Sorry I posted the same log twice above. Here is the combo fix log.
ComboFix 09-11-03.01 - James 03/11/2009 21:45.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1563 [GMT 0:00]
Running from: c:\documents and settings\James.X-WING\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1356 [VPS 091103-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1344558027-4278620720-11692346-1000
c:\$recycle.bin\S-1-5-21-3520112810-3141085873-887644257-1000
c:\documents and settings\James.X-WING\My Documents\backup.reg
c:\recycler\S-1-5-21-527237240-1592454029-1801674531-1003
c:\recycler\S-1-5-21-527237240-1592454029-1801674531-500
c:\recycler\S-1-5-21-57989841-1450960922-725345543-1003
c:\windows\system32\Data
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-10-03 to 2009-11-03 )))))))))))))))))))))))))))))))
.
2009-11-03 21:41 . 2006-09-21 14:39 105344 ----a-w- c:\windows\system32\drivers\nvata.sys
2009-10-31 18:26 . 2009-06-30 10:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-10-31 18:25 . 2009-10-31 18:25 -------- d-----w- c:\program files\Panda Security
2009-10-31 17:58 . 2009-10-31 16:36 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-10-31 16:36 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-10-31 16:36 . 2009-10-31 16:36 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-31 16:33 . 2009-10-31 16:33 -------- dc-h--w- c:\documents and settings\All Users.WINDOWS\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-31 16:33 . 2009-10-31 16:36 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2009-10-31 16:33 . 2009-10-31 16:33 -------- d-----w- c:\program files\Lavasoft
2009-10-30 08:04 . 2009-10-30 08:04 -------- d-----w- c:\documents and settings\James.X-WING\Application Data\Malwarebytes
2009-10-30 08:04 . 2009-09-10 14:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-30 08:04 . 2009-10-30 08:04 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-10-30 08:04 . 2009-09-10 14:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-30 07:55 . 2009-09-15 11:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-10-30 07:55 . 2009-09-15 11:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-10-30 07:55 . 2009-09-15 11:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-10-30 07:55 . 2009-09-15 11:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-30 07:55 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-10-30 07:55 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-10-30 07:55 . 2009-09-15 11:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-30 07:55 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-10-30 07:55 . 2003-03-18 21:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-10-30 07:55 . 2009-09-15 11:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-10-29 12:57 . 2009-10-30 13:18 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-10-28 16:21 . 2009-10-28 16:21 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-25 18:13 . 2009-10-25 18:13 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\BVRP Software
2009-10-25 18:05 . 2008-01-09 11:28 27632 ----a-w- c:\windows\system32\drivers\seehcri.sys
2009-10-25 18:03 . 2008-05-16 12:33 25512 ----a-w- c:\windows\system32\drivers\s0016nd5.sys
2009-10-25 18:03 . 2008-05-16 12:33 115752 ----a-w- c:\windows\system32\drivers\s0016unic.sys
2009-10-25 18:03 . 2008-05-16 12:33 114216 ----a-w- c:\windows\system32\drivers\s0016mgmt.sys
2009-10-25 18:03 . 2008-05-16 12:33 110632 ----a-w- c:\windows\system32\drivers\s0016obex.sys
2009-10-25 18:03 . 2008-05-16 12:33 10792 ----a-w- c:\windows\system32\drivers\s0016cr.sys
2009-10-25 18:03 . 2008-05-16 12:33 15016 ----a-w- c:\windows\system32\drivers\s0016mdfl.sys
2009-10-25 18:03 . 2008-05-16 12:33 89256 ----a-w- c:\windows\system32\drivers\s0016bus.sys
2009-10-25 18:03 . 2008-05-16 12:33 12200 ----a-w- c:\windows\system32\drivers\s0016whnt.sys
2009-10-25 18:03 . 2008-05-16 12:33 12200 ----a-w- c:\windows\system32\drivers\s0016wh.sys
2009-10-25 18:03 . 2008-05-16 12:33 12200 ----a-w- c:\windows\system32\drivers\s0016cmnt.sys
