Sorry for the delay, but my daughter needed to use the computer to study for her exams at university and I've only now been able to run ComboFix again. I did as you suggested and here is the log:
ComboFix 09-06-05.07 - Jim 10/06/2009 18:02.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.653 [GMT 10:00]
Running from: c:\documents and settings\Jim\Combo.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\drivers\UACwmyciispakrvbiv.sys
c:\windows\system32\UACbopxeiriwdbbnxd.dll
c:\windows\system32\UACdqlhnbgfmlamwdf.log
c:\windows\system32\UAChgujmqskylkyfxm.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjoteyutmdwyklvp.dll
c:\windows\system32\UACjpixrruqhxwgaxd.dll
c:\windows\system32\UACrqxwpowhfyaoerb.log
c:\windows\system32\UACsrrhbxcbaocgipo.log
c:\windows\system32\UACwgrvdtwcscrntjx.dll
c:\windows\system32\UACyvxoblryrwixumu.dat
----- BITS: Possible infected sites -----
hxxp://downloadsoftwareserver.com
.
((((((((((((((((((((((((( Files Created from 2009-05-10 to 2009-06-10 )))))))))))))))))))))))))))))))
.
2009-06-06 17:07 . 2009-06-06 17:07 3018113 ----a-r- c:\documents and settings\Jim\Combo.exe
2009-06-04 03:16 . 2009-06-04 03:16 -------- d-----w- c:\documents and settings\Veronica\Local Settings\Application Data\Opera
2009-05-27 13:37 . 2009-06-10 07:40 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-05-26 03:53 . 2009-06-06 06:11 -------- d-s---w- C:\ComboFix
2009-05-18 12:40 . 2009-05-18 12:40 -------- d-----w- c:\documents and settings\Jim\Application Data\Malwarebytes
2009-05-18 11:25 . 2009-05-30 16:35 -------- d-sh--w- c:\documents and settings\Josie.IM4WW3JLAA59UOC\PrivacIE
2009-05-18 11:17 . 2009-06-09 15:55 -------- d-sh--w- c:\documents and settings\Josie.IM4WW3JLAA59UOC\IETldCache
2009-05-15 14:33 . 2009-05-15 14:35 13037568 ----a-w- c:\documents and settings\Downloaded Files\seamonkey-1.1.16.en-US.win32.installer.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 14:18 . 2008-04-11 12:20 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-05-28 11:31 . 2008-04-13 13:18 20450 ----a-w- c:\windows\SIFBPCALIB.DAT
2009-05-27 14:11 . 2009-04-25 14:07 -------- d-----w- c:\documents and settings\Jim\Application Data\Imvu
2009-05-26 03:41 . 2008-04-06 16:54 107048 ----a-w- c:\documents and settings\Jim\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-21 10:46 . 2008-04-06 11:07 -------- d-----w- c:\program files\Brother's Keeper 6
2009-05-12 13:44 . 2008-06-05 12:28 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-10 14:49 . 2008-08-07 10:49 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-09 08:50 . 2009-05-09 08:46 -------- d-----w- c:\documents and settings\Jim\Application Data\MSN6
2009-05-09 08:46 . 2009-05-09 08:46 -------- d-----w- c:\documents and settings\All Users\Application Data\MSN6
2009-05-08 12:04 . 2009-05-08 12:04 -------- d-----w- c:\program files\AVG
2009-05-05 13:38 . 2009-05-05 13:38 -------- dc----w- c:\documents and settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81}
2009-05-05 09:21 . 2009-05-05 09:21 -------- d-----w- c:\program files\Trend Micro
2009-05-04 13:31 . 2009-04-25 14:06 80967 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\Uninstall.exe
2009-05-04 13:31 . 2009-04-25 14:06 -------- d-----w- c:\documents and settings\Jim\Application Data\IMVUClient
2009-05-04 13:30 . 2009-05-04 13:29 16034824 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\installer\SetupImvu_update.exe
2009-04-30 20:25 . 2009-04-30 20:25 95584 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\IMVUupdater.exe
2009-04-30 20:25 . 2009-04-30 20:25 49920 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\IMVUClient.exe
2009-04-30 20:25 . 2009-04-30 20:25 19200 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\imvuqualityagent.exe
2009-04-25 01:22 . 2009-04-25 01:22 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-04-25 01:22 . 2009-04-19 09:57 38208 ----a-w- c:\documents and settings\Jim\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-04-25 01:19 . 2009-04-25 01:19 -------- d-----w- c:\documents and settings\Jim\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-04-23 22:52 . 2009-04-23 22:52 38400 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\MemoryHook.dll
