It is no problem and here is the combofix log
ComboFix 10-02-27.04 - Administrator 02/27/2010 15:22:17.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1685 [GMT -8:00]
Running from: c:\documents and settings\Administrator\Desktop\Combo-Fix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.
2010-02-23 23:30 . 2010-02-11 18:42 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-23 23:30 . 2010-02-11 18:38 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-23 23:30 . 2010-02-11 18:39 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-23 23:30 . 2010-02-11 18:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-23 23:30 . 2010-02-11 18:38 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-23 23:30 . 2010-02-11 18:38 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-23 23:30 . 2010-02-11 18:38 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-23 23:30 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-23 23:30 . 2010-02-11 18:53 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-23 23:30 . 2010-02-23 23:30 -------- d-----w- c:\program files\Alwil Software
2010-02-23 23:30 . 2010-02-23 23:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-02-23 23:12 . 2010-02-23 23:12 -------- d-----w- C:\!KillBox
2010-02-23 23:08 . 2010-02-23 23:08 -------- d-----w- c:\program files\TrendMicro
2010-02-23 21:23 . 2010-02-26 00:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-23 21:23 . 2010-02-23 21:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-23 21:07 . 2009-08-13 15:16 512000 -c----w- c:\windows\system32\dllcache\jscript.dll
2010-02-23 04:52 . 2010-02-23 04:52 -------- d-----w- c:\windows\system32\xircom
2010-02-23 04:52 . 2010-02-23 04:52 -------- d-----w- c:\windows\system32\wbem\snmp
2010-02-23 04:52 . 2010-02-23 04:52 -------- d-----w- c:\program files\microsoft frontpage
2010-02-23 04:34 . 2010-02-23 04:34 -------- d-----w- c:\windows\system32\scripting
2010-02-23 04:34 . 2010-02-23 04:34 -------- d-----w- c:\windows\system32\en
2010-02-23 04:34 . 2010-02-23 04:34 -------- d-----w- c:\windows\system32\bits
2010-02-23 04:34 . 2010-02-23 04:34 -------- d-----w- c:\windows\l2schemas
2010-02-23 04:32 . 2010-02-23 04:32 -------- d-----w- c:\windows\ServicePackFiles
2010-02-23 04:09 . 2010-02-23 04:09 -------- d-----w- c:\windows\system32\XPSViewer
2010-02-23 04:09 . 2010-02-23 04:09 -------- d-----w- c:\program files\MSBuild
2010-02-23 04:09 . 2010-02-23 04:09 -------- d-----w- c:\program files\Reference Assemblies
2010-02-23 04:08 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-02-23 04:07 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-02-23 04:07 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-02-23 04:07 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-02-23 04:07 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-02-23 04:07 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-02-23 04:07 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-02-23 04:07 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-02-23 04:07 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-02-23 04:07 . 2010-02-23 04:08 -------- d-----w- C:\00f75dd1c68282ddef
2010-02-23 04:02 . 2010-02-23 04:02 -------- d-----w- c:\program files\MSXML 6.0
2010-02-22 03:30 . 2010-02-22 03:30 -------- d-----w- c:\program files\NCsoft
2010-02-22 03:21 . 2005-05-26 23:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2010-02-22 03:21 . 2010-02-22 03:21 -------- d-----w- c:\windows\Logs
2010-02-21 06:21 . 2009-05-18 22:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-21 06:21 . 2008-04-17 21:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-02-21 05:55 . 2010-02-25 07:05 -------- d-----w- C:\Downloads
2010-02-21 05:55 . 2010-02-25 07:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitComet
2010-02-21 05:54 . 2010-02-21 05:54 1036288 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9w5m5dpe.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
2010-02-21 05:54 . 2010-02-21 05:55 -------- d-----w- c:\program files\BitComet
2010-02-21 05:38 . 2010-02-21 05:38 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-02-19 21:34 . 2010-02-19 21:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-02-19 21:34 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-19 21:34 . 2010-02-19 21:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-19 21:34 . 2010-02-19 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-19 21:34 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-19 21:30 . 2010-02-19 21:30 -------- d-----w- c:\program files\CCleaner
2010-02-19 21:15 . 2010-02-19 21:15 -------- d-----w- c:\program files\MSXML 4.0