2009-10-25 18:03 . 2008-05-16 12:33 12200 ----a-w- c:\windows\system32\drivers\s0016cm.sys
2009-10-25 18:03 . 2008-05-16 12:33 120744 ----a-w- c:\windows\system32\drivers\s0016mdm.sys
2009-10-25 17:49 . 2009-10-25 17:49 -------- d-----w- c:\documents and settings\James.X-WING\Local Settings\Application Data\Sony Ericsson
2009-10-25 17:49 . 2009-10-25 17:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Sony Ericsson
2009-10-23 22:01 . 2009-10-23 22:01 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-10-22 19:42 . 2008-07-11 00:28 50200 ----a-w- c:\windows\system32\perf-SQLAgent$SQLEXPRESS-sqlagtctr10.0.1600.22.dll
2009-10-22 19:42 . 2008-07-11 00:28 79896 ----a-w- c:\windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.0.1600.22.dll
2009-10-22 19:41 . 2009-10-22 19:41 -------- d-----w- c:\windows\system32\RsFx
2009-10-22 19:40 . 2009-10-22 19:40 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2009-10-22 19:31 . 2009-10-22 19:41 -------- d-----w- c:\program files\Microsoft SQL Server
2009-10-22 19:31 . 2009-10-22 19:31 -------- d-----w- c:\program files\Microsoft Synchronization Services
2009-10-22 19:31 . 2009-10-22 19:31 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-22 19:30 . 2009-10-22 19:30 -------- d-----w- c:\documents and settings\James.X-WING\Local Settings\Application Data\Microsoft Help
2009-10-22 19:29 . 2009-10-22 19:31 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-10-22 19:28 . 2009-10-22 19:28 -------- d-----w- c:\program files\Microsoft SDKs
2009-10-22 17:00 . 2009-10-22 17:00 -------- d-----w- c:\documents and settings\James.X-WING\Local Settings\Application Data\Apple Computer
2009-10-21 19:41 . 2008-07-12 07:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2009-10-21 06:37 . 2009-10-23 18:43 -------- d-----w- c:\documents and settings\James.X-WING\Application Data\FreeCall
2009-10-18 09:44 . 2006-08-18 09:30 446464 ----a-w- c:\windows\system32\CapabilityTable.exe
2009-10-18 09:43 . 2006-09-11 16:27 356352 ------w- c:\windows\system32\nvuide.exe
2009-10-18 09:43 . 2006-08-07 15:39 110080 ----a-w- c:\windows\system32\drivers\nvtcp.sys
2009-10-18 09:43 . 2006-08-03 22:48 208896 ----a-w- c:\windows\system32\nvunrm.exe
2009-10-18 09:43 . 2006-06-07 18:49 208896 ----a-w- c:\windows\system32\nvusmb.exe
2009-10-18 09:43 . 2006-08-18 09:28 208896 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-10-18 09:42 . 2006-09-21 14:39 363008 ----a-w- c:\windows\system32\idecoiins.dll
2009-10-18 09:42 . 2006-09-21 14:39 363008 ----a-w- c:\windows\system32\idecoi.dll
2009-10-18 09:42 . 2006-09-11 16:27 35840 ----a-w- c:\windows\system32\NVCOI.DLL
2009-10-18 09:42 . 2006-08-07 15:39 18944 ----a-w- c:\windows\system32\drivers\nvnetbus.sys
2009-10-18 09:42 . 2006-08-07 15:39 52736 ----a-w- c:\windows\system32\drivers\NVENETFD.sys
2009-10-18 09:42 . 2006-08-07 15:39 1104896 ----a-w- c:\windows\system32\drivers\nvnrm.sys
2009-10-18 09:42 . 2006-08-07 15:38 261120 ----a-w- c:\windows\system32\drivers\nvsnpu.sys
2009-10-18 09:42 . 2006-08-03 22:48 35840 ----a-w- c:\windows\system32\nvconrm.dll
2009-10-18 09:42 . 2006-08-07 15:37 202240 ----a-w- c:\windows\system32\fdco1.dll
2009-10-18 09:42 . 2006-08-07 15:37 10240 ----a-w- c:\windows\system32\bdco1ins.dll
2009-10-18 09:42 . 2006-08-07 15:37 10240 ----a-w- c:\windows\system32\bdco1.dll
2009-10-16 06:16 . 2009-10-16 06:16 -------- d--h--r- c:\documents and settings\James.X-WING\Application Data\SecuROM
2009-10-16 06:13 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-10-16 06:13 . 2009-03-16 13:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-10-16 06:13 . 2009-03-09 14:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-10-16 06:13 . 2009-03-16 13:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-10-16 06:13 . 2007-04-04 18:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2009-10-14 16:12 . 2009-11-02 16:12 -------- d-----w- c:\documents and settings\James.X-WING\Application Data\skypePM
2009-10-14 16:12 . 2009-10-14 16:12 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-10-14 16:12 . 2009-11-02 20:27 -------- d-----w- c:\documents and settings\James.X-WING\Application Data\Skype
