Hi Myrti, here's the Combofix log:
ComboFix 10-10-06.02 - Administrator 10/07/2010 9:09.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.759.532 [GMT -4:00]
Running from: d:\frank\UTILITY SETUP\01-killers and cleaners\combofix\combofix 6-2-10\ComboFix.exe
. <<<added note, I updated cfix to current>>>
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\7EB69134C92CDBCC4FF1A22944E3A22B
c:\documents and settings\Administrator\Application Data\7EB69134C92CDBCC4FF1A22944E3A22B\coreappsetup700.exe
c:\documents and settings\Administrator\Application Data\7EB69134C92CDBCC4FF1A22944E3A22B\enemies-names.txt
c:\documents and settings\Administrator\Application Data\7EB69134C92CDBCC4FF1A22944E3A22B\local.ini
c:\documents and settings\Administrator\Application Data\7EB69134C92CDBCC4FF1A22944E3A22B\lsrslt.ini
c:\documents and settings\Administrator\Application Data\7EB69134C92CDBCC4FF1A22944E3A22B\synt700isorelease00.exe
c:\documents and settings\Administrator\Application Data\inst.exe
c:\documents and settings\Administrator\Application Data\jsdfgs.bat
c:\documents and settings\Administrator\Application Data\srsf.bat
c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\p8uo5LY6.exe
c:\program files\Mozilla Firefox\searchplugins\google_search.xml
C:\rundllxxxx.exe
c:\rundllxxxx.exe\config.bin
c:\rundllxxxx.exe\rundllxxxx.exe
c:\windows\system32\18467.exe
c:\windows\system32\cacletup.dll
c:\windows\system32\micr0st.dll
c:\windows\system32\msvcsv60.dll
c:\windows\system32\spool\prtprocs\w32x86\eIQ3w7.dll
c:\windows\system32\winlogon.bak
----- BITS: Possible infected sites -----
hxxp://www.samischeater.com
Infected copy of c:\windows\system32\drivers\i8042prt.sys was found and disinfected
Restored copy from - Kitty had a snack
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\winlogon.exe
Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\explorer.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
((((((((((((((((((((((((( Files Created from 2010-09-07 to 2010-10-07 )))))))))))))))))))))))))))))))
.
2010-10-07 12:46 . 2010-10-07 12:46 389120 ----a-w- c:\windows\system32\CF1085.exe
2010-10-05 13:31 . 2007-09-02 01:34 10989568 ----a-w- c:\windows\system32\shell31.dll
2010-10-05 00:09 . 2010-10-05 00:09 38257 ----a-w- c:\documents and settings\Administrator\Application Data\Genieo\Application\Partner\uninstall\homeyNews\partner_uninstall.exe
2010-10-05 00:06 . 2010-10-05 00:06 67072 --sha-r- c:\windows\system32\sessmgr6.dll
2010-10-04 20:34 . 2010-10-04 20:34 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2010-10-04 20:34 . 2010-10-04 20:34 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-10-02 13:38 . 2010-10-02 13:39 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-10-01 00:38 . 2010-10-01 03:20 -------- d-----w- c:\program files\SecEss
2010-09-30 19:27 . 2008-04-14 00:12 146432 ----a-w- c:\windows\Copy of regedit.exe
2010-09-30 19:13 . 2010-09-30 19:13 38252 ----a-w- c:\documents and settings\Administrator\Application Data\Genieo\Application\Partner\uninstall\myHomey\partner_uninstall.exe
2010-09-30 19:13 . 2010-09-30 19:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Genieo
2010-09-30 19:13 . 2010-10-05 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Update
2010-09-19 10:46 . 2010-09-19 10:46 455552 ----a-w- c:\documents and settings\Administrator\Application Data\Genieo\Application\Updater\genieo_temp\InstallMyHomey.exe
2010-09-19 10:45 . 2010-09-19 10:45 455552 ----a-w- c:\documents and settings\Administrator\Application Data\Genieo\Application\Updater\genieo_temp\InstallHomeyNews.exe
2010-09-19 10:45 . 2010-09-19 10:45 318952 ----a-w- c:\documents and settings\Administrator\Application Data\Genieo\Application\Updater\genieo_temp\homey_setup.exe
2010-09-15 03:37 . 2010-09-15 03:42 -------- d-----w- c:\windows\system32\URTTemp
2010-09-15 01:26 . 2010-09-15 01:26 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\PCHealth
