Here's the log:
ComboFix 09-12-04.02 - Gin 12/04/2009 21:26.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.112 [GMT -8:00]
Running from: e:\documents and settings\Gin\Desktop\schrauber.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-11-05 to 2009-12-05 )))))))))))))))))))))))))))))))
.
2009-12-05 05:11 . 2009-11-26 03:48 304408 ----a-w- e:\documents and settings\All Users\Application Data\avg9\update\backup\avgaspmx.dll
2009-11-29 05:14 . 2009-11-29 05:14 -------- d-----w- e:\documents and settings\Gin\Local Settings\Application Data\Identities
2009-11-29 04:31 . 2009-11-29 18:55 -------- d-----w- e:\documents and settings\All Users\Application Data\NOS
2009-11-29 04:31 . 2009-11-06 17:20 34112 ----a-w- e:\documents and settings\Gin\Application Data\Mozilla\Firefox\Profiles\klpigd9e.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-29 04:31 . 2009-11-06 17:20 32448 ----a-w- e:\documents and settings\Gin\Application Data\Mozilla\Firefox\Profiles\klpigd9e.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-11-29 04:31 . 2009-11-29 04:31 22352 ----a-w- e:\documents and settings\Gin\Application Data\Mozilla\Firefox\Profiles\klpigd9e.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-11-26 07:11 . 2009-11-26 07:11 -------- d-----w- e:\documents and settings\All Users\Application Data\Speedbit
2009-11-26 07:11 . 2009-11-26 07:11 -------- d-----w- e:\program files\SpeedBit Video Accelerator
2009-11-26 03:49 . 2009-11-26 03:49 -------- d-----w- E:\$AVG
2009-11-26 03:49 . 2009-11-26 03:49 12464 ----a-w- e:\windows\system32\avgrsstx.dll
2009-11-26 03:49 . 2009-11-26 03:49 25608 ----a-w- e:\windows\system32\drivers\AVGIDSxx.sys
2009-11-26 03:49 . 2009-11-26 03:49 161800 ----a-w- e:\windows\system32\drivers\avgrkx86.sys
2009-11-26 03:49 . 2009-11-26 03:49 360584 ----a-w- e:\windows\system32\drivers\avgtdix.sys
2009-11-26 03:49 . 2009-11-26 03:49 333192 ----a-w- e:\windows\system32\drivers\avgldx86.sys
2009-11-26 03:49 . 2009-11-26 03:49 28424 ----a-w- e:\windows\system32\drivers\avgmfx86.sys
2009-11-26 03:49 . 2009-12-05 05:09 -------- d-----w- e:\windows\system32\drivers\Avg
2009-11-26 03:48 . 2009-11-26 03:48 -------- d-----w- e:\program files\AVG
2009-11-26 03:48 . 2009-11-26 03:48 -------- d-----w- e:\documents and settings\All Users\Application Data\avg9
2009-11-25 22:03 . 2009-11-27 01:11 -------- d-----w- e:\documents and settings\Gin\Application Data\MxBoost
2009-11-25 21:57 . 2009-11-25 22:03 -------- d-----w- e:\program files\Maxthon2
2009-11-25 21:53 . 2009-11-25 21:53 -------- d-----w- e:\program files\Java
2009-11-25 21:52 . 2009-11-25 21:52 152576 ----a-w- e:\documents and settings\Gin\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-25 21:50 . 2009-11-25 21:50 79488 ----a-w- e:\documents and settings\Gin\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-24 09:31 . 2009-11-24 09:31 -------- d-----w- e:\program files\CCleaner
2009-11-24 07:09 . 2009-11-25 22:00 -------- d-----w- e:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-24 06:46 . 2009-11-24 06:46 -------- d-sh--w- e:\documents and settings\Gin\IECompatCache
2009-11-24 06:45 . 2009-11-24 06:45 -------- d-sh--w- e:\documents and settings\Gin\PrivacIE
2009-11-24 05:00 . 2009-11-24 05:00 -------- d-sh--w- e:\documents and settings\NetworkService\IETldCache
2009-11-24 04:59 . 2009-11-24 04:59 -------- d-sh--w- e:\documents and settings\Gin\IETldCache
2009-11-24 04:56 . 2009-10-02 04:44 92160 -c----w- e:\windows\system32\dllcache\iecompat.dll
2009-11-24 04:56 . 2009-11-24 04:56 -------- d-----w- e:\windows\ie8updates
2009-11-24 04:55 . 2009-08-29 08:08 12800 -c----w- e:\windows\system32\dllcache\xpshims.dll
2009-11-24 04:55 . 2009-08-29 08:08 594432 -c----w- e:\windows\system32\dllcache\msfeeds.dll
2009-11-24 04:55 . 2009-08-29 08:08 55296 -c----w- e:\windows\system32\dllcache\msfeedsbs.dll
2009-11-24 04:55 . 2009-08-29 08:08 1985536 -c----w- e:\windows\system32\dllcache\iertutil.dll
2009-11-24 04:55 . 2009-08-29 08:08 246272 -c----w- e:\windows\system32\dllcache\ieproxy.dll
