Ok it's all down. I noticed the fake Windows Security Center is gone now. Spybot will run now, but I didn't do a scan yet so these logs will be accurate.
ComboFix 08-12-29.02 - Lord Kandar 2008-12-30 12:39:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1706 [GMT -5:00]
Running from: c:\documents and settings\Lord Kandar\Desktop\Combo-Fix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Lord Kandar\Application Data\gadcom
c:\documents and settings\Lord Kandar\Application Data\SpeedRunner
c:\documents and settings\Lord Kandar\Application Data\SpeedRunner\config.cfg
c:\documents and settings\Lord Kandar\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\Lord Kandar\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\Lord Kandar\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\Microsoft Common
c:\program files\Microsoft Common\svchost.exe
c:\program files\Mjcore
c:\program files\Mjcore\Mjcore.dll
c:\program files\Spyware Guard 2008
c:\program files\Spyware Guard 2008\conf.cfg
c:\program files\Spyware Guard 2008\mbase.vdb
c:\program files\Spyware Guard 2008\quarantine.vdb
c:\program files\Spyware Guard 2008\queue.vdb
c:\program files\Spyware Guard 2008\spywareguard.exe
c:\program files\Spyware Guard 2008\vbase.vdb
c:\windows\reged.exe
c:\windows\spoolsystem.exe
c:\windows\sys.com
c:\windows\syscert.exe
c:\windows\sysexplorer.exe
c:\windows\system32\dfLklUvw.ini
c:\windows\system32\dfLklUvw.ini2
c:\windows\system32\drivers\71985e90.sys
c:\windows\system32\drivers\ati7ytxx.sys
c:\windows\system32\drivers\TDSSmqlt.sys
c:\windows\system32\gmwqmtdd.ini
c:\windows\system32\jkse73hedfdgf.dll
c:\windows\system32\TDSShrxx.dll
c:\windows\system32\TDSSkhyp.log
c:\windows\system32\TDSSkkai.log
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSmtvd.dat
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSoiqt.dll
c:\windows\system32\TDSSsahc.dll
c:\windows\system32\TDSSvkql.dll
c:\windows\system32\TDSSxfum.dll
c:\windows\system32\winscenter.exe
c:\windows\Temp\1116707112.exe
c:\windows\vmreg.dll
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSserv.sys
-------\Legacy_TDSSserv.sys
-------\Legacy_ati7ytxx
-------\Legacy_fci
-------\Legacy_icf
-------\Service_ati7ytxx
-------\Service_fci
-------\Service_icf
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-30 )))))))))))))))))))))))))))))))
.
2008-12-29 12:12 . 2008-12-29 12:12 <DIR> d-------- c:\program files\Avira
2008-12-29 12:12 . 2008-12-29 12:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-23 12:48 . 2008-12-23 12:51 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-23 12:48 . 2008-12-23 12:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-22 22:37 . 2008-12-23 14:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-22 22:08 . 2008-12-23 14:30 <DIR> d-------- c:\documents and settings\Lord Kandar\Application Data\Twain
2008-12-22 22:03 . 2008-12-22 23:49 <DIR> d-------- c:\program files\Webtools
2008-12-22 21:58 . 2008-12-22 21:58 45,056 --a------ c:\windows\system32\pmNhIApp.dll
2008-12-17 19:33 . 2008-12-17 19:33 <DIR> d-------- c:\program files\GPLGS
2008-12-17 19:29 . 2008-12-17 19:29 <DIR> d-------- c:\program files\Acro Software
2008-12-17 19:29 . 2007-07-12 22:33 87,552 --a------ c:\windows\system32\cpwmon2k.dll
2008-12-09 19:48 . 2008-12-09 19:48 <DIR> d-------- c:\documents and settings\Lord Kandar\Application Data\Xilisoft Corporation
2008-12-09 19:40 . 2008-12-09 19:40 0 --a------ c:\windows\muveeapp.INI
2008-12-09 19:36 . 2008-12-09 19:36 <DIR> d-------- c:\documents and settings\Lord Kandar\Application Data\muvee Technologies
2008-12-09 19:08 . 2008-12-09 19:30 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-29 15:13 . 2008-11-29 15:13 0 --a------ c:\windows\ativpsrm.bin
2008-11-29 15:12 . 2008-10-28 21:05 593,920 --a------ c:\windows\system32\ati2sgag.exe
2008-11-29 15:11 . 2008-11-29 15:11 <DIR> d-------- C:\ATI
2008-11-03 22:39 . 2008-12-18 22:37 <DIR> d-------- C:\mugen-hi
2008-11-03 22:25 . 2008-11-03 22:25 <DIR> d-------- C:\backup
2008-11-02 22:38 . 2008-11-02 22:38 <DIR> d-------- c:\program files\Fighter Factory
2008-11-01 19:19 . 2008-11-01 19:20 <DIR> d-------- C:\temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-23 19:52 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-16 01:27 --------- d-----w c:\program files\Magic Set Editor 2
2008-11-25 12:14 --------- d-----w c:\program files\SystemRequirementsLab
2008-11-25 12:14 --------- d-----w c:\documents and settings\Lord Kandar\Application Data\SystemRequirementsLab
2008-11-09 17:30 --------- d-----w c:\documents and settings\Lord Kandar\Application Data\BitTorrent
2008-11-07 00:21 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-10-29 03:10 3,341,824 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2008-10-29 01:18 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2007-05-23 01:25 30 ----a-w c:\documents and settings\Lord Kandar\haha.bat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-01 794624]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-07-25 344064]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-10-22 229438]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-06-02 565309]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=xpzogn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7ytxx.sys]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-01-10 24652]
S1 71985e90;71985e90;c:\windows\system32\drivers\71985e90.sys []
S3 SaiHFF0C;SaiHFF0C;c:\windows\system32\DRIVERS\SaiHFF0C.sys [2008-11-01 56576]
S3 SaiUFF0C;SaiUFF0C;c:\windows\system32\DRIVERS\SaiUFF0C.sys [2008-11-01 19584]
.
