I wasn't sure if you also needed attach.txt, so I attached it as an archive...
ComboFix 10-02-03.03 - Zalethon 02/03/2010 14:48:43.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.218 [GMT -5:00]
Running from: c:\documents and settings\Zalethon\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\kkalf.exe
c:\windows\system32\lijaduhi.dll
c:\windows\system32\lomds04.dll
c:\windows\winhelp.ini
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2010-01-03 to 2010-02-03 )))))))))))))))))))))))))))))))
.
2010-01-29 22:38 . 2010-01-29 22:38 -------- d-----w- c:\program files\Apple Software Update
2010-01-29 21:43 . 2010-01-29 21:44 -------- d-----w- c:\program files\ERUNT
2010-01-29 18:09 . 2010-01-29 18:09 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-01-28 09:00 . 2010-01-28 09:00 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2010-01-28 07:54 . 2010-01-28 07:54 -------- dc----w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-28 03:28 . 2010-01-28 03:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-01-28 03:17 . 2010-01-28 03:17 161296 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-01-28 00:08 . 2010-01-28 00:08 -------- d-----w- c:\documents and settings\Zalethon\Application Data\Malwarebytes
2010-01-28 00:08 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-28 00:08 . 2010-01-28 00:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-28 00:08 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-28 00:08 . 2010-01-28 00:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-27 22:08 . 2010-01-27 22:08 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-27 22:07 . 2010-02-02 05:36 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-27 22:07 . 2010-01-27 22:07 -------- d-----w- c:\documents and settings\Zalethon\Application Data\SUPERAntiSpyware.com
2010-01-27 22:06 . 2010-01-27 22:06 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-27 10:13 . 2010-01-27 18:19 -------- d-----w- C:\TEMP
2010-01-27 10:13 . 2010-01-28 21:57 163280 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-27 10:13 . 2010-01-28 21:54 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-27 10:13 . 2010-01-28 21:54 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-27 10:13 . 2010-01-28 21:57 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-27 10:13 . 2010-01-28 21:54 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-27 10:13 . 2010-01-28 21:54 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-27 10:13 . 2010-01-28 21:53 28240 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-27 10:12 . 2010-01-28 22:09 152672 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-27 10:12 . 2010-01-19 11:57 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-01-27 10:12 . 2010-01-27 10:12 -------- d-----w- c:\program files\Alwil Software
2010-01-27 10:12 . 2010-01-27 10:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-01-24 21:01 . 2010-01-27 09:50 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-01-23 20:55 . 2010-01-23 20:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\dvdcss
2010-01-23 07:20 . 2010-01-23 07:20 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\PCHealth
2010-01-23 00:10 . 2010-01-23 00:10 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-01-22 22:13 . 2010-01-22 22:13 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-22 18:16 . 2010-01-22 18:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-22 17:05 . 2010-01-22 17:05 -------- d-sh--w- c:\documents and settings\Owner\PrivacIE
2010-01-16 05:12 . 2010-01-16 05:12 -------- d-----w- c:\documents and settings\Zalethon\Application Data\CreeperMap
2010-01-16 05:12 . 2010-01-16 05:12 -------- d-----w- c:\documents and settings\Zalethon\Application Data\CreeperMap.BA6B793AB2C9FDD744493F22666C1F8DFA806A5E.1
2010-01-16 01:43 . 2010-01-16 01:43 -------- d-----w- c:\documents and settings\Zalethon\Application Data\CreeperWorld.BA6B793AB2C9FDD744493F22666C1F8DFA806A5E.1
2010-01-16 01:41 . 2010-01-16 01:41 -------- d-----w- c:\program files\iPod
2010-01-14 21:26 . 2010-01-29 22:39 -------- d-----w- c:\program files\QuickTime
2010-01-11 23:46 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-09 06:04 . 2010-01-16 22:45 -------- d-----w- C:\Python25
2010-01-08 02:31 . 2010-01-09 05:23 -------- d-----w- c:\program files\Arcade Tonk Tanks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-01 22:47 . 2010-01-27 22:08 117760 ----a-w- c:\documents and settings\Zalethon\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-29 22:38 . 2008-08-25 03:16 -------- d-----w- c:\program files\Common Files\Apple
2010-01-29 18:17 . 2008-05-29 02:42 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-01-28 09:02 . 2010-01-28 09:00 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-28 09:00 . 2010-01-28 09:00 52224 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-28 07:21 . 2009-07-17 00:23 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-27 22:09 . 2010-01-27 22:09 52224 ----a-w- c:\documents and settings\Zalethon\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-27 08:41 . 2009-03-19 17:38 -------- d-----w- c:\documents and settings\Zalethon\Application Data\Move Networks
2010-01-27 08:41 . 2008-12-08 07:56 -------- d-----w- c:\documents and settings\Guest\Application Data\U3
2010-01-26 23:23 . 2008-05-29 04:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-24 21:14 . 2009-02-05 04:07 -------- d-----w- c:\program files\Yahoo!
