Here is my combofix scan results.
ComboFix 09-04-23.02 - Main 22/04/2009 17:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.494.176 [GMT -4:00]
Running from: c:\documents and settings\Main\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\_000178_.tmp.dll
c:\windows\system32\_000192_.tmp.dll
c:\windows\system32\_000195_.tmp.dll
c:\windows\system32\_000198_.tmp.dll
c:\windows\system32\_000205_.tmp.dll
c:\windows\system32\_000216_.tmp.dll
c:\windows\system32\_000218_.tmp.dll
c:\windows\system32\_005159_.tmp.dll
c:\windows\system32\_005160_.tmp.dll
c:\windows\system32\_005161_.tmp.dll
c:\windows\system32\_005162_.tmp.dll
c:\windows\system32\_005169_.tmp.dll
c:\windows\system32\_005170_.tmp.dll
c:\windows\system32\_005171_.tmp.dll
c:\windows\system32\_005172_.tmp.dll
c:\windows\system32\_005174_.tmp.dll
c:\windows\system32\_005175_.tmp.dll
c:\windows\system32\_005178_.tmp.dll
c:\windows\system32\_005179_.tmp.dll
c:\windows\system32\_005181_.tmp.dll
c:\windows\system32\_005182_.tmp.dll
c:\windows\system32\_005183_.tmp.dll
c:\windows\system32\_005185_.tmp.dll
c:\windows\system32\_005187_.tmp.dll
c:\windows\system32\_005188_.tmp.dll
c:\windows\system32\_005189_.tmp.dll
c:\windows\system32\_005190_.tmp.dll
c:\windows\system32\_005191_.tmp.dll
c:\windows\system32\_005192_.tmp.dll
c:\windows\system32\_005193_.tmp.dll
c:\windows\system32\_005194_.tmp.dll
c:\windows\system32\_005195_.tmp.dll
c:\windows\system32\_005196_.tmp.dll
c:\windows\system32\_005197_.tmp.dll
c:\windows\system32\_005198_.tmp.dll
c:\windows\system32\_005199_.tmp.dll
c:\windows\system32\_005200_.tmp.dll
c:\windows\system32\_005201_.tmp.dll
c:\windows\system32\_005202_.tmp.dll
c:\windows\system32\_005203_.tmp.dll
c:\windows\system32\_005204_.tmp.dll
c:\windows\system32\_005205_.tmp.dll
c:\windows\system32\_005206_.tmp.dll
c:\windows\system32\_005208_.tmp.dll
c:\windows\system32\_005209_.tmp.dll
c:\windows\system32\_005210_.tmp.dll
c:\windows\system32\_005211_.tmp.dll
c:\windows\system32\_005212_.tmp.dll
c:\windows\system32\_005214_.tmp.dll
c:\windows\system32\_005215_.tmp.dll
c:\windows\system32\_005216_.tmp.dll
c:\windows\system32\_005217_.tmp.dll
c:\windows\system32\_005219_.tmp.dll
c:\windows\system32\_005220_.tmp.dll
c:\windows\system32\_005221_.tmp.dll
c:\windows\system32\_005222_.tmp.dll
c:\windows\system32\_005225_.tmp.dll
c:\windows\system32\_005226_.tmp.dll
c:\windows\system32\_005228_.tmp.dll
c:\windows\system32\_005229_.tmp.dll
c:\windows\system32\_005230_.tmp.dll
c:\windows\system32\_005231_.tmp.dll
c:\windows\system32\_005232_.tmp.dll
c:\windows\system32\_005233_.tmp.dll
c:\windows\system32\_005234_.tmp.dll
c:\windows\system32\_005235_.tmp.dll
c:\windows\system32\_005236_.tmp.dll
c:\windows\system32\_005237_.tmp.dll
c:\windows\system32\_005239_.tmp.dll
c:\windows\system32\_005240_.tmp.dll
c:\windows\system32\_005241_.tmp.dll
c:\windows\system32\_005242_.tmp.dll
c:\windows\system32\_005243_.tmp.dll
c:\windows\system32\_005246_.tmp.dll
c:\windows\system32\_005247_.tmp.dll
c:\windows\system32\_005248_.tmp.dll
c:\windows\system32\_005249_.tmp.dll
c:\windows\system32\_005250_.tmp.dll
c:\windows\system32\_005251_.tmp.dll
c:\windows\system32\_005252_.tmp.dll
c:\windows\system32\_005254_.tmp.dll
c:\windows\system32\_005255_.tmp.dll
c:\windows\system32\_005256_.tmp.dll
c:\windows\system32\_005257_.tmp.dll
c:\windows\system32\_005258_.tmp.dll
c:\windows\system32\_005259_.tmp.dll
c:\windows\system32\_005260_.tmp.dll
c:\windows\system32\_005261_.tmp.dll
c:\windows\system32\_005263_.tmp.dll
c:\windows\system32\_005264_.tmp.dll
c:\windows\system32\_005265_.tmp.dll
c:\windows\system32\_005266_.tmp.dll
c:\windows\system32\_005269_.tmp.dll
c:\windows\system32\_005270_.tmp.dll
c:\windows\system32\_005271_.tmp.dll
c:\windows\system32\_005274_.tmp.dll
c:\windows\system32\_005275_.tmp.dll