2010-02-19 07:13 . 2007-08-11 04:46 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-02-19 06:21 . 2010-02-19 06:21 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-02-19 05:54 . 2010-02-19 05:54 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2010-02-19 05:43 . 2010-02-19 05:43 -------- d-----w- c:\windows\system32\wbem\Repository
2010-02-19 04:11 . 2008-04-14 00:11 377984 ------w- c:\windows\system32\ati2dvaa.dll
2010-02-19 04:05 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-02-19 04:05 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-02-19 04:05 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-02-19 04:05 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-02-19 04:05 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-19 04:05 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-02-19 04:03 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-02-19 04:03 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-02-19 04:03 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-02-19 04:03 . 2009-07-31 04:35 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2010-02-19 04:02 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-02-19 04:02 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-02-19 04:02 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-02-18 21:14 . 2010-02-19 03:21 -------- d-----w- c:\windows\LastGood(2)
2010-02-18 06:52 . 2010-02-18 06:52 -------- d-----w- c:\windows\system32\LogFiles
2010-02-18 00:29 . 2010-02-18 00:29 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2010-02-17 22:35 . 2010-02-19 03:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer
2010-02-17 22:34 . 2010-02-21 06:21 -------- d-----w- c:\program files\iPod
2010-02-17 22:34 . 2010-02-21 06:21 -------- d-----w- c:\program files\iTunes
2010-02-17 22:34 . 2010-02-17 22:35 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-02-17 22:34 . 2010-02-17 22:34 -------- d-----w- c:\program files\Bonjour
2010-02-17 22:33 . 2010-02-17 22:34 -------- d-----w- c:\program files\QuickTime
2010-02-17 22:33 . 2010-02-17 22:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-02-17 22:33 . 2010-02-17 22:33 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple
2010-02-17 22:33 . 2010-02-17 22:33 -------- d-----w- c:\program files\Apple Software Update
2010-02-17 22:33 . 2010-02-21 06:21 -------- dc----w- c:\windows\system32\DRVSTORE
2010-02-17 22:32 . 2010-02-17 22:32 -------- d-----w- c:\program files\Common Files\Apple
2010-02-17 22:32 . 2010-02-17 22:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-02-17 22:32 . 2010-02-17 22:36 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2010-02-17 22:15 . 2010-02-17 22:24 -------- d---a-w- C:\Music
2010-02-17 07:14 . 2010-02-27 23:20 -------- d-----w- c:\program files\PeerBlock
2010-02-17 07:12 . 2010-02-17 07:12 0 ----a-w- c:\windows\nsreg.dat
2010-02-17 07:12 . 2010-02-17 07:12 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-02-17 07:09 . 2010-02-25 06:14 36968 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-17 07:09 . 2010-02-17 07:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\ATI
2010-02-17 07:09 . 2010-02-17 07:09 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ATI
2010-02-17 07:09 . 2010-02-17 07:09 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2010-02-17 07:09 . 2010-02-20 03:28 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
2010-02-17 07:07 . 2007-06-29 02:16 95488 ----a-r- c:\windows\system32\drivers\Rtnicxp.sys
2010-02-17 07:07 . 2010-02-17 07:07 -------- d-----w- c:\windows\OPTIONS
2010-02-17 07:07 . 2010-02-17 07:07 -------- d-----w- c:\program files\Trendnet
2010-02-17 07:06 . 2010-02-17 07:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\InstallShield
2010-02-17 07:05 . 2010-02-17 07:05 -------- d-----w- c:\program files\Common Files\ATI Technologies
2010-02-17 07:02 . 2010-02-17 07:02 -------- d-----w- c:\windows\system32\URTTemp
2010-02-17 07:02 . 2006-03-17 23:37 520192 ------w- c:\windows\system32\ati2sgag.exe
2010-02-17 07:02 . 2006-03-22 03:42 307200 ----a-r- c:\windows\system32\atiiiexx.dll
2010-02-17 07:02 . 2006-02-13 20:29 121995 ----a-r- c:\windows\system32\atiicdxx.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 00:24 . 2004-08-03 22:59 96512 ------w- c:\windows\system32\drivers\atapi.sys
2010-02-24 05:44 . 2010-02-24 05:44 -------- d-----w- c:\program files\ERUNT
2010-02-24 00:40 . 2010-02-24 00:40 -------- d-----w- c:\program files\Trend Micro
2010-02-23 04:37 . 2010-02-17 06:47 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-22 03:30 . 2010-02-17 06:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-17 07:04 . 2010-02-17 06:59 -------- d-----w- c:\program files\ATI Technologies
2010-02-17 06:58 . 2010-02-17 06:56 -------- d-----w- c:\program files\Common Files\InstallShield