2009-11-24 04:55 . 2009-08-29 08:08 11069440 -c----w- e:\windows\system32\dllcache\ieframe.dll
2009-11-17 03:01 . 2009-11-17 03:01 -------- d-----w- e:\program files\Reference Assemblies
2009-11-17 03:00 . 2008-07-06 12:06 89088 ----a-w- e:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2009-11-17 03:00 . 2008-07-06 12:06 89088 -c----w- e:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-11-17 03:00 . 2008-07-06 12:06 575488 -c----w- e:\windows\system32\dllcache\xpsshhdr.dll
2009-11-17 03:00 . 2008-07-06 12:06 575488 ------w- e:\windows\system32\xpsshhdr.dll
2009-11-17 03:00 . 2008-07-06 12:06 1676288 -c----w- e:\windows\system32\dllcache\xpssvcs.dll
2009-11-17 03:00 . 2008-07-06 12:06 1676288 ------w- e:\windows\system32\xpssvcs.dll
2009-11-17 03:00 . 2008-07-06 12:06 117760 ------w- e:\windows\system32\prntvpt.dll
2009-11-17 03:00 . 2008-07-06 10:50 597504 -c----w- e:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-11-17 03:00 . 2008-07-06 10:50 597504 ------w- e:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2009-11-17 02:54 . 2009-11-17 02:54 -------- d-----w- e:\program files\MSXML 6.0
2009-11-15 22:53 . 2009-11-15 22:53 -------- d-----w- e:\windows\system32\KB905474
2009-11-15 22:53 . 2009-03-11 06:26 1403264 ----a-w- e:\windows\system32\KB905474\wganotifypackageinner.exe
2009-11-15 22:53 . 2009-03-11 06:18 453512 ----a-w- e:\windows\system32\KB905474\wgasetup.exe
2009-11-15 22:51 . 2004-08-04 07:56 221184 ----a-w- e:\windows\system32\wmpns.dll
2009-11-15 22:49 . 2009-11-15 22:49 -------- d-----w- e:\windows\ServicePackFiles
2009-11-15 19:09 . 2009-11-15 19:09 -------- d-----w- e:\documents and settings\Gin\Local Settings\Application Data\Shoddy Battle
2009-11-15 19:08 . 2009-11-25 04:17 664 ----a-w- e:\windows\system32\d3d9caps.dat
2009-11-15 19:07 . 2009-11-25 21:53 411368 ----a-w- e:\windows\system32\deploytk.dll
2009-11-15 19:04 . 2009-11-26 20:46 -------- d-----w- e:\windows\system32\CatRoot_bak
2009-11-15 19:02 . 2009-11-15 19:02 -------- d-----w- e:\program files\Shoddy Battle
2009-11-15 19:01 . 2008-06-13 13:10 272128 -c----w- e:\windows\system32\dllcache\bthport.sys
2009-11-15 19:01 . 2008-06-13 13:10 272128 ------w- e:\windows\system32\drivers\bthport.sys
2009-11-15 18:52 . 2008-10-24 11:10 453632 -c----w- e:\windows\system32\dllcache\mrxsmb.sys
2009-11-15 18:51 . 2009-08-04 13:58 2136064 -c----w- e:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-15 18:51 . 2009-08-04 14:00 2180352 -c----w- e:\windows\system32\dllcache\ntoskrnl.exe
2009-11-15 18:51 . 2009-08-04 13:13 2015744 -c----w- e:\windows\system32\dllcache\ntkrpamp.exe
2009-11-15 18:51 . 2009-08-04 13:13 2057728 -c----w- e:\windows\system32\dllcache\ntkrnlpa.exe
2009-11-15 07:23 . 2009-01-08 02:21 26144 ----a-w- e:\windows\system32\spupdsvc.exe
2009-11-15 07:23 . 2009-11-26 07:48 -------- d--h--w- e:\windows\$hf_mig$
2009-11-15 05:12 . 2009-11-15 05:12 -------- d-----w- e:\program files\Common Files\InstallShield
2009-11-15 05:10 . 2009-11-25 21:56 -------- d-----w- e:\documents and settings\Gin\Local Settings\Application Data\Deployment
2009-11-15 05:05 . 2009-11-15 05:05 -------- d-----w- e:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-11-15 04:32 . 2009-11-15 04:32 -------- d-----w- e:\windows\system32\LogFiles
2009-11-15 04:25 . 2009-11-15 04:25 0 ----a-w- e:\windows\nsreg.dat
2009-11-15 04:25 . 2009-11-15 04:25 -------- d-----w- e:\documents and settings\Gin\Local Settings\Application Data\Mozilla
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-22 19:25 . 2009-11-15 03:55 12328 ----a-w- e:\documents and settings\Gin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-20 05:17 . 2009-11-20 05:10 -------- d-----w- e:\documents and settings\Gin\Application Data\uTorrent
2009-11-20 05:10 . 2009-11-20 05:10 -------- d-----w- e:\program files\uTorrent
2009-11-17 03:01 . 2009-11-17 03:01 -------- d-----w- e:\program files\MSBuild
2009-11-15 05:13 . 2009-11-15 05:13 -------- d--h--w- e:\program files\InstallShield Installation Information
