Hi Jimmy2012,
(1) Below is the combofix.txt:
ComboFix 08-11-29.03 - Owner 2008-11-30 0:34:50.2 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.393 [GMT 0:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt.txt
* Created a new restore point
FILE ::
c:\dfndrd_5.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-30 )))))))))))))))))))))))))))))))
.
2008-11-29 10:45 . 2008-11-29 10:45 <DIR> d--hs---- C:\FOUND.000
2008-11-28 12:28 . 2008-11-28 12:28 <DIR> d-------- C:\rsit
2008-11-27 17:53 . 2008-11-27 17:53 244 --ah----- C:\sqmnoopt19.sqm
2008-11-27 17:53 . 2008-11-27 17:53 232 --ah----- C:\sqmdata19.sqm
2008-11-26 21:09 . 2008-11-26 21:09 244 --ah----- C:\sqmnoopt18.sqm
2008-11-26 21:09 . 2008-11-26 21:09 232 --ah----- C:\sqmdata18.sqm
2008-11-26 20:45 . 2008-11-26 20:45 244 --ah----- C:\sqmnoopt17.sqm
2008-11-26 20:45 . 2008-11-26 20:45 232 --ah----- C:\sqmdata17.sqm
2008-11-26 16:34 . 2008-11-26 16:34 244 --ah----- C:\sqmnoopt16.sqm
2008-11-26 16:34 . 2008-11-26 16:34 232 --ah----- C:\sqmdata16.sqm
2008-11-26 15:23 . 2008-11-26 15:23 244 --ah----- C:\sqmnoopt15.sqm
2008-11-26 15:23 . 2008-11-26 15:23 232 --ah----- C:\sqmdata15.sqm
2008-11-26 15:09 . 2008-11-26 15:09 244 --ah----- C:\sqmnoopt14.sqm
2008-11-26 15:09 . 2008-11-26 15:09 232 --ah----- C:\sqmdata14.sqm
2008-11-26 14:57 . 2008-11-26 14:57 244 --ah----- C:\sqmnoopt13.sqm
2008-11-26 14:57 . 2008-11-26 14:57 232 --ah----- C:\sqmdata13.sqm
2008-11-26 14:54 . 2008-11-26 14:54 244 --ah----- C:\sqmnoopt12.sqm
2008-11-26 14:54 . 2008-11-26 14:54 232 --ah----- C:\sqmdata12.sqm
2008-11-23 16:40 . 2008-11-23 16:40 <DIR> d-------- c:\program files\ERUNT
2008-11-21 22:40 . 2008-11-21 22:40 <DIR> d-------- c:\program files\SpywareBlaster
2008-11-20 21:28 . 2008-11-20 21:27 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-19 11:43 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-19 11:43 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-16 23:29 . 2008-11-16 23:29 <DIR> d-------- c:\program files\Enigma Software Group
2008-11-16 20:43 . 2008-11-16 20:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2008-11-14 09:41 . 2008-11-14 09:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-11-14 07:56 . 2006-11-01 07:35 101,176 --a------ C:\tcpvcon.exe
2008-11-14 07:22 . 2008-11-14 07:22 244 --ah----- C:\sqmnoopt11.sqm
2008-11-14 07:22 . 2008-11-14 07:22 232 --ah----- C:\sqmdata11.sqm
2008-11-13 11:54 . 2008-11-13 11:54 <DIR> d-------- c:\documents and settings\LogMeInRemoteUser
2008-11-13 11:54 . 2003-01-21 03:00 13,942,408 -ra------ c:\documents and settings\LogMeInRemoteUser\MpSetup.exe
2008-11-13 11:40 . 2008-11-13 11:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\LogMeIn
2008-11-13 11:39 . 2008-10-16 20:35 83,288 --a------ c:\windows\system32\LMIRfsClientNP.dll
2008-11-13 11:39 . 2008-07-24 18:46 47,640 --a------ c:\windows\system32\drivers\LMIRfsDriver.sys
2008-11-13 11:39 . 2008-10-16 20:35 28,984 --a------ c:\windows\system32\LMIport.dll
