The updated copy failed to download. So I just went ahead with the older version.
ComboFix 08-10-24.02 - Mike 2008-10-26 18:54:14.7 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.351 [GMT -6:00]
Running from: C:\Documents and Settings\Mike\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\Drivers\TDSSmaxt.sys
C:\WINDOWS\system32\TDSSbivk.log
C:\WINDOWS\system32\TDSSbubx.dll
C:\WINDOWS\system32\TDSSbubx.log
C:\WINDOWS\system32\TDSScfgb.dll
C:\WINDOWS\system32\TDSScfum.dll
C:\WINDOWS\system32\TDSSfpmp.dll
C:\WINDOWS\system32\TDSSfxwp.dll
C:\WINDOWS\system32\TDSSnmxa.dll
C:\WINDOWS\system32\TDSSnmxh.log
C:\WINDOWS\system32\TDSSnrsr.dll
C:\WINDOWS\system32\TDSSofxh.dll
C:\WINDOWS\system32\TDSSoiqh.dll
C:\WINDOWS\system32\TDSSosvd.dat
C:\WINDOWS\system32\TDSSosvn.dat
C:\WINDOWS\system32\TDSSrhym.dll
C:\WINDOWS\system32\TDSSriqp.dll
C:\WINDOWS\system32\TDSSsbhc.dll
C:\WINDOWS\system32\TDSSthym.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS)
-------\Service_TDSSserv.sys)
((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.
2008-10-26 15:40 . 2008-10-26 15:41 <DIR> d-------- C:\WINDOWS\ERUNT
2008-10-26 15:37 . 2008-10-26 16:05 <DIR> d-------- C:\SDFix
2008-10-23 18:04 . 2008-10-23 18:04 18,773 --a------ C:\WINDOWS\uvozysyje.inf
2008-10-23 18:04 . 2008-10-23 18:04 18,434 --a------ C:\Documents and Settings\Mike\Application Data\boxuwyder.reg
2008-10-23 18:04 . 2008-10-23 18:04 18,124 --a------ C:\WINDOWS\SYSTEM32\hasy.vbs
2008-10-23 18:04 . 2008-10-23 18:04 16,834 --a------ C:\Documents and Settings\All Users\Application Data\ocyqyxal.dat
2008-10-23 18:04 . 2008-10-23 18:04 16,490 --a------ C:\Documents and Settings\All Users\Application Data\gohypiwuvi.dat
2008-10-23 18:04 . 2008-10-23 18:04 15,226 --a------ C:\WINDOWS\reha.lib
2008-10-23 18:04 . 2008-10-23 18:04 14,378 --a------ C:\WINDOWS\SYSTEM32\cawavip.bin
2008-10-23 18:04 . 2008-10-23 18:04 14,095 --a------ C:\WINDOWS\macajeb._dl
2008-10-23 18:04 . 2008-10-23 18:04 14,033 --a------ C:\WINDOWS\acowyjuj.reg
2008-10-23 18:04 . 2008-10-23 18:04 13,317 --a------ C:\WINDOWS\jyza.reg
2008-10-23 18:04 . 2008-10-23 18:04 11,939 --a------ C:\Program Files\Common Files\libegisu.exe
2008-10-23 18:04 . 2008-10-23 18:04 11,276 --a------ C:\WINDOWS\yriw.ban
2008-10-23 18:04 . 2008-10-23 18:04 11,004 --a------ C:\WINDOWS\lude._sy
2008-10-23 17:55 . 2008-10-23 17:55 <DIR> d-------- C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\AVGTOOLBAR
2008-10-06 19:47 . 2008-10-06 19:46 33,846 --a------ C:\WINDOWS\SYSTEM32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.bmp
2008-10-06 19:47 . 2008-10-06 19:47 3,400 --a------ C:\WINDOWS\SYSTEM32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.dat
2008-10-06 19:45 . 2008-10-06 19:46 10,886,008 --a------ C:\Program Files\dBpoweramp-Codec-WMA10Pro.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-25 06:46 --------- d-----w C:\Program Files\Soulseek
2008-10-25 01:18 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-24 02:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-24 01:36 --------- d-----w C:\Program Files\SpywareBlaster
2008-10-24 00:04 14,302 ----a-w C:\Program Files\Common Files\doleteq._sy
2008-10-24 00:04 12,061 ----a-w C:\Program Files\Common Files\uqegakeji._dl
2008-10-21 06:38 --------- d-----w C:\Documents and Settings\Mike\Application Data\uTorrent
2008-10-17 07:03 --------- d--h--w C:\Documents and Settings\Mike\Application Data\Move Networks