2010-01-24 02:05 . 2009-10-08 05:09 -------- d-----w- c:\documents and settings\Zalethon\Application Data\vlc
2010-01-23 21:10 . 2009-05-11 01:46 -------- d-----w- c:\documents and settings\Zalethon\Application Data\dvdcss
2010-01-23 20:56 . 2009-10-09 18:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2010-01-16 06:10 . 2009-12-24 19:36 -------- d-----w- c:\program files\KnuckleCracker
2010-01-16 05:17 . 2009-12-24 19:37 -------- d-----w- c:\documents and settings\Zalethon\Application Data\CreeperWorld
2010-01-16 01:42 . 2009-12-24 19:36 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-16 01:41 . 2009-03-17 23:55 -------- d-----w- c:\program files\iTunes
2010-01-15 22:15 . 2009-04-01 03:20 -------- d-----w- c:\documents and settings\Zalethon\Application Data\FileZilla
2010-01-14 16:12 . 2009-10-02 20:56 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-01 08:38 . 2010-01-01 08:35 -------- d-----w- c:\program files\DivX
2010-01-01 08:36 . 2010-01-01 08:35 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-12-27 22:07 . 2009-05-30 23:26 -------- d-----w- c:\program files\CamStudio
2009-12-25 22:05 . 2009-08-09 00:12 -------- d-----w- c:\documents and settings\Zalethon\Application Data\gtk-2.0
2009-12-24 21:23 . 2009-12-24 21:23 -------- d-----w- c:\documents and settings\Zalethon\Application Data\Wireshark
2009-12-24 20:56 . 2009-12-24 20:55 -------- d-----w- c:\program files\Wireshark
2009-12-24 20:56 . 2009-12-24 20:56 -------- d-----w- c:\program files\WinPcap
2009-12-24 19:37 . 2009-12-24 19:37 -------- d-----w- c:\documents and settings\Zalethon\Application Data\CreeperWorldDEMO.BA6B793AB2C9FDD744493F22666C1F8DFA806A5E.1
2009-12-21 19:14 . 2006-02-28 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-16 19:42 . 2009-12-25 08:33 872960 ----a-w- c:\documents and settings\Zalethon\Application Data\Mozilla\Firefox\Profiles\wyzs9ykz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 19:42 . 2009-12-25 08:33 43008 ----a-w- c:\documents and settings\Zalethon\Application Data\Mozilla\Firefox\Profiles\wyzs9ykz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 19:42 . 2009-12-25 08:33 340480 ----a-w- c:\documents and settings\Zalethon\Application Data\Mozilla\Firefox\Profiles\wyzs9ykz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 19:41 . 2009-12-25 08:33 346624 ----a-w- c:\documents and settings\Zalethon\Application Data\Mozilla\Firefox\Profiles\wyzs9ykz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-08 01:20 . 2009-10-06 00:21 3695616 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AutoLaunch.exe
2009-11-21 15:51 . 2006-02-28 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-20 17:08 . 2009-12-24 19:37 38784 ----a-w- c:\documents and settings\Zalethon\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-20 17:08 . 2009-12-24 19:37 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-14 00:49 . 2010-01-01 08:37 43528 ------w- c:\windows\system32\drivers\PxHelp20.sys
2009-11-14 00:49 . 2010-01-01 08:37 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-11-14 00:49 . 2010-01-01 08:37 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-11-14 00:49 . 2010-01-01 08:37 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-11-14 00:49 . 2010-01-01 08:37 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-11-14 00:49 . 2010-01-01 08:37 129784 ------w- c:\windows\system32\pxafs.dll
2009-11-14 00:47 . 2009-11-14 00:47 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2008-07-06 04:26 . 2008-07-06 03:24 248 ----a-w- c:\program files\Garden Plannerini.xml
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"Google Update"="c:\documents and settings\Zalethon\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-09-08 133104]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"EPSON Stylus CX5400"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE" [2003-05-27 99840]
