Ok here is the completed combofix log after 35 mins i decided to open the task manager and pressed ctrl alt del but then combofix finished and produced the log
ComboFix 10-04-14.01 - Gesflor 15/04/2010 0:27.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.511.251 [GMT 1:00]
Running from: c:\documents and settings\Gesflor\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Gesflor\Application Data\.#
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_006509_.tmp.dll
c:\windows\system32\_006510_.tmp.dll
c:\windows\system32\_006511_.tmp.dll
c:\windows\system32\_006512_.tmp.dll
c:\windows\system32\_006519_.tmp.dll
c:\windows\system32\_006520_.tmp.dll
c:\windows\system32\_006521_.tmp.dll
c:\windows\system32\_006522_.tmp.dll
c:\windows\system32\_006524_.tmp.dll
c:\windows\system32\_006525_.tmp.dll
c:\windows\system32\_006528_.tmp.dll
c:\windows\system32\_006529_.tmp.dll
c:\windows\system32\_006531_.tmp.dll
c:\windows\system32\_006532_.tmp.dll
c:\windows\system32\_006533_.tmp.dll
c:\windows\system32\_006535_.tmp.dll
c:\windows\system32\_006536_.tmp.dll
c:\windows\system32\_006538_.tmp.dll
c:\windows\system32\_006539_.tmp.dll
c:\windows\system32\_006543_.tmp.dll
c:\windows\system32\_006544_.tmp.dll
c:\windows\system32\_006546_.tmp.dll
c:\windows\system32\_006549_.tmp.dll
c:\windows\system32\_006551_.tmp.dll
c:\windows\system32\_006552_.tmp.dll
c:\windows\system32\_006553_.tmp.dll
c:\windows\system32\_006554_.tmp.dll
c:\windows\system32\_006555_.tmp.dll
c:\windows\system32\_006558_.tmp.dll
c:\windows\system32\_006559_.tmp.dll
c:\windows\system32\_006560_.tmp.dll
c:\windows\system32\_006561_.tmp.dll
c:\windows\system32\_006562_.tmp.dll
c:\windows\system32\_006567_.tmp.dll
c:\windows\system32\_006569_.tmp.dll
c:\windows\system32\_006570_.tmp.dll
c:\windows\system32\reboot.txt
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\STEC3.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
-------\Legacy_STEC3
-------\Service_STEC3
-------\Service_WinDriver
((((((((((((((((((((((((( Files Created from 2010-03-14 to 2010-04-14 )))))))))))))))))))))))))))))))
.
2010-04-14 16:55 . 2010-04-14 16:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
2010-04-14 16:55 . 2010-04-14 16:55 -------- d-----w- c:\documents and settings\Gesflor\Application Data\Simply Super Software
2010-04-13 19:13 . 2010-04-14 23:20 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-13 17:11 . 2010-04-13 17:11 -------- d-----w- c:\documents and settings\Gesflor\Application Data\Malwarebytes
2010-04-13 17:11 . 2010-04-13 17:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-12 07:33 . 2010-04-12 07:34 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-12 07:31 . 2010-04-12 07:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-04-11 20:04 . 2010-04-11 20:04 -------- d-----w- c:\documents and settings\All Users\Application Data\ReviverSoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-14 23:55 . 2008-02-25 11:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Kontiki
2010-04-14 23:44 . 2010-04-13 19:14 -------- d-----w- c:\program files\Spyware Doctor
2010-04-14 21:18 . 2010-04-14 21:18 -------- d-----w- c:\program files\Trend Micro
2010-04-14 16:56 . 2010-04-14 16:55 -------- d-----w- c:\program files\Trojan Remover
2010-04-13 17:14 . 2010-04-13 17:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-13 16:22 . 2009-12-14 12:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-04-12 12:33 . 2009-02-10 10:23 -------- d-----w- c:\program files\Uniblue
2010-04-12 07:38 . 2010-04-12 07:38 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-12 07:38 . 2010-04-12 11:07 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-04-12 07:34 . 2010-04-12 07:31 -------- d-----w- c:\program files\Lavasoft
2010-04-11 21:11 . 2009-02-10 10:24 -------- d-----w- c:\documents and settings\Gesflor\Application Data\Uniblue
