Wow! The message is gone. Thanks alot! Heres the log.
ComboFix 09-08-09.03 - Pop 08/09/2009 17:51.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.240 [GMT -5:00]
Running from: c:\documents and settings\Pop\Desktop\ComboFix.exe
AV: Webroot AntiVirus with AntiSpyware *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\program files\sFX
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\kb913800.exe
c:\windows\system32\bszip.dll
c:\windows\system32\filokinu.dll
c:\windows\system32\gunanami.dll
c:\windows\system32\hoyupatu.dll
c:\windows\system32\migisibi.dll
c:\windows\system32\newopuvo.dll
c:\windows\system32\rutijeri.dll
c:\windows\system32\sonumiwo.dll
c:\windows\system32\telelepu.dll
c:\windows\system32\vuladihi.dll
c:\windows\system32\vuseyiju.exe
c:\windows\system32\yapuzoke.dll
c:\windows\system32\yikiduta.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSIVXserv.sys
-------\Legacy_SFX
-------\Legacy_SFXDRV
-------\Service_MSIVXserv.sys
-------\Service_sfx
((((((((((((((((((((((((( Files Created from 2009-07-09 to 2009-08-09 )))))))))))))))))))))))))))))))
.
2009-08-09 21:46 . 2009-08-09 21:46 -------- d-----w- c:\program files\Carbonite
2009-08-09 21:41 . 2009-08-09 22:27 152576 ----a-w- c:\documents and settings\Pop\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-09 19:38 . 2009-08-09 19:38 -------- d-----w- c:\documents and settings\Pop\Application Data\Malwarebytes
2009-08-09 19:38 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-09 19:38 . 2009-08-09 19:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-09 19:38 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-09 19:38 . 2009-08-09 19:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-09 06:03 . 2009-08-09 06:03 -------- d--h--w- C:\$AVG8.VAULT$
2009-08-09 05:59 . 2009-08-09 05:59 -------- d-----w- c:\program files\AVG
2009-08-09 02:41 . 2009-08-09 02:41 -------- d-----w- c:\documents and settings\Pop\Local Settings\Application Data\Thinstall
2009-08-09 02:41 . 2009-08-09 02:41 -------- d-----w- c:\documents and settings\Pop\Application Data\Thinstall
2009-08-06 20:06 . 2009-08-06 20:06 -------- d-----w- c:\program files\Trend Micro
2009-08-05 23:08 . 2009-08-05 23:08 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-08-05 23:08 . 2009-07-15 09:48 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-08-05 23:08 . 2009-08-05 23:08 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-08-05 02:42 . 2009-08-05 02:42 -------- d-----w- c:\documents and settings\Nessa\Application Data\acccore
2009-08-03 03:02 . 2009-08-03 03:03 1012560 ----a-w- c:\documents and settings\Pop\Application Data\Adobe\Acrobat\6.0\Updater\Acro-Reader_606_Update.exe
2009-08-03 03:02 . 2009-08-03 03:02 2937168 ----a-w- c:\documents and settings\Pop\Application Data\Adobe\Acrobat\6.0\Updater\Acro-Reader_605_Update.exe
2009-07-19 22:24 . 2009-07-19 22:24 -------- d-----w- c:\documents and settings\Nessa\Application Data\TuneUp Software
2009-07-19 22:20 . 2009-07-19 22:20 -------- d-----w- c:\documents and settings\Nessa\Local Settings\Application Data\AOL OCP
2009-07-19 22:20 . 2009-07-19 22:20 -------- d-----w- c:\documents and settings\Nessa\Local Settings\Application Data\AOL
2009-07-18 16:16 . 2009-08-09 18:21 -------- d-----w- c:\program files\Pcsx2
2009-07-14 20:28 . 2009-07-14 20:28 -------- d-----w- c:\program files\MagicISO
2009-07-12 06:31 . 2009-07-12 06:31 19045 ----a-w- c:\documents and settings\Pop\Application Data\tyvunoxox.sys
2009-07-12 06:31 . 2009-07-12 06:31 18717 ----a-w- c:\program files\Common Files\monace.scr
2009-07-12 06:31 . 2009-07-12 06:31 16677 ----a-w- c:\windows\kexo.bat
2009-07-12 06:31 . 2009-07-12 06:31 15010 ----a-w- c:\documents and settings\Pop\Local Settings\Application Data\opagybeku.dll
2009-07-12 06:31 . 2009-07-12 06:31 14216 ----a-w- c:\windows\system32\enyx.com
2009-07-12 06:31 . 2009-07-12 06:31 12716 ----a-w- c:\windows\system32\ugexazu.reg
2009-07-12 06:31 . 2009-07-12 06:31 10631 ----a-w- c:\windows\ucoku.dat
2009-07-12 06:31 . 2009-07-12 06:31 10585 ----a-w- c:\windows\dukuwopyte.dll