Contents of the 'Scheduled Tasks' folder
2006-12-17 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2005-03-03 13:04]
2008-12-29 c:\windows\Tasks\sdfaalpd.job
- c:\windows\system32\rundll32.exe [2004-08-09 21:00]
.
- - - - ORPHANS REMOVED - - - -
BHO-{c5bf49a2-94f3-42bd-f434-3604812c897d} - c:\windows\system32\jkse73hedfdgf.dll
HKCU-Run-prunnet - c:\windows\system32\prunnet.exe
HKCU-Run-rs32net - c:\windows\System32\rs32net.exe
HKCU-Run-Twain - c:\documents and settings\Lord Kandar\Application Data\Twain\Twain.exe
HKCU-Run-gadcom - c:\documents and settings\Lord Kandar\Application Data\gadcom\gadcom.exe
HKCU-Run-jsf8j34rgfght - c:\docume~1\LORDKA~1\LOCALS~1\Temp\winloggn.exe
HKCU-Run-xsjfn83jkemfofght - c:\docume~1\LORDKA~1\LOCALS~1\Temp\winlogin.exe
HKCU-Run-SpeedRunner - c:\documents and settings\Lord Kandar\Application Data\SpeedRunner\SpeedRunner.exe
HKCU-Run-SfKg6wIP - c:\documents and settings\Lord Kandar\Application Data\Microsoft\Windows\wlkie.exe
HKCU-Run-Jnskdfmf9eldfd - c:\docume~1\LORDKA~1\LOCALS~1\Temp\csrssc.exe
HKLM-Run-079ff997 - c:\windows\system32\ddtmqwmg.dll
SharedTaskScheduler-{D5BF49A2-94F1-42BD-F434-3604812C807D} - c:\windows\system32\tyshb36rfjdf.dll
SharedTaskScheduler-{C5BF49A2-94F3-42BD-F434-3604812C897D} - c:\windows\system32\jkse73hedfdgf.dll
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\qoMfDuVP.dll
Notify-jmqunul - jmqunul32.dll
Notify-qoMfDuVP - qoMfDuVP.dll
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\Lord Kandar\Application Data\Mozilla\Firefox\Profiles\nxyf6nhz.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPOFFICE.DLL
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin3.dll
ATTENTION: FIREFOX POLICES IS IN FORCE
c:\program files\Mozilla Firefox\\defaults\pref\activex.js - pref("general.useragent.vendorComment", "ax");
c:\program files\Mozilla Firefox\\defaults\pref\activex.js - pref("security.xpconnect.activex.global.hosting_flags", 9);
c:\program files\Mozilla Firefox\\defaults\pref\activex.js - pref("security.classID.allowByDefault", false);
c:\program files\Mozilla Firefox\\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID22D6F312-B0F6-11D0-94AB-0080C74C7E95", "AllAccess");
c:\program files\Mozilla Firefox\\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6BF52A52-394A-11D3-B153-00C04F79FAA6", "AllAccess");
c:\program files\Mozilla Firefox\\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA9FC132B-096D-460B-B7D5-1DB0FAE0C062", "AllAccess");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-30 12:46:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????9?5?2?1??????? ???B?????????????H<C? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\WIDCOMM\Bluetooth Software\BTStackServer.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\HPQ\Shared\hpqwmi.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-12-30 12:50:26 - machine was rebooted [Lord Kandar]
ComboFix-quarantined-files.txt 2008-12-30 17:50:23
Pre-Run: 34,310,045,696 bytes free
Post-Run: 34,378,854,400 bytes free
235