I shut down comodo and a few other things and ran combofix under the name kickyourass.exe here is the log it produced:
ComboFix 11-05-21.03 - Me 05/21/2011 23:35:18.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.318 [GMT 3:00]
Running from: c:\documents and settings\Me.TIM\Desktop\Kickyourass.exe
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users.WINDOWS2\Application Data\SecTaskMan\_entreelist.dll
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\hannah\WINDOWS
c:\documents and settings\Mahjong\UNWISE.EXE
c:\documents and settings\me\Application Data\PriceGong
c:\documents and settings\me\Application Data\PriceGong\Data\1.xml
c:\documents and settings\me\Application Data\PriceGong\Data\a.xml
c:\documents and settings\me\Application Data\PriceGong\Data\b.xml
c:\documents and settings\me\Application Data\PriceGong\Data\c.xml
c:\documents and settings\me\Application Data\PriceGong\Data\d.xml
c:\documents and settings\me\Application Data\PriceGong\Data\e.xml
c:\documents and settings\me\Application Data\PriceGong\Data\f.xml
c:\documents and settings\me\Application Data\PriceGong\Data\g.xml
c:\documents and settings\me\Application Data\PriceGong\Data\h.xml
c:\documents and settings\me\Application Data\PriceGong\Data\i.xml
c:\documents and settings\me\Application Data\PriceGong\Data\J.xml
c:\documents and settings\me\Application Data\PriceGong\Data\k.xml
c:\documents and settings\me\Application Data\PriceGong\Data\l.xml
c:\documents and settings\me\Application Data\PriceGong\Data\m.xml
c:\documents and settings\me\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\me\Application Data\PriceGong\Data\n.xml
c:\documents and settings\me\Application Data\PriceGong\Data\o.xml
c:\documents and settings\me\Application Data\PriceGong\Data\p.xml
c:\documents and settings\me\Application Data\PriceGong\Data\q.xml
c:\documents and settings\me\Application Data\PriceGong\Data\r.xml
c:\documents and settings\me\Application Data\PriceGong\Data\s.xml
c:\documents and settings\me\Application Data\PriceGong\Data\t.xml
c:\documents and settings\me\Application Data\PriceGong\Data\u.xml
c:\documents and settings\me\Application Data\PriceGong\Data\v.xml
c:\documents and settings\me\Application Data\PriceGong\Data\w.xml
c:\documents and settings\me\Application Data\PriceGong\Data\x.xml
c:\documents and settings\me\Application Data\PriceGong\Data\y.xml
c:\documents and settings\me\Application Data\PriceGong\Data\z.xml
c:\documents and settings\me\WINDOWS
c:\documents and settings\youssef\WINDOWS
c:\program files\dialers
c:\program files\WinPCap
c:\program files\WinPCap\install.log
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ABP470N5
-------\Service_abp470n5
-------\Legacy_ABP470N5
-------\Service_abp470n5
.
.
((((((((((((((((((((((((( Files Created from 2011-04-21 to 2011-05-21 )))))))))))))))))))))))))))))))
.
.
2011-05-20 16:56 . 2011-05-20 17:00 -------- d-----w- C:\52d9b97d3a4e2130724323
2011-05-20 16:40 . 2011-05-18 20:10 331805736 ----a-w- C:\WindowsXP-KB936929-SP3-x86-ENU.exe
2011-05-18 15:47 . 2011-05-18 15:47 -------- d-----w- c:\documents and settings\Family
2011-05-16 18:12 . 2011-05-16 18:13 -------- d-----w- c:\program files\Ask.com
2011-05-16 18:12 . 2011-05-16 18:12 -------- d-----w- c:\program files\Foxit Software
2011-05-14 22:00 . 2011-05-14 22:00 -------- d-----w- C:\VritualRoot
2011-05-14 21:54 . 2011-05-14 21:54 -------- d-----w- c:\program files\ERUNT
2011-05-11 11:44 . 2011-05-11 11:45 -------- d-----r- C:\MS Office 2007 ENG
2011-05-11 06:49 . 2011-05-11 06:51 -------- d-----w- c:\program files\Security Task Manager
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows2\system32\GPhotos.scr
2011-03-04 06:45 . 2003-07-16 16:43 434176 ----a-w- c:\windows2\system32\vbscript.dll
2011-03-03 13:21 . 2003-07-16 16:45 1857920 ----a-w- c:\windows2\system32\win32k.sys
2011-04-14 16:26 . 2011-05-10 17:16 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2007-08-12 06:12 . 2006-12-24 10:49 135680 -c--a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
------- Sigcheck -------
.
[-] 2008-04-14 . 865A48ECBD314A8089BB108FF5DF9532 . 220160 . . [5.1.2600.5512] . . c:\windows2\regedit.exe
[-] 2008-04-14 . 865A48ECBD314A8089BB108FF5DF9532 . 220160 . . [5.1.2600.5512] . . c:\windows2\ServicePackFiles\i386\regedit.exe
[7] 2008-04-14 . 058710B720282CA82B909912D3EF28DB . 146432 . . [5.1.2600.5512] . . c:\windows2\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\regedit.exe
[7] 2004-08-03 . 783AFC80383C176B22DBF8333343992D . 146432 . . [5.1.2600.2180] . . c:\windows2\$NtServicePackUninstall$\regedit.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 19:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows2\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows2\System32\igfxtray.exe" [2005-06-21 237568]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-10-09 513344]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-05-09 2552648]
.
c:\documents and settings\Me.TIM\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows2\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BCMSMMSG"=BCMSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS2\\System32\\igfxtray.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\LSDSMCAUVUTYBOG.scr"=
"c:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe"=
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows2\system32\drivers\cmdGuard.sys [5/2/2011 8:36 PM 242472]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows2\system32\drivers\cmdhlp.sys [5/2/2011 8:36 PM 29400]
S3 BCM42XX;Broadcom iLine10(tm) Network Adapter Driver;c:\windows2\system32\drivers\bcm42xx5.sys [5/10/2011 6:31 PM 54271]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ABP470N5
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-21 c:\windows2\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-28 19:44]
.
2011-05-21 c:\windows2\Tasks\WGASetup.job
- c:\windows2\system32\KB905474\wgasetup.exe [2011-05-13 19:18]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe" //mailurl:mailto:egyptainhollandiatissueculture@msn.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows2\system32\GPhotos.scr/200
FF - ProfilePath - c:\documents and settings\Me.TIM\Application Data\Mozilla\Firefox\Profiles\6tv5e5pb.default\
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-21 23:56
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS2\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS2\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(748)
c:\windows2\system32\guard32.dll
.
- - - - - - - > 'explorer.exe'(960)
c:\windows2\system32\WININET.dll
c:\windows2\system32\guard32.dll
c:\windows2\system32\ieframe.dll
.
Completion time: 2011-05-22 00:10:43 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-21 21:10
.
Pre-Run: 30,751,260,672 bytes free
Post-Run: 30,250,291,200 bytes free
.
Current=4 Default=4 Failed=1 LastKnownGood=6 Sets=1,2,3,4,6
- - End Of File - - C119386E6443DF67E2011AD241A55CBB