2010-09-14 23:02 . 2010-09-14 23:02 -------- d-----w- c:\windows\system32\winrm
2010-09-14 23:02 . 2010-09-14 23:02 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2010-09-14 22:49 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-09-14 22:49 . 2010-06-21 15:27 354304 -c----w- c:\windows\system32\dllcache\srv.sys
2010-09-14 22:47 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-09-14 22:45 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-09-14 22:43 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-09-14 22:43 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-09-14 22:43 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-09-14 22:40 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-09-14 22:39 . 2010-09-15 13:22 -------- d--h--w- c:\windows\$hf_mig$
2010-09-14 22:39 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-09-14 22:39 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-09-14 22:27 . 2010-09-14 22:53 -------- d-----w- c:\program files\Remote Desktop
2010-09-14 22:06 . 2010-09-14 22:06 -------- d-----w- c:\windows\system32\scripting
2010-09-14 22:06 . 2010-09-14 22:06 -------- d-----w- c:\windows\l2schemas
2010-09-14 22:06 . 2010-09-14 22:06 -------- d-----w- c:\windows\system32\en
2010-09-14 22:06 . 2010-09-14 22:06 -------- d-----w- c:\windows\system32\bits
2010-09-14 21:50 . 2008-04-14 00:11 12800 ----a-w- c:\windows\system32\credssp.dll
2010-09-14 21:49 . 2008-04-14 00:12 155136 ----a-w- c:\windows\system32\mssha.dll
2010-09-14 21:48 . 2004-08-04 02:41 11868 ------w- c:\windows\system32\drivers\mdmxsdk.sys
2010-09-14 21:47 . 2004-08-04 02:41 1041536 ------w- c:\windows\system32\drivers\hsfdpsp2.sys
2010-09-13 15:59 . 2010-09-13 16:00 -------- d-----w- c:\program files\NVPlayer
2010-09-13 13:30 . 2010-05-07 21:41 265416 ----a-w- c:\windows\system32\PROUnstl.exe
2010-09-09 17:05 . 2010-09-09 17:05 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Karen's Power Tools
2010-09-09 17:02 . 2010-09-09 17:06 -------- d-----w- c:\program files\Karen's Power Tools
2010-09-09 16:50 . 2010-09-09 16:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\ISP Monitor
2010-09-09 16:46 . 2010-09-09 16:46 737280 ----a-w- c:\windows\iun6002.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-07 12:55 . 2008-03-05 04:59 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-10-06 12:41 . 2010-03-12 19:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2010-10-05 22:32 . 2010-08-24 23:52 768 ----a-w- c:\windows\system32\d3d8caps.dat
2010-10-04 15:59 . 2010-05-26 14:28 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-10-01 02:30 . 2010-10-01 00:21 112 ----a-w- c:\documents and settings\All Users\Application Data\J71R5Tb.dat
2010-09-30 22:11 . 2010-09-30 22:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-30 22:07 . 2010-09-30 22:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-09-30 22:07 . 2010-09-30 22:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-30 19:33 . 2008-03-06 17:38 -------- d-----w- c:\program files\uTorrent
2010-09-30 19:12 . 2008-03-06 17:38 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
2010-09-27 15:01 . 2008-09-02 17:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\dvdcss
2010-09-21 13:19 . 2008-03-03 16:30 104424 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-15 13:51 . 2008-03-03 19:29 -------- d-----w- c:\program files\Microsoft.NET
2010-09-14 22:08 . 2008-03-03 15:32 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-09-13 13:31 . 2008-03-03 16:22 -------- d-----w- c:\program files\Intel
2010-08-30 18:31 . 2008-03-03 19:53 -------- d-----w- c:\program files\Sony
2010-08-24 18:10 . 2008-03-03 20:17 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-08-24 17:28 . 2010-05-26 14:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Roxio
2010-08-24 12:17 . 2008-12-23 16:52 -------- d-----w- c:\documents and settings\All Users\Application Data\CraigsPal