2009-10-14 16:08 . 2009-10-14 16:08 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Skype
2009-10-14 05:22 . 2009-08-13 15:16 512000 -c----w- c:\windows\system32\dllcache\jscript.dll
2009-10-12 20:05 . 2009-10-12 20:05 -------- d-----w- c:\windows\system32\scripting
2009-10-12 20:05 . 2009-10-12 20:05 -------- d-----w- c:\windows\system32\en
2009-10-12 20:05 . 2009-10-12 20:05 -------- d-----w- c:\windows\l2schemas
2009-10-12 20:05 . 2009-10-12 20:05 -------- d-----w- c:\windows\system32\bits
2009-10-12 18:24 . 2009-10-12 18:24 -------- d-----w- c:\windows\system32\MpEngineStore
2009-10-11 19:05 . 2004-08-03 21:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2009-10-11 18:53 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-10-11 18:53 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-10-11 18:52 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-10-11 18:52 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-10-11 18:52 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-10-11 18:52 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-10-11 18:52 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-10-11 18:52 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-10-11 18:52 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-10-11 18:52 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-10-11 18:52 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-10-11 18:52 . 2009-08-04 15:13 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-11 18:52 . 2009-08-04 19:44 2189184 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-10-11 18:52 . 2009-08-04 14:20 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-11 18:51 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-10-11 18:51 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-10-11 18:40 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-10-11 18:38 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-10-11 18:37 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-10-11 18:37 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-10-11 18:35 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-10-11 18:35 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-10-11 17:21 . 2009-10-11 20:10 -------- d-----w- c:\documents and settings\James.X-WING\Local Settings\Application Data\Adobe
2009-10-11 17:10 . 2009-10-11 17:10 -------- d-----w- C:\Hodder Education
2009-10-11 15:36 . 2009-10-11 15:36 -------- d-----w- c:\documents and settings\James.X-WING\Application Data\DivX
2009-10-11 14:20 . 1999-09-04 20:23 91136 ----a-r- c:\windows\system32\msls2.dll
2009-10-11 14:12 . 2009-10-31 12:17 -------- d-----w- c:\documents and settings\James.X-WING\Local Settings\Application Data\Temp
2009-10-11 13:16 . 2006-10-06 06:17 53248 ------w- c:\windows\Ctregrun.exe
2009-10-11 13:13 . 2005-06-15 03:07 11264 ----a-r- c:\windows\InRes.DLL
2009-10-11 13:11 . 2008-04-13 18:45 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2009-10-11 13:11 . 2008-04-13 19:17 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2009-10-11 13:11 . 2008-04-13 18:45 52864 ----a-w- c:\windows\system32\drivers\dmusic.sys
2009-10-11 13:11 . 2008-04-13 18:45 56576 ----a-w- c:\windows\system32\drivers\swmidi.sys
2009-10-11 13:11 . 2008-04-13 16:39 142592 ----a-w- c:\windows\system32\drivers\aec.sys
2009-10-11 13:11 . 2008-04-13 18:45 2944 ----a-w- c:\windows\system32\drivers\drmkaud.sys
2009-10-11 13:11 . 2008-04-13 18:45 172416 ----a-w- c:\windows\system32\drivers\kmixer.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-31 07:32 . 2007-11-01 07:57 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-28 16:21 . 2007-10-30 16:39 -------- d-----w- c:\program files\Java
2009-10-27 21:39 . 2007-10-01 13:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-27 10:32 . 2007-10-01 13:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-25 18:03 . 2009-10-25 18:03 148736 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\hpe82D.dll
