Ok i ran ComboFix. and here is the log:
ComboFix 08-05-01.3 - Owner 2008-05-07 14:35:51.1 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\hosts
C:\WINDOWS\system32\CMMGR32.EXE
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\Config.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\BrowserSearch\BrowserSearch.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\BrowserSearch\BrowserSearch.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Configurator\Configurator.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Configurator\Configurator.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\ErrorSearch\ErrorSearchOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\ErrorSearch\ErrorSearchOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Free_Credit_Score\Free_Credit_ScoreOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Free_Credit_Score\Free_Credit_ScoreOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Free_Music\Free_MusicOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Free_Music\Free_MusicOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Layouts\ToolbarLayout.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Layouts\ToolbarLayout.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Manager\ManagerOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Manager\ManagerOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Reference\ReferenceOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Reference\ReferenceOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\RelatedSearch\RelatedSearchOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\RelatedSearch\RelatedSearchOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Ringtones\RingtonesOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Ringtones\RingtonesOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Screensavers\ScreensaversOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Screensavers\ScreensaversOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Toolbar\TBProductsOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Toolbar\TBProductsOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\ToolbarLogo\ToolbarLogoOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\ToolbarSearch\ToolbarSearchOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\TravelSearch\TravelSearchOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\TravelSearch\TravelSearchOptions.xml.backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Weather\AlertArchive.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Weather\WeatherOptions.xml
C:\WINDOWS\system32\config\systemprofile\Application Data\Starware316\Weather\WeatherOptions.xml.backup
C:\WINDOWS\system32\dunybokh.ini
C:\WINDOWS\system32\enyvdvpl.ini
C:\WINDOWS\system32\iowktyuf.ini
C:\WINDOWS\system32\kbobsyoa.ini
C:\WINDOWS\system32\kebiktwe.ini
C:\WINDOWS\system32\lmgjvtcn.ini
C:\WINDOWS\system32\lxooaxwq.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mxeqqtcd.ini
C:\WINDOWS\system32\nttmqpfo.ini
C:\WINDOWS\system32\ojttohrf.ini
C:\WINDOWS\system32\otbsodue.ini
C:\WINDOWS\system32\pwhrstmf.ini
C:\WINDOWS\system32\srpupbeg.ini
C:\WINDOWS\system32\sxallijq.ini
C:\WINDOWS\system32\tpydbsro.ini
C:\WINDOWS\system32\tsknweit.ini
C:\WINDOWS\system32\uvwvumqh.ini
C:\WINDOWS\system32\vofhkgde.ini
C:\WINDOWS\system32\wadknbpd.ini
C:\WINDOWS\system32\xommsbxy.ini
C:\WINDOWS\system32\xybay.bak2
C:\WINDOWS\system32\xybay.ini
C:\WINDOWS\system32\xybay.ini2
C:\WINDOWS\system32\xybay.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DOMAINSERVICE
-------\Legacy_SZKG5
((((((((((((((((((((((((( Files Created from 2008-04-07 to 2008-05-07 )))))))))))))))))))))))))))))))
.
2008-05-05 11:29 . 2008-05-05 11:30 <DIR> d-------- C:\Program Files\Panda Security
2008-05-04 14:17 . 2008-05-06 08:51 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-04 14:15 . 2008-05-04 14:15 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-04 13:50 . 2008-05-04 13:50 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-05-04 13:49 . 2008-05-04 13:50 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-04 13:49 . 2008-05-04 13:49 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-04 13:49 . 2008-05-04 13:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-04 02:18 . 2008-05-04 02:18 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-04 02:18 . 2008-05-04 02:18 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-05-04 02:16 . 2008-05-04 02:16 45,568 --a------ C:\WINDOWS\system32\avgfwdx.dll
2008-05-04 02:16 . 2008-05-04 02:16 22,528 --a------ C:\WINDOWS\system32\drivers\avgfwdx.sys
2008-05-03 19:40 . 2008-05-07 11:17 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-03 19:36 . 2008-05-07 11:20 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-03 19:36 . 2008-05-03 19:36 <DIR> d-------- C:\Program Files\AVG