2008-10-04 04:06 --------- d-----w C:\Documents and Settings\Jen\Application Data\Apple Computer
2008-09-26 05:55 --------- d-----w C:\Program Files\ratDVD
2008-09-26 05:48 4,730,740 ----a-w C:\Program Files\ratDVDSetup-0.78.1444.exe
2008-09-09 03:49 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-09 03:20 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-08 06:11 38,528 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-08 06:11 17,200 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-09-04 23:50 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-08-30 11:55 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-29 21:15 --------- d-----w C:\Documents and Settings\Lucy63\Application Data\AVGTOOLBAR
2008-08-28 21:22 --------- d-----w C:\Documents and Settings\Mike\Application Data\Apple Computer
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-28 06:54 --------- d-----w C:\Program Files\iTunes
2008-08-28 06:53 --------- d-----w C:\Program Files\iPod
2008-08-28 06:52 --------- d-----w C:\Program Files\QuickTime
2008-08-28 06:52 --------- d-----w C:\Program Files\Bonjour
2008-08-28 06:36 --------- d-----w C:\Program Files\Safari
2008-08-28 05:04 --------- d-----w C:\Program Files\Apple Software Update
2008-08-27 02:56 --------- d-----w C:\Documents and Settings\Mike\Application Data\AVGTOOLBAR
2008-08-10 03:20 267,056 ----a-w C:\Program Files\utorrent.exe
2008-08-05 23:55 2,869,536 ----a-w C:\Program Files\spywareblastersetup41.exe
2008-08-03 21:41 9,346,664 ----a-w C:\Program Files\zlsSetup_60_667_000.exe
2008-08-03 04:28 50,688 ----a-w C:\Program Files\ATF-Cleaner.exe
2008-08-03 03:09 4,614,888 ----a-w C:\Program Files\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
2008-08-02 21:55 48,367,896 ----a-w C:\Program Files\avg_free_stf_en_8_138a1332.exe
2008-07-30 05:01 6,046,584 ----a-w C:\Program Files\Firefox Setup 2.0.0.16.exe
2008-07-29 00:28 812,344 ----a-w C:\Program Files\HJTInstall.exe
2008-06-14 10:39 128,368 ----a-w C:\Program Files\Download_mbam-setup.exe
2008-06-12 07:26 4,257,184 ----a-w C:\Program Files\registryboosteraff.exe
2008-06-11 22:33 9,722,720 ----a-w C:\Program Files\spybotsd152.exe
2008-05-13 08:13 486,108,144 ----a-w C:\Program Files\ADBEPHSPCS3_WWE.exe
2008-05-05 03:36 304,957 ----a-w C:\Program Files\hjsplit.zip
2008-04-29 04:04 1,071,480 ----a-w C:\Program Files\dBpoweramp-Codec-m4a.exe
2008-03-26 23:37 6,104,632 ----a-w C:\Program Files\picasaweb-current-setup.exe
2008-03-26 23:23 13,445,041 ----a-w C:\Program Files\ps701up.exe
2008-03-13 02:33 90,044,946 ----a-w C:\Program Files\ableton_live_demo_702_en.zip
2008-01-17 23:19 1,958 ----a-w C:\Program Files\AT&T Self Support Tool.lnk
2008-01-17 23:19 1,741 ----a-w C:\Program Files\AT&T Help.lnk
2007-12-25 23:35 54,330,664 ----a-w C:\Program Files\iTunesSetup.exe
2007-12-20 02:08 5,914,648 ----a-w C:\Program Files\SUPERAntiSpyware.exe
2007-10-05 03:35 842,672 ----a-w C:\Program Files\slsk156c.exe
2007-09-30 22:01 6,016,952 ----a-w C:\Program Files\Firefox Setup 2.0.0.7.exe
2007-09-21 07:59 5,651,713 ----a-w C:\Program Files\The-Codecs-5.0.zip
2007-09-21 05:26 23,769,896 ----a-w C:\Program Files\DivXInstaller.exe
2007-06-12 02:57 4,044,152 ----a-w C:\Program Files\dBpoweramp-encoder-helix.exe
2007-06-12 02:52 4,112,760 ----a-w C:\Program Files\dMC-r12[1].1.exe
2007-05-18 23:16 3,362,502 ----a-w C:\Program Files\cxp_free.exe
