Hi - I managed to get ComboFix onto the desktop and run it as descirbed in your first reply using Task Manager, see below for the log text (I am replying from the affected PC which loads correctly and can access online now)
—————
ComboFix 10-06-11.01 - Simon 12/06/2010 15:20:55.11.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.696 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}
c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}\chrome.manifest
c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}\chrome\content\_cfg.js
c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}\chrome\content\overlay.xul
c:\documents and settings\Simon\Local Settings\Application Data\{ACAA8184-6337-4DB8-8073-84A381748ADA}\install.rdf
c:\windows\Nindbdi.dll
c:\windows\oxehegurixu.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\svchost.exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\Packet.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\STEC3.sys
c:\windows\system32\wpcap.dll
c:\windows\Temp\_ex-08.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
——-\Legacy_STEC3
——-\Service_NPF
——-\Service_STEC3
((((((((((((((((((((((((( Files Created from 2010-05-12 to 2010-06-12 )))))))))))))))))))))))))))))))
.
2010-05-25 21:55 . 2010-05-25 21:55 ——– d—–w- c:\documents and settings\Simon\Application Data\DivX
2010-05-25 21:55 . 2010-03-31 01:58 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys
2010-05-25 21:55 . 2010-03-31 01:58 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2010-05-25 21:55 . 2010-03-31 01:58 133616 ——w- c:\windows\system32\pxafs.dll
2010-05-25 21:49 . 2010-05-25 21:55 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-05-18 21:10 . 2010-05-18 21:10 ——– d—–w- c:\program files\Common Files\Java
2010-05-18 21:09 . 2010-04-12 16:29 411368 —-a-w- c:\windows\system32\deployJava1.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-12 14:33 . 2007-05-13 17:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Kontiki
2010-05-31 23:25 . 2007-08-27 19:07 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-05-31 02:52 . 2009-04-09 18:25 ——– d—–w- c:\documents and settings\Simon\Application Data\Spotify
2010-05-31 02:52 . 2010-02-25 00:38 0 —-a-w- c:\windows\Chucitubal.bin
2010-05-27 18:10 . 2010-02-25 00:38 120 —-a-w- c:\windows\Slenasoyuyebiy.dat
2010-05-25 21:53 . 2009-12-21 00:18 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-05-24 23:06 . 2007-05-13 17:20 ——– d—–w- c:\program files\Kontiki
2010-05-18 21:09 . 2004-05-19 13:22 ——– d—–w- c:\program files\Java
2010-04-29 01:14 . 2010-04-29 01:14 ——– d—–w- c:\program files\QuickTime
2010-04-24 07:33 . 2010-04-24 07:33 ——– d—–w- c:\documents and settings\All Users\Application Data\93890029
2010-04-19 21:54 . 2010-04-19 21:54 20747 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-04-19 21:54 . 2008-08-22 18:55 ——– d—–w- c:\program files\RALINK
2010-03-31 01:58 . 2005-11-26 11:27 125424 ——w- c:\windows\system32\pxinsi64.exe
2010-03-31 01:58 . 2005-11-26 11:27 123888 ——w- c:\windows\system32\pxcpyi64.exe
2010-03-31 01:58 . 2003-07-30 01:02 44944 ——w- c:\windows\system32\drivers\pxhelp20.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-06-01 196608]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 68856]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-26 204800]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"LVCOMSX"="c:\windows\System32\LVCOMSX.EXE" [2004-05-21 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-06-01 217088]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 81920]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-23 292152]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"4oD"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
7digital Locker.lnk - c:\program files\7digital Locker\7digitalLocker.exe [2007-5-1 2734100]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
AOL 8.0 Tray Icon.lnk - c:\program files\AOL 8.0\aoltray.exe [2004-5-19 36937]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2010-4-19 593920]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\My Games\\Supreme Commander\\Supreme Commander\\bin\\SupremeCommander.exe"=
"f:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\GPGNet\\GPG.Multiplayer.Client.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"f:\\program files\\itunes\\iTunes.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\burst\\core-new1.1.3\\btdownloadheadless.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\Program Files\\Star Wars Galactic Battleground\\Game\\Battlegrounds.exe"=
"c:\\WINDOWS\\SYSTEM32\\dplaysvr.exe"=
S3 lgmcbus;LGE Mobile driver (WDM);c:\windows\system32\DRIVERS\lgmcbus.sys –> c:\windows\system32\DRIVERS\lgmcbus.sys [?]