2009-11-15 05:13 . 2009-11-15 05:13 -------- d-----w- e:\program files\SigmaTel
2009-11-15 04:49 . 2009-11-15 03:47 86327 ----a-w- e:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-15 03:49 . 2009-11-15 03:49 -------- d-----w- e:\program files\microsoft frontpage
2009-11-15 03:44 . 2009-11-15 03:44 21640 ----a-w- e:\windows\system32\emptyregdb.dat
2009-09-11 14:33 . 2004-08-04 07:56 133632 ----a-w- e:\windows\system32\msv1_0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedBitVideoAccelerator"="e:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [2009-11-26 1435240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="e:\program files\Java\jre6\bin\jusched.exe" [2009-11-25 149280]
"AVG9_TRAY"="e:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-26 2020120]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-26 03:49 12464 ----a-w- e:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"e:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"e:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"e:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"e:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"e:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
R0 AVGIDSErHrxpx;AVG9IDSErHr;e:\windows\system32\drivers\AVGIDSxx.sys [11/25/2009 7:49 PM 25608]
R0 AvgRkx86;avgrkx86.sys;e:\windows\system32\drivers\avgrkx86.sys [11/25/2009 7:49 PM 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;e:\windows\system32\drivers\avgldx86.sys [11/25/2009 7:49 PM 333192]
R1 AvgTdiX;AVG Network Redirector;e:\windows\system32\drivers\avgtdix.sys [11/25/2009 7:49 PM 360584]
R2 avg9emc;AVG E-mail Scanner;e:\program files\AVG\AVG9\avgemc.exe [11/25/2009 7:48 PM 906520]
R2 avg9wd;AVG WatchDog;e:\program files\AVG\AVG9\avgwdsvc.exe [11/25/2009 7:48 PM 285392]
R2 AVGIDSAgent;AVG9IDSAgent;e:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [11/25/2009 7:48 PM 5832712]
R2 VideoAcceleratorService;VideoAcceleratorService;e:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> e:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 AVGIDSDriverxpx;AVG9IDSDriver;e:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [11/25/2009 7:48 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;e:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [11/25/2009 7:48 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;e:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [11/25/2009 7:48 PM 25736]
.
Contents of the 'Scheduled Tasks' folder
2009-12-05 e:\windows\Tasks\WGASetup.job
- e:\windows\system32\KB905474\wgasetup.exe [2009-11-15 06:18]
.
.
------- Supplementary Scan -------
.
LSP: e:\progra~1\SPEEDB~1\sblsp.dll
TCP: {DEEEB8BE-4337-4556-8C7C-80AE5EBE1B41} = 208.67.222.222,208.67.220.220
FF - ProfilePath - e:\documents and settings\Gin\Application Data\Mozilla\Firefox\Profiles\klpigd9e.default\
FF - component: e:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: e:\documents and settings\Gin\Application Data\Mozilla\Firefox\Profiles\klpigd9e.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - e:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
e:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-HijackThis - e:\documents and settings\Gin\Desktop\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-04 21:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(632)
e:\program files\SpeedBit Video Accelerator\Accelerator.dll
e:\windows\system32\WININET.dll
e:\program files\SpeedBit Video Accelerator\CommPipe.dll
e:\program files\SpeedBit Video Accelerator\Collector.dll
- - - - - - - > 'explorer.exe'(712)
e:\windows\system32\WININET.dll
e:\windows\system32\ieframe.dll
e:\windows\system32\webcheck.dll
.
Completion time: 2009-12-04 21:39
ComboFix-quarantined-files.txt 2009-12-05 05:39
Pre-Run: 498,905,088 bytes free
Post-Run: 521,887,744 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(3)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 28E2F3167C445BC7CB249885AE6C3911