"EPSON Stylus CX5400 (Copy 1)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE" [2003-05-27 99840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-01-28 2757512]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Zalethon\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 02:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 17:47 57344 ----a-w- c:\windows\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2009-08-13 20:51 177440 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-03-13 00:56 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-11-10 10:43 136600 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2004-10-22 15:53 53248 ----a-w- c:\windows\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"npkcmsvc"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Freeciv-2.1.8-gtk2\\civserver.exe"=
"c:\\Program Files\\Freeciv-2.1.8-gtk2\\civclient.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Zalethon\\My Documents\\Program Files\\Armagetron Advanced\\armagetronad.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\Zalethon\\My Documents\\Program Files\\Armagetron Advanced Dev\\3 Alpha\\ArmagetronAd.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Bontago\\Bontago.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\Zalethon\\My Documents\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57043:TCP"= 57043:TCP

ando Media Booster
"57043:UDP"= 57043:UDP

ando Media Booster
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [9/30/2009 7:19 PM 64160]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1/27/2010 5:13 AM 163280]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/27/2010 5:13 AM 19024]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [10/20/2009 1:19 PM 50704]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 5:19 PM 13592]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1028432]
.
Contents of the 'Scheduled Tasks' folder
2010-02-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 00:21]
2010-02-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-57989841-1993962763-725345543-1004Core.job
- c:\documents and settings\Zalethon\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-08 14:02]
2010-02-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-57989841-1993962763-725345543-1004UA.job
- c:\documents and settings\Zalethon\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-08 14:02]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Zalethon\Application Data\Mozilla\Firefox\Profiles\wyzs9ykz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\Zalethon\Application Data\Mozilla\Firefox\Profiles\wyzs9ykz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Zalethon\Application Data\Mozilla\Firefox\Profiles\wyzs9ykz.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\Zalethon\Application Data\Mozilla\Firefox\Profiles\wyzs9ykz.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\Zalethon\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
SharedTaskScheduler-{e91defb4-5008-41c3-980f-e669d9491bfc} - c:\windows\system32\lijaduhi.dll
SharedTaskScheduler-{2a2850c3-1bea-47bb-abae-e2d7685acb5d} - c:\windows\system32\lijaduhi.dll
SSODL-fudetutum-{e91defb4-5008-41c3-980f-e669d9491bfc} - c:\windows\system32\lijaduhi.dll
SSODL-kemavudej-{2a2850c3-1bea-47bb-abae-e2d7685acb5d} - c:\windows\system32\lijaduhi.dll
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
AddRemove-HijackThis - c:\documents and settings\Administrator\Desktop\HijackThis.exe
AddRemove-wxPython2.8-unicode-py25_is1 - c:\python25\Lib\site-packages\wx-2.8-msw-unicode\unins000.exe
AddRemove-Audacity_is1 - c:\documents and settings\Zalethon\My Documents\Program FilesAudacity\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-03 15:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(676)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3588)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\wscntfy.exe
c:\documents and settings\Zalethon\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
.
**************************************************************************
.