S3 lgmcmdfl;LGE Mobile USB WMC Modem Filter;c:\windows\system32\DRIVERS\lgmcmdfl.sys –> c:\windows\system32\DRIVERS\lgmcmdfl.sys [?]
S3 lgmcmdm;LGE Mobile USB WMC Modem Driver;c:\windows\system32\DRIVERS\lgmcmdm.sys –> c:\windows\system32\DRIVERS\lgmcmdm.sys [?]
S3 lgmcmgmt;LGE Mobile USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\lgmcmgmt.sys –> c:\windows\system32\DRIVERS\lgmcmgmt.sys [?]
S3 lgmcnd5;LGE Mobile USB WMC Ethernet ELDA (NDIS);c:\windows\system32\DRIVERS\lgmcnd5.sys –> c:\windows\system32\DRIVERS\lgmcnd5.sys [?]
S3 lgmcobex;LGE Mobile USB WMC OBEX Interface;c:\windows\system32\DRIVERS\lgmcobex.sys –> c:\windows\system32\DRIVERS\lgmcobex.sys [?]
S3 lgmcunic;LGE Mobile USB WMC Ethernet ELDA (WDM);c:\windows\system32\DRIVERS\lgmcunic.sys –> c:\windows\system32\DRIVERS\lgmcunic.sys [?]
S3 NaiFiltr;NaiFiltr;c:\windows\SYSTEM32\DRIVERS\NaiFiltr.sys [15/06/2004 19:36 23296]
.
Contents of the 'Scheduled Tasks' folder
2010-05-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://news.bbc.co.uk/
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local;
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: + &Download Express: download this file - c:\program files\Download Express\Add_Url.htm
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
Trusted Zone: belamionline.com\www
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - f:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - f:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - f:\progra~1\DOWNLO~1\mdpph.dll
DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6}
DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab
FF - ProfilePath - c:\documents and settings\Simon\Application Data\Mozilla\Firefox\Profiles\mjwfozk6.default\
FF - prefs.js: browser.startup.homepage - hxxp://news.bbc.co.uk/
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Simon\Application Data\Mozilla\Firefox\Profiles\mjwfozk6.default\extensions\{D249FD00-4DF9-11D9-9FDC-0080481ADA61}\components\mpint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin9.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
BHO-{0d3c8bef-d82d-4d63-aefe-a0e9cc1fe6af} - (no file)
HKCU-Run-Steam - (no file)
HKLM-Run-Ifiqixowet - c:\windows\oxehegurixu.dll
HKLM-Run-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
AddRemove-Microsoft Interactive Training - c:\windows\orun32.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-12 15:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1648002289-3947860720-1545137810-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:21,9f,be,bd,63,0f,34,82,cd,84,4e,26,3c,0f,cd,83,fe,a7,67,d3,eb,52,5d,
3a,88,05,96,cd,99,25,30,ae,b5,9b,23,e6,a8,4e,7f,52,c8,c1,ff,63,31,09,ed,b8,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(216)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\progra~1\mcafee.com\vso\mcvsrte.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\wanmpsvc.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\SoftwareDistribution\Download\60cd82908dbb295dedb9fb0ac86f3dfb\update\update.exe
.
**************************************************************************
.
Completion time: 2010-06-12 15:44:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-12 14:44
ComboFix2.txt 2009-10-01 17:00
Pre-Run: 32,631,459,840 bytes free
Post-Run: 32,450,301,952 bytes free
Current=4 Default=4 Failed=2 LastKnownGood=1 Sets=1,2,3,4
- - End Of File - - 218F5EBD1C723B985C5067864DC17D9D