OK, it's completed. Here is the log from the Combo-fix.
ComboFix 09-07-23.02 - HP_Administrator 07/23/2009 23:20.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.447 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1335 [VPS 090723-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: CA Anti-Virus *On-access scanning enabled* (Outdated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\program files\smbols~1
c:\recycler\S-1-5-21-2856212118-2892828900-201305014-1008
c:\recycler\S-1-5-21-3329523479-2079964671-2664348731-1009
c:\recycler\S-1-5-21-3381561272-153511819-2455406854-1008
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\temp\tn3
c:\temp\tn3\cache.dsk
c:\windows\cookies.ini
c:\windows\IA
c:\windows\Installer\105d6cb.msi
c:\windows\Installer\1076632.msi
c:\windows\Installer\10e6cd.msi
c:\windows\Installer\11b71.msp
c:\windows\Installer\11b7a.msi
c:\windows\Installer\11d7c1.msp
c:\windows\Installer\1348c57.msi
c:\windows\Installer\148acf.msi
c:\windows\Installer\148ada.msi
c:\windows\Installer\14c4ae7.msp
c:\windows\Installer\14dd945.msi
c:\windows\Installer\15c88c.msi
c:\windows\Installer\1618639.msp
c:\windows\Installer\17d215.msi
c:\windows\Installer\17e3e75.msp
c:\windows\Installer\17e3e87.msp
c:\windows\Installer\17e3e9a.msp
c:\windows\Installer\187f5fc.msp
c:\windows\Installer\19339f5.msp
c:\windows\Installer\19c185.msi
c:\windows\Installer\1b06473.msp
c:\windows\Installer\1b06486.msp
c:\windows\Installer\1b06499.msp
c:\windows\Installer\1b064ac.msp
c:\windows\Installer\1b064bf.msp
c:\windows\Installer\1ce613c.msi
c:\windows\Installer\1d5fea.msi
c:\windows\Installer\1d79fb.msi
c:\windows\Installer\1e352ea.msi
c:\windows\Installer\1e353c8.msi
c:\windows\Installer\1e67af2.msp
c:\windows\Installer\1eeda16.msi
c:\windows\Installer\1f14133.msi
c:\windows\Installer\1fcd9d4.msi
c:\windows\Installer\1fcd9e6.msp
c:\windows\Installer\1fcd9fa.msp
c:\windows\Installer\1fcda0d.msp
c:\windows\Installer\1fcda20.msp
c:\windows\Installer\1fcda33.msp
c:\windows\Installer\1fcda46.msp
c:\windows\Installer\21179ee.msi
c:\windows\Installer\211ebcb.msp
c:\windows\Installer\220bb4c.msp
c:\windows\Installer\23391.msi
c:\windows\Installer\25547ec.msi
c:\windows\Installer\25547f2.msi
c:\windows\Installer\25547fc.msi
c:\windows\Installer\2554808.msi
c:\windows\Installer\256cd4.msi
c:\windows\Installer\2646581.msp
c:\windows\Installer\26e1241.msp
c:\windows\Installer\272212.msp
c:\windows\Installer\299eed.msi
c:\windows\Installer\2a18823.msp
c:\windows\Installer\2ac5f5.msi
c:\windows\Installer\2ac5f8.msi
c:\windows\Installer\2d36ce.msi
c:\windows\Installer\2d370f.msi
c:\windows\Installer\2d3713.msi
c:\windows\Installer\313354b.msi
c:\windows\Installer\313355e.msp
c:\windows\Installer\3133571.msp
c:\windows\Installer\3328bf.msp
c:\windows\Installer\3328d2.msp
c:\windows\Installer\3328e5.msp
c:\windows\Installer\3328f9.msp
c:\windows\Installer\33290c.msp
c:\windows\Installer\33291f.msp
c:\windows\Installer\332932.msp
c:\windows\Installer\36876e.msi
c:\windows\Installer\36e474.msp
c:\windows\Installer\36e48a.msp
c:\windows\Installer\36e49e.msp
c:\windows\Installer\4065795.msp
c:\windows\Installer\40657a8.msp
c:\windows\Installer\40657bb.msp
c:\windows\Installer\40657d8.msp
c:\windows\Installer\40657eb.msp