c:\windows\system32\_005277_.tmp.dll
c:\windows\system32\_005280_.tmp.dll
c:\windows\system32\_005282_.tmp.dll
c:\windows\system32\_005283_.tmp.dll
c:\windows\system32\_005284_.tmp.dll
c:\windows\system32\_005285_.tmp.dll
c:\windows\system32\_005288_.tmp.dll
c:\windows\system32\_005289_.tmp.dll
c:\windows\system32\_005290_.tmp.dll
c:\windows\system32\_005291_.tmp.dll
c:\windows\system32\_005292_.tmp.dll
c:\windows\system32\_005297_.tmp.dll
c:\windows\system32\_005299_.tmp.dll
c:\windows\system32\_005300_.tmp.dll
c:\windows\system32\apurabaf.ini
c:\windows\system32\efapiteb.ini
c:\windows\system32\erabizuv.ini
c:\windows\system32\imuwabid.ini
c:\windows\system32\isusijim.ini
c:\windows\system32\uyeberiv.ini
C:\xcrashdump.dat
----- BITS: Possible infected sites -----
hxxp://82.98.235.205
.
((((((((((((((((((((((((( Files Created from 2009-03-22 to 2009-04-22 )))))))))))))))))))))))))))))))
.
2009-04-22 02:33 . 2009-04-22 02:33 -------- d-----w c:\documents and settings\Main\Application Data\Malwarebytes
2009-04-22 02:33 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-22 02:33 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-22 02:33 . 2009-04-22 02:33 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-22 02:33 . 2009-04-22 02:33 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-22 01:52 . 2009-04-22 01:52 -------- d-----w c:\program files\Trend Micro
2009-04-22 01:24 . 2009-04-22 01:24 -------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2009-04-22 01:09 . 2009-04-21 23:32 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-21 23:18 . 2009-04-21 23:32 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-21 23:14 . 2009-04-21 23:14 -------- dc-h--w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-21 23:10 . 2009-04-21 23:10 -------- d-----w c:\program files\Lavasoft
2009-04-21 23:10 . 2009-04-21 23:10 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-21 22:22 . 2009-04-22 07:52 -------- d--h--w C:\$AVG8.VAULT$
2009-04-21 22:17 . 2009-04-21 22:17 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-21 22:17 . 2009-04-21 22:17 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-21 22:17 . 2009-04-21 22:17 325640 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-21 22:16 . 2009-04-22 12:33 -------- d-----w c:\windows\system32\drivers\Avg
2009-04-21 22:16 . 2009-04-22 01:42 -------- d-----w c:\documents and settings\Main\Application Data\AVGTOOLBAR
2009-04-21 22:16 . 2009-04-21 22:16 -------- d-----w c:\program files\AVG
2009-04-21 22:16 . 2009-04-21 23:26 -------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-04-21 21:34 . 2009-04-21 23:09 -------- d-----w c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-04-21 21:34 . 2009-04-21 23:09 -------- d-----w c:\program files\SDHelper (Spybot - Search & Destroy)
2009-04-21 21:34 . 2009-04-21 21:34 -------- d-----w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-04-21 21:34 . 2009-04-21 21:34 -------- d-----w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-04-21 20:46 . 2009-04-21 20:46 -------- d-----w c:\windows\SxsCaPendDel
2009-04-21 12:33 . 2004-08-04 09:00 769536 ----a-w c:\windows\system32\dllcache\sprb0410.dll
2009-04-21 12:32 . 2005-01-11 00:00 128512 ----a-w c:\windows\system32\dllcache\dhtmled.ocx
2009-04-21 12:31 . 2006-09-14 08:31 151040 ----a-w c:\windows\system32\dllcache\cdfview.dll
2009-04-21 12:30 . 2004-08-04 09:00 96768 ----a-w c:\windows\system32\dllcache\psbase.dll
2009-04-21 12:29 . 2006-06-14 09:00 82944 ----a-w c:\windows\system32\drivers\wdmaud.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-22 21:56 . 2009-04-22 08:48 892 ----a-w C:\aaw7boot.log
2009-04-22 10:52 . 2007-09-26 12:46 268 ---ha-w C:\sqmdata01.sqm
2009-04-22 10:52 . 2007-09-26 12:46 244 ---ha-w C:\sqmnoopt01.sqm
2009-04-22 09:57 . 2007-09-26 10:29 268 ---ha-w C:\sqmdata00.sqm
