Ran Combofix...still getting redirected....ARG!!

Anyways, thank you for bearing with me and my computer, seems like its being pretty stubborn!
Heres the log
ComboFix 10-04-15.02 - Owner 04/16/2010 3:59.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.597 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-2675569189-239620596-998515361-1003
c:\windows\system32\reboot.txt
D:\Autorun.inf
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((( Files Created from 2010-03-16 to 2010-04-16 )))))))))))))))))))))))))))))))
.
2010-04-16 11:07 . 2008-04-14 00:12 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2010-04-16 11:07 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2010-04-15 05:09 . 2010-04-15 05:09 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-04-14 21:24 . 2010-04-14 21:24 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-04-14 21:23 . 2010-04-14 21:41 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-04-14 21:21 . 2010-04-14 21:21 -------- d-----w- c:\program files\Common Files\Java
2010-04-14 21:21 . 2010-04-14 21:21 12800 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1dd0def2-n\decora-d3d.dll
2010-04-14 21:21 . 2010-04-14 21:21 61440 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1dd0def2-n\decora-sse.dll
2010-04-14 21:21 . 2010-04-14 21:21 503808 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2bd188cf-n\msvcp71.dll
2010-04-14 21:21 . 2010-04-14 21:21 499712 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2bd188cf-n\jmc.dll
2010-04-14 21:21 . 2010-04-14 21:21 348160 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2bd188cf-n\msvcr71.dll
2010-04-14 21:20 . 2010-04-14 21:20 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-14 11:15 . 2010-04-14 11:15 -------- d-----w- C:\_OTM
2010-04-14 00:44 . 2010-03-30 07:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-14 00:44 . 2010-03-30 07:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-14 00:31 . 2010-04-14 00:31 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-04-13 23:17 . 2010-04-15 11:32 -------- d-----w- c:\program files\trend micro
2010-04-13 23:16 . 2010-04-13 23:21 -------- d-----w- C:\rsit
2010-04-13 23:07 . 2010-04-13 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-13 13:57 . 2010-04-14 11:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-12 08:48 . 2008-04-14 01:39 142592 -c--a-w- c:\windows\system32\dllcache\aec.sys
2010-04-12 08:48 . 2008-04-14 01:39 142592 ----a-w- c:\windows\system32\drivers\aec.sys
2010-04-12 08:42 . 2010-04-12 08:42 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-04-11 11:14 . 2010-04-11 11:14 460640 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcclix.dll
2010-04-11 11:14 . 2010-04-11 11:14 395032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgclitx.dll
2010-04-11 11:14 . 2010-04-11 11:14 1101152 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchsvx.exe
2010-04-11 11:14 . 2010-04-11 11:14 557920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2010-04-11 11:14 . 2010-04-11 11:14 301408 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchclx.dll
2010-04-11 11:14 . 2010-04-11 11:14 623384 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcertx.dll
2010-04-11 07:10 . 2010-04-11 07:10 1038688 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-04-11 07:10 . 2010-04-11 07:10 1689952 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-04-11 07:09 . 2010-04-11 07:09 624920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-04-11 07:09 . 2010-04-11 07:09 813336 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-04-09 20:49 . 2010-04-09 20:51 -------- dc-h--w- c:\windows\ie8
2010-04-09 10:05 . 2010-04-09 10:05 -------- d-----w- c:\program files\ERUNT
2010-04-09 10:03 . 2010-04-09 10:03 388096 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-04-09 10:03 . 2010-04-09 10:03 -------- d-----w- c:\program files\TrendMicro
2010-04-09 08:50 . 2010-04-09 08:50 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Yahoo
2010-04-09 08:28 . 2010-04-09 08:28 -------- d-----w- c:\program files\Common Files\Skype
2010-04-09 08:28 . 2010-04-09 08:28 -------- d-----r- c:\program files\Skype
2010-04-08 07:34 . 2010-04-09 08:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-08 07:34 . 2010-04-09 08:30 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-04-08 06:59 . 2010-04-08 07:31 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-04-08 06:55 . 2010-04-08 07:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-04-08 06:55 . 2010-04-08 06:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-04-08 06:55 . 2010-04-08 06:55 -------- d-----w- c:\program files\NortonInstaller
2010-04-08 06:55 . 2010-04-08 06:55 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-04-08 06:25 . 2010-04-08 06:25 -------- d-----w- C:\$AVG
2010-04-08 02:37 . 2010-02-23 21:04 1664256 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-04-08 02:34 . 2010-04-08 02:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-04-08 02:34 . 2010-04-08 02:34 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-08 02:34 . 2010-04-08 02:34 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-08 02:34 . 2010-04-08 02:34 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-08 02:34 . 2010-04-16 10:46 -------- d-----w- c:\windows\system32\drivers\Avg
2010-04-08 02:34 . 2010-04-08 02:37 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-04-08 02:29 . 2010-04-08 02:29 -------- d-----w- c:\program files\AVG
2010-04-08 02:28 . 2010-04-16 10:45 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-04-08 00:28 . 2010-04-08 00:28 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\VS Revo Group
2010-04-08 00:27 . 2009-12-30 18:20 27064 ----a-w- c:\windows\system32\drivers\revoflt.sys
2010-04-08 00:27 . 2010-04-08 00:27 -------- d-----w- c:\program files\VS Revo Group
2010-04-07 21:13 . 2010-04-07 21:13 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
2010-04-05 09:51 . 2010-04-15 13:34 -------- d-----w- c:\documents and settings\Owner\Application Data\vlc
2010-04-05 09:42 . 2010-04-05 09:42 -------- d-----w- c:\program files\VideoLAN
2010-03-20 08:21 . 2010-03-20 08:23 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\kSolo
2010-03-20 08:21 . 2010-03-20 08:21 -------- d-----w- c:\program files\kSolo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-16 04:44 . 2010-03-07 15:19 -------- d-----w- c:\documents and settings\Owner\Application Data\Skype
2010-04-15 12:12 . 2010-02-18 07:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-14 21:28 . 2005-03-23 18:20 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-14 21:20 . 2005-03-27 06:01 -------- d-----w- c:\program files\Java
2010-04-14 12:56 . 2005-03-23 16:52 75264 ----a-w- c:\windows\system32\drivers\ipsec.sys
2010-04-12 23:05 . 2008-10-13 02:32 7 -c--a-w- c:\windows\sbacknt.bin
2010-04-12 07:37 . 2008-10-04 02:23 -------- d-----w- c:\documents and settings\Owner\Application Data\Yahoo!