2010-08-23 12:29 . 2010-08-23 12:29 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{D69A48BF-7653-4AA8-94BC-5847522A4573}
2010-08-23 12:26 . 2010-08-23 12:25 -------- d-----w- c:\program files\Common Files\Native Instruments
2010-08-23 12:26 . 2010-08-23 12:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Native Instruments
2010-08-23 12:26 . 2010-08-23 12:26 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{0CC51CB2-911C-40BB-BC1B-BD3CAC590222}
2010-08-23 12:25 . 2010-08-23 12:25 -------- d-----w- c:\program files\Native Instruments
2010-08-23 12:25 . 2010-08-23 12:25 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{D7CFB71A-972A-44FF-AE44-8780EB53ABB2}
2010-08-17 13:17 . 2004-08-04 01:07 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-13 16:46 . 2010-08-11 17:24 16 ----a-w- c:\windows\msocreg32.dat
2010-08-11 17:24 . 2010-08-11 17:24 -------- d-----w- c:\program files\IK Multimedia
2010-08-11 17:23 . 2008-03-03 16:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-11 17:23 . 2010-08-11 17:23 -------- d-----w- c:\documents and settings\Administrator\Application Data\InstallShield
2010-07-27 06:30 . 2010-07-27 06:30 8462336 ------w- c:\windows\system32\SET261.tmp
2010-07-22 15:49 . 2004-08-04 01:07 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2010-09-14 22:41 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-15 15:23 . 2010-07-15 15:23 654456 ----a-w- c:\windows\system32\ncs2dmix.dll
2010-07-15 15:23 . 2010-07-15 15:23 506488 ----a-w- c:\windows\system32\accesor.dll
2010-07-15 14:45 . 2010-07-15 14:45 27591840 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\msgup1000_1270_us_u2.exe
2010-07-14 14:16 . 2010-07-14 14:16 182784 ----a-w- c:\windows\system32\Ncs2Setp.dll
2010-07-14 13:39 . 2010-07-14 13:39 134264 ----a-w- c:\windows\system32\ncs2instutility.dll
2010-07-14 13:20 . 2010-07-14 13:20 1813112 ----a-w- c:\windows\system32\ncscolib.dll
2010-07-12 12:45 . 2010-07-12 12:45 3584 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{121634B0-2F4A-11D3-ADA3-00C04F52DD53}\Icon386ED4E3.exe
2007-06-27 01:57 . 2008-03-03 18:51 32768 ----a-w- c:\program files\tarsier.exe
2007-06-27 01:21 . 2008-03-03 18:51 110 ----a-w- c:\program files\screensaveroff.reg
2006-07-05 12:06 . 2008-03-03 18:51 1628813 ----a-w- c:\program files\flash player 8.exe
2005-11-14 13:47 . 2008-03-03 18:51 987136 ----a-w- c:\program files\flash player 7.exe
2005-04-18 01:23 . 2008-03-03 18:51 68 ----a-w- c:\program files\search.vbs
2003-02-08 21:49 . 2008-03-03 18:51 37888 ----a-w- c:\program files\wizmo.exe
2008-03-11 12:51 . 2008-03-11 12:51 0 --sh--w- c:\windows\SD2C70EBC.tmp
.
------- Sigcheck -------
[7] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
[7] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\termsrv.dll
[-] 2008-04-14 . E93FC3D9A106DDCD8887547FA01A33FC . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
[-] 2004-08-04 . 2FC602F08EE290DEBE26D8510993D6A5 . 295424 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Privoxy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Privoxy.lnk
backup=c:\windows\pss\Privoxy.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Showcalc.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Showcalc.lnk
backup=c:\windows\pss\Showcalc.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-06-21 21:44 126976 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-06-21 21:48 155648 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NGTray]
2008-04-23 01:35 218504 ----a-w- c:\program files\Symantec\Ghost\ngtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2009-07-24 12:33 240112 ----a-w- c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MDM"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"idsvc"=3 (0x3)
"odserv"=3 (0x3)
"LiveUpdate"=3 (0x3)
"aawservice"=2 (0x2)
"SymSnapService"=3 (0x3)
"IntuitUpdateService"=2 (0x2)
"Pml Driver HPH11"=3 (0x3)
"WRConsumerService"=2 (0x2)
