Here is the log after running ComboFix:
ComboFix 09-08-04.04 - ICIUSER 08/05/2009 14:15.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.657 [GMT -7:00]
Running from: c:\documents and settings\edrie.kelly\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\edrie.kelly\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\vsfocejkdpaswr.sys
c:\windows\system32\vsfoceqptbairr.dll
c:\windows\system32\vsfocequlqbuwq.dll
c:\windows\system32\vsfocesvpqkajr.dat
c:\windows\system32\vsfocevseflovh.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_vsfocepqjxjkcd
((((((((((((((((((((((((( Files Created from 2009-07-05 to 2009-08-05 )))))))))))))))))))))))))))))))
.
2009-08-05 14:48 . 2009-08-05 14:48 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2009-08-03 20:15 . 2009-08-03 20:48 -------- d-----w- C:\Lop SD
2009-08-02 16:54 . 2009-08-02 16:54 -------- d-----w- c:\program files\ERUNT
2009-07-28 04:10 . 2009-08-04 03:44 117760 ----a-w- c:\documents and settings\edrie.kelly\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-28 04:10 . 2009-07-28 04:10 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2009-07-28 04:09 . 2009-07-29 05:46 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-28 04:09 . 2009-07-28 04:09 -------- d-----w- c:\documents and settings\edrie.kelly\Application Data\SUPERAntiSpyware.com
2009-07-28 04:00 . 2008-06-20 00:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-07-28 03:59 . 2009-07-28 03:59 -------- d-----w- c:\program files\Panda Security
2009-07-21 01:48 . 2009-07-21 01:48 -------- d-----w- c:\documents and settings\edrie.kelly\Local Settings\Application Data\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-05 04:43 . 2008-12-25 06:25 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Google Updater
2009-07-31 04:01 . 2007-02-06 16:24 -------- d-----w- c:\documents and settings\edrie.kelly\Application Data\AdobeUM
2009-07-28 04:09 . 2009-01-24 03:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-28 01:31 . 2008-11-22 17:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-13 20:36 . 2008-11-22 17:19 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 20:36 . 2008-11-22 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-29 16:12 . 1980-01-01 00:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 1980-01-01 00:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 1980-01-01 00:00 17408 ------w- c:\windows\system32\corpol.dll
2009-06-16 14:55 . 1980-01-01 00:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 1980-01-01 00:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 22:24 . 2009-05-26 22:38 -------- d-----w- c:\documents and settings\edrie.kelly\Application Data\vlc
2009-06-15 16:11 . 2009-05-12 16:26 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-03 19:27 . 1980-01-01 00:00 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-05-12 16:16 . 2009-05-12 16:09 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2008-01-28 05:02 . 2009-05-26 22:32 4333568 ----a-w- c:\program files\mplayerc09.exe
2006-03-20 22:37 . 2007-10-29 22:51 5689344 ----a-w- c:\program files\mplayerc.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-08-03_13.42.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-05 21:13 . 2009-08-05 21:13 16384 c:\windows\Temp\Perflib_Perfdata_8fc.dat
+ 2009-08-05 21:21 . 2009-08-05 21:21 16384 c:\windows\Temp\Perflib_Perfdata_328.dat
+ 2007-01-23 20:37 . 2009-08-05 21:21 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-01-23 20:37 . 2009-08-03 13:41 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-01-23 20:37 . 2009-08-05 21:21 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-01-23 20:37 . 2009-08-03 13:41 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-01-23 20:37 . 2009-08-05 21:21 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-21 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-03 45056]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-08-17 184320]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-07 761947]
"OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2005-11-30 1843200]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2005-04-11 151552]
"DisplayManager"="c:\program files\Samsung\DisplayManager\DMLoader.exe" [2005-11-16 356352]
"Remote Console"="c:\mpc\system_monitor\agent\winvnc.exe" [2007-01-23 368640]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2005-12-28 569413]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-05-21 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-22 136600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-12-10 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-13 520024]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-08 61952]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-11-14 88203]
c:\documents and settings\edrie.kelly\Start Menu\Programs\Startup\
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-12-1 110592]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2005-11-30 18:23 49152 ----a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3894:UDP"= 3894:UDP:MPC-Notebook-System-Manager-Agent-3894
"3930:TCP"= 3930:TCP:MPC-Notebook-System-Manager-Web-Server-3930
"5800:TCP"= 5800:TCP:MPC-Notebook-System-Manager-Remote-console-5800
"5900:TCP"= 5900:TCP:MPC-Notebook-System-Manager-Remote-console-5900
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/12/2009 9:09 AM 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [7/27/2009 9:00 PM 28544]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 caniodrvr;caniodrvr;c:\mpc\system_monitor\agent\drivers\Caniodrvr.sys [8/24/2005 2:47 PM 4096]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [1/23/2007 1:24 PM 4300]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 1029456]
R2 NMWebSrv;MPC Notebook System Manager Web Server;c:\mpc\jetty\NMWebSrv.exe -s c:\mpc\jetty\NMWebSrv.conf --> c:\mpc\jetty\NMWebSrv.exe -s c:\mpc\jetty\NMWebSrv.conf [?]
R2 SMAgent;MPC Notebook System Manager Agent;c:\mpc\system_monitor\agent\smaagent.exe NML 0 --> c:\mpc\system_monitor\agent\smaagent.exe NML 0 [?]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [10/21/2005 4:19 AM 36352]
S2 gupdate1c96659d3874570;Google Update Service (gupdate1c96659d3874570);c:\program files\Google\Update\GoogleUpdate.exe [12/24/2008 11:27 PM 133104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\docume~1\EDRIE~1.KEL\APPLIC~1\Mozilla\Firefox\Profiles\qws8wp0z.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - plugin: c:\documents and settings\edrie.kelly\Application Data\Mozilla\Firefox\Profiles\qws8wp0z.default\extensions\
[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-05 14:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(932)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\Softex\OmniPass\opxpgina.dll
- - - - - - - > 'explorer.exe'(2148)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\progra~1\SYMANT~1\SYMANT~1\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\mpc\jetty\NMWebSrv.exe
c:\progra~1\SYMANT~1\SYMANT~1\Rtvscan.exe
c:\program files\Softex\OmniPass\OmniServ.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\mpc\system_monitor\agent\smaagent.exe
c:\mpc\java\bin\java.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\ati2evxx.exe
c:\program files\SAMSUNG\DisplayManager\DisplayManager.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\SAMSUNG\MagicKBD\MagicKBD.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\Macromed\Flash\FlashUtil9e.exe
.
**************************************************************************
.
Completion time: 2009-08-05 14:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-05 21:37
ComboFix2.txt 2009-08-03 13:48
Pre-Run: 19,948,314,624 bytes free
Post-Run: 20,034,772,992 bytes free
194 --- E O F --- 2009-07-28 17:35