Here is the combofix and i will add the SystemLook in 1 minute.
EDIT: here is the system look it will be below the combo fix information.
Also I might add that I do not see the vipre bit defender and webroot in my add/delete programs list. I already deleted them.
ComboFix 09-07-14.08 - Koib 07/15/2009 16:43.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1429 [GMT -6:00]
Running from: g:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: g:\documents and settings\Koib\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
AV: Webroot Internet Security Essentials *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
FW: Webroot Internet Security Essentials *disabled* {63671000-11A2-46DD-BADD-A084CABCDEAE}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 )))))))))))))))))))))))))))))))
.
2009-07-15 18:25 . 2009-07-15 18:25 ——– d–h–w- g:\windows\PIF
2009-07-15 18:09 . 2009-07-15 22:15 ——– d—–w- g:\program files\Steam
2009-07-15 07:44 . 2009-07-15 07:44 ——– d–h–w- G:\$AVG8.VAULT$
2009-07-15 07:22 . 2009-07-15 07:18 2052888 —-a-w- g:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-15 07:19 . 2009-07-15 07:19 11952 —-a-w- g:\windows\system32\avgrsstx.dll
2009-07-15 07:19 . 2009-07-15 07:19 108552 —-a-w- g:\windows\system32\drivers\avgtdix.sys
2009-07-15 07:19 . 2009-07-15 07:19 327688 —-a-w- g:\windows\system32\drivers\avgldx86.sys
2009-07-15 07:19 . 2009-07-15 07:19 27784 —-a-w- g:\windows\system32\drivers\avgmfx86.sys
2009-07-15 07:19 . 2009-07-15 07:20 ——– d—–w- g:\windows\system32\drivers\Avg
2009-07-15 07:18 . 2009-07-15 07:18 ——– d—–w- g:\documents and settings\All Users\Application Data\avg8
2009-07-14 12:51 . 2009-07-14 12:56 54 —-a-w- g:\windows\system32\rp_stats.dat
2009-07-14 12:51 . 2009-07-14 12:56 39 —-a-w- g:\windows\system32\rp_rules.dat
2009-07-14 11:56 . 2009-07-14 11:56 ——– d—–w- G:\9730defa55092ed98421161886824de3
2009-07-14 11:53 . 2009-07-14 11:53 ——– d—–w- G:\4ff181e91bb7a14437d6194a4e47f989
2009-07-14 11:43 . 2009-07-14 11:43 ——– d—–w- G:\abe1124a1e68c47e519c6362
2009-07-14 11:43 . 2009-07-14 11:53 ——– d—–w- G:\452011e74e259b6fac71557b6119
2009-07-14 11:19 . 2009-07-14 11:23 ——– d—–w- g:\documents and settings\All Users\Application Data\BitDefender
2009-06-28 07:51 . 2009-06-28 07:51 ——– d—–w- g:\program files\Common Files\Skype
2009-06-27 15:39 . 2009-06-27 15:39 ——– d—–w- g:\program files\Common Files\DivX Shared
2009-06-27 01:47 . 2009-06-27 01:47 ——– d—–w- g:\documents and settings\All Users\Application Data\Sunbelt
2009-06-27 01:47 . 2009-06-27 01:47 ——– d—–w- g:\documents and settings\Koib\Application Data\Sunbelt
2009-06-27 01:44 . 2009-06-27 01:45 ——– d—–w- g:\program files\Sunbelt Software
2009-06-27 01:13 . 2009-06-27 01:45 181024 –sha-w- g:\windows\system32\drivers\fidbox.dat
2009-06-27 01:13 . 2009-06-27 01:45 16416 –sha-w- g:\windows\system32\drivers\fidbox2.dat
2009-06-27 01:03 . 2009-06-27 01:39 ——– d—–w- g:\documents and settings\All Users\Application Data\ParetoLogic
2009-06-27 01:03 . 2009-06-27 01:39 ——– d—–w- g:\program files\Common Files\ParetoLogic
2009-06-27 01:02 . 2009-06-27 01:02 ——– d—–w- g:\documents and settings\Koib\Local Settings\Application Data\Downloaded Installations
2009-06-21 05:28 . 2009-06-21 05:37 ——– d—–w- g:\program files\Razor
2009-06-20 01:44 . 2009-06-20 01:44 1685856 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\MoveMediaPlayerWinSilent_071503000010.exe
2009-06-19 06:21 . 2009-06-19 06:21 ——– d—–w- g:\documents and settings\All Users\Application Data\nView_Profiles
2009-06-17 10:23 . 2009-06-17 10:23 ——– d—–w- g:\documents and settings\Koib\Application Data\SoundSpectrum
