When you said please include the log, I thought you wanted me to attach the actual file. My mistake.
ComboFix 09-07-01.01 - OmNiExiZt 07/02/2009 0:14.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.826 [GMT -7:00]
Running from: c:\documents and settings\OmNiExiZt\Desktop\newname.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\driver\driver.dll
c:\program files\driver\driver.sys
c:\program files\Manson\liser.dll
c:\program files\Manson\liser.exe
c:\windows\010112010146118114.dat
c:\windows\kb913800.exe
c:\windows\ld10.exe
c:\windows\setup.exe
c:\windows\soc_1245369225.exe
c:\windows\system32\drivers\qgsmupgubu.sys
c:\windows\system32\drivers\SKYNETsbgbankf.sys
c:\windows\system32\drivers\str.sys
c:\windows\system32\drivers\UACvjlqgrueejedvml.sys
c:\windows\system32\net.net
c:\windows\system32\SKYNETaoxxoaku.dll
c:\windows\system32\SKYNETcuqwtcbm.dat
c:\windows\system32\SKYNETerrpuxty.dat
c:\windows\system32\SKYNETlvtlswqt.dll
c:\windows\system32\UACawmvvmlmyyrdnoo.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjoupaokbrsntikr.dll
c:\windows\system32\UAClrxhhabklostxea.dll
c:\windows\system32\UACmifvfynwseteoyi.dat
c:\windows\system32\UACmsuhutrbmoeaaee.log
c:\windows\system32\UACndohppklydvkjyn.dll
c:\windows\system32\UACnmjyxodedkxgxcn.log
c:\windows\system32\UACplankoavlocwyum.dll
c:\windows\system32\UACqepiuywyntpsyrm.log
c:\windows\system32\uactmp.db
c:\windows\system32\UACwnoujctvvkswvkj.dll
c:\windows\system32\UACydoyecredlgwbbs.db
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_DRIVER
-------\Legacy_DRIVERDRV
-------\Legacy_MUYDGXYPO
-------\Service_driver
-------\Service_driverdrv
-------\Service_muydgxypo
-------\Service_SKYNETkfdshiel
((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))))))
.
2009-07-01 17:28 . 2009-07-01 17:28 -------- d-----w- c:\program files\Trend Micro
2009-06-29 00:01 . 2009-02-12 09:35 38208 ----a-w- c:\documents and settings\OmNiExiZt\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-06-29 00:01 . 2009-06-29 00:01 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-28 23:58 . 2009-06-28 23:58 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-06-28 23:58 . 2009-06-29 00:47 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-28 23:58 . 2009-06-29 00:47 -------- d-----w- c:\program files\NOS
2009-06-23 18:34 . 2009-06-23 18:34 -------- d-----w- c:\documents and settings\Guest\Application Data\Protector Suite
2009-06-23 18:34 . 2009-06-23 18:34 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Symantec
2009-06-19 04:44 . 2009-06-27 05:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-19 04:44 . 2009-06-19 04:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-19 01:53 . 2009-06-19 01:53 1 ---h--w- c:\windows\bf23567.dat
2009-06-19 01:53 . 2009-06-19 01:53 2 ----a-w- c:\windows\0101120101465452.dat
2009-06-18 23:53 . 2009-07-02 07:20 -------- d-----w- c:\program files\driver
2009-06-18 17:20 . 2009-06-18 17:20 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-06-18 17:18 . 2008-04-13 17:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-06-18 17:18 . 2008-04-13 17:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-06-18 17:17 . 2004-09-29 19:15 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2009-06-18 17:17 . 2004-09-29 19:14 69632 ----a-w- c:\windows\system32\HPZipm12.exe
2009-06-18 17:17 . 2004-09-29 19:12 278584 ----a-w- c:\windows\system32\HPZidr12.dll
2009-06-18 17:17 . 2004-09-29 19:09 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2009-06-18 17:17 . 2004-09-29 19:09 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2009-06-18 17:17 . 2004-09-29 19:08 61440 ----a-w- c:\windows\system32\HPZinw12.exe
2009-06-18 17:17 . 2009-06-18 17:17 -------- d-----w- c:\program files\HP
2009-06-18 17:16 . 2009-06-18 17:21 102262 ----a-w- c:\windows\hpoins05.dat
2009-06-18 17:14 . 2009-06-18 17:14 -------- d-----w- C:\Temp
2009-06-17 07:05 . 2009-07-02 07:20 -------- d-sh--r- c:\program files\Manson
2009-06-17 06:35 . 2009-06-17 06:35 -------- d-----w- c:\windows\Sun
2009-06-15 23:32 . 2009-06-15 23:32 -------- d-----w- c:\program files\uTorrent
2009-06-15 23:32 . 2009-06-28 06:58 -------- d-----w- c:\documents and settings\OmNiExiZt\Application Data\uTorrent
2009-06-15 04:23 . 2009-06-15 04:23 -------- d-----w- c:\windows\system32\LogFiles
2009-06-06 06:53 . 2009-06-06 06:53 -------- d-----w- c:\documents and settings\OmNiExiZt\Local Settings\Application Data\Identities
2009-06-05 06:21 . 2009-06-05 06:21 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-06-05 06:20 . 2009-06-05 06:21 -------- d-----w- c:\windows\SHELLNEW
