Ok Shaba,
I ran the ComboFix program as requested. Below is the log:
===================
Combofix log
===================
ComboFix 09-06-25.07 - Owner 06/26/2009 12:59.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.446.137 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090626-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Manson\liser.dll
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\Install.txt
c:\windows\jsr468ijdfghfjsw3rw3i6tjag81.exe
c:\windows\system32\drivers\UACogrqltenbmlvakb.sys
c:\windows\system32\Install.txt
c:\windows\system32\net.net
c:\windows\system32\tpsaxyd.exe
c:\windows\system32\UACidoexwbpjydsubq.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UAClrrtkmodxiaowlh.db
c:\windows\system32\UACmtkvfshsbqxmbvt.dll
c:\windows\system32\UACoshimotybirjiph.dll
c:\windows\system32\UACpvtoypnmktavbou.dll
c:\windows\system32\uactmp.db
c:\windows\system32\UACuvgnowyulyfvdwe.dat
c:\windows\system32\UACxurqhhbluuqpqmy.dll
c:\windows\system32\wiawow32.sys
D:\Autorun.inf
D:\Desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACD.SYS
-------\Legacy_UACD.SYS
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
-------\Legacy_jsr468ijdfghfjsw3rw3i6tjag80
-------\Service_jsr468ijdfghfjsw3rw3i6tjag80
((((((((((((((((((((((((( Files Created from 2009-05-26 to 2009-06-26 )))))))))))))))))))))))))))))))
.
2080-06-20 19:58 . 2009-06-26 17:09 -------- d-sh--r- c:\program files\Manson
2080-06-20 19:58 . 2009-06-26 16:44 -------- d-----w- c:\documents and settings\All Users\Application Data\14620314
2080-06-20 19:58 . 2009-06-26 16:44 -------- d-----w- c:\documents and settings\All Users\Application Data\94630306
2080-06-20 19:57 . 2080-06-20 19:57 19968 ----a-w- c:\windows\system32\UACupxmkjyoeajtxhf.dll
2080-06-07 02:42 . 2007-09-25 20:13 774144 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\dmtb225o.default\extensions\yyginstantplay@yoyogames.com\plugins\NPYYGInstantPlay.dll
2080-05-12 19:42 . 2080-05-12 19:42 8854 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\Uninstall_Project64__9559F7CA5E344237A2D9D856464AD727.exe
2080-05-12 19:42 . 2080-05-12 19:42 40960 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2080-05-12 19:42 . 2080-05-12 19:42 40960 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2080-05-12 19:32 . 2080-05-12 19:44 -------- d-----w- c:\program files\Project64 1.6
2009-06-26 14:54 . 2009-06-26 14:54 -------- d-----w- c:\program files\Trend Micro
2009-06-23 21:20 . 2009-06-23 21:20 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-23 20:52 . 2009-06-23 20:52 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2080-05-06 18:29 . 2005-07-29 12:15 -------- d-----w- c:\program files\Google
2080-05-02 13:21 . 2008-07-17 19:27 -------- d-----w- c:\documents and settings\All Users\Application Data\TrackMania
2009-06-26 17:20 . 2007-06-02 19:12 -------- d-----w- c:\documents and settings\Owner\Application Data\OpenOffice.org2
2009-06-26 17:17 . 2006-11-19 18:37 -------- d-----w- c:\program files\Greetings Workshop
2009-06-26 16:48 . 2007-09-22 15:53 -------- d-----w- c:\documents and settings\Owner\Application Data\LimeWire
2009-06-26 16:39 . 2006-10-28 18:30 -------- d-----w- c:\documents and settings\Owner\Application Data\StumbleUpon
2009-06-23 20:11 . 2006-06-29 22:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-23 20:11 . 2006-06-29 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-23 18:57 . 2009-06-20 21:38 -------- d-----w- c:\documents and settings\Administrator\Application Data\AOL
2009-06-23 18:57 . 2005-07-29 12:41 -------- d-----w- c:\documents and settings\Owner\Application Data\AOL
2009-06-23 18:57 . 2005-07-29 12:25 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-06-23 18:57 . 2005-07-29 12:25 -------- d-----w- c:\program files\Common Files\AOL
2009-06-23 18:50 . 2007-03-30 19:05 -------- d-----w- c:\documents and settings\Owner\Application Data\foobar2000
2009-06-21 16:06 . 2009-06-21 16:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\Lavasoft
2009-05-07 15:44 . 2004-08-26 16:11 344064 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-26 16:12 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-26 16:11 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 09:58 . 2004-08-26 16:12 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:26 . 2004-08-26 16:12 583168 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-12 18:11 . 2009-04-12 18:11 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-02-06 23:51 . 2007-06-26 23:28 88 --sh--r- c:\windows\system32\109DE72A6B.sys
2009-02-06 23:51 . 2007-06-26 23:23 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-28 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2006-01-24 7094272]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-06-13 2752512]