2009-06-17 10:22 . 2009-06-17 10:22 ——– d—–w- g:\program files\SoundSpectrum
2009-06-16 06:35 . 2009-06-16 06:35 97144 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-16 06:35 . 2009-06-20 01:45 4183416 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071503000010.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-15 22:04 . 2008-06-17 23:29 9 —-a-w- g:\windows\mvraidver.dat
2009-07-15 07:08 . 2009-05-13 18:45 ——– d—–w- g:\program files\Common Files\BitDefender
2009-07-15 07:08 . 2009-05-13 18:47 ——– d—–w- g:\program files\BitDefender
2009-07-15 07:07 . 2009-05-13 18:57 81984 —-a-w- g:\windows\system32\bdod.bin
2009-07-15 05:50 . 2008-06-20 15:23 ——– d—–w- g:\documents and settings\Koib\Application Data\mIRC
2009-07-15 05:21 . 2008-06-20 15:23 ——– d—–w- g:\program files\mIRC
2009-07-14 22:37 . 2009-01-12 20:22 ——– d—–w- g:\documents and settings\All Users\Application Data\Google Updater
2009-07-14 12:58 . 2009-01-15 03:58 ——– d—–w- g:\documents and settings\All Users\Application Data\Lavasoft
2009-07-14 12:54 . 2009-01-15 04:01 ——– d—–w- g:\program files\Spybot - Search & Destroy
2009-07-14 12:19 . 2009-01-15 04:01 ——– d—–w- g:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-14 12:00 . 2008-06-18 06:14 14648 —-a-w- g:\documents and settings\Koib\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-14 11:55 . 2009-01-28 21:10 64648 —-a-w- g:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-30 18:09 . 2008-12-19 08:39 ——– d—–w- g:\documents and settings\Koib\Application Data\Skype
2009-06-30 17:15 . 2008-12-19 08:41 ——– d—–w- g:\documents and settings\Koib\Application Data\skypePM
2009-06-28 07:51 . 2008-12-19 08:39 ——– d—–r- g:\program files\Skype
2009-06-28 07:51 . 2008-12-19 08:39 ——– d—–w- g:\documents and settings\All Users\Application Data\Skype
2009-06-27 18:59 . 2008-06-23 09:58 ——– d—–w- g:\program files\Soulseek
2009-06-27 15:41 . 2009-01-14 09:43 ——– d—–w- g:\program files\DivX
2009-06-27 01:45 . 2009-06-27 01:13 6608 –sha-w- g:\windows\system32\drivers\fidbox.idx
2009-06-27 01:45 . 2009-06-27 01:13 2612 –sha-w- g:\windows\system32\drivers\fidbox2.idx
2009-06-27 01:00 . 2009-06-12 19:28 ——– d—–w- g:\documents and settings\Koib\Application Data\Webroot
2009-06-20 01:45 . 2009-06-04 12:59 127872 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\uninstall.exe
2009-06-20 01:45 . 2009-03-20 03:20 ——– d—–w- g:\documents and settings\Koib\Application Data\Move Networks
2009-06-17 23:39 . 2009-06-10 02:23 117760 —-a-w- g:\documents and settings\Koib\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-17 23:38 . 2009-02-10 15:39 ——– d—–w- g:\program files\ProxyFirewall
2009-06-17 10:21 . 2008-12-24 23:23 ——– d—–w- g:\program files\iTunes
2009-06-14 21:02 . 2009-06-14 21:02 ——– d—–w- g:\program files\MSXML 4.0
2009-06-12 20:24 . 2009-06-06 11:41 ——– d—–w- g:\documents and settings\All Users\Application Data\BOINC
2009-06-12 19:29 . 2009-06-12 19:29 ——– d—–w- g:\program files\MSSOAP
2009-06-12 19:28 . 2009-06-12 19:28 ——– d—–w- g:\program files\Webroot
2009-06-12 19:27 . 2009-06-12 19:27 164 —-a-w- g:\windows\install.dat
2009-06-07 02:00 . 2009-06-07 01:59 267776 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setigraphics_6.03_windows_intelx86.exe
2009-06-07 02:00 . 2009-06-07 01:59 406016 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe
2009-06-07 02:00 . 2009-06-07 01:59 448600 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\libfftw3f-3-1-1a_upx.dll
2009-06-07 02:00 . 2009-06-07 01:59 389120 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\cufft.dll
