Here are the logs you requested:
ComboFix 09-02-19.01 - Absurd 2009-02-23 13:56:59.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3007.2376 [GMT -5:00]
Running from: d:\documents and settings\Absurd\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\Absurd\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: COMODO Firewall *disabled*
* Created a new restore point
FILE ::
c:\desktop aug 4th\Eye_Candy_Impact_by-sameer\Alien.Skin.Eye.Candy.v5.1.exe
c:\desktop aug 4th\slr mods\zmodeler_v107\zmodeler_v107.exe
c:\temporary internet files\Content.IE5\HPLG6G0R\offline[1].mmz
d:\program files\ZModeler\zmuninst.exe
e:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\ppclean.exe
e:\documents and settings\Studio\Local Settings\Temporary Internet Files\Content.IE5\OZPRUIZ1\ppclean[1].exe
f:\documents and settings\All Users\Application Data\AOL Downloads\lpaolcom_setupSTUS\comps\toolbar\toolbr.exe
f:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\28301546.tmp
f:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\640226EE.tmp
f:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\643D1AAE.exe
f:\documents and settings\Michael\CMS_RS_Grabber_v1.4.8\Grabber.exe
f:\program files\KORG\KORG USB-MIDI Driver\EzSetup64.exe
f:\program files\KORG\KORG USB-MIDI Driver\UnInstDrv64.exe
f:\program files\Magix\Samplitude_V8_professional\cdburnprofiler.exe
f:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
f:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\openssl.exe
f:\program files\NVIDIA Corporation\NetworkAccessManager\bin\instlsp64.exe
f:\program files\ProxyFinderEnterprise\ProxyFinder.exe
f:\program files\Windows NT\prokycoqyq.html
f:\windows\Installer\{1BA16E5A-72B9-44B7-9FDA-FB6CE7FF6C0C}\Icon158F1431.exe
f:\windows\Installer\{1BA16E5A-72B9-44B7-9FDA-FB6CE7FF6C0C}\Icon16CBC2752.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\desktop aug 4th\Eye_Candy_Impact_by-sameer\Alien.Skin.Eye.Candy.v5.1.exe
c:\desktop aug 4th\slr mods\zmodeler_v107\zmodeler_v107.exe
c:\temporary internet files\Content.IE5\HPLG6G0R\offline[1].mmz
d:\program files\ZModeler\zmuninst.exe
d:\windows\system32\msvcsv60.dll
e:\documents and settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\ppclean.exe
e:\documents and settings\Studio\Local Settings\Temporary Internet Files\Content.IE5\OZPRUIZ1\ppclean[1].exe
f:\documents and settings\All Users\Application Data\AOL Downloads\lpaolcom_setupSTUS\comps\toolbar\toolbr.exe
f:\documents and settings\Michael\CMS_RS_Grabber_v1.4.8\Grabber.exe
f:\program files\KORG\KORG USB-MIDI Driver\EzSetup64.exe
f:\program files\KORG\KORG USB-MIDI Driver\UnInstDrv64.exe
f:\program files\Magix\Samplitude_V8_professional\cdburnprofiler.exe
f:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
f:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\openssl.exe
f:\program files\NVIDIA Corporation\NetworkAccessManager\bin\instlsp64.exe
f:\program files\ProxyFinderEnterprise\ProxyFinder.exe
f:\program files\Windows NT\prokycoqyq.html
f:\windows\Installer\{1BA16E5A-72B9-44B7-9FDA-FB6CE7FF6C0C}\Icon158F1431.exe
f:\windows\Installer\{1BA16E5A-72B9-44B7-9FDA-FB6CE7FF6C0C}\Icon16CBC2752.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-23 to 2009-02-23 )))))))))))))))))))))))))))))))
.