"AOL Fast Start"="c:\program files\America Online 9.0\AOL.EXE" [2005-06-23 50776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2007-05-30 77824]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-03-15 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"PhilipsDM"="c:\program files\Philips\Philips Device Manager\Bin\DeviceManager.exe" [2006-12-21 663552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"HostManager"="c:\program files\Common Files\AOL\1122639952\EE\AOLHostManager.exe" [2004-11-03 125528]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2005-03-12 147456]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-08 53248]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-12-09 67584]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
BoontyBox Clickgames.lnk - c:\program files\Boonty\BoontyBox\BoontyBox.exe [2006-10-13 898656]
Greetings Workshop Reminders.lnk - c:\program files\Greetings Workshop\GWREMIND.EXE [1996-6-25 40448]
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2007-9-17 147456]
Mavis Beacon Teaches Typing 11.lnk - c:\program files\Broderbund\Mavis Beacon Teaches Typing 11\MiniMavis.exe [2008-1-8 2326528]
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]
PowerReg Scheduler V3.exe [2006-6-8 225280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
AGEIA PhysX System Tray Icon.lnk - c:\program files\AGEIA Technologies\TrayIcon.exe [2006-1-17 331776]
BigFix.lnk - c:\program files\BigFix\BigFix.exe [2005-7-29 1742384]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
KODAK Picture Transfer Software.lnk - c:\program files\Kodak\KODAK Picture Transfer Software\pts.exe [2006-6-27 737280]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-4-1 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1122639952\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\Unzipped\\vbalink172l\\vbaserver.exe"=
"c:\\Program Files\\KODAK\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\WINDOWS\\system32\\ElectricSheep.scr"=
"c:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\BZFlag2.0.10\\bzflag.exe"=
"c:\\Program Files\\RapidSolution\\Videoraptor\\VideoRaptor.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7/5/2008 3:11 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/5/2008 3:11 PM 20560]
S3 ldiskl;ldiskl;\??\c:\docume~1\Owner\LOCALS~1\Temp\ldiskl.sys --> c:\docume~1\Owner\LOCALS~1\Temp\ldiskl.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{582610B8-E496-4813-993C-4B027173FE38}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
2080-06-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
2080-06-20 c:\windows\Tasks\Spybot - Search & Destroy.job
- c:\progra~1\SPYBOT~1\SpybotSD.exe [2009-06-23 19:31]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-_AntiSpyware - c:\program files\McAfee\McAfee AntiSpyware\MssCli.exe
HKLM-Run-URLLSTCK.exe - c:\program files\Norton Internet Security\UrlLstCk.exe
HKLM-Run-SSC_UserPrompt - c:\program files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
HKLM-Run-MCUpdateExe - c:\progra~1\mcafee.com\agent\McUpdate.exe
HKLM-Run-MCAgentExe - c:\progra~1\mcafee.com\agent\mcagent.exe
HKLM-Run-IS CfgWiz - c:\program files\Norton Internet Security\cfgwiz.exe
HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-AOL Spyware Protection - c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: StumbleUpon: &Blog This - StumbleUponIEBar.dll/blogimage
Trusted Zone: stumbleupon.com
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\dmtb225o.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|
http://onemorelevel.com/games.php?g...kampf.com/|http://nb.ikalliance.com/index.php
FF - prefs.js: keyword.URL - hxxp://www.ask.com/web?o=101447&l=dis&q=
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\dmtb225o.default\extensions\yyginstantplay@yoyogames.com\plugins\NPYYGInstantPlay.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-26 13:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2268)
c:\program files\Broderbund\Mavis Beacon Teaches Typing 11\KeyHook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\aolshare\aolshcpy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\progra~1\COMMON~1\AOL\112263~1\EE\AOLServiceHost.exe
c:\program files\America Online 9.0\waol.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\docume~1\Owner\LOCALS~1\Temp\EAD5.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\OpenOffice.org 2.2\program\soffice.exe
c:\program files\OpenOffice.org 2.2\program\soffice.bin
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\system32\wscntfy.exe
c:\program files\Java\jre1.6.0\bin\jucheck.exe
c:\windows\system32\dwwin.exe
.
**************************************************************************
.
Completion time: 2009-06-26 13:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-26 17:31
Pre-Run: 101,477,613,568 bytes free
Post-Run: 101,745,029,120 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
271 --- E O F --- 2009-06-23 19:07