Ok, I ran the combofix with the code requested and I also ran AntiMalware. I will post the logs below.
Combofix Log
ComboFix 09-11-13.03 - barb 11/12/2009 16:05.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.304 [GMT -5:00]
Running from: c:\documents and settings\barb\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\barb\Desktop\CFScript.txt
FILE ::
"c:\windows\system32\beghghk.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\beghghk.dll
.
((((((((((((((((((((((((( Files Created from 2009-10-12 to 2009-11-12 )))))))))))))))))))))))))))))))
.
2009-11-11 15:03 . 2008-04-14 00:12 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2009-11-11 15:03 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-11-02 18:27 . 2009-11-02 18:27 -------- d-----w- c:\program files\Trend Micro
2009-11-02 17:43 . 2009-11-02 17:43 -------- d-sh--w- c:\windows\system32\config\systemprofile\UserData
2009-11-02 14:46 . 2009-11-02 14:46 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-11-02 14:46 . 2009-11-02 14:46 -------- d-sh--w- c:\windows\system32\config\systemprofile\IECompatCache
2009-10-29 18:24 . 2009-10-29 18:24 -------- d-sh--w- c:\documents and settings\barb\IECompatCache
2009-10-29 18:24 . 2009-10-29 18:24 -------- d-sh--w- c:\documents and settings\barb\PrivacIE
2009-10-29 17:23 . 2009-10-29 17:23 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-29 17:22 . 2009-10-29 17:22 -------- d-sh--w- c:\documents and settings\barb\IETldCache
2009-10-29 17:17 . 2009-10-29 17:18 -------- dc-h--w- c:\windows\ie8
2009-10-29 17:16 . 2009-10-29 17:16 -------- d-----w- c:\program files\Microsoft Silverlight
2009-10-29 17:15 . 2009-10-29 17:20 -------- d--h--w- c:\windows\msdownld.tmp
2009-10-16 19:35 . 2009-10-30 15:06 -------- d-----w- c:\program files\Kodak
2009-10-16 19:34 . 2009-10-30 15:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Kodak
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-21 18:27 . 2008-08-19 16:04 -------- d-----w- c:\program files\Common Files\Adobe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}]
2009-03-09 02:09 271672 ----a-w- c:\program files\PriceGong\1.2.0\PriceGongIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"vptray"="c:\program files\NavNT\vptray.exe" [2001-09-24 73728]
"pdfFactory Dispatcher v2"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [2003-11-11 385024]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
printkey.exe [2002-4-5 589824]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"\\\\Vantage\\epicor\\prgs91d\\bin\\prowin32.exe"=
"c:\\Program Files\\FileMaker\\FileMaker Pro 8.5\\FileMaker Pro.exe"=
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
*Deregistered* - PROCEXP113
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZRxdm603QPUS&fl=0&ptb=jAkLWQlOzTBgM1KTpVGyTA&ind=2009070108&url=http://cap.ask.com/web&q={searchTerms}&l=zz&o=sb&gcht=qp
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-12 16:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(492)
c:\windows\system32\NavLogon.dll
.
Completion time: 2009-11-12 16:13
ComboFix-quarantined-files.txt 2009-11-12 21:13
ComboFix2.txt 2009-11-12 16:25
ComboFix3.txt 2009-11-11 15:09
Pre-Run: 31,056,486,400 bytes free
Post-Run: 31,042,318,336 bytes free
- - End Of File - - 02D29F20912FDF0B976CE652F4F8E822
AntiMalware Log
Malwarebytes' Anti-Malware 1.41
Database version: 3156
Windows 5.1.2600 Service Pack 3
11/12/2009 4:42:07 PM
mbam-log-2009-11-12 (16-42-07).txt
Scan type: Full Scan (C:\|)
Objects scanned: 152053
Time elapsed: 20 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 18
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 61
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Qoobox\Quarantine\C\WINDOWS\system32\beghghk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\sys.dat.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\wbem\proquota.exe.vir (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP187\A0014104.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP188\A0014125.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP188\A0014132.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP189\A0014181.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP200\A0015713.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP200\A0015724.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP202\A0015852.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP203\A0015971.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP205\A0016102.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP206\A0016130.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP211\A0016238.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP211\A0016295.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP211\A0016309.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP212\A0016652.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP213\A0016677.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP213\A0016685.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP213\A0016688.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016838.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016846.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016847.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016848.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016849.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016850.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016855.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016856.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016858.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016863.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016864.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016865.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016866.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016867.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016868.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016887.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016870.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016871.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016872.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016873.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016874.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016875.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016876.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016877.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016886.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016889.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016890.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016891.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016892.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016893.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP215\A0016897.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP216\A0016918.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP216\A0016948.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP216\A0016970.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP216\A0018055.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP216\A0018231.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP217\A0018316.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP217\A0018396.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP217\A0018478.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP175\A0012522.exe (Adware.Ziniky) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{1CC64A03-C6DF-4185-A5B6-ECD4D7D1A022}\RP176\A0012592.exe (Adware.Ziniky) -> Quarantined and deleted successfully.