2009-10-22 19:40 . 2008-09-02 10:24 -------- d-----w- c:\program files\Microsoft.NET
2009-10-11 11:29 . 2009-07-24 06:09 -------- d-----w- c:\program files\NVIDIA Corporation
2009-10-11 08:26 . 2009-09-20 06:12 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\HpUpdate
2009-10-10 11:42 . 2008-04-29 17:11 77000 ----a-w- c:\documents and settings\James.X-WING.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-08 20:15 . 2008-12-16 21:52 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\dvdcss
2009-10-08 16:00 . 2009-08-02 10:11 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\Skype
2009-10-08 15:09 . 2009-08-02 10:12 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\skypePM
2009-10-01 06:08 . 2009-10-01 06:08 -------- d-----w- c:\program files\Common Files\Futuremark Shared
2009-10-01 05:49 . 2009-10-01 05:49 -------- d-----w- c:\program files\SystemRequirementsLab
2009-10-01 05:48 . 2009-10-01 05:48 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\SystemRequirementsLab
2009-09-27 17:19 . 2009-09-27 17:19 3674112 ----a-w- c:\windows\system32\nvwssr.dll
2009-09-27 15:12 . 2009-09-27 15:12 888832 ----a-w- c:\windows\system32\nvapi.dll
2009-09-27 15:12 . 2009-09-27 15:12 7655872 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-09-27 15:12 . 2009-09-27 15:12 5900416 ----a-w- c:\windows\system32\nv4_disp.dll
2009-09-27 15:12 . 2009-09-27 15:12 2194024 ----a-w- c:\windows\system32\nvcuvid.dll
2009-09-27 15:12 . 2009-09-27 15:12 2007040 ----a-w- c:\windows\system32\nvcuda.dll
2009-09-27 15:12 . 2009-09-27 15:12 1714792 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-09-27 15:12 . 2009-09-27 15:12 170600 ----a-w- c:\windows\system32\nvcodins.dll
2009-09-27 15:12 . 2009-09-27 15:12 170600 ----a-w- c:\windows\system32\nvcod.dll
2009-09-27 15:12 . 2009-09-27 15:12 1604482 ----a-w- c:\windows\system32\nvdata.bin
2009-09-27 15:12 . 2009-09-27 15:12 10756096 ----a-w- c:\windows\system32\nvoglnt.dll
2009-09-26 17:49 . 2009-09-26 17:49 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\ImgBurn
2009-09-26 17:24 . 2009-09-26 17:22 -------- d-----w- c:\program files\AVS4YOU
2009-09-26 17:24 . 2008-10-14 17:53 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-09-26 17:22 . 2008-10-14 17:53 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\AVS4YOU
2009-09-26 10:27 . 2008-04-29 18:36 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\Apple Computer
2009-09-25 19:48 . 2009-09-14 18:46 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\Tropico 3 Demo
2009-09-25 05:37 . 2004-08-04 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-23 18:27 . 2008-05-01 17:45 -------- d-----w- c:\program files\Microsoft Works
2009-09-20 09:08 . 2008-03-07 08:45 -------- d-----w- c:\program files\iPod
2009-09-20 09:08 . 2007-10-02 09:45 -------- d-----w- c:\program files\Common Files\Apple
2009-09-20 06:12 . 2007-10-01 14:54 -------- d-----w- c:\program files\HP
2009-09-18 18:07 . 2009-09-18 18:05 -------- d-----w- c:\documents and settings\James.X-WING.000\Application Data\HP
2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 16:44 . 2009-10-21 19:42 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-09-04 16:44 . 2009-10-21 19:42 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-09-04 16:29 . 2009-10-21 19:42 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-09-04 16:29 . 2009-10-21 19:42 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-09-04 16:29 . 2009-10-21 19:42 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-09-04 16:29 . 2009-10-21 19:42 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-09-04 16:29 . 2009-10-21 19:42 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-14 12:36 . 2009-08-14 12:36 70936 ----a-w- c:\windows\system32\PhysXLoader.dll