2007-05-16 04:44 1,055,648 ----a-w C:\Program Files\qmpsetup_win_ie_07010901.exe
2007-04-10 05:52 206,039 ----a-w C:\Program Files\RAR.zip
2007-03-18 05:43 877,976 ----a-w C:\Program Files\7z444.exe
2007-03-18 03:18 1,202,303 ----a-w C:\Program Files\wrar37b4.exe
2007-02-28 00:06 881 ----a-w C:\Program Files\fixreg.zip
2007-02-13 02:57 4,964,776 ----a-w C:\Program Files\Windows-KB890830-V1.24.exe
2007-02-02 00:02 313,344 ----a-w C:\Program Files\hjsplit.exe
2006-12-29 04:29 40,409,184 ----a-w C:\Program Files\MIS_9_0_183_1_trial30OEM_Release.exe
2006-12-26 13:22 70,873,480 ----a-w C:\Program Files\tis2007_trial.exe
2006-12-24 11:50 4,813,736 ----a-w C:\Program Files\Windows-KB890830-V1.23.exe
2004-11-07 21:58 0 -c--a-w C:\Documents and Settings\Lucy63\4.dat
2004-11-07 21:58 0 -c--a-w C:\Documents and Settings\Lucy63\3.dat
2004-11-07 03:56 0 -c--a-w C:\Documents and Settings\Jen\4.dat
2004-11-07 03:56 0 -c--a-w C:\Documents and Settings\Jen\3.dat
2006-11-22 20:13 104 --sh--w C:\WINDOWS\Microsoft.NET\ergafx.dll
.
------- Sigcheck -------
2002-08-29 04:00 516608 2246d8d8f4714a2cedb21ab9b1849abb C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2004-08-04 01:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2008-10-23 17:55 502272 9b1bd82bd0761b5ba986af66d2809c30 C:\WINDOWS\SYSTEM32\winlogon.exe
2002-08-29 04:00 200192 fe84e045a09a4abc4deef7270448b64e C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
2004-08-04 01:56 295424 b60c877d16d9c880b952fda04adf16e6 C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
2008-04-13 18:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\termsrv.dll
2008-10-23 17:55 295424 40ffc19a8d4875e9e19cecdc76ef9201 C:\WINDOWS\SYSTEM32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="1" [X]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-04 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxpers"="C:\WINDOWS\System32\igfxpers.exe" [2005-09-20 114688]
"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"LexPPS.exe"="C:\WINDOWS\system32\lexpps.exe" [2003-05-02 174592]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2004-09-20 36953]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-09-20 24576]
SBC Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2008-01-17 217088]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-20 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-08-26 15:47 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.HFYU"= huffyuv.dll
"msacm.avis"= ff_acm.acm
"vidc.i263"= C:\WINDOWS\system32\i263_32.drv
"msacm.imc"= C:\WINDOWS\system32\imc32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\utorrent.exe"=
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-30 97928]
S1 mssmbioss;mssmbioss;C:\WINDOWS\system32\drivers\mssmbioss.sys [ ]
S2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-02 76040]
.
Contents of the 'Scheduled Tasks' folder
2008-10-14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\w7ntqjtq.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-26 18:59:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSpqxt.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tsd32.dll
.
Completion time: 2008-10-26 19:08:24 - machine was rebooted [Mike]
ComboFix-quarantined-files.txt 2008-10-27 01:08:22
Pre-Run: 41,686,433,792 bytes free
Post-Run: 41,708,421,120 bytes free
219 --- E O F --- 2008-10-23 21:32:03
Edited by MVV, 26 October 2008 - 05:11 PM.