Here's the full combofix log:
ComboFix 10-06-03.01 - Brad 06/05/2010 16:03:23.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1306 [GMT -4:00]
Running from: c:\documents and settings\Brad\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ActiveArmor Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Brad\Application Data\inst.exe
c:\documents and settings\Brad\Local Settings\Application Data\Windows Server\flags.ini
c:\documents and settings\Brad\Local Settings\Application Data\Windows Server\uses32.dat
C:\feed.txt
c:\windows\desktop\Virtual Pool 3.lnk
c:\windows\system32\Chip.dll
c:\windows\system32\ernel32.dll
c:\windows\system32\Pvt.tmp
----- BITS: Possible infected sites -----
hxxp://goldencaravela.net
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe
.
((((((((((((((((((((((((( Files Created from 2010-05-05 to 2010-06-05 )))))))))))))))))))))))))))))))
.
2010-06-05 15:12 . 2010-06-02 20:58 72192 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\5mYW5.dll
2010-06-05 15:09 . 2010-06-02 20:58 72192 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\9qGM9gM7g.dll
2010-06-04 20:35 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-04 20:35 . 2010-06-04 20:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-04 20:35 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-03 01:57 . 2010-06-03 01:57 -------- d-----w- c:\program files\Trend Micro
2010-06-03 00:57 . 2010-06-03 00:57 -------- d-----w- c:\documents and settings\Brad\Application Data\Malwarebytes
2010-06-03 00:57 . 2010-06-03 00:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-02 22:22 . 2010-06-02 22:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-02 22:22 . 2010-06-02 22:22 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-06-01 18:26 . 2010-06-03 02:06 -------- d-----w- c:\program files\Ask.com
2010-06-01 05:28 . 2010-06-01 05:28 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2010-05-31 15:31 . 2010-05-31 15:40 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-05-25 03:50 . 2010-05-25 03:50 -------- d-----w- c:\documents and settings\Danielle\Local Settings\Application Data\Identities
2010-05-22 17:07 . 2008-04-14 00:12 26112 ----a-w- c:\windows\system32\stu2.exe
2010-05-19 17:22 . 2010-05-19 17:22 -------- d-----w- c:\documents and settings\Shelley\Application Data\Media Player Classic
2010-05-17 19:43 . 2010-05-17 19:43 -------- d-----w- c:\documents and settings\Danielle\Application Data\Search Settings
2010-05-17 19:43 . 2010-05-17 19:43 -------- d-----w- c:\documents and settings\Danielle\Application Data\pdfforge
2010-05-16 04:13 . 2010-04-12 21:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-11 21:48 . 2010-05-11 21:48 -------- d-----w- c:\documents and settings\Shelley\Application Data\Search Settings
2010-05-11 21:48 . 2010-05-11 21:48 -------- d-----w- c:\documents and settings\Shelley\Application Data\pdfforge
2010-05-11 09:08 . 2010-05-24 02:51 670024 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-05-11 03:58 . 2010-05-11 03:58 -------- d-----w- c:\documents and settings\Justin\Application Data\Search Settings
2010-05-11 03:58 . 2010-05-11 03:58 -------- d-----w- c:\documents and settings\Justin\Application Data\pdfforge
2010-05-11 00:55 . 2001-10-28 20:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2010-05-11 00:55 . 2010-05-11 00:56 -------- d-----w- c:\program files\PDFCreator
2010-05-11 00:55 . 1998-07-06 04:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-05 19:59 . 2008-12-15 19:57 -------- d-----w- c:\documents and settings\Brad\Application Data\uTorrent
2010-06-05 15:48 . 2010-04-04 16:36 -------- d-----w- c:\documents and settings\Brad\Application Data\Acsati
2010-06-05 14:27 . 2010-04-21 16:55 -------- d-----w- c:\documents and settings\Brad\Application Data\Goah
2010-06-03 21:49 . 2009-01-22 22:43 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2010-06-03 21:46 . 2009-04-15 05:12 -------- d-----w- c:\documents and settings\Brad\Application Data\Wuzoid
2010-06-03 20:15 . 2010-03-27 13:22 -------- d-----w- c:\documents and settings\Brad\Application Data\Zaam
2010-06-03 02:07 . 2009-11-10 04:30 -------- d-----w- c:\program files\Yahoo!
2010-06-03 02:07 . 2009-11-10 17:33 -------- d-----w- c:\program files\LimeWire
2010-06-03 01:48 . 2008-11-11 00:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Kodak
2010-06-03 01:45 . 2008-11-11 00:12 -------- d-----w- c:\program files\Kodak EasyShare software
2010-06-03 01:08 . 2008-11-07 00:57 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-02 22:22 . 2008-12-15 11:58 -------- d-----w- c:\program files\Lavasoft
2010-06-02 20:03 . 2009-01-22 04:33 -------- d-----w- c:\documents and settings\Justin\Application Data\LimeWire
2010-06-02 07:03 . 2008-11-11 05:11 -------- d-----w- c:\documents and settings\Danielle\Application Data\LimeWire
2010-06-01 18:27 . 2010-06-01 18:27 8462336 ----a-w- c:\documents and settings\Justin\Application Data\LimeWire\browser\xulrunner\xul.dll
2010-05-31 17:43 . 2008-11-09 12:35 -------- d-----w- c:\documents and settings\Brad\Application Data\DivX
2010-05-31 15:54 . 2010-05-31 15:54 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-31 15:40 . 2008-11-09 12:34 -------- d-----w- c:\program files\DivX
2010-05-31 15:40 . 2010-05-31 15:40 56978 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-05-31 15:40 . 2010-05-31 15:40 56766 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-05-31 15:40 . 2010-05-31 15:40 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-05-31 15:40 . 2010-05-31 15:40 57679 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 84040 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 54629 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-05-31 15:39 . 2010-05-31 15:39 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-31 15:38 . 2010-05-31 15:38 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-31 15:38 . 2010-05-31 15:38 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-05-31 15:38 . 2009-04-10 10:20 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-05-31 15:31 . 2010-05-31 15:31 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-31 15:31 . 2010-05-31 15:40 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-05-31 15:31 . 2010-05-31 15:40 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-05-28 21:33 . 2010-05-28 21:33 61440 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-29ad05e5-n\decora-sse.dll
2010-05-28 21:33 . 2010-05-28 21:33 503808 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-365bf0f9-n\msvcp71.dll
2010-05-28 21:33 . 2010-05-28 21:33 499712 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-365bf0f9-n\jmc.dll
2010-05-28 21:33 . 2010-05-28 21:33 348160 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-365bf0f9-n\msvcr71.dll
2010-05-28 21:33 . 2010-05-28 21:33 12800 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-29ad05e5-n\decora-d3d.dll
2010-05-25 13:24 . 2010-05-25 13:24 503808 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6a088a4d-n\msvcp71.dll
2010-05-25 13:24 . 2010-05-25 13:24 61440 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3127e312-n\decora-sse.dll
2010-05-25 13:24 . 2010-05-25 13:24 499712 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6a088a4d-n\jmc.dll
2010-05-25 13:24 . 2010-05-25 13:24 348160 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6a088a4d-n\msvcr71.dll
2010-05-25 13:24 . 2010-05-25 13:24 12800 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3127e312-n\decora-d3d.dll
2010-05-24 15:57 . 2010-05-24 15:57 503808 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-402fa89c-n\msvcp71.dll
2010-05-24 15:57 . 2010-05-24 15:57 499712 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-402fa89c-n\jmc.dll
2010-05-24 15:57 . 2010-05-24 15:57 348160 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-402fa89c-n\msvcr71.dll
2010-05-24 15:57 . 2010-05-24 15:57 12800 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-49cdf5fc-n\decora-d3d.dll
2010-05-24 15:57 . 2010-05-24 15:57 61440 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-49cdf5fc-n\decora-sse.dll
2010-05-22 23:44 . 2010-05-22 23:44 61440 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-67d6d222-n\decora-sse.dll
2010-05-22 23:44 . 2010-05-22 23:44 503808 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-706ff738-n\msvcp71.dll
2010-05-22 23:44 . 2010-05-22 23:44 499712 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-706ff738-n\jmc.dll
2010-05-22 23:44 . 2010-05-22 23:44 348160 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-706ff738-n\msvcr71.dll
2010-05-22 23:44 . 2010-05-22 23:44 12800 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-67d6d222-n\decora-d3d.dll
2010-05-17 19:09 . 2010-05-17 19:09 503808 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3ef3c848-n\msvcp71.dll
2010-05-17 19:09 . 2010-05-17 19:09 499712 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3ef3c848-n\jmc.dll
2010-05-17 19:09 . 2010-05-17 19:09 348160 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-3ef3c848-n\msvcr71.dll
2010-05-17 19:09 . 2010-05-17 19:09 61440 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5b753baf-n\decora-sse.dll
2010-05-17 19:09 . 2010-05-17 19:09 12800 ----a-w- c:\documents and settings\Danielle\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5b753baf-n\decora-d3d.dll
2010-05-17 18:38 . 2010-05-17 18:38 503808 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5cd94474-n\msvcp71.dll
2010-05-17 18:38 . 2010-05-17 18:38 499712 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5cd94474-n\jmc.dll
2010-05-17 18:38 . 2010-05-17 18:38 348160 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5cd94474-n\msvcr71.dll
2010-05-17 18:38 . 2010-05-17 18:38 12800 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7cd3504c-n\decora-d3d.dll
2010-05-17 18:38 . 2010-05-17 18:38 61440 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7cd3504c-n\decora-sse.dll
2010-05-17 15:57 . 2010-05-17 15:57 503808 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-76ab067c-n\msvcp71.dll
2010-05-17 15:57 . 2010-05-17 15:57 499712 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-76ab067c-n\jmc.dll
2010-05-17 15:57 . 2010-05-17 15:57 348160 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-76ab067c-n\msvcr71.dll
2010-05-17 15:57 . 2010-05-17 15:57 61440 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-54001205-n\decora-sse.dll
2010-05-17 15:57 . 2010-05-17 15:57 12800 ----a-w- c:\documents and settings\Shelley\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-54001205-n\decora-d3d.dll
2010-05-16 04:13 . 2008-11-08 04:34 -------- d-----w- c:\program files\Common Files\Java
2010-05-16 04:13 . 2010-05-16 04:13 503808 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-59d27524-n\msvcp71.dll
2010-05-16 04:13 . 2010-05-16 04:13 499712 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-59d27524-n\jmc.dll
2010-05-16 04:13 . 2010-05-16 04:13 348160 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-59d27524-n\msvcr71.dll
2010-05-16 04:13 . 2010-05-16 04:13 61440 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5cf69dcb-n\decora-sse.dll
2010-05-16 04:13 . 2010-05-16 04:13 12800 ----a-w- c:\documents and settings\Brad\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5cf69dcb-n\decora-d3d.dll
2010-05-16 04:13 . 2008-11-08 04:35 -------- d-----w- c:\program files\Java
2010-05-14 21:30 . 2008-12-15 11:58 -------- d-----w- c:\program files\uTorrent
2010-03-31 01:58 . 2008-11-09 12:34 44944 ----a-w- c:\windows\system32\drivers\PxHelp20.sys
2010-03-31 01:58 . 2008-11-09 12:34 133616 ------w- c:\windows\system32\pxafs.dll
2010-03-31 01:58 . 2008-11-09 12:34 125424 ------w- c:\windows\system32\pxinsi64.exe
2010-03-31 01:58 . 2008-11-09 12:34 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-03-17 21:27 . 2010-03-17 21:27 3663 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2010-03-17 21:27 . 2009-02-11 21:37 1085616 ----a-w- c:\windows\system32\SpoonUninstall.exe
2010-03-17 21:25 . 2010-03-17 21:25 1259 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp m4b Audio book Encoder.dat
2010-03-17 21:25 . 2010-03-17 21:25 3175 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp m4a Utilities.dat
2010-03-10 18:00 . 2010-03-14 12:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-03-09 11:09 . 2004-08-04 12:00 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll
2003-08-27 22:19 . 2008-11-08 04:57 36963 -c--a-r- c:\program files\Common Files\SM1updtr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-08-07 700416]
"Aim6"="" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RoxioDragToDisc"="c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2004-01-28 1179648]
"SM1BG"="c:\windows\SM1BG.EXE" [2003-08-27 94208]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-29 17331200]
"EPSON Stylus CX4800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE" [2005-02-02 98304]
"RemoteControl"="c:\program files\Roxio\Roxio DVDMax Player\PDVDServ.exe" [2003-10-27 32768]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-03-18 2046816]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-30 13:55 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [1/22/2009 6:44 PM 12552]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/11/2009 6:22 AM 721904]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/22/2009 6:43 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/22/2009 6:43 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [1/23/2009 9:42 AM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/23/2009 9:42 AM 297752]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/4/2010 4:36 PM 304464]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/8/2008 3:25 AM 24652]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/4/2010 4:35 PM 20952]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [12/23/2008 10:58 AM 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [12/23/2008 10:58 AM 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [12/23/2008 10:58 AM 42112]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [12/23/2008 10:58 AM 23680]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: intuit.com\ttlc
FF - ProfilePath - c:\documents and settings\Brad\Application Data\Mozilla\Firefox\Profiles\g6xuc01e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.rr.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npagent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-{24F796D3-1E4A-7E93-8D91-18271346ADC1} - c:\documents and settings\Brad\Application Data\Acsati\luuxu.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-05 16:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sppm.sys >>UNKNOWN [0x8A4A4938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba8ecf28
\Driver\ACPI -> ACPI.sys @ 0xba666cb8
\Driver\atapi -> atapi.sys @ 0xba5fbb40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579014
ParseProcedure -> ntkrnlpa.exe @ 0x80577c76
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579014
ParseProcedure -> ntkrnlpa.exe @ 0x80577c76
NDIS: NVIDIA nForce Networking Controller -> SendCompleteHandler -> NDIS.sys @ 0xba4d7bb0
PacketIndicateHandler -> NDIS.sys @ 0xba4e4a21
SendHandler -> NDIS.sys @ 0xba4c287b
user & kernel MBR OK
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ôw*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1140)
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-06-05 16:26:16 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-05 20:26
Pre-Run: 10,591,428,608 bytes free
Post-Run: 10,551,771,136 bytes free
- - End Of File - - 546B87C79638929D2B81C14D2E12E485