c:\windows\Installer\40657fd.msp
c:\windows\Installer\40fb163.msi
c:\windows\Installer\4165ebb.msp
c:\windows\Installer\4165ece.msp
c:\windows\Installer\432f8a3.msi
c:\windows\Installer\460be.msi
c:\windows\Installer\4667655.msp
c:\windows\Installer\4bcbb.msi
c:\windows\Installer\4ee94e.msi
c:\windows\Installer\51db26a.msp
c:\windows\Installer\5367142.msp
c:\windows\Installer\5367156.msp
c:\windows\Installer\54799d.msp
c:\windows\Installer\5479b0.msp
c:\windows\Installer\5479c3.msp
c:\windows\Installer\5b6e6ef.msp
c:\windows\Installer\5b6e6f8.msi
c:\windows\Installer\5b6e70a.msp
c:\windows\Installer\5cebf0.msp
c:\windows\Installer\5cebf1.msp
c:\windows\Installer\60ade2.msi
c:\windows\Installer\68aea8.msi
c:\windows\Installer\693f03.msi
c:\windows\Installer\72189.msi
c:\windows\Installer\7218b.msi
c:\windows\Installer\7218c.msi
c:\windows\Installer\72193.msi
c:\windows\Installer\78659a.msp
c:\windows\Installer\7865ae.msp
c:\windows\Installer\791035.msi
c:\windows\Installer\79559.msp
c:\windows\Installer\813b3.msi
c:\windows\Installer\81644.msi
c:\windows\Installer\880e4.msi
c:\windows\Installer\888ee0.msp
c:\windows\Installer\888ef2.msp
c:\windows\Installer\8898ff.msp
c:\windows\Installer\889912.msp
c:\windows\Installer\88992f.msp
c:\windows\Installer\9d7a88.msi
c:\windows\Installer\a76cd8.msp
c:\windows\Installer\a9c30e.msp
c:\windows\Installer\ac5f97.msi
c:\windows\Installer\b6a9b.msi
c:\windows\Installer\b7cf9f.msi
c:\windows\Installer\c1c338.msi
c:\windows\Installer\c768e3.msi
c:\windows\Installer\cab8c1.msp
c:\windows\Installer\cc17b3.msi
c:\windows\Installer\cc17bb.msi
c:\windows\Installer\cc17c2.msi
c:\windows\Installer\cc17cc.msi
c:\windows\Installer\cc17dc.msi
c:\windows\Installer\cc17f1.msi
c:\windows\Installer\cc17f9.msi
c:\windows\Installer\cc180f.msi
c:\windows\Installer\cc1858.msi
c:\windows\Installer\cc185e.msi
c:\windows\Installer\cc1864.msi
c:\windows\Installer\cc186a.msi
c:\windows\Installer\ce28f.msi
c:\windows\Installer\d3e95.msi
c:\windows\Installer\ec9148.msp
c:\windows\Installer\f3ad8d.msi
c:\windows\Installer\f3eea9.msp
c:\windows\Installer\f3eebc.msp
c:\windows\Installer\f3eed4.msp
c:\windows\Installer\f559b2.msp
c:\windows\Installer\f8c5cb.msp
c:\windows\Installer\f8c5de.msp
c:\windows\Installer\f8c5f1.msp
c:\windows\Installer\f8c604.msp
c:\windows\Installer\f8c617.msp
c:\windows\Installer\f8c62a.msp
c:\windows\Installer\f8c63c.msp
c:\windows\Installer\fbb477.msp
c:\windows\Installer\fbb48b.msp
c:\windows\Installer\fbb538.msp
c:\windows\Installer\fc8a26.msp
c:\windows\Installer\fcdbb.msi
c:\windows\kb913800.exe
c:\windows\msa.exe
c:\windows\pppatc~1
c:\windows\system32\cpmsky-uninst.exe
c:\windows\system32\drivers\UACnnodstbvuk.sys
c:\windows\system32\msxml71.dll
c:\windows\system32\UACdihqhfnytk.db
c:\windows\system32\UACeaemcwruem.dll
c:\windows\system32\UAChblbfmbaka.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiwvakbkvrb.dll
c:\windows\system32\UACltrmhcedav.dll
c:\windows\system32\UACroyiltnanu.dll
c:\windows\system32\UACwamoqdnpnk.dll
c:\windows\winhelp.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
——-\Legacy_ABEL
——-\Legacy_NPF
——-\Service_Abel
——-\Service_RkHit
((((((((((((((((((((((((( Files Created from 2009-06-24 to 2009-07-24 )))))))))))))))))))))))))))))))
.