2009-07-12 06:31 . 2009-07-12 06:31 10252 ----a-w- c:\windows\ymin.vbs
2009-07-12 06:17 . 2009-07-12 14:37 -------- d-----w- c:\program files\AlfaVid
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-09 22:58 . 2009-03-10 23:21 -------- d-----w- c:\documents and settings\Pop\Application Data\LimeWire
2009-08-09 22:28 . 2009-03-11 22:02 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-09 21:43 . 2005-12-15 06:03 -------- d-----w- c:\program files\Java
2009-08-07 20:49 . 2009-04-06 22:14 -------- d-----w- c:\documents and settings\Nessa\Application Data\LimeWire
2009-08-07 20:24 . 2009-05-07 20:24 84992 --sha-w- c:\windows\system32\meseleru.dll
2009-08-06 04:58 . 2009-05-06 04:58 84992 --sha-w- c:\windows\system32\yaromido.dll
2009-08-05 23:07 . 2009-06-25 05:12 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-08-05 16:58 . 2009-05-05 16:58 83968 --sha-w- c:\windows\system32\goyobilo.dll
2009-08-04 16:57 . 2009-05-04 16:57 84480 --sha-w- c:\windows\system32\zeyeloja.dll
2009-08-04 04:57 . 2009-05-04 04:57 83968 --sha-w- c:\windows\system32\doluwuhi.dll
2009-08-03 03:02 . 2009-03-05 00:51 -------- d-----w- c:\documents and settings\Pop\Application Data\AdobeUM
2009-07-13 03:28 . 2009-03-03 21:49 2018 ----a-w- c:\documents and settings\Pop\Application Data\wklnhst.dat
2009-07-12 14:53 . 2005-12-15 06:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-07-12 06:31 . 2009-07-12 06:31 16395 ----a-w- c:\documents and settings\All Users\Application Data\zypehel.vbs
2009-07-12 06:31 . 2009-07-12 06:31 15742 ----a-w- c:\documents and settings\All Users\Application Data\vociganani.dat
2009-07-12 06:31 . 2009-07-12 06:31 15043 ----a-w- c:\documents and settings\All Users\Application Data\ujeca.dat
2009-07-01 00:42 . 2009-07-01 00:42 -------- d-----w- c:\documents and settings\Pop\Application Data\PSPdisp
2009-07-01 00:41 . 2009-07-01 00:36 -------- d-----w- c:\program files\PSPdisp
2009-06-30 21:33 . 2009-06-07 23:57 -------- d-----w- c:\documents and settings\Pop\Application Data\gtk-2.0
2009-06-27 19:56 . 2009-04-09 16:02 -------- d-----w- c:\program files\AIM6
2009-06-27 19:56 . 2009-06-27 19:56 -------- d-----w- c:\program files\AIM Toolbar
2009-06-27 19:56 . 2009-06-27 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM Toolbar
2009-06-27 19:55 . 2005-12-15 06:12 -------- d-----w- c:\program files\Common Files\Nullsoft
2009-06-27 03:09 . 2009-04-09 16:12 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-06-26 16:18 . 2005-08-16 10:18 659456 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2005-08-16 10:18 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-25 05:13 . 2009-06-25 05:13 -------- d-----w- c:\documents and settings\Pop\Application Data\TuneUp Software
2009-06-25 05:12 . 2009-06-25 05:12 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-06-25 05:10 . 2009-06-25 05:10 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-25 04:55 . 2005-12-15 06:09 -------- d-----w- c:\program files\MUSICMATCH
2009-06-25 04:52 . 2009-04-09 16:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Tencent
2009-06-25 04:50 . 2005-12-15 06:15 -------- d-----w- c:\program files\Dell
2009-06-25 04:48 . 2009-05-20 23:19 -------- d-----w- c:\program files\Oberon Media
2009-06-25 04:46 . 2009-03-11 00:32 -------- d-----w- c:\program files\Common Files\Apple
2009-06-25 04:42 . 2005-12-15 06:11 -------- d-----w- c:\program files\Common Files\AOL
2009-06-25 04:42 . 2005-12-15 06:11 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-06-21 17:51 . 2009-06-18 21:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-19 13:08 . 2009-06-18 21:56 -------- d-----w- c:\program files\NOS
2009-06-18 21:59 . 2009-06-18 21:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-18 21:56 . 2009-06-18 21:56 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-06-16 14:55 . 2005-08-16 10:18 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2005-08-16 10:18 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 01:37 . 2005-12-15 06:10 -------- d-----w- c:\program files\Sonic