2009-04-23 22:52 . 2009-04-23 22:52 288768 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\cal3d.dll
2009-04-23 22:52 . 2009-04-23 22:52 185856 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\boost_python.dll
2009-04-23 22:52 . 2009-04-23 22:52 256000 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\audiere.dll
2009-04-23 22:51 . 2009-04-23 22:51 28672 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\CallStack.dll
2009-04-22 17:28 . 2009-04-22 17:28 9433600 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\xul.dll
2009-04-19 22:37 . 2009-04-19 22:37 152576 ----a-w- c:\documents and settings\Jim\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-16 13:25 . 2009-04-16 13:25 -------- d-----w- c:\documents and settings\Josie.IM4WW3JLAA59UOC\Application Data\Windows Search
2009-04-10 02:01 . 2008-05-17 08:17 104648 ----a-w- c:\documents and settings\Veronica\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-06 22:11 . 2008-04-18 15:15 34 ----a-w- c:\windows\system32\BD2040.DAT
2009-04-06 16:04 . 2009-04-06 16:04 271929 ----a-w- c:\documents and settings\Jim\Application Data\IMVUClient\pixomatic.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-05-26_04.05.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-10 08:00 . 2009-06-10 08:00 16384 c:\windows\temp\Perflib_Perfdata_7f8.dat
+ 2009-06-01 21:35 . 2009-06-10 07:38 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-01 21:35 . 2009-06-10 07:38 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-06-10 07:40 . 2009-06-10 07:38 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2009-06-01 21:35 . 2009-06-10 07:38 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-06 08:25 . 2009-06-01 12:39 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-04-06 08:25 . 2009-05-23 09:09 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-04-06 08:25 . 2009-06-01 12:39 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Rover Australia screen saver"="c:\program files\FlashWiz\Screen Saver\TaskTray.exe" [2002-02-06 370176]
"AdwareProMFCT"="c:\program files\AdwarePro\StartApp.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NAV Agent"="c:\progra~1\NORTON~1\NORTON~1\navapw32.exe" [2001-07-20 50256]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-16 136600]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2008-01-07 864256]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-09-14 648488]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-09-14 705832]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ZoneAlarm.lnk - c:\program files\Zone Labs\ZoneAlarm\zonealarm.exe [2008-4-6 417056]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NVMCTRAY.DLL,NvTaskbarInit
"updateMgr"=c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"nwiz"=nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="1"
"UpdatesDisableNotify"="1"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [6/04/2009 11:29 PM 55152]
R2 NProtectService;Norton Unerase Protection;c:\program files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE [6/04/2008 6:39 PM 135168]
R2 ScFBPNT;CanoScan FBP Port Driver;c:\windows\system32\drivers\SCFBPNT.SYS [6/04/2008 9:28 PM 16288]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [6/02/2009 6:08 PM 533360]
S3 qcusbser;ZTE USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\ZTEusbser.sys --> c:\windows\system32\DRIVERS\ZTEusbser.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1637723038-682003330-1004.job
- c:\documents and settings\Jim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-06 17:00]
2009-05-08 c:\windows\Tasks\Norton AntiVirus - Scan my computer.job
- c:\progra~1\NORTON~1\NORTON~1\NAVW32.exe [2001-07-20 23:14]
2009-06-10 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-04-06 02:23]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-10 18:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-10 18:12
ComboFix-quarantined-files.txt 2009-06-10 08:11
ComboFix2.txt 2009-06-06 07:35
Pre-Run: 100,257,193,984 bytes free
Post-Run: 100,068,651,008 bytes free
Current=2 Default=2 Failed=1 LastKnownGood=5 Sets=1,2,3,4,5
183 --- E O F --- 2009-06-09 15:57