2009-06-07 02:00 . 2009-06-07 01:59 1445888 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.08_windows_intelx86__cuda.exe
2009-06-07 02:00 . 2009-06-07 01:59 192512 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\cudart.dll
2009-06-07 01:53 . 2009-06-06 11:41 ——– d—–w- g:\program files\BOINC
2009-06-04 12:59 . 2009-05-01 06:30 4183416 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071500000347.dll
2009-06-04 12:59 . 2009-06-04 12:59 1685856 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\MoveMediaPlayerWin_071500000347.exe
2009-05-29 19:49 . 2009-05-29 19:49 828160 —-a-w- g:\windows\boinc.scr
2009-05-25 12:56 . 2009-05-25 12:56 ——– d—–w- g:\program files\The Rosetta Stone
2009-05-23 08:40 . 2008-08-07 15:08 ——– d—a-w- g:\documents and settings\All Users\Application Data\TEMP
2009-05-22 13:01 . 2008-06-18 07:09 ——– d–h–w- g:\program files\InstallShield Installation Information
2009-05-19 20:56 . 2009-05-19 20:56 ——– d—–w- g:\documents and settings\All Users\Application Data\Razer
2009-05-19 20:56 . 2009-05-19 20:56 ——– d—–w- g:\program files\DIFX
2009-05-19 07:36 . 2009-06-21 04:43 2884832 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\vwpt.exe
2009-05-19 07:36 . 2009-06-21 04:43 28 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\unregister.bat
2009-05-19 07:36 . 2009-06-21 04:43 1484856 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\toolbar.exe
2009-05-19 07:36 . 2009-06-21 04:43 25 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\register.bat
2009-05-19 07:36 . 2009-06-21 04:43 97072 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\bsetutil.exe
2009-05-19 07:36 . 2009-06-21 04:43 142040 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\alsetup.exe
2009-05-19 07:36 . 2009-06-21 04:43 30512 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\Uninstaller.exe
2009-05-19 07:36 . 2009-06-21 04:43 111920 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\AOLSearch.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- g:\windows\system32\localspl.dll
2009-05-01 21:02 . 2009-05-01 21:02 90112 —-a-w- g:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- g:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- g:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 —-a-w- g:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 —-a-w- g:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 —-a-w- g:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 —-a-w- g:\windows\system32\DivX.dll
2009-04-29 04:56 . 2006-02-28 12:00 827392 —-a-w- g:\windows\system32\wininet.dll
2009-04-29 04:55 . 2006-02-28 12:00 78336 —-a-w- g:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2006-02-28 12:00 1847168 —-a-w- g:\windows\system32\win32k.sys
2009-06-12 16:56 . 2008-06-17 23:58 134648 —-a-w- g:\program files\mozilla firefox\components\brwsrcmp.dll
2009-03-06 00:08 . 2009-07-14 11:24 49664 —-a-w- g:\program files\mozilla firefox\components\FFComm.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- g:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- g:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="g:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-30 133104]
"DAEMON Tools Lite"="g:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"SpybotSD TeaTimer"="g:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Steam"="g:\program files\steam\steam.exe" [2009-07-15 1217784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="g:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="g:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
