
I recently did a Malwarebytes scan which detected that I had the above trojan, i followed some online help and just wondered if i posted some logs you could tell me my system is now clean

Thanks in advance...
ComboFix 08-12-11.01 - mark walker 2008-12-11 20:20:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1466 [GMT 0:00]
Running from: c:\documents and settings\mark walker\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mark walker\Desktop\WinXP_EN_PRO_BF.EXE
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\mark walker\Application Data\inst.exe
c:\windows\system32\tmp.reg
.
((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
.
2008-12-11 16:37 . 2008-12-11 16:37 <DIR> d-------- c:\documents and settings\mark walker\Application Data\Red Kawa
2008-12-11 16:36 . 2008-12-11 16:36 <DIR> d-------- c:\program files\AviSynth 2.5
2008-12-11 16:35 . 2008-12-11 16:36 <DIR> d-------- c:\program files\Red Kawa
2008-12-11 16:35 . 2008-12-11 16:35 <DIR> d-------- C:\OpenCandy
2008-12-09 19:27 . 2008-12-09 19:27 <DIR> d-------- C:\temp
2008-12-09 19:27 . 2008-12-09 19:27 <DIR> d-------- c:\program files\PQDVD
2008-12-08 19:07 . 2008-12-08 19:07 <DIR> d-------- c:\program files\Panda Security
2008-12-08 16:49 . 2008-12-08 16:49 <DIR> d-------- c:\program files\MediaMonkey
2008-12-08 16:46 . 2008-12-08 16:44 737,280 --a------ c:\windows\iun6002.exe
2008-12-08 16:45 . 2008-12-08 16:46 <DIR> d-------- c:\program files\Codec Pack - All In 1
2008-12-05 22:28 . 2008-12-05 22:28 7,320,080 --a------ c:\windows\system32\xa35534687.exe
2008-12-05 22:28 . 2008-12-05 22:28 7,320,080 --a------ c:\windows\system32\xa35533984.exe
2008-12-05 20:43 . 2008-12-05 20:43 <DIR> d-------- c:\program files\Common Files\xing shared
2008-12-05 20:20 . 2008-12-05 20:20 <DIR> d-------- c:\documents and settings\mark walker\Temp
2008-12-03 14:16 . 2008-12-03 14:16 <DIR> d-------- c:\documents and settings\dad\Application Data\vlc
2008-12-03 07:27 . 2008-12-03 07:27 <DIR> d-------- c:\documents and settings\dad\Application Data\Teleca
2008-12-03 07:26 . 2008-12-03 07:26 <DIR> d-------- c:\documents and settings\dad\Application Data\Sony Ericsson
2008-12-02 21:28 . 2008-12-02 21:28 <DIR> d-------- c:\documents and settings\mark walker\Application Data\Teleca
2008-12-02 21:27 . 2008-12-02 21:27 <DIR> d-------- c:\documents and settings\mark walker\Application Data\Sony Ericsson
2008-12-02 21:24 . 2008-12-02 21:24 <DIR> d-------- c:\program files\Common Files\Teleca Shared
2008-12-02 21:24 . 2008-12-02 21:24 <DIR> d-------- c:\program files\Common Files\Sony Ericsson Shared
2008-12-02 21:24 . 2008-12-02 21:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Teleca
2008-12-01 21:13 . 2008-12-01 21:13 <DIR> d-------- c:\documents and settings\mark walker\Application Data\MAGIX
2008-12-01 21:13 . 2008-12-01 21:39 28 --a------ c:\windows\Robota.INI
2008-12-01 21:10 . 2008-12-01 21:12 <DIR> d-------- c:\program files\MAGIX
2008-12-01 21:10 . 2008-12-01 21:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\MAGIX
2008-12-01 21:10 . 2006-03-31 14:57 430,080 --a------ c:\windows\system32\MXRestore.exe
2008-12-01 21:10 . 2007-04-27 09:43 120,200 --a------ c:\windows\system32\DLLDEV32i.dll
2008-12-01 21:10 . 2007-04-18 22:07 53,248 --a------ c:\windows\system32\mgxasio2.dll
2008-12-01 21:10 . 2003-04-18 15:29 44,544 --a------ c:\windows\system32\msxml4a.dll
2008-12-01 21:10 . 2004-03-11 15:49 14,182 --a------ c:\windows\system32\DLLAV32.lib
2008-12-01 21:09 . 2008-12-01 21:12 <DIR> d-------- c:\windows\system32\MAGIX
2008-11-26 20:11 . 2008-11-26 20:13 <DIR> d-------- c:\windows\NV8844076.TMP
2008-11-26 20:11 . 2008-10-07 13:33 201,157 --a------ c:\windows\system32\nvapps.nvb
2008-11-26 20:10 . 2008-11-26 20:10 <DIR> d-------- C:\NVIDIA
2008-11-26 20:08 . 2008-11-26 20:09 <DIR> d-------- c:\program files\iTunes
2008-11-26 20:08 . 2008-11-26 20:08 <DIR> d-------- c:\program files\iPod
2008-11-26 20:08 . 2008-11-26 20:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-26 20:07 . 2008-11-26 20:08 <DIR> d-------- c:\program files\QuickTime
2008-11-26 20:00 . 2008-11-26 20:00 <DIR> d-------- c:\program files\SystemRequirementsLab
2008-11-26 20:00 . 2008-11-26 20:00 <DIR> d-------- c:\documents and settings\mark walker\Application Data\SystemRequirementsLab
2008-11-26 19:47 . 2008-12-02 19:52 <DIR> d-------- c:\documents and settings\mark walker\Application Data\vlc
2008-11-26 19:47 . 2008-11-26 19:48 <DIR> d-------- c:\documents and settings\mark walker\Application Data\dvdcss
2008-11-26 19:46 . 2008-11-26 19:46 <DIR> d-------- c:\program files\VideoLAN
2008-11-23 17:26 . 2008-11-23 17:26 <DIR> d-------- c:\documents and settings\dad\Application Data\Canon
2008-11-21 17:20 . 2008-12-05 22:30 <DIR> d-------- c:\program files\DVDFab 5
2008-11-19 08:55 . 2008-11-19 08:55 <DIR> d-------- c:\documents and settings\James Ben Sophie\Application Data\Logitech
2008-11-17 19:31 . 2008-11-17 19:31 <DIR> d-------- c:\documents and settings\dad\Application Data\Logitech
2008-11-17 17:21 . 2008-11-17 17:21 <DIR> d-------- c:\documents and settings\mark walker\Application Data\Logitech
2008-11-17 17:21 . 2008-11-17 17:21 <DIR> d-------- c:\documents and settings\mark walker\Application Data\Leadertech
2008-11-17 17:21 . 2008-11-17 17:21 130,208 -r------- c:\windows\bwUnin-8.1.1.87-8876480SL.exe
2008-11-17 17:20 . 2008-11-17 17:20 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-11-17 17:20 . 2008-11-17 17:20 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-11-17 17:18 . 2008-11-17 17:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\Logitech
2008-11-17 17:18 . 2008-05-02 02:38 301,656 --a------ c:\windows\system32\BtCoreIf.dll
2008-11-17 17:18 . 2008-05-02 02:39 170,512 --a------ c:\windows\system32\kemutb.dll
2008-11-17 17:18 . 2008-05-02 02:39 145,936 --a------ c:\windows\system32\KemUtil.dll
2008-11-17 17:18 . 2008-05-02 02:40 117,264 --a------ c:\windows\system32\KemWnd.dll
2008-11-17 17:18 . 2008-05-02 02:40 84,496 --a------ c:\windows\system32\KemXML.dll
2008-11-17 17:17 . 2008-11-17 17:21 <DIR> d-------- c:\program files\Logitech
2008-11-17 17:17 . 2008-11-17 17:21 <DIR> d-------- c:\program files\Common Files\Logishrd
2008-11-17 17:17 . 2008-11-17 17:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\LogiShrd
2008-11-14 19:17 . 2008-11-14 19:17 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2008-11-14 10:34 . 2008-11-22 12:42 <DIR> d-------- c:\documents and settings\mark walker\Application Data\Canon
2008-11-14 10:22 . 2008-11-14 10:22 <DIR> d-------- c:\documents and settings\mark walker\Application Data\CD-LabelPrint
2008-11-14 10:04 . 2008-11-14 10:04 <DIR> d-------- c:\program files\Common Files\CANON
2008-11-14 10:01 . 2008-11-14 10:01 <DIR> d--h----- c:\windows\system32\CanonIJ Uninstaller Information
2008-11-14 10:01 . 2008-11-14 10:01 <DIR> d--h----- c:\program files\CanonBJ
2008-11-14 10:01 . 2008-11-14 10:01 <DIR> d--h----- c:\documents and settings\All Users\Application Data\CanonBJ
2008-11-14 10:01 . 2007-03-23 07:30 1,400,832 --a------ c:\windows\system32\CNC610C.DLL
2008-11-14 10:01 . 2007-04-15 20:00 215,040 --a------ c:\windows\system32\CNMLM93.DLL
2008-11-14 10:01 . 2007-04-13 05:46 200,704 --a------ c:\windows\system32\CNC610L.DLL
2008-11-14 10:01 . 2007-03-15 05:12 188,416 --a------ c:\windows\system32\CNC610O.DLL
2008-11-14 10:01 . 2007-03-23 07:29 98,304 --a------ c:\windows\system32\CNC610I.DLL
2008-11-14 09:59 . 2008-11-14 10:18 <DIR> d-------- c:\program files\Canon
2008-11-14 09:56 . 2008-11-14 09:56 <DIR> d-------- c:\program files\ScanSoft
2008-11-14 09:56 . 2008-11-14 09:56 <DIR> d-------- c:\program files\Common Files\ScanSoft Shared
2008-11-14 09:56 . 2008-11-14 09:56 <DIR> d-------- c:\documents and settings\mark walker\Application Data\ScanSoft
2008-11-14 09:56 . 2008-11-14 09:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\ScanSoft
2008-11-14 09:56 . 2008-11-14 09:56 412 --a------ c:\windows\MAXLINK.INI
2008-11-12 19:27 . 2008-11-12 19:27 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-12 17:00 . 2008-10-24 11:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 16:59 . 2008-09-04 17:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-11 20:28 3,343,904 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-11 20:28 27,204 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-11 20:27 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-11 20:26 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-11 20:24 663,584 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-11 20:24 3,348 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-11 19:51 --------- d-----w c:\program files\SUPERAntiSpyware
2008-12-11 18:04 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-11 12:02 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-09 19:15 --------- d-----w c:\documents and settings\mark walker\Application Data\Vso
2008-12-06 14:53 --------- d-----w c:\program files\MixMeister Fusion + Video
2008-12-05 23:38 167 ----a-w c:\documents and settings\mark walker\udownload.dat
2008-12-05 22:29 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-12-05 22:29 47,360 ----a-w c:\documents and settings\mark walker\Application Data\pcouffin.sys
2008-12-05 22:17 --------- d-----w c:\documents and settings\mark walker\Application Data\Azureus
2008-12-05 20:43 --------- d-----w c:\program files\Common Files\Real
2008-12-03 19:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-03 19:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-12-02 21:24 --------- d-----w c:\program files\Sony Ericsson
2008-12-02 21:24 --------- d-----w c:\documents and settings\All Users\Application Data\Sony Ericsson
2008-11-26 20:08 --------- d-----w c:\program files\Common Files\Apple
2008-11-26 20:08 --------- d-----w c:\program files\Bonjour
2008-11-26 19:54 --------- d-----w c:\program files\Safari
2008-11-25 18:14 --------- d-----w c:\program files\eMule
2008-11-25 18:13 --------- d-----w c:\program files\CrossLoop
2008-11-21 17:42 --------- d-----w c:\documents and settings\All Users\Application Data\vsosdk
2008-11-21 17:15 --------- d-----w c:\program files\Azureus
2008-11-17 17:21 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-13 18:51 --------- d-----w c:\program files\Common Files\Adobe
2008-11-10 18:49 --------- d-----w c:\program files\EPSON Print CD
2008-11-08 13:55 81 ----a-w c:\documents and settings\James Ben Sophie\CTX.DAT
2008-11-01 15:33 --------- d-----w c:\documents and settings\dad\Application Data\Malwarebytes
2008-10-31 09:13 --------- d-----w c:\program files\NoteBurner
2008-10-28 13:21 96,976 ----a-w c:\windows\system32\drivers\klin.dat
2008-10-28 13:21 87,855 ----a-w c:\windows\system32\drivers\klick.dat
2008-10-28 12:58 --------- d-----w c:\program files\Kaspersky Lab
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-22 17:04 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 14:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-10-02 10:07 453,152 ----a-w c:\windows\system32\NVUNINST.EXE
2008-09-30 16:43 1,286,152 ------w c:\windows\system32\msxml4.dll
2008-09-19 17:04 410,976 ----a-w c:\windows\system32\deploytk.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-06-11 21:18 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008061120080612\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE" [2008-12-11 1809648]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TalkTalk"="c:\program files\TalkTalk\bin\sprtcmd.exe" [2005-08-15 192512]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NoteBurner"="c:\program files\NoteBurner\VTBurnerGUI.exe" [2007-12-19 4345856]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 c:\windows\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
c:\documents and settings\dad\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-21 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-11 19:51 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys [2008-10-31 13440]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2006-10-10 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2007-02-27 55024]
R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [2003-12-01 53248]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2008-12-01 1527900]
S3 iadusb;MT882;c:\windows\system32\DRIVERS\glauiad.sys []
S3 Navcar;Navman In-car Navigator USB Driver Service;c:\windows\system32\DRIVERS\Navcar.sys [2007-12-16 30329]
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2007-10-16 30464]
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2007-10-16 12672]
S3 STETH;SpeedTouch Ethernet Adapter NT Driver;c:\windows\system32\DRIVERS\steth.sys [2007-10-16 40320]
*Newly Created Service* - SASDIFSV
.
Contents of the 'Scheduled Tasks' folder
2008-11-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {99F7FCCF-C640-4071-AA42-7A9351AEA407} = 62.24.218.222 62.24.218.223
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O16 -: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
c:\windows\Downloaded Program Files\MSIWDev.inf
FF - ProfilePath - c:\documents and settings\mark walker\Application Data\Mozilla\Firefox\Profiles\hc6iem83.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF - plugin: c:\program files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-11 20:25:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\klogon.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(3760)
c:\windows\system32\nview.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-12-11 20:30:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-11 20:29:48
Pre-Run: 323,713,593,344 bytes free
Post-Run: 323,537,367,040 bytes free
WinXP_EN_PRO_BF.EXE
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
296 --- E O F --- 2008-12-11 12:02:55