2008-11-13 11:38 . 2008-11-13 11:38 <DIR> d-------- c:\program files\LogMeIn
2008-11-13 11:38 . 2008-10-16 20:35 87,352 --a------ c:\windows\system32\LMIinit.dll
2008-11-13 11:38 . 2008-11-13 11:38 1,024 --a------ C:\.rnd
2008-11-12 10:42 . 2008-11-12 10:42 57 --a------ c:\windows\WININIT.INI
2008-11-11 10:43 . 2008-11-11 10:43 <DIR> d-------- c:\program files\X-Cleaner
2008-11-11 07:56 . 2008-11-11 07:56 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-11 07:56 . 2008-11-11 07:56 <DIR> d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-11 07:56 . 2008-11-11 07:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-10 15:52 . 2008-11-10 15:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sunbelt
2008-11-10 15:51 . 2008-11-10 15:51 <DIR> d-------- c:\program files\Sunbelt Software
2008-11-10 11:17 . 2008-11-10 11:17 <DIR> d-------- c:\program files\Lavasoft
2008-11-10 11:17 . 2008-11-10 11:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-09 22:31 . 2008-11-26 09:45 63 --a------ c:\windows\system\SysSD.dll
2008-11-09 22:26 . 2008-11-09 22:26 <DIR> d-------- c:\program files\SpywareDetector
2008-11-09 10:13 . 2008-11-09 10:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\SITEguard
2008-11-09 10:06 . 2008-11-09 10:06 <DIR> d-------- c:\program files\Common Files\iS3
2008-11-09 10:05 . 2008-11-09 10:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\STOPzilla!
2008-11-08 13:53 . 2008-11-08 13:53 <DIR> d-------- c:\program files\SUPERAntiSpyware
2008-11-08 13:53 . 2008-11-08 13:53 <DIR> d-------- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2008-11-08 13:53 . 2008-11-08 13:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-10-27 23:38 . 2008-10-27 23:38 244 --ah----- C:\sqmnoopt10.sqm
2008-10-27 23:38 . 2008-10-27 23:38 232 --ah----- C:\sqmdata10.sqm
2008-10-24 23:22 . 2008-10-24 23:22 244 --ah----- C:\sqmnoopt09.sqm
2008-10-24 23:22 . 2008-10-24 23:22 232 --ah----- C:\sqmdata09.sqm
2008-10-22 19:30 . 2008-10-22 19:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\TVU Networks
2008-10-16 20:35 . 2008-10-16 20:35 23,736 --a------ c:\windows\system32\lmimirr.dll
2008-10-16 20:35 . 2008-10-16 20:35 10,040 --a------ c:\windows\system32\lmimirr2.dll
2008-10-06 18:34 . 2008-10-06 18:34 <DIR> d-------- c:\windows\system32\athan
2008-10-06 18:34 . 2008-10-06 18:34 <DIR> d-------- c:\program files\Athan
2008-10-06 18:34 . 2008-10-06 18:34 737,280 --a------ c:\windows\iun6002.exe
2008-10-03 18:41 . 2008-10-03 18:41 6,066,176 --a------ c:\windows\system32\SET344.tmp
2008-10-03 09:03 . 2008-10-03 09:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\Raxco
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 14:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-15 17:57 332,800 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 18:41 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
2008-10-03 09:00 53,192 ----a-w c:\windows\system32\drivers\rp_skt32.sys
2008-09-30 16:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 12:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-15 12:57 1,846,016 ------w c:\windows\system32\dllcache\win32k.sys
2008-09-04 16:42 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-09-04 16:42 1,106,944 ------w c:\windows\system32\dllcache\msxml3.dll
2008-08-28 11:04 333,056 ------w c:\windows\system32\dllcache\srv.sys
2008-08-27 09:24 3,593,216 ----a-w c:\windows\system32\SET33C.tmp
2008-08-27 09:24 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-08-25 09:38 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-08-25 09:38 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-08-23 06:56 635,848 ------w c:\windows\system32\dllcache\iexplore.exe
2008-08-23 06:54 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-08-14 11:00 2,180,352 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 11:00 2,180,352 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2008-08-14 10:58 2,136,064 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2008-08-14 10:51 138,368 ------w c:\windows\system32\dllcache\afd.sys
2008-08-14 10:22 2,057,728 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-08-14 10:22 2,057,728 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2008-08-14 10:22 2,015,744 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2007-12-14 21:01 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2006-05-18 23:33 6,642,360 ----a-w c:\program files\FXTS2Install.EXE
2006-03-27 19:01 39,056 ----a-w c:\documents and settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2003-01-21 19:00 13,942,408 ----a-w c:\windows\system32\config\systemprofile\MpSetup.exe
2003-01-21 03:00 13,942,408 ----a-r c:\documents and settings\Guest\MpSetup.exe
2003-01-21 03:00 13,942,408 ----a-r c:\documents and settings\Default User\MpSetup.exe
2003-01-21 03:00 13,942,408 ----a-r c:\documents and settings\Administrator\MpSetup.exe
2003-01-21 03:00 13,942,408 ------r c:\documents and settings\Owner\MpSetup.exe
2006-07-12 15:48 32 --sha-w c:\windows\{ACE21A30-4237-4988-ACDA-60C27D621C83}.dat
2006-07-12 16:42 32 --sha-w c:\windows\{DF48C522-F20B-4EDB-B7D9-C216EF1773A1}.dat
2007-02-14 16:44 32 --sha-w c:\windows\{8250D635-A9A5-46AF-B6A1-6397C0F7F383}.dat
2007-02-14 16:52 32 --sha-w c:\windows\{AD34C441-B173-4D57-A022-6664CF138E61}.dat
2007-02-14 17:00 32 --sha-w c:\windows\{53D5AFAB-8CB7-4059-8FDA-3B679FC5788E}.dat
2006-07-12 15:48 32 --sha-w c:\windows\system32\{9608D285-8DC4-4ED7-AE33-4B49442BFC6A}.dat
2006-07-12 16:42 32 --sha-w c:\windows\system32\{CBD23991-5F3A-4859-AF9D-85925302C7A3}.dat
2007-02-14 16:44 32 --sha-w c:\windows\system32\{37098E44-65EE-4670-B870-5234549F4BF6}.dat
2007-02-14 16:52 32 --sha-w c:\windows\system32\{E5589549-38EB-474D-B4D8-1AD2605EB0DF}.dat
2007-02-14 17:00 32 --sha-w c:\windows\system32\{0CA2D1D7-7F25-4103-81D1-FA0C46204BF3}.dat
.
((((((((((((((((((((((((((((( snapshot@2008-11-29_12.02.03.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-02-11 01:51:30 118,784 ----a-w c:\windows\system32\hkcmd.exe
+ 2004-02-11 01:55:32 155,648 ----a-w c:\windows\system32\igfxtray.exe
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 00:23 3953560 c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2008-11-01 00:23 3953560 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP665\A0657659.dll
2008-11-01 00:23 3953560 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP678\A0661075.dll
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegBHO-Global.reg
2008-11-20 21:29 2577 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657722.reg
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS1-Global.reg
2008-11-19 23:46 2335 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP664\A0657655.reg
2008-11-20 07:53 2271 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP666\A0657702.reg
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS2-Global.reg
2008-11-19 11:43 354 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP664\A0657645.reg
2008-11-20 20:55 246 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657755.reg
c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUS2-Owner.reg
2008-11-20 07:17 244 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP665\A0657693.reg
2008-11-20 20:55 244 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657752.reg
2004-08-04 15:56 25600 c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2004-08-04 15:56 25600 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658397.dll
c:\documents and settings\Owner\Desktop\install_flash_player(2).exe
2008-11-09 15:14 1851544 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP675\A0660871.exe
2008-11-29 20:01 8664 c:\program files\Common Files\Authentium\AntiVirus\defvn.dll
2008-11-17 16:46 0 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP662\A0656624.dll
2008-11-30 00:07 0 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP681\A0662276.dll
2008-11-27 06:59 530578 c:\program files\Common Files\Scanner\PPClean.exe
2008-11-14 20:51 530578 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP664\A0657649.exe
2008-11-25 21:33 530578 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP675\A0660893.exe
2008-10-22 16:10 73360 c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
2008-10-22 16:10 73360 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP663\A0657586.dll
c:\program files\Spyware Doctor\PCTWSC.dll
2008-06-02 16:20 182152 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658561.dll
c:\program files\SpywareDetector\SDNotify.dll
2008-10-14 17:02 462848 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP675\A0660884.dll
2007-09-05 14:11 148720 c:\program files\Virgin Broadband\PCguard\resources\zk_en_US\Fws_Rsrc.dll
2007-09-05 14:11 148720 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP662\A0657485.dll
2007-09-05 14:11 148720 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP680\A0662158.dll
2007-03-06 01:22 14048 c:\windows\$hf_mig$\KB956390-IE7\spmsg.dll
2007-03-06 02:22 14048 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661038.dll
2007-03-06 01:22 213216 c:\windows\$hf_mig$\KB956390-IE7\spuninst.exe
2007-03-06 02:22 213216 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661037.exe
2007-03-06 01:22 22752 c:\windows\$hf_mig$\KB956390-IE7\update\spcustom.dll
2007-03-06 02:22 22752 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661039.dll
2007-03-06 01:23 716000 c:\windows\$hf_mig$\KB956390-IE7\update\update.exe
2007-03-06 02:23 716000 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661041.exe
2007-03-06 01:23 371424 c:\windows\$hf_mig$\KB956390-IE7\update\updspapi.dll
2007-03-06 02:23 371424 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661042.dll
2007-11-30 12:39 17272 c:\windows\$hf_mig$\KB956391\spmsg.dll
2007-11-30 13:39 17272 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661050.dll
2007-11-30 12:39 231288 c:\windows\$hf_mig$\KB956391\spuninst.exe
2007-11-30 13:39 231288 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661049.exe
2007-11-30 12:39 26488 c:\windows\$hf_mig$\KB956391\update\spcustom.dll
2007-11-30 13:39 26488 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661051.dll
2007-11-30 12:39 755576 c:\windows\$hf_mig$\KB956391\update\update.exe
2007-11-30 13:39 755576 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661053.exe
2007-11-30 12:39 382840 c:\windows\$hf_mig$\KB956391\update\updspapi.dll
2007-11-30 13:39 382840 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP677\A0661054.dll
2004-08-04 13:32 208952 c:\windows\ime\imjp8_1\IMJPMIG.EXE
2004-08-04 13:32 208952 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP682\A0662285.exe
c:\windows\LastGood.Tmp\system32\cdm.dll
2008-07-18 22:10 94920 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658464.dll
c:\windows\LastGood.Tmp\system32\mucltui.dll
2008-07-18 22:07 270880 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658473.dll
c:\windows\LastGood.Tmp\system32\muweb.dll
2008-07-18 22:07 210976 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658474.dll
c:\windows\LastGood.Tmp\system32\wuapi.dll
2008-07-18 22:09 563912 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658465.dll
c:\windows\LastGood.Tmp\system32\wuauclt.exe
2008-07-18 22:10 53448 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658466.exe
c:\windows\LastGood.Tmp\system32\wuaueng.dll
2008-07-18 22:09 1811656 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658468.dll
c:\windows\LastGood.Tmp\system32\wucltui.dll
2008-07-18 22:09 325832 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658469.dll
c:\windows\LastGood.Tmp\system32\wups.dll
2008-07-18 22:10 36552 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658470.dll
c:\windows\LastGood.Tmp\system32\wups2.dll
2008-07-18 22:10 45768 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658471.dll
c:\windows\LastGood.Tmp\system32\wuweb.dll
2008-07-18 22:09 205000 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658472.dll
2008-11-26 09:45 63 c:\windows\system\SysSD.dll
2008-11-17 09:46 63 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP662\A0657502.dll
2008-11-25 09:45 63 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP674\A0660838.dll
c:\windows\system32\_000006_.tmp.dll
2008-03-19 10:47 1845248 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP680\A0662142.dll
2008-10-16 14:09 92696 c:\windows\system32\cdm.dll
2008-07-18 22:10 94920 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657756.dll
2004-08-04 15:56 15360 c:\windows\system32\ctfmon.exe
2004-08-04 15:56 15360 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP682\A0662286.EXE
2008-10-16 14:09 92696 c:\windows\system32\dllcache\cdm.dll
2008-07-18 22:10 94920 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657758.dll
2004-08-04 15:56 15360 c:\windows\system32\dllcache\ctfmon.exe
2004-08-04 15:56 15360 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP682\A0662290.exe
2004-08-04 13:32 208952 c:\windows\system32\dllcache\imjpmig.exe
2004-08-04 13:32 208952 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP682\A0662289.exe
2003-03-31 12:00 59392 c:\windows\system32\dllcache\imscinst.exe
2003-03-31 12:00 59392 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP682\A0662291.exe
2003-03-31 12:00 455168 c:\windows\system32\dllcache\tintsetp.exe
2003-03-31 12:00 455168 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP682\A0662292.exe
2008-10-16 14:12 561688 c:\windows\system32\dllcache\wuapi.dll
2008-07-18 22:09 563912 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657763.dll
2008-10-16 14:09 51224 c:\windows\system32\dllcache\wuauclt.exe
2008-07-18 22:10 53448 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657764.exe
2008-10-16 14:13 1809944 c:\windows\system32\dllcache\wuaueng.dll
2008-07-18 22:09 1811656 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657766.dll
2008-10-16 14:12 323608 c:\windows\system32\dllcache\wucltui.dll
2008-07-18 22:09 325832 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657767.dll
2008-10-16 14:08 34328 c:\windows\system32\dllcache\wups.dll
2008-07-18 22:10 36552 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658479.dll
2008-10-16 14:13 202776 c:\windows\system32\dllcache\wuweb.dll
2008-07-18 22:09 205000 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657769.dll
c:\windows\system32\drivers\npf.sys
2003-04-04 15:07 30336 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP680\A0662147.sys
c:\windows\system32\ftpupd.exe
2006-06-28 23:09 0 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP680\A0662143.exe
2003-03-31 12:00 59392 c:\windows\system32\IME\PINTLGNT\ImScInst.exe
2003-03-31 12:00 59392 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP682\A0662287.exe
2003-03-31 12:00 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
2003-03-31 12:00 455168 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP682\A0662288.exe
c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
2008-11-09 15:15 84661 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP675\A0660861.exe
2008-10-16 14:06 268648 c:\windows\system32\mucltui.dll
2008-07-18 22:07 270880 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657770.dll
2008-10-16 14:06 208744 c:\windows\system32\muweb.dll
2008-07-18 22:07 210976 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657771.dll
c:\windows\system32\nsprs.dll
2007-02-05 09:02 0 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP680\A0662144.dll
c:\windows\system32\packet.dll
2003-04-04 15:03 57344 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP680\A0662148.dll
c:\windows\system32\pthreadVC.dll
2002-03-02 04:10 53299 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP680\A0662149.dll
c:\windows\system32\wpcap.dll
2003-04-04 14:54 208896 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP680\A0662150.dll
2008-10-16 14:12 561688 c:\windows\system32\wuapi.dll
2008-07-18 22:09 563912 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657757.dll
2008-10-16 14:09 51224 c:\windows\system32\wuauclt.exe
2008-07-18 22:10 53448 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657759.exe
2008-10-16 14:13 1809944 c:\windows\system32\wuaueng.dll
2008-07-18 22:09 1811656 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657761.DLL
2008-10-16 14:12 323608 c:\windows\system32\wucltui.dll
2008-07-18 22:09 325832 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657762.dll
2008-10-16 14:08 34328 c:\windows\system32\wups.dll
2008-07-18 22:10 36552 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658461.dll
2008-10-16 14:09 43544 c:\windows\system32\wups2.dll
2008-07-18 22:10 45768 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP668\A0658463.dll
2008-10-16 14:13 202776 c:\windows\system32\wuweb.dll
2008-07-18 22:09 205000 {FCC443C4-52B9-4B44-8B32-15F132C6CD04}\RP667\A0657768.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"X-Cleaner Deluxe"="c:\progra~1\X-CLEA~1\XCleaner_full.exe" [2008-08-07 1062920]
"RamBooster"="c:\program files\RamBooster 2.0\Rambooster.exe" [2005-11-17 561664]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"IndexCleaner"="c:\program files\Virgin Broadband\PCguard\IdxClnR.exe" [2007-09-05 61168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\Media\SYNTPLPR.EXE" [2004-05-20 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\Media\SYNTPENH.EXE" [2004-05-20 532480]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\System32\IME\PINTLGNT\ImScInst.exe" [2003-03-31 59392]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-03-31 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2003-03-31 455168]
"PCguard"="c:\program files\Virgin Broadband\PCguard\Rps.exe" [2007-09-05 310000]
"-FreedomNeedsReboot"="c:\program files\Virgin Broadband\PCguard\ZkRunOnceR.exe" [2007-09-05 13552]
"Broadbandadvisor.exe"="c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2007-08-07 2061552]
"Athan"="c:\program files\Athan\Athan.exe" [2008-08-18 1069056]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2006-02-23 67264]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-16 20:35 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
"msacm.l3codec"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchApp]
Alaunch [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\-FreedomNeedsReboot]
--a------ 2007-09-05 14:10 13552 c:\program files\Virgin Broadband\PCguard\zkrunoncer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares destiny]
--a------ 2008-07-04 16:48 3266560 c:\program files\Ares Destiny\AresDestiny.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadbandadvisor.exe]
--a------ 2007-08-07 18:49 2061552 c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-04 13:32 208952 c:\windows\ime\imjp8_1\IMJPMIG.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
--a------ 2007-10-25 16:33 563984 c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2007-10-25 16:37 2178832 c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
--a------ 2008-07-24 18:46 63048 c:\program files\LogMeIn\x86\LogMeInSystray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 2003-03-31 12:00 59392 c:\windows\system32\IME\PINTLGNT\ImScInst.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCguard]
--a------ 2007-09-05 14:10 310000 c:\program files\Virgin Broadband\PCguard\RPS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2003-03-31 12:00 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2003-03-31 12:00 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--------- 2008-09-16 12:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-01-24 20:24 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2004-05-20 19:57 532480 c:\program files\Synaptics\SynTP\Media\SYNTPENH.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2004-05-20 19:57 98304 c:\program files\Synaptics\SynTP\Media\SYNTPLPR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-11-03 18:20 866584 c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SpyHunter Security Suite"=c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\PPMate\\ppmate.exe"=
"c:\\Program Files\\PPMate\\ppamnet.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 SMBHC;Microsoft SM Bus Host Controller Driver;c:\windows\system32\DRIVERS\SMBHC.sys [2004-07-06 6784]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\c:\windows\system32\drivers\LMIRfsDriver.sys [2008-11-13 47640]
R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2004-06-01 10386]
R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2004-05-31 4054]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\DRIVERS\i2220ntx.sys [1980-01-01 140288]
R3 SMBBATT;Microsoft Smart Battery Driver;c:\windows\system32\DRIVERS\SMBBATT.sys [2004-07-06 16128]
S0 szkg5;szkg;c:\windows\system32\DRIVERS\szkg.sys []
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys [2008-07-24 12856]
S3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2005-09-22 44160]
S3 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys []
S4 LMIRfsClientNP;LMIRfsClientNP; []
.
Contents of the 'Scheduled Tasks' folder
2008-11-29 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2008-11-30 c:\windows\Tasks\User_Feed_Synchronization-{DFF125AF-B8E9-40A9-BEF7-D53F6E4D8A65}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
2008-11-28 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Norton SystemWorks\OBC.exe [2002-08-29 21:30]
2008-11-30 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe
MSConfigStartUp-HotKeysCmds - c:\windows\system32\bak\hkcmd.exe
MSConfigStartUp-IgfxTray - c:\windows\system32\bak\igfxtray.exe
MSConfigStartUp-LManager - c:\program files\Launch Manager\bak\QtZgAcer.EXE
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-30 00:36:56
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet004\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\Owner\LOCALS~1\Temp\ASFWHide"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1332)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2008-11-30 0:37:46
ComboFix-quarantined-files.txt 2008-11-30 00:37:46
ComboFix2.txt 2008-11-29 12:03:34
Pre-Run: 1,582,235,648 bytes free
Post-Run: 1,608,843,264 bytes free
437 --- E O F --- 2008-11-27 23:46:20
---------------------------------------------------------------------------------
---------------------------------------------------------------------------------
(2)Below is the HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:41:16 AM, on 30-Nov-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Virgin Broadband\PCguard\Fws.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\Media\SYNTPLPR.EXE
C:\Program Files\Synaptics\SynTP\Media\SYNTPENH.EXE
C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe
C:\Program Files\Athan\Athan.exe
C:\Program Files\RamBooster 2.0\Rambooster.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\PROGRA~1\NORTON~3\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virgin Broadband\PCguard\rpsupdaterR.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Virgin Broadband\PCguard\RPS.exe
C:\Program Files\Virgin Broadband\advisor\BroadbandadvisorComHandler.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.comR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Virgin Broadband\PCguard\pkR.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\Media\SYNTPLPR.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\Media\SYNTPENH.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCguard] "C:\Program Files\Virgin Broadband\PCguard\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Virgin Broadband\PCguard\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [Broadbandadvisor.exe] "C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Virgin Broadband\PCguard\IdxClnR.exe"
O4 - HKCU\..\Run: [X-Cleaner Deluxe] "C:\PROGRA~1\X-CLEA~1\XCleaner_full.exe" -turbo -autostart -NOREBOOT
O4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster 2.0\Rambooster.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Virgin Broadband\PCguard\IdxClnR.exe"
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O8 - Extra context menu item: &Search - ?p=ZCxdm490YYMY
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspxO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {B8C681FD-D629-4CCE-90CD-89493F1F2799} (MovexWorkplaceExtension Object) -
https://online.omega.../ieui/IEMod.cabO18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Virgin Broadband PCguard Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Virgin Broadband\PCguard\rpsupdaterR.exe
O23 - Service: PCguard Firewall (RP_FWS) - Virgin Media - C:\Program Files\Virgin Broadband\PCguard\Fws.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~3\SPEEDD~1\nopdb.exe
O23 - Service: STOPzilla Service (szserver) - Unknown owner - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (file missing)
--
End of file - 10608 bytes
I have also completed the 3rd step which is cleaning the flash drives.
Thank You