2009-04-22 09:57 . 2007-09-26 10:29 244 ---ha-w C:\sqmnoopt00.sqm
2009-04-22 08:47 . 2008-11-27 23:01 -------- d-----w c:\documents and settings\All Users\Application Data\Part Long Boob Idle
2009-04-22 08:44 . 2007-10-17 02:11 268 ---ha-w C:\sqmdata19.sqm
2009-04-22 08:44 . 2007-10-17 02:11 244 ---ha-w C:\sqmnoopt19.sqm
2009-04-22 01:27 . 2006-12-14 05:42 -------- d-----w c:\program files\SpywareBlaster
2009-04-22 00:00 . 2008-11-27 23:00 -------- d-----w c:\documents and settings\Main\Application Data\Greymemo
2009-04-21 23:21 . 2007-10-16 10:46 268 ---ha-w C:\sqmdata18.sqm
2009-04-21 23:21 . 2007-10-16 10:46 244 ---ha-w C:\sqmnoopt18.sqm
2009-04-21 23:16 . 2006-12-14 05:37 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-21 22:54 . 2008-05-06 20:16 -------- d-----w c:\program files\RegCure
2009-04-21 21:01 . 2005-03-21 12:55 71384 ----a-w c:\documents and settings\Main\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-21 19:47 . 2007-10-16 01:51 268 ---ha-w C:\sqmdata17.sqm
2009-04-21 19:47 . 2007-10-16 01:51 244 ---ha-w C:\sqmnoopt17.sqm
2009-04-21 19:44 . 2006-10-04 20:49 -------- d-----w c:\documents and settings\Administrator\Application Data\Lavasoft
2009-04-21 19:36 . 2007-10-15 22:56 268 ---ha-w C:\sqmdata16.sqm
2009-04-21 19:36 . 2007-10-15 22:56 244 ---ha-w C:\sqmnoopt16.sqm
2009-04-21 19:10 . 2007-10-11 13:49 268 ---ha-w C:\sqmdata15.sqm
2009-04-21 19:10 . 2007-10-11 13:49 244 ---ha-w C:\sqmnoopt15.sqm
2009-04-21 18:31 . 1980-01-01 04:00 250032 --sha-r C:\ntldr
2009-04-21 11:01 . 2008-11-27 22:59 -------- d-----w c:\program files\Windows Live
2009-04-18 20:09 . 2007-10-11 11:07 268 ---ha-w C:\sqmdata14.sqm
2009-04-18 20:09 . 2007-10-11 11:07 244 ---ha-w C:\sqmnoopt14.sqm
2009-04-17 16:36 . 2007-10-10 13:02 268 ---ha-w C:\sqmdata13.sqm
2009-04-17 16:36 . 2007-10-10 13:02 244 ---ha-w C:\sqmnoopt13.sqm
2009-04-17 12:43 . 2007-10-10 07:07 268 ---ha-w C:\sqmdata12.sqm
2009-04-17 12:43 . 2007-10-10 07:07 244 ---ha-w C:\sqmnoopt12.sqm
2009-04-17 12:19 . 2007-10-09 20:10 268 ---ha-w C:\sqmdata11.sqm
2009-04-17 12:19 . 2007-10-09 20:10 244 ---ha-w C:\sqmnoopt11.sqm
2009-04-15 12:50 . 2007-10-05 17:31 268 ---ha-w C:\sqmdata10.sqm
2009-04-15 12:50 . 2007-10-05 17:31 244 ---ha-w C:\sqmnoopt10.sqm
2009-03-27 11:33 . 2007-10-05 14:09 268 ---ha-w C:\sqmdata09.sqm
2009-03-27 11:33 . 2007-10-05 14:09 244 ---ha-w C:\sqmnoopt09.sqm
2009-03-26 12:18 . 2007-10-05 12:11 268 ---ha-w C:\sqmdata08.sqm
2009-03-26 12:18 . 2007-10-05 12:11 244 ---ha-w C:\sqmnoopt08.sqm
2009-03-21 14:18 . 2009-04-21 12:30 986112 ----a-w c:\windows\system32\dllcache\kernel32.dll
2009-03-13 12:40 . 2007-10-04 19:35 268 ---ha-w C:\sqmdata07.sqm
2009-03-13 12:40 . 2007-10-04 19:35 244 ---ha-w C:\sqmnoopt07.sqm
2009-03-06 14:44 . 2009-04-21 12:31 283648 ----a-w c:\windows\system32\dllcache\pdh.dll
2009-03-06 14:44 . 1980-01-01 04:00 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 1980-01-01 04:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-03 00:18 . 1980-01-01 04:00 826368 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-02-28 04:54 . 2004-08-30 15:45 636072 ----a-w c:\windows\system32\dllcache\iexplore.exe
2009-02-27 12:47 . 2007-10-04 18:11 268 ---ha-w C:\sqmdata06.sqm
2009-02-27 12:47 . 2007-10-04 18:11 244 ---ha-w C:\sqmnoopt06.sqm
2009-02-25 12:52 . 2007-10-02 18:41 268 ---ha-w C:\sqmdata05.sqm
2009-02-25 12:52 . 2007-10-02 18:41 244 ---ha-w C:\sqmnoopt05.sqm
2009-02-25 11:35 . 2009-02-25 11:35 -------- d-----w c:\program files\Greymemo
2009-02-20 10:20 . 2007-05-09 01:52 13824 ------w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 1980-01-01 04:00 70656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 1980-01-01 04:00 161792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-02-09 12:54 . 2007-09-29 13:26 268 ---ha-w C:\sqmdata04.sqm