2009-02-22 14:28 . 2009-02-22 14:28 <DIR> d-------- d:\program files\Java
2009-02-22 14:28 . 2009-02-22 14:28 73,728 --a------ d:\windows\system32\javacpl.cpl
2009-02-21 18:38 . 2009-02-21 18:38 268 --ah----- D:\sqmdata19.sqm
2009-02-21 18:38 . 2009-02-21 18:38 244 --ah----- D:\sqmnoopt19.sqm
2009-02-21 18:34 . 2009-02-21 18:34 <DIR> d-------- D:\_OTMoveIt
2009-02-21 18:24 . 2009-02-21 18:24 268 --ah----- D:\sqmdata18.sqm
2009-02-21 18:24 . 2009-02-21 18:24 244 --ah----- D:\sqmnoopt18.sqm
2009-02-21 17:49 . 2009-02-21 17:49 268 --ah----- D:\sqmdata17.sqm
2009-02-21 17:49 . 2009-02-21 17:49 244 --ah----- D:\sqmnoopt17.sqm
2009-02-21 15:53 . 2009-02-21 15:53 268 --ah----- D:\sqmdata16.sqm
2009-02-21 15:53 . 2009-02-21 15:53 244 --ah----- D:\sqmnoopt16.sqm
2009-02-21 09:12 . 2009-02-21 09:12 268 --ah----- D:\sqmdata15.sqm
2009-02-21 09:12 . 2009-02-21 09:12 244 --ah----- D:\sqmnoopt15.sqm
2009-02-21 01:24 . 2009-02-21 01:24 <DIR> d-------- d:\documents and settings\Absurd\Application Data\Viewpoint
2009-02-21 00:16 . 2009-02-21 00:17 <DIR> d-------- D:\rsit
2009-02-16 16:05 . 2009-02-16 16:05 <DIR> d-------- d:\program files\Trend Micro
2009-02-16 14:01 . 2009-02-16 14:01 268 --ah----- D:\sqmdata14.sqm
2009-02-16 14:01 . 2009-02-16 14:01 244 --ah----- D:\sqmnoopt14.sqm
2009-02-15 20:31 . 2009-02-22 14:28 410,984 --a------ d:\windows\system32\deploytk.dll
2009-02-15 17:42 . 2009-02-15 17:42 268 --ah----- D:\sqmdata13.sqm
2009-02-15 17:42 . 2009-02-15 17:42 244 --ah----- D:\sqmnoopt13.sqm
2009-02-15 02:20 . 2009-02-15 13:14 287 --a------ d:\windows\LEXSTAT.INI
2009-02-15 02:19 . 2009-02-15 02:19 <DIR> d-------- d:\program files\Lexmark 640 Series
2009-02-15 02:19 . 2004-05-24 13:23 311,296 --a------ d:\windows\system32\LEXBCES.EXE
2009-02-15 02:19 . 1997-04-08 20:08 299,520 --a------ d:\windows\uninst.exe
2009-02-15 02:19 . 2004-05-24 13:21 201,216 --a------ d:\windows\system32\LEXP2P32.DLL
2009-02-15 02:19 . 2004-05-24 13:42 200,704 --a------ d:\windows\system32\lexlmpm.dll
2009-02-15 02:19 . 2004-05-24 13:26 198,144 --a------ d:\windows\system32\LEX2KUSB.DLL
2009-02-15 02:19 . 2004-05-24 13:22 174,592 --a------ d:\windows\system32\LEXPPS.EXE
2009-02-15 02:19 . 2004-05-24 13:22 147,456 --a------ d:\windows\system32\LEXBCE.DLL
2009-02-15 02:19 . 2006-03-28 05:29 73,728 --a------ d:\windows\system32\lxdapwr.dll
2009-02-14 07:10 . 2009-02-14 07:10 268 --ah----- D:\sqmdata12.sqm
2009-02-14 07:10 . 2009-02-14 07:10 244 --ah----- D:\sqmnoopt12.sqm
2009-02-14 06:33 . 2009-02-14 06:33 0 --a------ d:\windows\nsreg.dat
2009-02-14 06:31 . 2009-02-14 06:31 <DIR> d-------- d:\documents and settings\stickam\Application Data\Logitech
2009-02-14 06:31 . 2009-02-21 23:03 <DIR> d-------- d:\documents and settings\stickam
2009-02-14 06:01 . 2009-02-14 06:01 <DIR> d-------- d:\documents and settings\Absurd\Application Data\MSNInstaller
2009-02-14 05:54 . 2009-02-14 05:54 268 --ah----- D:\sqmdata11.sqm
2009-02-14 05:54 . 2009-02-14 05:54 244 --ah----- D:\sqmnoopt11.sqm
2009-02-12 15:50 . 2009-02-12 15:50 268 --ah----- D:\sqmdata10.sqm
2009-02-12 15:50 . 2009-02-12 15:50 244 --ah----- D:\sqmnoopt10.sqm
2009-02-12 14:36 . 2009-02-12 14:36 268 --ah----- D:\sqmdata09.sqm
2009-02-12 14:36 . 2009-02-12 14:36 244 --ah----- D:\sqmnoopt09.sqm
2009-02-12 14:08 . 2009-02-12 14:08 268 --ah----- D:\sqmdata08.sqm
2009-02-12 14:08 . 2009-02-12 14:08 244 --ah----- D:\sqmnoopt08.sqm
2009-01-27 18:49 . 2009-01-27 18:49 <DIR> d-------- d:\program files\AviSynth 2.5
2009-01-27 18:49 . 2009-01-27 18:49 43,698 --a------ d:\windows\system32\xvid-uninstall.exe
2009-01-27 18:48 . 2009-01-27 18:48 <DIR> d-------- d:\program files\Gabest
2009-01-27 18:47 . 2009-01-27 18:49 <DIR> d-------- d:\program files\AutoGK
2009-01-27 18:24 . 2009-01-27 18:25 <DIR> d-------- d:\program files\E.M. DVD Copy
2009-01-27 17:51 . 2009-01-27 17:51 <DIR> d-------- d:\documents and settings\Absurd\Application Data\NeroDigital™
2009-01-27 15:32 . 2009-01-27 15:32 <DIR> d--h----- D:\BJPrinter
2009-01-27 15:32 . 2002-02-12 14:00 97,280 --a------ d:\windows\system32\CNMLM3w.DLL
2009-01-27 15:32 . 2002-01-17 11:48 36,864 --a------ d:\windows\system32\CNMCP3W.EXE
2009-01-27 15:32 . 2002-02-12 14:00 5,632 --a------ d:\windows\system32\CNMVS3w.DLL
2009-01-27 15:28 . 2008-04-14 00:17 25,856 --a------ d:\windows\system32\drivers\usbprint.sys
2009-01-27 15:28 . 2008-04-14 00:17 25,856 --a--c--- d:\windows\system32\dllcache\usbprint.sys
2009-01-27 14:57 . 2009-01-27 14:57 <DIR> d-------- d:\program files\DVDx
2009-01-26 23:01 . 2009-01-26 23:01 <DIR> d-------- d:\windows\Hot Item Finder
2009-01-26 23:01 . 2009-01-26 23:07 <DIR> d-------- d:\program files\HotItemFinder
2009-01-26 22:43 . 2009-01-26 22:43 <DIR> d-------- d:\windows\AuctionYen
2009-01-26 22:43 . 2009-01-26 23:00 <DIR> d-------- d:\program files\AuctionYen
2009-01-25 01:23 . 2009-01-25 01:23 <DIR> d-------- d:\program files\eBay
2009-01-25 01:23 . 2009-01-25 01:23 <DIR> d-------- d:\documents and settings\All Users\eBay
2009-01-23 00:36 . 2009-01-23 00:37 <DIR> d-------- d:\program files\InventoryBuilder
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-23 19:02 --------- d-----w d:\documents and settings\Absurd\Application Data\DMCache
2009-02-23 18:57 --------- d-----w d:\program files\ZModeler
2009-02-22 04:02 --------- d-----w d:\program files\AVG
2009-02-22 04:01 --------- d-----w d:\documents and settings\All Users\Application Data\avg8
2009-02-22 03:38 --------- d-----w d:\program files\TVAnts
2009-02-22 03:36 --------- d--h--w d:\program files\InstallShield Installation Information
2009-02-22 03:23 --------- d-----w d:\program files\Microsoft Bootvis
2009-02-22 03:22 --------- d-----w d:\program files\Google
2009-02-22 02:30 --------- d-----w d:\program files\Bonjour
2009-02-21 04:23 --------- d-----w d:\program files\Viewpoint
2009-02-21 04:23 --------- d-----w d:\documents and settings\All Users\Application Data\Viewpoint
2009-02-16 16:45 --------- d-----w d:\program files\SUPERAntiSpyware
2009-02-16 06:11 --------- d-----w d:\program files\Malwarebytes' Anti-Malware
2009-02-11 15:19 38,496 ----a-w d:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 ----a-w d:\windows\system32\drivers\mbam.sys
2009-02-07 13:56 325,128 ----a-w d:\windows\system32\drivers\avgldx86.sys
2009-02-07 13:56 107,272 ----a-w d:\windows\system32\drivers\avgtdix.sys
2009-01-23 05:36 25 ----a-w d:\program files\InventoryBuildersettings.ini
2009-01-22 12:08 --------- d-----w d:\program files\Common Files\Macromedia
2009-01-22 07:09 --------- d-----w d:\program files\SmartFTP Client
2009-01-22 04:00 --------- d-----w d:\documents and settings\Absurd\Application Data\SmartFTP
2009-01-19 09:51 31,504 ----a-w d:\windows\system32\drivers\cmdhlp.sys
2009-01-19 09:50 101,776 ----a-w d:\windows\system32\drivers\cmdguard.sys
2009-01-19 08:59 --------- d-----w d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-19 08:59 --------- d-----w d:\documents and settings\Absurd\Application Data\SUPERAntiSpyware.com
2009-01-19 08:46 --------- d-----w d:\documents and settings\Administrator.UNPARALL-5F4EE2\Application Data\Malwarebytes
2009-01-19 08:31 --------- d-----w d:\program files\Common Files\Wise Installation Wizard
2009-01-15 00:48 --------- d-----w d:\program files\Hammertap
2009-01-07 18:33 3,519 ----a-w d:\windows\bcm1C.tmp
2008-08-14 16:31 1 ----a-w d:\documents and settings\Absurd\SI.bin
2008-04-07 03:47 22,328 ----a-w d:\documents and settings\Absurd\Application Data\PnkBstrK.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-02-21_22.53.21.73 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-22 19:28:44 144,792 ----a-w d:\windows\system32\java.exe
+ 2009-02-22 19:28:44 144,792 ----a-w d:\windows\system32\javaw.exe
+ 2009-02-22 19:28:44 148,888 ----a-w d:\windows\system32\javaws.exe
+ 2009-02-23 19:02:00 16,384 ----atw d:\windows\temp\Perflib_Perfdata_f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="d:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"Aim6"="d:\program files\AIM6\aim6.exe" [2008-06-12 50528]
"IDMan"="d:\program files\Internet Download Manager\IDMan.exe" [2007-06-20 800256]
"SUPERAntiSpyware"="d:\program files\SUPERAntiSpyware\11b60ed9-558f-4a2f-bedc-e58aa3a9e0f8.exe" [2008-12-22 1830128]
"msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DigidesignMMERefresh"="g:\digidesign\Digidesign\Drivers\MMERefresh.exe" [2007-10-30 77824]
"M-Audio Taskbar Icon"="d:\windows\System32\M-AudioTaskBarIcon.exe" [2005-12-13 91136]
"COMODO Firewall Pro"="d:\program files\COMODO\Firewall\cfp.exe" [2009-01-19 1797880]
"COMODO Internet Security"="d:\program files\COMODO\Firewall\cfp.exe" [2009-01-19 1797880]
"AVG8_TRAY"="d:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-21 1601304]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-02-22 148888]
"nwiz"="nwiz.exe" [2007-12-05 d:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="d:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]
d:\documents and settings\Absurd\Start Menu\Programs\Startup\
Adobe Gamma.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-14 113664]
d:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-07-14 113664]
Logitech SetPoint.lnk - d:\program files\Logitech\SetPoint\SetPoint.exe [2008-04-02 789008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"NoStrCmpLogical"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoStrCmpLogical"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 d:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-01-09 12:30 72208 d:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-07 08:56 10520 d:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=d:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\GIGABYTE\\@BIOS\\gwflash.exe"=
"d:\\WINDOWS\\system32\\PnkBstrA.exe"=
"d:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\GIGABYTE\\EasyTune4\\update.exe"=
"d:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"e:\\rainbow 6 vegas 2\\Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"d:\\Program Files\\AIM6\\aim6.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"g:\\Avast\\avgupd.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"d:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Dreamweaver 8\\Dreamweaver.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R0 DigiFilter;DigiFilter;d:\windows\system32\drivers\DigiFilt.sys [2008-04-04 16384]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);d:\windows\system32\drivers\sfsync03.sys [2005-12-06 35328]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;d:\windows\system32\drivers\avgldx86.sys [2008-10-27 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;d:\windows\system32\drivers\avgtdix.sys [2008-10-27 107272]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;d:\windows\system32\drivers\cmdguard.sys [2008-07-08 101776]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;d:\windows\system32\drivers\cmdhlp.sys [2008-07-08 31504]
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-12-22 8944]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-12-22 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;d:\progra~1\AVG\AVG8\avgemc.exe [2009-02-21 903960]
R2 avg8wd;AVG Free8 WatchDog;d:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-21 298264]
R2 MAudioUSBService;M-Audio USB Installer;d:\program files\M-Audio\Fast Track Pro\MAUSBInst.exe [2008-06-08 49152]
R3 MAUSB;Service for M-Audio Fast Track Pro Driver (WDM);d:\windows\system32\drivers\mausb.sys [2008-06-08 102528]
R3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408]
R3 SUPERWEBCAM;SuperWebcam, WDM Virtual Video Capture Device;d:\windows\system32\drivers\superwebcam.sys [2008-04-02 31872]
S3 ETDrv;ETDrv;d:\windows\system32\drivers\ETDrv.sys [2008-04-07 185280]
S3 GVTDrv;GVTDrv;d:\windows\system32\drivers\GVTDrv.sys [2008-04-07 24944]
S3 MAUSBFTP;Service for M-Audio Fast Track Pro (WDM);d:\windows\system32\drivers\mausb.sys [2008-06-08 102528]
.
Contents of the 'Scheduled Tasks' folder
2009-02-17 d:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- d:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-05-16 10:45]
2008-04-03 d:\windows\Tasks\Uniblue SpeedUpMyPC.job
- d:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-05-16 10:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Download All Links with IDM - d:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - d:\program files\Internet Download Manager\IEExt.htm
Trusted Zone: stickam.com\www
TCP: {2BA77C4F-C5DA-4A32-BD8D-C0D21D48050B} = 167.206.254.2,167.206.254.1
FF - ProfilePath - d:\documents and settings\Absurd\Application Data\Mozilla\Firefox\Profiles\lmgq9aad.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - component: d:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: d:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: g:\downloads\adobe\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-23 14:02:08
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1390067357-1935655697-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{43994940-0A76-B9E2-F1CB-C506B574D3E1}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"hafdokpcgjhpicod"=hex:6e,62,61,6c,69,70,69,6e,6c,63,6a,62,6e,62,62,62,6e,6b,
6f,63,69,62,6d,68,62,6f,6b,63,65,6f,6e,69,6f,6d,68,70,6c,64,62,67,6d,6f,64,\
"jafdokpcgjhpicodiifh"=hex:66,61,61,6c,6b,70,6a,62,6a,62,6c,69,00,06
"panepddoiadpipfamhcalkabhkefmmlo"=hex:65,61,61,6c,6c,70,70,61,68,66,00,69
[HKEY_USERS\S-1-5-21-1390067357-1935655697-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:3c,10,da,82,f9,db,48,11,d9,7f,fc,87,ab,11,47,28,5a,3f,7b,4b,1d,45,f1,
41,84,42,6d,4d,3d,24,51,57,25,d2,27,c9,eb,65,bd,32,54,d2,f5,3e,10,ea,57,f8,\
"??"=hex:aa,f8,e9,f9,d4,11,1c,24,45,24,ef,c9,3e,c1,c2,96
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1727FC36-5D3D-4896-9DEE-AFE8A6A530BF}\Version*Version]
"Version"=hex:ac,6b,4e,f9,2e,07,46,fc,be,30,0c,b0,01,30,18,29,be,30,0c,b0,01,
30,18,29,be,30,0c,b0,01,30,18,29,be,30,0c,b0,01,30,18,29,be,30,0c,b0,01,30,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{524c79c3-e349-42ec-ac21-97f6e2154ab8}]
@Denied: (Full) (Everyone)
"Model"=dword:000000c2
"Therad"=dword:0000000f
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):7b,84,7b,03,0a,a5,a2,62,4b,84,89,32,ad,57,a2,5d,12,ea,b6,3c,50,
6b,fd,90,36,06,f2,1d,df,0a,0c,f7,60,b0,95,3b,90,69,bd,1c,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):cd,56,a9,70,ca,1a,9c,a7,01,d5,66,44,1a,d2,f0,46,22,95,6b,de,bc,
28,54,81,bb,c5,ae,20,82,16,74,d3,0a,1b,7c,5b,63,37,84,0f,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{81206d2a-a17d-4619-be46-ef500303c97f}]
@Denied: (Full) (Everyone)
"Model"=dword:0000007c
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(744)
d:\program files\SUPERAntiSpyware\SASWINLO.dll
d:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
d:\program files\common files\logishrd\bluetooth\LBTServ.dll
d:\windows\System32\BCMLogon.dll
.
------------------------ Other Running Processes ------------------------
.
d:\windows\system32\LEXBCES.EXE
d:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
d:\windows\system32\LEXPPS.EXE
d:\program files\Bonjour\mDNSResponder.exe
d:\program files\COMODO\Firewall\cmdagent.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
d:\program files\NVIDIA Corporation\nTune\nTuneService.exe
d:\windows\system32\IoctlSvc.exe
d:\windows\system32\PnkBstrA.exe
d:\program files\AVG\AVG8\avgrsx.exe
d:\progra~1\AVG\AVG8\avgnsx.exe
d:\program files\AVG\AVG8\avgcsrvx.exe
d:\windows\system32\wscntfy.exe
d:\windows\system32\rundll32.exe
d:\program files\Internet Download Manager\IEMonitor.exe
d:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2009-02-23 14:06:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-23 19:06:03
ComboFix2.txt 2009-02-22 19:17:32
ComboFix3.txt 2009-02-22 04:18:51
ComboFix4.txt 2009-02-22 03:54:37
Pre-Run: 4,358,213,632 bytes free
Post-Run: 4,405,899,264 bytes free
356 --- E O F --- 2009-02-21 22:20:54
--------------------------------------------------------------------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.34
Database version: 1795
Windows 5.1.2600 Service Pack 3
2/23/2009 2:15:46 PM
mbam-log-2009-02-23 (14-15-46).txt
Scan type: Quick Scan
Objects scanned: 74737
Time elapsed: 3 minute(s), 8 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)