2010-04-09 08:49 . 2008-10-04 02:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-04-09 08:28 . 2010-03-07 15:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-04-08 12:02 . 2010-03-07 15:22 -------- d-----w- c:\documents and settings\Owner\Application Data\skypePM
2010-04-07 23:39 . 2009-01-26 21:01 -------- d-----w- c:\program files\Bonjour
2010-04-07 23:36 . 2009-01-26 21:06 -------- d-----w- c:\program files\QuickTime
2010-04-07 23:35 . 2008-10-04 02:32 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller
2010-04-07 23:35 . 2008-09-04 10:21 -------- d-----w- c:\program files\Common Files\aolshare
2010-04-07 23:35 . 2008-09-04 10:21 -------- d-----w- c:\program files\Common Files\AOL
2010-04-07 23:29 . 2008-10-04 02:23 -------- d-----w- c:\program files\Yahoo!
2010-03-14 22:14 . 2008-09-04 10:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-14 21:44 . 2010-03-14 21:44 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-14 21:44 . 2010-03-14 21:44 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-14 21:44 . 2010-03-14 21:44 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-14 21:44 . 2010-03-14 21:44 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-14 21:44 . 2010-03-14 21:44 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-14 21:44 . 2010-03-14 21:44 300616 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-14 21:44 . 2010-03-14 21:44 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-14 21:44 . 2010-03-14 21:44 329312 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-14 21:44 . 2008-09-04 10:21 -------- d-----w- c:\program files\Common Files\Real
2010-03-14 21:43 . 2010-03-14 21:40 -------- d-----w- c:\program files\real
2010-03-14 21:42 . 2010-03-14 21:42 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-10 06:15 . 2005-03-23 16:52 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 16:20 . 2008-10-06 19:34 -------- d-----w- c:\documents and settings\Owner\Application Data\AdobeUM
2010-03-07 15:22 . 2010-03-07 15:22 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-02-25 06:24 . 2005-03-23 16:53 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2005-03-23 16:52 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 23:32 . 2008-10-04 02:41 98416 -c--a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-20 23:18 . 2008-09-04 10:20 -------- d-----w- c:\program files\Microsoft Works
2010-02-17 16:10 . 2005-03-23 16:52 2189952 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-04 05:59 2066816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03 . 2010-02-28 05:21 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2005-03-23 16:52 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2005-03-23 16:52 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 21:04 1664256 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-14 202256]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"SunKist"="c:\program files\Digital Media Reader\shwicon2k.exe" [2004-05-27 139264]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 169264]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-15 344064]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-12 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-08 02:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:coh
"9102:TCP"= 9102:TCP:coh2
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/7/2010 7:34 PM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/7/2010 7:34 PM 242696]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [4/7/2010 7:31 PM 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [4/7/2010 7:31 PM 308064]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/3/2008 8:24 PM 24652]
S0 kzizy;kzizy; [x]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/25/2008 5:20 AM 717296]
S3 AMDMSRIO;AMDMSRIO;\??\c:\docume~1\Owner\LOCALS~1\Temp\Safe To Delete 3_0_4_8\AMDMSRIO.sys --> c:\docume~1\Owner\LOCALS~1\Temp\Safe To Delete 3_0_4_8\AMDMSRIO.sys [?]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [4/7/2010 7:34 PM 369920]
S3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [9/4/2008 2:14 AM 200192]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [4/7/2010 5:27 PM 27064]
S3 Usbattspimpa;Usbattspimpa;c:\windows\system32\drivers\atinxbxx.sys [10/4/2008 11:49 AM 31744]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 11:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2010-04-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2008-09-04 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-03-23 00:12]
2008-09-04 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-03-23 00:12]
2008-09-04 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-03-23 00:12]
2010-04-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2643034619-977133499-1762504408-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 05:09]
2010-04-16 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2643034619-977133499-1762504408-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 05:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
AddRemove-Malwarebytes' Anti-Malware_is1 - l:\malwarebytes' anti-malware\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-16 04:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86B93AC8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf76d6f28
\Driver\ACPI -> ACPI.sys @ 0xf74e9cb8
\Driver\atapi -> atapi.sys @ 0xf746b852
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x80577c76
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x80577c76
NDIS: Broadcom 802.11g Network Adapter -> SendCompleteHandler -> NDIS.sys @ 0xf7332bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7321a0d
SendHandler -> NDIS.sys @ 0xf7335b40
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(856)
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(920)
c:\windows\system32\WININET.dll
.
Completion time: 2010-04-16 04:12:37
ComboFix-quarantined-files.txt 2010-04-16 11:12
Pre-Run: 34,446,360,576 bytes free
Post-Run: 34,517,954,560 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - C4DDB0578CEFC5786DD792C3B145921A