2009-02-09 12:54 . 2007-09-29 13:26 244 ---ha-w C:\sqmnoopt04.sqm
2009-02-09 11:24 . 2007-09-27 18:15 268 ---ha-w C:\sqmdata03.sqm
2009-02-09 11:24 . 2007-09-27 18:15 244 ---ha-w C:\sqmnoopt03.sqm
2009-02-09 10:20 . 2009-04-21 12:30 399360 ----a-w c:\windows\system32\dllcache\rpcss.dll
2009-02-09 10:20 . 2009-04-21 12:30 723456 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:20 . 2009-04-21 12:30 723456 ----a-w c:\windows\system32\dllcache\lsasrv.dll
2009-02-09 10:20 . 1980-01-01 04:00 399360 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:20 . 2009-04-21 12:32 473088 ----a-w c:\windows\system32\dllcache\fastprox.dll
2009-02-09 10:20 . 2009-04-21 12:30 616960 ----a-w c:\windows\system32\dllcache\advapi32.dll
2009-02-09 10:20 . 2009-04-21 12:30 616960 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:20 . 2009-04-21 12:30 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:20 . 2009-04-21 12:30 714752 ----a-w c:\windows\system32\dllcache\ntdll.dll
2009-02-09 10:20 . 2009-04-21 12:32 453120 ----a-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-02-09 10:19 . 2009-04-21 12:30 1846272 ----a-w c:\windows\system32\win32k.sys
2009-02-09 10:19 . 2009-04-21 12:30 1846272 ----a-w c:\windows\system32\dllcache\win32k.sys
2009-02-06 17:24 . 2009-04-21 12:29 2180480 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 17:24 . 2009-04-21 12:29 2180480 ----a-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 17:22 . 2009-04-21 12:32 2136064 ----a-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 17:14 . 2009-04-21 12:30 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 17:14 . 2009-04-21 12:30 110592 ----a-w c:\windows\system32\dllcache\services.exe
2009-02-06 16:54 . 1980-01-01 04:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 16:54 . 1980-01-01 04:00 35328 ----a-w c:\windows\system32\dllcache\sc.exe
2009-02-06 16:49 . 2009-04-21 12:32 2015744 ----a-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-06 16:49 . 2009-04-21 12:29 2057728 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 16:49 . 2009-04-21 12:29 2057728 ----a-w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 16:39 . 2009-04-21 12:32 227840 ----a-w c:\windows\system32\dllcache\wmiprvse.exe
2009-02-03 20:08 . 2009-04-21 12:30 55808 ----a-w c:\windows\system32\dllcache\secur32.dll
2009-02-03 20:08 . 1980-01-01 04:00 55808 ----a-w c:\windows\system32\secur32.dll
2009-01-30 12:59 . 2007-09-26 17:57 268 ---ha-w C:\sqmdata02.sqm
2009-01-30 12:59 . 2007-09-26 17:57 244 ---ha-w C:\sqmnoopt02.sqm
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"WeatherEye"="c:\program files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2009-01-16 4519832]
"bleh chin"="c:\docume~1\Main\APPLIC~1\Greymemo\BIRDINTERMORE.exe" [2009-02-25 614400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-20 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-20 532480]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-11 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-11 118784]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2004-07-14 151552]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2004-09-01 2876416]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2004-07-30 319488]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-25 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-21 1932568]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-21 516440]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-04 110592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2006-10-12 245760]
Kodak EasyShare software.lnk - c:\documents and settings\Main\My Documents\My Pictures\Kodak EasyShare software\bin\EasyShare.exe [2004-8-11 757760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-21 22:17 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= c:\windows\system32\zapovine.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0smrgdf .\Appdata\Data\\