2009-08-06 19:24 . 2009-10-11 11:17 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 19:24 . 2009-10-11 11:17 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 19:24 . 2009-10-11 11:17 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 19:24 . 2008-10-16 13:09 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 19:24 . 2009-10-11 11:17 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 19:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 19:23 . 2009-10-11 11:17 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 19:23 . 2009-10-11 11:17 1929952 ----a-w- c:\windows\system32\wuaueng.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeCall"="f:\apps\FreeCall\FreeCall.exe" [2009-07-30 9156912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-23 1657448]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"HP Software Update"="f:\apps\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="f:\apps\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2007-05-11 2512392]
"CTAPR2"="f:\apps\Creative\Sound Blaster X-Fi\Console Launcher\CTAPR2.exe" [2007-02-15 57344]
"VolPanel"="f:\apps\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-02-28 180224]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"avast!"="f:\apps\Avast4\ashDisp.exe" [2009-09-15 81000]
"Malwarebytes Anti-Malware (reboot)"="f:\apps\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - f:\apps\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"idsvc"=3 (0x3)
"CachemanService"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"f:\\apps\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"f:\\apps\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"f:\\apps\\Sony Ericsson\\Update Service\\Update Service.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"f:\\apps\\FreeCall\\FreeCall.exe"=
"f:\\Games\\Warhammer_Dawn_of_War_2-WiCKED\\DOW2.exe"=
"f:\\Games\\Batman Arkham Asylum\\Binaries\\ShippingPC-BmGame.exe"=
"f:\\Games\\Borderlands\\Binaries\\Borderlands.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [31/10/2009 16:36 64288]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [31/10/2009 18:26 28552]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30/10/2009 07:55 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/10/2009 07:55 20560]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 11:17 1179232]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [25/10/2009 18:05 27632]
R3 t3;Sound Blaster X-Fi Xtreme Audio;c:\windows\system32\drivers\t3.sys [11/10/2009 13:09 733184]
R3 t3filt;t3filt;c:\windows\system32\drivers\t3filt.sys [11/10/2009 13:09 1656576]
S2 OMSI download service;Sony Ericsson OMSI download service;f:\apps\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [25/10/2009 18:03 90112]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [25/10/2009 18:03 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [25/10/2009 18:03 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [25/10/2009 18:03 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [25/10/2009 18:03 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [25/10/2009 18:03 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [25/10/2009 18:03 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [25/10/2009 18:03 115752]
S4 CachemanService;Cacheman Service;f:\apps\Cacheman\CachemanServ.exe [10/09/2009 23:13 221240]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [11/07/2008 00:28 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [10/07/2008 01:49 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [11/07/2008 00:28 369688]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
*Deregistered* - PROCEXP113
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-11-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 16:36]
2009-11-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-179605362-725345543-1003Core.job
- c:\documents and settings\James.X-WING\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-11 14:12]
2009-11-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-179605362-725345543-1003UA.job
- c:\documents and settings\James.X-WING\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-11 14:12]
2009-10-31 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- f:\apps\Spybot - Search & Destroy\SpybotSD.exe [2008-05-01 15:31]