2010-02-17 06:56 . 2010-02-17 06:56 -------- d-----w- c:\documents and settings\Administrator\Application Data\VCOM
2010-02-17 06:56 . 2010-02-17 06:56 -------- d-----w- c:\program files\VCOM
2010-02-17 06:56 . 2010-02-17 06:53 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-17 06:56 . 2010-02-17 06:56 -------- d-----w- c:\program files\CyberLink
2010-02-17 06:56 . 2010-02-17 06:56 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-17 06:55 . 2010-02-17 06:55 8854 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{DA5E6A2D-DEAA-4152-A43A-FDBDE29AA724}\Uninstall_DAMN_NFO_V_DA5E6A2DDEAA4152A43AFDBDE29AA724.exe
2010-02-17 06:55 . 2010-02-17 06:55 49152 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{DA5E6A2D-DEAA-4152-A43A-FDBDE29AA724}\DAMN_NFO_Viewer.exe_DA5E6A2DDEAA4152A43AFDBDE29AA724.exe
2010-02-17 06:55 . 2010-02-17 06:55 49152 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{DA5E6A2D-DEAA-4152-A43A-FDBDE29AA724}\ARPPRODUCTICON.exe
2010-02-17 06:55 . 2010-02-17 06:55 -------- d-----w- c:\program files\[bleep] NFO Viewer 2.10.0031 RC3
2010-02-17 06:55 . 2010-02-17 06:55 -------- d-----w- c:\program files\FlashGet
2010-02-17 06:55 . 2010-02-17 06:55 -------- d-----w- c:\program files\Google
2010-02-17 06:54 . 2010-02-17 06:54 -------- d-----w- c:\program files\Common Files\L&H
2010-02-17 06:54 . 2010-02-17 06:54 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-02-17 06:53 . 2010-02-17 06:53 -------- d-----w- c:\program files\Microsoft Works
2010-02-17 06:53 . 2010-02-17 06:53 -------- d-----w- c:\program files\TuneUp Utilities 2006
2010-02-17 06:53 . 2010-02-17 06:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\TuneUp Software
2010-02-17 06:53 . 2010-02-17 06:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\Ahead
2010-02-17 06:52 . 2010-02-17 06:52 29926 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{4781569D-5404-1F26-4B2B-6DF444445167}\ARPPRODUCTICON.exe
2010-02-17 06:51 . 2010-02-17 06:51 -------- d-----w- c:\program files\Common Files\Ahead
2010-02-17 06:51 . 2010-02-17 06:51 -------- d-----w- c:\program files\Nero
2010-02-17 06:44 . 2010-02-17 06:44 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-23 03:51 . 2010-01-23 03:51 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2009-12-31 16:50 . 2005-09-02 19:39 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:21 . 2005-07-03 02:09 667136 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:20 . 2004-08-04 00:56 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-16 18:43 . 2010-02-17 06:43 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-04 00:56 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 18:22 . 2005-01-19 04:51 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.
------- Sigcheck -------
[-] 2010-02-27 . 1494C60EE680E8E79A2D3E25D5FE50FF . 96512 . . [5.1.2600.2180] . . c:\windows\system32\drivers\atapi.sys
[7] 2010-02-21 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[7] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"PeerBlock"="c:\program files\PeerBlock\peerblock.exe" [2010-02-09 1700976]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-03 45056]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Reboot.exe [2004-9-30 334336]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21945:TCP"= 21945:TCP:BitComet 21945 TCP
"21945:UDP"= 21945:UDP:BitComet 21945 UDP
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/23/2010 3:30 PM 162512]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/23/2010 3:30 PM 19024]
.
Contents of the 'Scheduled Tasks' folder
2010-02-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Download All by FlashGet - c:\progra~1\FlashGet\jc_all.htm
IE: Download using FlashGet - c:\progra~1\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9w5m5dpe.default\
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9w5m5dpe.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-27 15:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A316A9A]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba8ecf28
\Driver\ACPI -> ACPI.sys @ 0xba77fcb8
\Driver\atapi -> atapi.sys @ 0xba7117b4
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xba61ebd4
PacketIndicateHandler -> NDIS.sys @ 0xba60ca0d
SendHandler -> NDIS.sys @ 0xba620b40
user & kernel MBR OK
copy of MBR has been found in sector 0x012A14C00
malicious code @ sector 0x012A14C03 !
PE file found in sector at 0x012A14C19 !
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(732)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-02-27 15:31:15
ComboFix-quarantined-files.txt 2010-02-27 23:31
Pre-Run: 99,246,284,800 bytes free
Post-Run: 99,234,885,632 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 8907967D8257BEB894CE37C54745CE5F