2009-06-15 10:08 . 2009-03-19 23:07 3218 ----a-w- c:\documents and settings\Nessa\Application Data\wklnhst.dat
2009-06-11 00:30 . 2009-03-03 01:31 -------- d-----w- c:\documents and settings\Pop\Application Data\Apple Computer
2009-06-03 19:24 . 2005-08-16 10:18 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-30 15:46 . 2009-03-05 01:32 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-30 15:46 . 2009-03-05 01:32 56 --sh--r- c:\windows\system32\8E5818C53D.sys
2009-05-19 06:36 . 2009-06-27 03:10 2884832 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\vwpt.exe
2009-05-19 06:36 . 2009-06-27 03:10 28 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\unregister.bat
2009-05-19 06:36 . 2009-06-27 03:09 1484856 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\toolbar.exe
2009-05-19 06:36 . 2009-06-27 03:09 25 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\register.bat
2009-05-19 06:36 . 2009-06-27 03:09 97072 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\bsetutil.exe
2009-05-19 06:36 . 2009-06-27 03:09 142040 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\alsetup.exe
2009-05-19 06:36 . 2009-06-27 03:10 30512 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\Uninstaller.exe
2009-05-19 06:36 . 2009-06-27 03:09 111920 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\AOLSearch.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2009-02-14 18:00 238968 ----a-w- c:\program files\Webroot\Spy Sweeper\Backup\CtxMenu_1_0_0_10.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-20 114688]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-12-15 26112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-07-31 283792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-09 149280]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
c:\documents and settings\Nessa\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-3-10 139776]
c:\documents and settings\Pop\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-3-10 139776]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe"=
"c:\\Program Files\\AIM6\\aolsoftware.exe"=
"c:\\WINDOWS\\stsystra.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58146:TCP"= 58146:TCP:Pando Media Booster
"58146:UDP"= 58146:UDP:Pando Media Booster
"8085:TCP"= 8085:TCP:sfx
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2/13/2009 6:09 PM 29808]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [8/5/2009 6:08 PM 604488]
R2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\Spy Sweeper\WRConsumerService.exe [2/27/2009 10:13 PM 1180976]
S3 libusb0;LibUsb-Win32 - Kernel Driver 03/20/2007, 0.1.12.1;c:\windows\system32\drivers\libusb0.sys [12/21/2008 7:06 PM 28672]
S3 pspdisp;pspdisp;c:\windows\system32\drivers\pspdisp.sys [12/25/2008 9:24 AM 3072]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-08-09 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 08:54]
2009-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2009-08-04 c:\windows\Tasks\wrSpySweeper_L93AB4CC322624BCF9E3662FAEF1944B9.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2009-02-28 18:08]
2009-08-04 c:\windows\Tasks\wrSpySweeper_L93AB4CC322624BCF9E3662FAEF1944B9.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2009-02-28 18:08]
2009-07-19 c:\windows\Tasks\wrSpySweeper_LC7856BBDD7474B84B05D68881107C52C.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2009-02-28 18:08]
2009-07-19 c:\windows\Tasks\wrSpySweeper_LC7856BBDD7474B84B05D68881107C52C.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2009-02-28 18:08]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game06.zylom.com/activex/zylomgamesplayer.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-09 17:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3220)
c:\program files\Webroot\Spy Sweeper\Backup\CtxMenu_1_0_0_10.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wscntfy.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-08-09 18:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-09 23:02
Pre-Run: 56,657,428,480 bytes free
Post-Run: 59,655,380,992 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
255 --- E O F --- 2009-08-09 22:15