0lsdelete
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Documents and Settings\\Main\\Application Data\\Greymemo\\Load Bows Bias.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltw2k.sys [2005-02-16 10272]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-21 64160]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-21 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-21 108552]
S1 SMBHC;Microsoft SM Bus Host Controller Driver;c:\windows\system32\DRIVERS\SMBHC.sys [2001-08-17 6784]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-21 298264]
S2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2004-07-19 4096]
S2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2004-08-15 78208]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-21 953168]
S2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2004-06-01 4054]
S3 SMBBATT;Microsoft Smart Battery Driver;c:\windows\system32\DRIVERS\SMBBATT.sys [2004-08-04 16128]
S3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\DRIVERS\urvpndrv.sys [2005-02-16 27968]
--- Other Services/Drivers In Memory ---
*Deregistered* - AFD
*Deregistered* - agp440
*Deregistered* - ALG
*Deregistered* - anbmService
*Deregistered* - Arp1394
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avg8wd
*Deregistered* - AvgLdx86
*Deregistered* - AvgMfx86
*Deregistered* - AvgTdiX
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - BthServ
*Deregistered* - Cdfs
*Deregistered* - Compbatt
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - EpmPsd
*Deregistered* - EpmShd
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fax
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - ImapiService
*Deregistered* - IntelIde
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - irda
*Deregistered* - Irmon
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - Lavasoft Ad-Aware Service
*Deregistered* - Lbd
*Deregistered* - LexBceS
*Deregistered* - LmHosts
*Deregistered* - MASPINT
*Deregistered* - MDM
*Deregistered* - mdmxsdk
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - MSIServer
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NWCWorkstation
*Deregistered* - NwlnkIpx
*Deregistered* - NwlnkNb
*Deregistered* - NwlnkSpx
*Deregistered* - NWRDR
*Deregistered* - osanbm
*Deregistered* - PartMgr
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasirda
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Sophos AutoUpdate Service
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - Symantec Core LC
*Deregistered* - symlcbrd
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - urvpndrv
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d0d3a4f1-dd46-11db-adb2-000e35af895f}]
\Shell\AutoRun\command - F:\LaunchU3.exe
.
Contents of the 'Scheduled Tasks' folder
2009-04-22 c:\windows\Tasks\A573010E9184BF1A.job
- c:\docume~1\main\applic~1\greymemo\Load Bows Bias.exe [2008-11-27 11:36]
2009-04-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 23:31]
2009-04-22 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
2008-05-06 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Skype - c:\program files\Skype\Phone\Skype.exe
Notify-dimsntfy - (no file)
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-22 18:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1544)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\acer\eManager\anbmServ.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\rundll32.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\palmOne\HOTSYNC.EXE
c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-04-22 18:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-22 22:11
Pre-Run: 7,899,987,968 bytes free
Post-Run: 7,876,763,648 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect
525 --- E O F --- 2009-04-21 19:09