"WebrootSpySweeperService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"IP Monitor"=3 (0x3)
"BroadCamService"=2 (0x2)
"rpcapd"=3 (0x3)
"RoxWatch12"=2 (0x2)
"9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269"=2 (0x2)
"CinemaNow Service"=2 (0x2)
"NIHardwareService"=2 (0x2)
"RoxMediaDB12"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Symantec\\Ghost\\GhostSrv.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"=
"c:\\Program Files\\IP Monitor\\IPMonitor.exe"=
"c:\\Program Files\\IP Monitor\\IPMonSvc.exe"=
"c:\\Program Files\\Microsoft Office2007\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Roxio 2010\\Venue\\Venue.exe"=
"c:\\Program Files\\Sony\\Vegas Pro 9.0\\VegSrv90.exe"=
"c:\\Program Files\\Symantec\\Ghost\\ngserver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVPlayer\\NVPlayer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"5555:TCP"= 5555:TCP:remote 5555
"5555:UDP"= 5555:UDP:remore 5555 2
"9050:UDP"= 9050:UDP:*:Disabled:vidalia
"8118:UDP"= 8118:UDP:*:Disabled:vidalia
"64634:TCP"= 64634:TCP:*:Disabled:64634
"64634:UDP"= 64634:UDP:*:Disabled:64634 2
"25:TCP"= 25:TCP:*:Disabled:IP Monitor:TCP:25
"86:TCP"= 86:TCP:*:Disabled:BroadCam Video Streaming Server TCP/IP Port
"1935:TCP"= 1935:TCP:*:Disabled:BroadCam Video Streaming Server Flash Video Server
"123:UDP"= 123:UDP:*:Disabled:time sync
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [5/26/2010 10:38 AM 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [5/26/2010 10:38 AM 15856]
R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [5/26/2010 10:38 AM 25584]
S0 jlcey;jlcey; [x]
S0 tguho;tguho; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 5:10 PM 32512]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/3/2004 9:07 PM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [6/2/2009 7:05 PM 457200]
S4 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [6/23/2009 5:40 PM 127352]
S4 IP Monitor;IP Monitor Network Address Monitor;c:\progra~1\IPMONI~1\ipmonsvc.exe [4/5/2010 1:59 PM 164352]
S4 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [7/17/2009 9:32 AM 3576320]
S4 RoxMediaDB12;RoxMediaDB12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [7/24/2009 8:33 AM 1116656]
S4 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [7/24/2009 8:33 AM 219632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.gooofullsearch.com/
uInternet Settings,ProxyServer = localhost:8118
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: cinemanow.com
Trusted Zone: fastestdeploy.com
Trusted Zone: fastestdeploy.com
TCP: {36F3399F-AC03-4CE2-A2DB-9F6FBCF714A5} = 192.168.1.1
DPF: ATLApplicationLocatorAXInstall - hxxp://192.168.0.136/LaunchVCPC.cab
DPF: {7E866715-C9B6-4C64-AAB8-342E0D137213} - hxxp://192.168.0.51/EDVR.CAB
DPF: {CCDA56E6-AE8D-4A43-846F-EE464650864A} - hxxp://192.168.0.100/WebView.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\obn3q3vk.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\obn3q3vk.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\obn3q3vk.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\obn3q3vk.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.order.1 - Google
FF - user.js: keyword.URL - hxxp://search.fast-find.net/?sid=10101063100&s=.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-rundllxxxx.exe - c:\rundllxxxx.exe\rundllxxxx.exe
HKU-Default-Run-rundllxxxx.exe - c:\rundllxxxx.exe\rundllxxxx.exe
HKU-Default-Run-KOO9RV9K4Z - c:\windows\system32\config\SYSTEM~1\LOCALS~1\Temp\Hr2.exe
MSConfigStartUp-coreappsetup700 - c:\documents and settings\Administrator\Application Data\7EB69134C92CDBCC4FF1A22944E3A22B\coreappsetup700.exe
MSConfigStartUp-HNUGROXRme - c:\docume~1\ADMINI~1\LOCALS~1\Temp\avp.exe
MSConfigStartUp-HNUGROXRnfc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\c8kax.exe
MSConfigStartUp-HNUGROXRnjbb - c:\docume~1\ADMINI~1\LOCALS~1\Temp\dy7zc2kcnd.exe
MSConfigStartUp-HNUGROXRnnD - c:\docume~1\ADMINI~1\LOCALS~1\Temp\fhdld62v.exe