2008-05-03 19:36 . 2008-05-03 19:41 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-05-03 19:36 . 2008-05-04 02:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-03 19:36 . 2008-05-03 19:36 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-03 19:36 . 2008-05-03 19:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-03 03:28 . 2008-05-03 03:28 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Samsung
2008-05-03 03:26 . 2008-05-03 03:26 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-05-03 03:26 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-05-03 03:26 . 2007-07-03 16:58 106,792 --a------ C:\WINDOWS\system32\drivers\sscdmdm.sys
2008-05-03 03:26 . 2007-07-03 16:54 80,552 --a------ C:\WINDOWS\system32\drivers\sscdbus.sys
2008-05-03 03:26 . 2007-07-03 16:57 11,944 --a------ C:\WINDOWS\system32\drivers\sscdmdfl.sys
2008-05-03 03:26 . 2007-07-03 17:00 9,256 --a------ C:\WINDOWS\system32\drivers\sscdwhnt.sys
2008-05-03 03:26 . 2007-07-03 17:00 9,256 --a------ C:\WINDOWS\system32\drivers\sscdwh.sys
2008-05-03 03:26 . 2007-07-03 16:56 9,256 --a------ C:\WINDOWS\system32\drivers\sscdcmnt.sys
2008-05-03 03:26 . 2007-07-03 16:56 9,256 --a------ C:\WINDOWS\system32\drivers\sscdcm.sys
2008-05-03 03:25 . 2006-07-24 16:05 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-05-03 03:25 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-05-03 03:24 . 2008-05-03 03:24 <DIR> d-------- C:\Program Files\Samsung
2008-04-27 01:22 . 2008-04-27 01:22 <DIR> d-------- C:\Program Files\Red Kawa
2008-04-16 11:38 . 2008-04-16 11:39 <DIR> d-------- C:\Program Files\iTunes
2008-04-16 11:35 . 2008-04-16 11:36 <DIR> d-------- C:\Program Files\QuickTime
2008-04-09 10:00 . 2008-04-09 10:00 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\InstallShield
2008-04-09 09:40 . 2007-10-16 12:33 244,232 --a------ C:\WINDOWS\system32\Msflxgrd.ocx
2008-04-09 09:40 . 2007-10-16 12:33 164,144 --a------ C:\WINDOWS\system32\COMCT232.OCX
2008-04-09 09:34 . 2007-10-17 12:20 1,066,176 -ra------ C:\WINDOWS\system32\mscoe363.rra
2008-04-09 09:34 . 2007-10-17 12:20 24,576 -ra------ C:\WINDOWS\system32\BAZLib.dll
2008-04-09 09:28 . 2007-10-17 12:20 20,480 -ra------ C:\WINDOWS\system32\SysRestore.dll
2008-04-09 09:05 . 2008-04-10 07:22 <DIR> d-------- C:\Program Files\Ascentive
2008-04-09 09:05 . 2007-08-10 12:56 303,104 --a------ C:\WINDOWS\system32\ciplListBar.ocx
2008-04-09 09:05 . 2008-03-12 14:13 208,896 --a------ C:\WINDOWS\system32\ConTest.dll
2008-04-09 09:05 . 2007-08-10 12:56 155,648 --a------ C:\WINDOWS\system32\ciplImageList.ocx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-04 18:48 --------- d-----w C:\Program Files\SmartDraw 7
2008-05-04 18:17 --------- d-----w C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-05-04 06:39 --------- d-----w C:\Program Files\McAfee.com
2008-05-04 06:37 --------- d-----w C:\Program Files\McAfee
2008-05-04 05:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-05-04 05:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-05-04 05:27 --------- d-----w C:\Program Files\Common Files\AOL
2008-05-04 05:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-05-03 07:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-02 15:01 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-04-27 05:22 --------- d-----w C:\Program Files\AviSynth 2.5
2008-04-16 15:38 --------- d-----w C:\Program Files\iPod
2008-04-16 15:16 --------- d-----w C:\Program Files\Apple Software Update
2008-04-03 05:58 --------- d-----w C:\Documents and Settings\Owner\Application Data\Azureus
2008-04-02 17:56 --------- d-----w C:\Program Files\PopCap Games
2008-04-02 17:05 --------- d-----w C:\Program Files\Azureus
2008-03-31 22:40 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 4
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-16 18:02 --------- d-----w C:\Program Files\FT8D91
2008-03-16 01:51 --------- d-----w C:\Program Files\RCA
2008-03-14 06:33 --------- d-----w C:\Program Files\Project64 1.6
2008-03-07 13:24 97,216 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-03-05 06:16 98,048 ----a-w C:\WINDOWS\system32\dpvoic.dll
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-18 17:40 691,545 ----a-w C:\WINDOWS\unins000.exe
2007-12-31 22:25 284 -c--a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2007-01-23 19:07 1,847,296 -c--a-w C:\Program Files\mozilla firefox\plugins\Seadragon.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8ED64A7D-8A76-47F0-81D1-7810D35D3CE4}]
2008-03-05 02:16 98048 --a------ C:\WINDOWS\system32\dpvoic.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-04 02:18 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B0AF8D8E-9485-4EBE-B7D9-E5F291EE5C92}]
C:\WINDOWS\system32\yabyx.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-04 02:18 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-04 02:18 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"MSI Configuration"="msiconf.exe" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-06 08:51 1481968]