Completion time: 2010-02-03 15:13:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-03 20:13
Pre-Run: 84,063,121,408 bytes free
Post-Run: 86,641,672,192 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - A36C23FB1DE87C34E935BEBECF881776
dds.txt:
DDS (Ver_09-09-29.01) - NTFSx86
Run by Zalethon at 15:14:50.31 on Wed 02/03/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.149 [GMT -5:00]
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Zalethon\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Zalethon\Desktop\dds.com
============== Pseudo HJT Report ===============
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: The Weather Channel Toolbar: {2e5e800e-6ac0-411e-940a-369530a35e43} - c:\windows\system32\TwcToolbarIe7.dll
uRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
uRun: [Google Update] "c:\documents and settings\zalethon\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [EPSON Stylus CX5400] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O5 "LPT1:" /M "Stylus CX5400"
mRun: [EPSON Stylus CX5400 (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE /P28 "EPSON Stylus CX5400 (Copy 1)" /O6 "USB001" /M "Stylus CX5400"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\zalethon\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2E5E800E-6AC0-411E-940A-369530A35E43} - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\zalethon\applic~1\mozilla\firefox\profiles\wyzs9ykz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\zalethon\application data\mozilla\firefox\profiles\wyzs9ykz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\zalethon\application data\mozilla\firefox\profiles\wyzs9ykz.default\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\zalethon\application data\mozilla\firefox\profiles\wyzs9ykz.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\zalethon\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-9-30 64160]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-1-27 163280]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-1-27 19024]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-1-27 40384]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-1-27 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-1-27 40384]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1028432]
=============== Created Last 30 ================
2010-02-03 14:38 <DIR> a-dshr-- C:\cmdcons
2010-02-03 14:35 261,632 a------- c:\windows\PEV.exe
2010-02-03 14:35 161,792 a------- c:\windows\SWREG.exe
2010-02-03 14:35 98,816 a------- c:\windows\sed.exe
2010-02-03 14:35 77,312 a------- c:\windows\MBR.exe
2010-01-28 02:54 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-27 22:17 161,296 a------- c:\windows\system32\drivers\tmcomm.sys
2010-01-27 19:08 <DIR> --d----- c:\docume~1\zalethon\applic~1\Malwarebytes
2010-01-27 19:08 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-27 19:08 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-27 19:08 19,160 a------- c:\windows\system32\drivers\mbam.sys
2010-01-27 19:08 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2010-01-27 17:08 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-27 17:07 <DIR> --d----- c:\program files\SUPERAntiSpyware
2010-01-27 17:07 <DIR> --d----- c:\docume~1\zalethon\applic~1\SUPERAntiSpyware.com
2010-01-27 17:06 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2010-01-27 05:13 <DIR> --d----- C:\TEMP
2010-01-27 05:12 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-01-16 00:12 <DIR> --d----- c:\docume~1\zalethon\applic~1\CreeperMap.BA6B793AB2C9FDD744493F22666C1F8DFA806A5E.1
2010-01-16 00:12 <DIR> --d----- c:\docume~1\zalethon\applic~1\CreeperMap
2010-01-15 20:43 <DIR> --d----- c:\docume~1\zalethon\applic~1\CreeperWorld.BA6B793AB2C9FDD744493F22666C1F8DFA806A5E.1
2010-01-15 20:41 <DIR> --d----- c:\program files\iPod
2010-01-11 18:46 471,552 -c------ c:\windows\system32\dllcache\aclayers.dll
2010-01-09 01:04 <DIR> --d----- C:\Python25
2010-01-07 21:31 <DIR> --d----- c:\program files\Arcade Tonk Tanks
==================== Find3M ====================
2010-01-14 11:12 181,120 -------- c:\windows\system32\MpSigStub.exe
2009-12-21 14:14 916,480 -------- c:\windows\system32\wininet.dll
2009-11-21 10:51 471,552 a------- c:\windows\apppatch\aclayers.dll
2009-11-13 19:49 129,784 -------- c:\windows\system32\pxafs.dll
2009-11-13 19:49 120,056 -------- c:\windows\system32\pxcpyi64.exe
2009-11-13 19:49 118,520 -------- c:\windows\system32\pxinsi64.exe
2009-11-13 19:47 90,112 a------- c:\windows\system32\dpl100.dll
2009-11-13 19:47 856,064 a------- c:\windows\system32\divx_xx0c.dll
2009-11-13 19:47 856,064 a------- c:\windows\system32\divx_xx07.dll
2009-11-13 19:47 847,872 a------- c:\windows\system32\divx_xx0a.dll
2009-11-13 19:47 843,776 a------- c:\windows\system32\divx_xx16.dll
2009-11-13 19:47 839,680 a------- c:\windows\system32\divx_xx11.dll
2009-11-13 19:47 696,320 a------- c:\windows\system32\DivX.dll
2008-07-05 23:26 248 a------- c:\program files\Garden Plannerini.xml
============= FINISH: 15:15:27.60 ===============