"NvMediaCenter"="g:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
"QuickTime Task"="g:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"AVG8_TRAY"="g:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-15 1948440]
"RTHDCPL"="RTHDCPL.EXE" - g:\windows\RTHDCPL.exe [2007-03-21 16126464]
"nwiz"="nwiz.exe" - g:\windows\system32\nwiz.exe [2008-09-18 1657376]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - g:\windows\KHALMNPR.Exe [2007-04-11 56080]
g:\documents and settings\Koib\Start Menu\Programs\Startup\
MarvellTrayStartup.lnk - g:\program files\Marvell\61xx\tray\RaidTray.bat [2008-6-17 201]
g:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - g:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - g:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "g:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 18:05 356352 —-a-w- g:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-15 07:19 11952 —-a-w- g:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"Spooler"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasAuto"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"RasMan"=3 (0x3)
"RemoteAccess"=2 (0x2)
"iPod Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"g:\\Program Files\\mIRC\\mirc.exe"=
"g:\\Valve\\Condition Zero\\czero.exe"=
"g:\\Program Files\\EA Games\\Ultima Online Mondain's Legacy\\client.exe"=
"c:\\ijji\\ENGLISH\\u_gbound.exe"=
"g:\\Program Files\\AIM6\\aim6.exe"=
"g:\\Program Files\\iTunes\\iTunes.exe"=
"g:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"g:\\Program Files\\DNA\\btdna.exe"=
"g:\\WINDOWS\\system32\\sessmgr.exe"=
"g:\\Program Files\\Soulseek\\slsk.exe"=
"g:\\Program Files\\Steam\\steam.exe"=
"g:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"g:\\Program Files\\EA Games\\Ultima Online 2D Client\\client.exe"=
"g:\\Program Files\\Steam\\steamapps\\[removed]\\counter-strike\\hl.exe"=
"g:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"g:\\Program Files\\Skype\\Phone\\Skype.exe"=
"g:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58354:TCP"= 58354:TCP:*:Disabled:Pando Media Booster
"58354:UDP"= 58354:UDP:*:Disabled:Pando Media Booster
R0 mv61xx;mv61xx;g:\windows\system32\drivers\mv61xx.sys [6/15/2007 1:52 AM 143256]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;g:\windows\system32\drivers\avgldx86.sys [7/15/2009 1:19 AM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;g:\windows\system32\drivers\avgtdix.sys [7/15/2009 1:19 AM 108552]
R1 SASDIFSV;SASDIFSV;g:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 5:17 PM 8944]
R1 SASKUTIL;SASKUTIL;g:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 5:17 PM 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;g:\progra~1\AVG\AVG8\avgemc.exe [7/15/2009 1:18 AM 906520]
R2 avg8wd;AVG Free8 WatchDog;g:\progra~1\AVG\AVG8\avgwdsvc.exe [7/15/2009 1:18 AM 298776]
R2 MRUWebService;MRU Web Service;g:\program files\Marvell\61xx\Apache2\bin\Apache.exe [5/22/2007 6:17 PM 20539]
R2 Viewpoint Manager Service;Viewpoint Manager Service;g:\program files\Viewpoint\Common\ViewpointService.exe [6/19/2008 11:42 AM 24652]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;g:\windows\system32\drivers\l151x86.sys [6/18/2008 1:09 AM 37376]
R3 Marvell RAID;Marvell RAID Event Agent;g:\program files\Marvell\61xx\svc\mvraidsvc.exe [6/12/2007 12:54 PM 61440]
S1 SBRE;SBRE;\??\g:\windows\system32\drivers\SBREdrv.sys –> g:\windows\system32\drivers\SBREdrv.sys [?]
S2 WRConsumerService;Webroot Client Service;"g:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" –> g:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [?]