2009-06-05 06:19 . 2009-06-05 06:19 -------- d-----w- c:\program files\Microsoft.NET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 18:45 . 2009-01-10 13:18 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-01 18:45 . 2009-01-10 13:18 -------- d-----w- c:\program files\Symantec
2009-07-01 18:45 . 2009-01-10 13:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-29 15:55 . 2005-10-01 09:57 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-28 07:47 . 2009-06-27 16:41 54 ----a-w- c:\documents and settings\OmNiExiZt\Application Data\MTC-savedfolder.dat
2009-06-27 04:16 . 2009-06-12 23:17 34 ----a-w- c:\documents and settings\OmNiExiZt\Application Data\MTC-savedinstructor.dat
2009-06-23 18:34 . 2009-06-23 18:15 51552 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-23 18:34 . 2009-06-23 18:15 128 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\fusioncache.dat
2009-06-18 17:51 . 2009-06-18 17:51 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-06-18 17:51 . 2009-06-18 17:51 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-06-06 10:11 . 2005-10-01 08:20 51552 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-13 03:21 . 2009-05-13 03:21 -------- d-----w- c:\program files\Microsoft Silverlight
2009-05-07 15:32 . 2005-09-30 17:46 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2005-09-30 17:46 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2005-09-30 17:46 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2005-09-30 17:46 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2005-09-30 17:46 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2005-04-16 172032]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-04-14 45056]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-07-20 32768]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-05-15 184320]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-01-14 151552]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-01-21 167936]
"Biomenu"="c:\program files\Protector Suite QL\menusw.exe" [2005-07-26 1073664]
"PartSeal"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ATI CATALYST System Tray.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-7-20 32768]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-6-21 487424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-07-26 03:06 39936 ----a-w- c:\windows\system32\fusstub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-21 00:42 73728 ----a-w- c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli fusstub
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:driver
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [3/19/2009 10:52 PM 33792]
S2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [10/4/2004 5:47 AM 98304]
S2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [7/25/2005 8:08 PM 13440]
S2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [7/25/2005 8:08 PM 33024]
S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
S2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [10/4/2004 4:40 AM 118784]
S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;c:\windows\system32\drivers\fa410nd5.sys [9/30/2005 4:07 AM 24618]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe --> c:\program files\NOS\bin\getPlus_HelperSvc.exe [?]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [9/30/2005 10:52 AM 214272]
.
Contents of the 'Scheduled Tasks' folder
2009-01-10 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-09-30 00:12]
2009-01-10 c:\windows\Tasks\Registration reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-09-30 00:12]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-net - c:\windows\system32\net.net
HKLM-Run-net - c:\windows\system32\net.net
Notify-NavLogon - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.sony.com/vaiopeople
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\OmNiExiZt\Application Data\Mozilla\Firefox\Profiles\96667qnt.default\
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-02 00:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(252)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\fusstub.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus.dll
c:\windows\system32\biologon.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\passport.dll
c:\program files\Protector Suite QL\config.dll
c:\program files\Protector Suite QL\BhTcAll.dll
c:\program files\Protector Suite QL\BhDevTfm.dll
c:\program files\Protector Suite QL\remote.dll
c:\windows\system32\VESWinlogon.dll
- - - - - - - > 'lsass.exe'(308)
c:\windows\system32\fusstub.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus.dll
.
Completion time: 2009-07-02 0:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-02 07:36
Pre-Run: 57,409,130,496 bytes free
Post-Run: 57,344,507,904 bytes free
227 --- E O F --- 2009-06-11 10:05