MSConfigStartUp-HNUGROXRnyc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\csrss.exe
MSConfigStartUp-HNUGROXRnZ - c:\docume~1\ADMINI~1\LOCALS~1\Temp\cmd.exe
MSConfigStartUp-HNUGROXRoMc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\gdi32.exe
MSConfigStartUp-HNUGROXRota - c:\docume~1\ADMINI~1\LOCALS~1\Temp\install.exe
MSConfigStartUp-HNUGROXRotc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\hexdump.exe
MSConfigStartUp-HNUGROXRouqc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\iexplarer.exe
MSConfigStartUp-HNUGROXRprc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\login.exe
MSConfigStartUp-HNUGROXRpuc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\lsass.exe
MSConfigStartUp-HNUGROXRpw+ - c:\docume~1\ADMINI~1\LOCALS~1\Temp\nvsvc32.exe
MSConfigStartUp-HNUGROXRpZ - c:\docume~1\ADMINI~1\LOCALS~1\Temp\mdm.exe
MSConfigStartUp-HNUGROXRre - c:\docume~1\ADMINI~1\LOCALS~1\Temp\user.exe
MSConfigStartUp-HNUGROXRrg - c:\docume~1\ADMINI~1\LOCALS~1\Temp\smss.exe
MSConfigStartUp-HNUGROXRrrb - c:\docume~1\ADMINI~1\LOCALS~1\Temp\taskmgr.exe
MSConfigStartUp-HNUGROXRrse - c:\docume~1\ADMINI~1\LOCALS~1\Temp\svchost.exe
MSConfigStartUp-HNUGROXRrtc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\sysedit.exe
MSConfigStartUp-HNUGROXRruf - c:\docume~1\ADMINI~1\LOCALS~1\Temp\spoolsv.exe
MSConfigStartUp-HNUGROXRrvc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\setup.exe
MSConfigStartUp-HNUGROXRrxe - c:\docume~1\ADMINI~1\LOCALS~1\Temp\system.exe
MSConfigStartUp-HNUGROXRsa - c:\docume~1\ADMINI~1\LOCALS~1\Temp\win.exe
MSConfigStartUp-HNUGROXRsPc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\win32.exe
MSConfigStartUp-HNUGROXRspe - c:\docume~1\ADMINI~1\LOCALS~1\Temp\winamp.exe
MSConfigStartUp-HNUGROXRsre - c:\docume~1\ADMINI~1\LOCALS~1\Temp\wininst.exe
MSConfigStartUp-HNUGROXRssc - c:\docume~1\ADMINI~1\LOCALS~1\Temp\winlogon.exe
MSConfigStartUp-MKaoc - c:\windows\debug.exe
MSConfigStartUp-MKasc - c:\windows\drweb.exe
MSConfigStartUp-MKayc - c:\windows\csrss.exe
MSConfigStartUp-MKbMc - c:\windows\gdi32.exe
MSConfigStartUp-MKbta - c:\windows\install.exe
MSConfigStartUp-MKbtc - c:\windows\hexdump.exe
MSConfigStartUp-MKbuqc - c:\windows\iexplarer.exe
MSConfigStartUp-MKcrc - c:\windows\login.exe
MSConfigStartUp-MKcZ - c:\windows\mdm.exe
MSConfigStartUp-MKdw+ - c:\windows\nvsvc32.exe
MSConfigStartUp-MKeg - c:\windows\smss.exe
MSConfigStartUp-MKerb - c:\windows\taskmgr.exe
MSConfigStartUp-MKeta - c:\windows\services.exe
MSConfigStartUp-MKetc - c:\windows\sysedit.exe
MSConfigStartUp-MKeuf - c:\windows\spoolsv.exe
MSConfigStartUp-MKevc - c:\windows\setup.exe
MSConfigStartUp-MKexe - c:\windows\system.exe
MSConfigStartUp-MKfPc - c:\windows\win32.exe
MSConfigStartUp-3.5 - c:\windows\win32.exe
MSConfigStartUp-MKfpe - c:\windows\winamp.exe
MSConfigStartUp-MKfre - c:\windows\wininst.exe
MSConfigStartUp-MKfsc - c:\windows\winlogon.exe
MSConfigStartUp-MKZe - c:\windows\avp.exe
MSConfigStartUp-MKZSc - c:\windows\avp32.exe
MSConfigStartUp-uPc+MV0Na0LaXms - c:\windows\system32\ht1tuvr8fb.dll
MSConfigStartUp-uPc+MV0NMtaGuo - c:\windows\system32\h67eist.dll
MSConfigStartUp-uPc+MV0NskaGuo - c:\windows\system32\lzqxz2o.dll
MSConfigStartUp-wupdate - c:\windows\system32\wupdate.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1612)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Symantec\Ghost\ngserver.exe
c:\windows\system32\wscntfy.exe
c:\program files\Symantec\Ghost\bin\dbserv.exe
c:\program files\Symantec\Ghost\bin\rteng9.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2010-10-07 09:23:41 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-07 13:23
Pre-Run: 5,741,277,184 bytes free
Post-Run: 6,849,581,056 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[Boot Loader]
Timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Pro 1" /noexecute=optin /fastdetect
- - End Of File - - 2E517214DC5307BF50BD49E25BBE7353
Thanks for helping!