S3 LachesisFltr;Lachesis Mouse Driver;g:\windows\system32\drivers\Lachesis.sys [5/19/2009 2:56 PM 12032]
S3 MBAMSwissArmy;MBAMSwissArmy;g:\windows\system32\drivers\mbamswissarmy.sys [12/12/2008 12:46 AM 38496]
S3 SASENUM;SASENUM;g:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 5:17 PM 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-07-15 g:\windows\Tasks\Google Software Updater.job
- g:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-12 21:13]
2009-07-15 g:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1343024091-682003330-1004Core.job
- g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-30 13:41]
2009-07-15 g:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1343024091-682003330-1004UA.job
- g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-30 13:41]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: &Winamp; Search - g:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
FF - ProfilePath - g:\documents and settings\Koib\Application Data\Mozilla\Firefox\Profiles\vkd103lr.default\
FF - prefs.js: browser.search.selectedEngine - Answers.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: g:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: g:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: g:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-15 16:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(720)
g:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(3968)
g:\windows\system32\WPDShServiceObj.dll
g:\windows\system32\PortableDeviceTypes.dll
g:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-15 16:51
ComboFix-quarantined-files.txt 2009-07-15 22:50
ComboFix2.txt 2009-07-15 22:10
Pre-Run: 125,166,792,704 bytes free
Post-Run: 125,147,951,104 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
262 — E O F — 2009-07-15 07:03
SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 16:56 on 15/07/2009 by Koib (Administrator - Elevation successful)
========== dir ==========
G:\452011e74e259b6fac71557b6119 - Parameters: "/s"
—Files—
dotnetfx35setup.exe –a— 2959376 bytes [06:26 30/07/2008] [06:26 30/07/2008]
G:\452011e74e259b6fac71557b6119\dotnetfx20 d—– [11:43 14/07/2009]
aspnet.msp –a— 2926080 bytes [23:29 29/07/2008] [23:29 29/07/2008]
clr.msp –a— 6083072 bytes [23:31 29/07/2008] [23:31 29/07/2008]
crt.msp –a— 506368 bytes [23:33 29/07/2008] [23:33 29/07/2008]
dw.msp –a— 553472 bytes [23:35 29/07/2008] [23:35 29/07/2008]
netfx20a_x86.msi –a— 93184 bytes [23:27 29/07/2008] [23:27 29/07/2008]
netfx_ca.msp –a— 911360 bytes [23:37 29/07/2008] [23:37 29/07/2008]
netfx_core.msp –a— 3403264 bytes [23:39 29/07/2008] [23:39 29/07/2008]
netfx_other.msp –a— 6487040 bytes [23:41 29/07/2008] [23:41 29/07/2008]
prexp.msp –a— 1013248 bytes [23:43 29/07/2008] [23:43 29/07/2008]
winforms.msp –a— 2543616 bytes [23:45 29/07/2008] [23:45 29/07/2008]
G:\452011e74e259b6fac71557b6119\dotnetfx30 d—– [11:43 14/07/2009]
netfx30a_x86.msi –a— 142336 bytes [01:12 30/07/2008] [01:12 30/07/2008]
rgb9rast_x86.msi –a— 94720 bytes [04:40 30/07/2008] [04:40 30/07/2008]
wcf.msp –a— 3376640 bytes [01:18 30/07/2008] [01:18 30/07/2008]
wcs.msp –a— 1043456 bytes [01:26 30/07/2008] [01:26 30/07/2008]
wf.msp –a— 1448448 bytes [01:34 30/07/2008] [01:34 30/07/2008]
wf_32.msp –a— 291840 bytes [01:40 30/07/2008] [01:40 30/07/2008]
wic_x86_enu.exe –a— 1227048 bytes [04:40 30/07/2008] [04:40 30/07/2008]
wpf1.msp –a— 4137984 bytes [02:22 30/07/2008] [02:22 30/07/2008]
wpf2.msp –a— 2679808 bytes [02:37 30/07/2008] [02:37 30/07/2008]
wpf2_32.msp –a— 23040 bytes [03:07 30/07/2008] [03:07 30/07/2008]
wpf_other.msp –a— 3697664 bytes [03:15 30/07/2008] [03:15 30/07/2008]
wpf_other_32.msp –a— 250880 bytes [03:23 30/07/2008] [03:23 30/07/2008]
xps.msp –a— 278016 bytes [03:28 30/07/2008] [03:28 30/07/2008]
xpsepsc-x86-en-us.exe –a— 3049000 bytes [04:40 30/07/2008] [04:40 30/07/2008]
G:\452011e74e259b6fac71557b6119\dotnetfx30\x86 d—– [11:43 14/07/2009]
msxml6.msi –a— 1527296 bytes [05:13 30/07/2008] [05:13 30/07/2008]
G:\452011e74e259b6fac71557b6119\dotnetfx35 d—– [11:43 14/07/2009]
G:\452011e74e259b6fac71557b6119\dotnetfx35\x86 d—– [11:43 14/07/2009]
netfx35_x86.exe –a— 8164360 bytes [05:47 30/07/2008] [05:47 30/07/2008]
G:\452011e74e259b6fac71557b6119\tools d—– [11:43 14/07/2009]
clwireg.exe –a— 114200 bytes [00:43 30/07/2008] [00:43 30/07/2008]
-=End Of File=-