2009-07-23 06:08 . 2009-07-23 06:08 ——– d—–w- c:\program files\ERUNT
2009-07-23 02:14 . 2009-07-23 02:14 137732 —-a-w- c:\windows\msb.exe
2009-07-22 07:26 . 2009-07-22 07:26 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-19 23:55 . 2009-07-19 23:55 ——– d—–w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Installer3660
2009-07-18 19:48 . 2009-07-18 19:49 ——– d—–w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Temp
2009-07-18 02:48 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-07-18 02:48 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\dllcache\hidserv.dll
2009-07-18 02:48 . 2004-08-04 03:58 14848 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2009-07-18 02:48 . 2004-08-04 03:58 14848 —-a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-07-02 00:00 . 2009-07-02 00:00 ——– d—–w- c:\windows\system32\wbem\Repository
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-24 04:20 . 2005-11-11 00:59 ——– d—–w- c:\program files\Google
2009-07-23 07:32 . 2008-08-30 08:09 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-07-23 04:50 . 2008-01-09 02:27 94208 —-a-w- c:\windows\DUMP8f11.tmp
2009-07-23 04:46 . 2008-06-29 16:01 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-23 04:46 . 2008-06-29 16:01 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-07-23 00:23 . 2007-12-30 05:13 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Google Updater
2009-07-23 00:22 . 2007-02-16 18:42 ——– d—–w- c:\program files\Windows Media Connect 2
2009-07-23 00:22 . 2006-12-14 02:58 ——– d—–w- c:\program files\Smilebox
2009-07-23 00:22 . 2006-06-10 14:36 ——– d—–w- c:\program files\Sierra On-Line
2009-07-23 00:22 . 2005-11-11 00:46 ——– d—a-w- c:\program files\TurboTax Online
2009-07-23 00:22 . 2006-11-13 02:37 ——– d—–w- c:\program files\Scrapbook Designer
2009-07-23 00:22 . 2005-11-11 00:31 ——– d—–w- c:\program files\Rhapsody
2009-07-23 00:22 . 2006-06-10 22:29 ——– d—–w- c:\program files\LimeWire
2009-07-23 00:22 . 2006-07-03 20:26 ——– d—–w- c:\program files\Hemera Products
2009-07-23 00:22 . 2005-11-11 00:40 ——– d—a-w- c:\program files\IntelliMoverDemo
2009-07-23 00:22 . 2008-07-01 00:28 ——– d—–w- c:\program files\FinePixViewer
2009-07-23 00:22 . 2006-02-07 01:02 ——– d—–w- c:\program files\CallWave
2009-07-22 15:31 . 2008-08-21 06:25 ——– d—–w- c:\program files\IEPro
2009-07-22 15:30 . 2008-11-30 00:30 ——– d—–w- c:\program files\UnicodeImageMaker
2009-07-19 20:57 . 2008-02-02 22:47 1367 —-a-w- c:\windows\system32\HPA.DAT
2009-07-17 20:21 . 2008-01-09 02:37 334352 —-a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-01 03:45 . 2008-03-21 01:43 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\LimeWire
2009-06-18 04:29 . 2008-07-19 20:42 ——– d—–w- c:\program files\RegCure
2009-06-18 04:29 . 2005-11-11 00:54 ——– d—–w- c:\program files\PC-Doctor 5 for Windows
2009-06-18 04:29 . 2005-11-11 00:30 ——– d—–w- c:\program files\MSN Encarta Standard
2009-06-16 16:28 . 2009-06-16 16:28 390664 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-11 06:28 . 2008-10-03 15:11 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2009-06-11 05:56 . 2009-06-11 05:56 ——– d—–w- c:\program files\VersalSoft
2009-06-11 05:56 . 2009-06-11 05:56 ——– d—–w- c:\program files\Universal
2009-06-11 02:23 . 2009-06-11 02:23 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys
2009-06-11 02:23 . 2009-06-11 02:23 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2009-06-11 02:23 . 2005-04-25 17:03 44944 ——w- c:\windows\system32\drivers\pxhelp20.sys
2009-06-08 19:00 . 2009-06-15 05:03 110592 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\f6ektngu.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
2009-05-30 21:19 . 2009-05-30 21:14 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\U3
2009-05-03 00:40 . 2009-03-09 23:17 82380 —-a-w- c:\windows\system32\drivers\AFS2K.SYS
2009-04-28 22:24 . 2009-04-28 22:24 8552 —-a-w- c:\windows\system32\drivers\asctrm.sys
2009-07-23 02:06 . 2008-10-17 19:05 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2008-05-16 22:04 . 2008-05-16 22:03 848 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uniblue SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [2007-12-07 9479448]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-30 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2008-08-02 181488]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-06-14 234736]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Share-to-Web Namespace Daemon"="c:\program files\HP\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 69632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-28 198160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
VZAccess Manager.lnk - c:\program files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe [2009-3-2 1787184]
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2006-2-9 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SABWinLogon]
2008-04-07 02:50 176128 —-a-w- c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\CallWave\\IAM.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\lxbmcoms.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56642:TCP"= 56642:TCP:Pando P2P TCP Listening Port
"56642:UDP"= 56642:UDP:Pando P2P UDP Listening Port
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12/7/2008 12:01 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12/7/2008 12:01 AM 20560]
R2 lxbm_device;lxbm_device;c:\windows\system32\lxbmcoms.exe -service –> c:\windows\system32\lxbmcoms.exe -service [?]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [8/30/2008 3:07 AM 210216]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [5/9/2008 11:08 AM 174336]
S1 rxp;rxp;\??\c:\windows\system32\drivers\rxp.sys –> c:\windows\system32\drivers\rxp.sys [?]
S1 SABKUTIL;SABKUTIL;\??\c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys –> c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys [?]
S3 UBWipRFBMLg;UBWipRFBMLg;\??\c:\downloads\Windows\Downloads\MHS\GNFDQ –> c:\downloads\Windows\Downloads\MHS\GNFDQ [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q106&bd;=pavilion&pf;=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.callwave.com/iam/DemoIntro.html?u=0f5ab0f3e201a2176ba63427dc04bc729318fe15fe61a8ad81d3e2d0bb7349025c&Ver;=3.09.7.0&OS;=WinNT:5.1.2600SP:2.0&co;=0
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949}
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: trymedia.com
FF - ProfilePath - c:\docume~1\HP_ADM~1\APPLIC~1\Mozilla\Firefox\Profiles\f6ektngu.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p;=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-23 23:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UBWipRFBMLg]
"ImagePath"="\??\c:\downloads\Windows\Downloads\MHS\GNFDQ"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3329523479-2079964671-2664348731-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
@SACL=
[HKEY_USERS\S-1-5-21-3329523479-2079964671-2664348731-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ò*k*"\OpenWithList]
@Class="Shell"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(744)
c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(820)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
- - - - - - - > 'explorer.exe'(3824)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
c:\windows\arservice.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
c:\windows\system32\drivers\dcfssvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lxbmcoms.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\HP Share-to-Web\hpgs2wnf.exe
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
c:\progra~1\Webshots\webshots.scr
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-07-24 23:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-24 04:48
Pre-Run: 99,542,085,632 bytes free
Post-Run: 99,543,715,840 bytes free
405 — E O F — 2008-08-12 22:51