2009-10-31 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- f:\apps\Spybot - Search & Destroy\SDUpdate.exe [2008-05-01 15:31]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://go.divx.com/divx/divx6/new/en?rcv=1&dist=divxdotcom
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
FF - ProfilePath - c:\documents and settings\James.X-WING\Application Data\Mozilla\Firefox\Profiles\vzp3oe7s.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\documents and settings\James.X-WING\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: f:\apps\codecs\Real Alternative\browser\plugins\nppl3260.dll
FF - plugin: f:\apps\codecs\Real Alternative\browser\plugins\nprpjplug.dll
FF - plugin: f:\apps\Opera\program\plugins\npdsplay.dll
FF - plugin: f:\apps\Opera\program\plugins\NPOFFICE.DLL
FF - plugin: f:\apps\Opera\program\plugins\nppl3260.dll
FF - plugin: f:\apps\Opera\program\plugins\npqtplugin.dll
FF - plugin: f:\apps\Opera\program\plugins\npqtplugin2.dll
FF - plugin: f:\apps\Opera\program\plugins\npqtplugin3.dll
FF - plugin: f:\apps\Opera\program\plugins\npqtplugin4.dll
FF - plugin: f:\apps\Opera\program\plugins\npqtplugin5.dll
FF - plugin: f:\apps\Opera\program\plugins\nprpjplug.dll
FF - plugin: f:\apps\Opera\program\plugins\NPSWF32.dll
FF - plugin: f:\apps\Opera\program\plugins\npwmsdrm.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
f:\apps\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-03 21:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1960408961-179605362-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:d9,12,1f,d5,d3,3f,38,78,8f,f4,e2,e2,8f,38,fe,9a,88,53,ca,a1,12,
4b,97,ea,5e,dd,97,2d,5e,00,a8,95,0d,5b,ab,cd,de,e8,16,b9,1a,f9,5b,d9,fa,e1,\
"rkeysecu"=hex:8b,75,25,fe,27,3c,3f,a4,9c,ed,3a,c1,52,e1,5f,92
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="7E04CD018D3A30BDE6C5D99CF944736172FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933C038D530D6EB34528EDD5E5BE2F6E667A2D97226D213B55588EF44A3BD22FD9E8033E8A7278E97BB5F85D867584E88E6B2BEA9619D97D2BBB1F92A30FD4BFC19E72F2E373FD5864A29CEA7D04913234450F9091B4C504FF95C42854CC1D0ACB6CEFB9598B8EA388D5FA3CF28EE32C35607C9112142B2CCBF4E9EF53868B89BEB73FA235EFD2EAD9B610CDC71628401F4EF007105652E99467C47EEB8C2AB69F1CBECAE20ED2000D1BFF42CB32E04863A594FAC608F59150A14DA381718F74FC57FF866F3DBE95AC9BFACEF79D2D19605475198CE0C6BB549735AEF9EA11017296C28CA7B8E54FB69DA65AC5045B104796F02626E9C4304092F2B82A10E8A9DA12269B0544250375540B83ECA6C8C39FEBB408663F65F9E128E9734F2FE9F56F6E58FC0A7A5EFF4F651A05001A4EB3040CB53D8D643E635F08C4B1F6C0BAE47B62ED0F79D5AE8AE7D21FCE50D3E82792BF06200F19E220EF35958AC6ABA388A332A48A5E2F818F45A7B11538DFCA2B975B3F8F6E61AFC823158359D4D0E634F00B97270AA0B7B6945DC04C42598C22A944C888B67BB897F00A03906FAF5F9D5F76F34502A12364636F76136793E0295C2AA65E1ABFAFB85FBFE24CD5A5868F5B516D1929A7E8ED4EC3119FA378C9EDC027047EFEFC6AD2B857115305910C21A1D2AF656BA3870746BA1FD370B18FBF492F5CA80F37E9A1AC1AB933CE7E9BDBF525A3293CA1A69987797C7E3A86922657DC2F0B27AF6E40E189608D6FAA8B3F93D8CF48F11F3AE481B9591D147FABD4A0D181E78CAF9D0D7344C40B78A02A1ED0D5915695888941F244FDBA1A0BF9ED4D1E7991AB245485F879C6B6A9421AAD6320D4F116C8E96CCA5AE08C77318B9489CD69131FE88569BC40C22CE98A29304E02840CA9EB05593F5D25F8E82DEA47D06C194AC8669AD1B65CFDC191C99C65493DEEAB0C78E91CBAD8B8B15945F9BE0E83798CF9E81217E24D6F7CFA78A53418619B5AEBDBB34DFACDE1ECBF3580071E4777430A2DC2C7B82BDB64FC672E854BB756A8561BDC550938688F76F0055C5DBFAE5BAF3FCE8DBC459BBC70CBB5E2BF743394A1290772EC9EFA3B4D97C4204F66C0D2CF5D61BFA71B0923D0ACAAEF7C30732E536231AA3783C2A700AEA94691F286D180F53264C567FA706DAF4F5026C784C143759A6690F423B6BDADA3A46854370652CCF125382B5CDCF1A83F7230506E3670388B650BE09DABAA9D049FE1B03624FBB1D8DAA4B76B819E93699495F4FB4438C7C0A3BFDD1EF4ADAC3F68A996273E3B27FE8FD471903B5EDBC637618A7E2E0C6F482A0850AC55653A1A1F77A8F388588B19811"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1176)
c:\windows\system32\nvappfilter.dll
.
Completion time: 2009-11-03 21:52
ComboFix-quarantined-files.txt 2009-11-03 21:52
Pre-Run: 25,116,704,768 bytes free
Post-Run: 25,112,219,648 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer