4027-9045-27B83F0C2B03}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{DBD1E57D-81F0-4027-9045-27B83F0C2B03}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{DBD1E57D-81F0-4027-9045-27B83F0C2B03}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{DBD1E57D-81F0-4027-9045-27B83F0C2B03}\install.rdf
c:\documents and settings\Owner\Start Menu\Programs\Windows XP Repair
c:\documents and settings\Owner\Start Menu\Programs\Windows XP Repair\Uninstall Windows XP Repair.lnk
c:\documents and settings\Owner\Start Menu\Programs\Windows XP Repair\Windows XP Repair.lnk
c:\program files\SelectRebates\FFToolbar(2)\chrome\sahtoolbar.jar
c:\program files\SelectRebates\FFToolbar(2)\defaults\preferences\sahtoolbar.js
c:\program files\SelectRebates\FFToolbar(2)\install.rdf
c:\program files\SelectRebates\SahImages\alert.png
c:\program files\SelectRebates\SahImages\check.png
c:\program files\SelectRebates\SahImages\close.png
c:\program files\SelectRebates\SelectAlerts.dat
c:\program files\SelectRebates\SelectRebatesA.dat
c:\program files\SelectRebates\SelectRebatesB.dat
c:\program files\SelectRebates\SelectRebatesBT.dat
c:\program files\SelectRebates\Toolbar\AddtoList.bmp
c:\program files\SelectRebates\Toolbar\basis.xml
c:\program files\SelectRebates\Toolbar\Basis.xml.dym
c:\program files\SelectRebates\Toolbar\Blank.bmp
c:\program files\SelectRebates\Toolbar\CashBack.bmp
c:\program files\SelectRebates\Toolbar\Coupons.bmp
c:\program files\SelectRebates\Toolbar\GroceryCoupon.bmp
c:\program files\SelectRebates\Toolbar\i_magnifying.bmp
c:\program files\SelectRebates\Toolbar\icons.bmp
c:\program files\SelectRebates\Toolbar\logo.bmp
c:\program files\SelectRebates\Toolbar\logo_24.bmp
c:\program files\SelectRebates\Toolbar\logo_HotSpots.bmp
c:\program files\SelectRebates\Toolbar\ReviewSite.bmp
c:\program files\SelectRebates\Toolbar\RightControls.dym
c:\program files\SelectRebates\Toolbar\sahtb-alert.bmp
c:\program files\SelectRebates\Toolbar\sahtb-go.bmp
c:\program files\SelectRebates\Toolbar\sahtb-grocerycoupons.bmp
c:\program files\SelectRebates\Toolbar\sahtb-icons.bmp
c:\program files\SelectRebates\Toolbar\sahtb-restaurant.bmp
c:\program files\SelectRebates\Toolbar\sahtb-wishlist.bmp
c:\program files\SelectRebates\Toolbar\Scissors.bmp
c:\windows\ijiqetala.dll
c:\windows\IsUn0411.exe
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-06-11 to 2011-07-11 )))))))))))))))))))))))))))))))
.
.
2011-07-10 03:20 . 2011-07-10 03:20 388096 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-01 21:52 . 2011-07-01 21:52 180736 ----a-w- c:\windows\bridgeauditscan.exe
2011-07-01 17:01 . 2011-07-01 17:01 -------- d-----w- c:\windows\system32\wbem\Repository
2011-07-01 17:01 . 2011-07-01 17:01 -------- d--h--w- c:\program files\WinMaximizer
2011-07-01 13:35 . 2011-07-01 13:35 -------- d--h--w- c:\documents and settings\All Users\Application Data\WinMaximizer
2011-06-28 16:19 . 2011-06-28 16:19 -------- d-sh--w- c:\documents and settings\Administrator.CULVERHOUSE\PrivacIE
2011-06-28 15:34 . 2011-07-11 11:33 0 ----a-w- c:\windows\Fgogiriyijike.bin
2011-06-28 15:34 . 2011-07-11 14:19 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\{DBD1E57D-81F0-4027-9045-27B83F0C2B03}
2011-06-16 03:17 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\drivers\hidserv.dll
2011-06-16 03:01 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2011-06-14 21:44 . 2008-04-14 00:11 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2011-06-14 21:44 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-17 11:52 . 2011-05-20 12:36 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-04 21:24 . 2006-03-10 00:26 69632 ----a-w- c:\windows\system32\Clifford Uninstall.exe
2011-05-02 15:31 . 2004-08-26 18:01 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19 . 2004-08-26 16:12 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11 . 2004-08-26 16:12 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2004-08-26 16:11 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2004-08-26 16:11 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2004-08-26 16:11 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2004-08-26 16:12 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start
http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVWSzItQUxZTUYtU0xLTFUtQVoyVUItNkdPS0ItSkhGTkg&inst=NzctNTEyMTI5NjEyLVQxLVVDQUxMKzEtQkFSOEcrMS1VQ0FMTDIrMi1UQjgrMi1GTCs4LVFJWDErNC1YMjAxMCsyLUYxME0rNS1WSVAxMCsxLUYxME0xMEQrMg&prod=90&ver=10.0.1187" [?]
"*bridgeauditscan.exe"="c:\windows\bridgeauditscan.exe" [2011-07-01 180736]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 17:29 937920 ---ha-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-30 15:45 35736 ---ha-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 23:43 69632 ----a-w- c:\windows\ALCMTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
2005-06-02 00:56 57344 ---ha-w- c:\program files\Realtek\InstallShield\AzMixerSel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F.lux]
2009-08-29 06:00 966656 ---ha-w- c:\documents and settings\Owner\Local Settings\Apps\F.lux\flux.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-01-13 14:47 163840 ----a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-01-13 14:47 131072 ----a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-01-13 14:46 135168 ----a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 07:42 212992 ---ha-w- c:\windows\SMINST\Recguard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-31 01:30 68856 ---ha-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R1 SABKUTIL;SABKUTIL;c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys [x]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [2007-10-09 38144]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-10 136176]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-10 136176]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\DRIVERS\NwUsbCdFil.sys [2008-07-07 20480]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2008-05-09 174336]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v3.sys [2007-12-28 287232]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - DCFS2K
*NewlyCreated* - MDMXSDK
*NewlyCreated* - WUAUSERV
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-10 20:27]
.
2011-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-10 20:27]
.
2011-07-11 c:\windows\Tasks\WinMaximizer-Owner-Startup.job
- c:\program files\WinMaximizer\WinMaximizer.exe [2011-07-01 20:21]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.gateway.com/
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKLM-Run-Sjegiyogovi - c:\windows\ijiqetala.dll
MSConfigStartUp-3145505604 - c:\documents and settings\Owner\Local Settings\Application Data\dqi.exe
MSConfigStartUp-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
MSConfigStartUp-DXDllRegExe - dxdllreg.exe
MSConfigStartUp-Iviku - c:\windows\widext.dll
MSConfigStartUp-Sjegiyogovi - c:\windows\ijiqetala.dll
MSConfigStartUp-tplsis70t - c:\documents and settings\Owner\Application Data\6339077DDBD6B58811114A339A45E7EE\tplsis70t.exe
MSConfigStartUp-VDPLtsHLVdsd - c:\documents and settings\All Users\Application Data\VDPLtsHLVdsd.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-07-11 10:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-150285021-2557789645-293097356-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,01,fa,46,f1,88,95,4f,ab,67,dd,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,33,01,fa,46,f1,88,95,4f,ab,67,dd,\
.
Completion time: 2011-07-11 10:35:02
ComboFix-quarantined-files.txt 2011-07-11 14:34
.
Pre-Run: 17,460,162,560 bytes free
Post-Run: 22,244,933,632 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 5276A680DBBA01B168D40CE3C362E3B5