Okay, I did it, and here's the log it gave me:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ComboFix 10-02-27.04 - Mike 02/28/2010 15:39:27.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.255.50 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
—– BITS: Possible infected sites —–
hxxp://armmf.adobe.com
.
((((((((((((((((((((((((( Files Created from 2010-01-28 to 2010-02-28 )))))))))))))))))))))))))))))))
.
2010-02-26 23:19 . 2010-02-26 23:19 ——– d—–w- c:\documents and settings\Mike\Application Data\Malwarebytes
2010-02-26 23:18 . 2010-01-07 23:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-26 23:18 . 2010-02-26 23:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-26 23:18 . 2010-01-07 23:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-26 23:18 . 2010-02-26 23:19 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-26 06:41 . 2010-02-26 06:41 847040 —-a-w- c:\documents and settings\Mike\Application Data\Facebook\axfbootloader.dll
2010-02-26 06:41 . 2010-02-26 06:41 5582848 —-a-w- c:\documents and settings\Mike\Application Data\Facebook\npfbplugin_1_0_3.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-28 15:48 . 2010-01-29 16:40 50354 —-a-w- c:\documents and settings\Mike\Application Data\Facebook\uninstall.exe
2010-02-28 15:48 . 2010-01-29 16:40 ——– d—–w- c:\documents and settings\Mike\Application Data\Facebook
2010-02-04 19:47 . 2008-08-27 18:29 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-27 03:20 . 2010-01-27 03:20 5578752 —-a-w- c:\documents and settings\Mike\Application Data\Facebook\npfbplugin_1_0_1.dll
2010-01-27 03:19 . 2010-01-27 03:19 503808 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-669cdafd-n\msvcp71.dll
2010-01-27 03:19 . 2010-01-27 03:19 348160 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-669cdafd-n\msvcr71.dll
2010-01-27 03:19 . 2010-01-27 03:19 499712 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-669cdafd-n\jmc.dll
2010-01-27 03:19 . 2010-01-27 03:19 61440 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4e1397f2-n\decora-sse.dll
2010-01-27 03:19 . 2010-01-27 03:19 12800 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4e1397f2-n\decora-d3d.dll
2010-01-20 17:40 . 2010-01-20 17:40 ——– d—–w- c:\program files\Common Files\Java
2010-01-20 17:40 . 2010-01-20 17:40 114688 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-6dd66fc7-n\jogl_cg.dll
2010-01-20 17:40 . 2010-01-20 17:40 348160 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-5329d67b-n\msvcr71.dll
2010-01-20 17:40 . 2010-01-20 17:40 20480 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-6dd66fc7-n\jogl_awt.dll
2010-01-20 17:40 . 2010-01-20 17:40 61440 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-5329d67b-n\decora-sse.dll
2010-01-20 17:40 . 2010-01-20 17:40 503808 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-5329d67b-n\msvcp71.dll
2010-01-20 17:40 . 2010-01-20 17:40 499712 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-5329d67b-n\jmc.dll
2010-01-20 17:40 . 2010-01-20 17:40 315392 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-6dd66fc7-n\jogl.dll
2010-01-20 17:40 . 2010-01-20 17:40 20480 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\45\4f710eed-32d3c5cb-n\gluegen-rt.dll
2010-01-20 17:40 . 2010-01-20 17:40 12800 —-a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-5329d67b-n\decora-d3d.dll
2010-01-20 17:39 . 2009-07-15 23:13 ——– d—–w- c:\program files\Java
2010-01-20 17:05 . 2009-07-10 15:09 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-18 04:13 . 2008-12-23 01:59 ——– d—–w- c:\documents and settings\Mike\Application Data\ZoomBrowser EX
2010-01-18 04:13 . 2008-12-23 01:48 ——– d—–w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-12-31 16:50 . 2001-08-18 11:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2002-03-05 15:56 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 00:14 . 2009-07-15 23:15 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2001-08-18 11:00 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2001-08-18 11:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 . 1980-01-01 05:00 2189184 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 1980-01-01 05:00 2066048 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2001-08-18 11:00 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2001-06-20 23:19 . 2001-06-19 23:34 40960 -c–a-w- c:\program files\ACMonitor_X83.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-10-16 19:12 1119488 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"DellTouch"="c:\windows\DELLMMKB.EXE" [2001-09-23 163840]
"wcmdmgr"="c:\windows\wt\updater\wcmdmgrl.exe" [2002-05-08 20480]
"nwiz"="nwiz.exe" [2002-03-09 364544]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"Atomic.exe"="c:\program files\Atomic Clock Sync\Atomic.exe" [2004-05-12 524288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-13 13:36 12464 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ\\Icq.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [8/17/2008 5:40 AM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [8/17/2008 5:40 AM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/13/2009 6:35 AM 285392]
R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [8/6/2001 11:41 AM 28672]
R3 Msikbd2k;DellTouch;c:\windows\SYSTEM32\DRIVERS\Msikbd2k.sys [10/3/2000 1:18 PM 6942]
S0 MFX;MFX;c:\windows\SYSTEM32\DRIVERS\MFX.sys []
S2 BulkUsb;Genesys Logic USB Scanner Controller NT 5.0;c:\windows\SYSTEM32\DRIVERS\usbscan.sys [7/12/2002 4:37 PM 15104]
S3 SPCA508A;Micro WebCam;c:\windows\SYSTEM32\DRIVERS\SPCA508A.SYS [4/23/2001 1:23 PM 98073]
.
Contents of the 'Scheduled Tasks' folder
2010-02-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
——- Supplementary Scan ——-
.
uStart Page =
https://login.yahoo.com/config/login?.done=…ch&.intl=us
uInternet Connection Wizard,ShellNext = hxxp://www.dellnet.com/
Trusted Zone: aol.com\free
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\kznpupyw.default\
FF - prefs.js: browser.startup.homepage - www.thebreastcancersite.com
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Mike\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\Mike\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\kSolo\npAVX.dll
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PC Pitstop Optimize Reminder - c:\program files\PCPitstop\Optimize2\Reminder.exe
AddRemove-RoadRash - c:\electronicarts\RoadRash\DeIsL1.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-28 15:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\windows\system32\drivers\MFX.sys 20780 bytes executable
C:\x___x
scan completed successfully
hidden files: 2
**************************************************************************
.
Completion time: 2010-02-28 15:56:55
ComboFix-quarantined-files.txt 2010-02-28 22:56
Pre-Run: 11,939,512,320 bytes free
Post-Run: 11,954,876,416 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 92DD04853BDB52B35B7BE59059EB8599