"AOL Fast Start"="C:\Program Files\America Online 9.0a\AOL.exe" [2005-07-12 07:17 50776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1131383480\ee\AOLSoftware.exe" [2006-09-25 20:52 50736]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-09-28 14:30 936960]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 16:20 2061816]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-04 02:17 1177368]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk.disabled [2007-01-14 23:33:37 1757]
HP Digital Imaging Monitor.lnk.disabled [2007-02-10 20:24:52 1808]
Kodak EasyShare software.lnk.disabled [2007-06-06 20:02:19 1837]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-05-06 08:51 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yabyx]
C:\WINDOWS\system32\yabyx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra--c--- 2006-10-23 08:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLSPScheduler]
--a------ 2007-01-25 17:34 8784 C:\Program Files\Common Files\AOL\1131383480\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 15:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan]
--a--c--- 2006-07-28 11:43 460336 C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GPLv3]
C:\WINDOWS\system32\orsbdypt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 20:52 50736 C:\Program Files\Common Files\AOL\1131383480\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
--a------ 2005-04-12 17:44 1187899 C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 02:41 8523776 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
--a------ 2006-07-28 11:43 116272 C:\Program Files\mcafee.com\antivirus\oasclnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter]
--a--c--- 2006-07-28 11:43 460336 C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscRun]
--a------ 2007-01-25 17:34 153168 C:\Program Files\Common Files\AOL\1131383480\ee\SSCRun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2007-03-14 03:43 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"6338ca3e.exe"=C:\Documents and Settings\Owner\Local Settings\Application Data\6338ca3e.exe
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
"MSI Configuration"=msiconf.exe
"Performance Center"=C:\Program Files\Ascentive\Performance Center\ApcMain.exe -m
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"EmailScan"=C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
"AOLSPScheduler"=C:\Program Files\Common Files\AOL\1131383480\ee\services\sscAntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe
"SoundMan"=SOUNDMAN.EXE
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"InCD"=C:\Program Files\Nero\Nero 7\InCD\InCD.exe
"nwiz"=nwiz.exe /install
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"Recguard"=%WINDIR%\SMINST\RECGUARD.EXE
"OASClnt"=C:\Program Files\mcafee.com\antivirus\oasclnt.exe
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"SunKistEM"=C:\Program Files\Digital Media Reader\shwiconem.exe
"ASM"="C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe" HIDEMAIN
"hcsystray"=C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
"VirusScan Online"=C:\Program Files\McAfee.com\VSO\mcvsshld.exe
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
"SearchIndexer"=rundll32.exe "C:\WINDOWS\system32\hqmuvwvu.dll",sitypnow
"NWEReboot"=
"ImgTask"=C:\WINDOWS\Imgtask.exe
"LyraUpdates"="C:\Program Files\RCA\Auto Updater\Auto Updater.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-05-04 02:18]
R0 ulvcsslx;ulvcsslx;C:\WINDOWS\system32\drivers\qxnudjns.dat []
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-03 19:36]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-04 02:17]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-04 02:17]
R2 avgfws8;AVG8 Firewall;C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-05-04 02:17]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-04 02:18]
R3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-05-04 02:16]
S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-05-04 02:16]
S3 MAC607;MAC607 Filter;C:\WINDOWS\system32\DRIVERS\MAC607.sys [2007-06-25 02:35]
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2007-06-15 11:49]
S3 XBox;XBox Filter;C:\WINDOWS\system32\DRIVERS\XBox.sys [2007-06-25 02:36]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd5d32d1-5c90-11d9-926d-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d03084d1-6658-11d9-8f0e-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
"2008-05-06 20:19:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-04 10:04:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2008-05-02 13:00:00 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-07 14:51:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ulvcsslx]
"ImagePath"="system32\drivers\qxnudjns.dat"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1131383480\EE\services\safetyCore\ver210_5_4_1\aolavupd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\Program Files\Common Files\AOL\1131383480\EE\anotify.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-07 15:16:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-07 19:15:46
Pre-Run: 25,961,144,320 bytes free
Post-Run: 25,949,483,008 bytes free
332 --- E O F --- 2008-04-10 04:32:03