2010-04-11 21:04 . 2004-06-19 16:10 -------- d-----w- c:\program files\Microsoft Encarta
2010-04-11 20:58 . 2004-01-01 09:56 -------- d-----w- c:\program files\HP
2010-04-11 20:56 . 2009-05-20 09:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Transparent
2010-04-11 20:53 . 2009-12-29 21:42 -------- d-----w- c:\program files\PokerStars
2010-04-11 20:52 . 2009-12-17 13:30 -------- d-----w- c:\program files\FilmOn HDi Player
2010-04-11 20:38 . 2009-04-27 16:27 -------- d-----w- c:\documents and settings\Gesflor\Application Data\Azureus
2010-04-11 20:37 . 2010-04-11 20:37 -------- d-----w- c:\program files\CCleaner
2010-04-10 19:16 . 2009-12-14 12:58 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-03-29 23:46 . 2010-04-13 17:11 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 23:45 . 2010-04-13 17:11 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-19 04:50 . 2009-04-25 12:05 -------- d-----w- c:\documents and settings\Gesflor\Application Data\Skype
2010-03-19 00:00 . 2009-04-25 12:13 -------- d-----w- c:\documents and settings\Gesflor\Application Data\skypePM
2010-03-12 09:42 . 2009-12-14 12:58 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-12 09:42 . 2010-03-12 09:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-12 09:42 . 2009-12-14 12:58 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-12 09:40 . 2009-12-14 12:58 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-11 12:38 . 2004-08-23 19:32 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2004-02-24 20:34 17408 ----a-w- c:\windows\system32\corpol.dll
2010-02-24 18:57 . 2009-05-27 14:36 -------- d-----w- c:\documents and settings\Gesflor\Application Data\DVD Flick
2010-02-12 10:03 . 2010-03-07 14:38 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-04 15:53 . 2010-04-12 07:38 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
1757-03-18 11:38 . 1757-03-18 11:38 4263 -csh--w- c:\windows\windllreg1c.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 14:04 1664256 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2003-11-03 221184]
"Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2003-10-29 135168]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-12-05 3022848]
"nwiz"="nwiz.exe" [2003-12-05 753664]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-23 136600]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-19 198160]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2010-02-27 1165192]
c:\documents and settings\Gesflor\Start Menu\Programs\Startup\
Lotus Organizer EasyClip.lnk - c:\lotus\organize\easyclip.exe [1998-9-3 87040]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-2-9 82026]
CLOCKEX.lnk - c:\program files\TClock\TCLOCKEX.EXE [2000-3-9 89088]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-12 09:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/04/2010 08:38 64288]
R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [07/03/2005 09:13 4064]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [14/12/2009 13:58 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [14/12/2009 13:58 242696]
R2 FastPara;FastPara;c:\windows\system32\drivers\fastpara.sys [31/08/2005 07:54 35008]
R3 BT4501G;SpeedTouch 121g Wireless USB Adapter Driver;c:\windows\system32\drivers\BT4501G.sys [14/12/2009 13:20 349824]
S3 musbehco;musbehco;\??\c:\docume~1\Owner\LOCALS~1\Temp\musbehco.sys --> c:\docume~1\Owner\LOCALS~1\Temp\musbehco.sys [?]
S3 ulusbc;NEC 616 CONTROL Driver;c:\windows\system32\drivers\ulusbc.sys [03/01/2005 14:49 43264]
S3 ulusbe;NEC 616 ENUMERATION Driver;c:\windows\system32\drivers\ulusbe.sys [03/01/2005 14:49 12928]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-04-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 07:37]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyServer = 80.177.7.30:1080
DPF: {1803B9EF-9905-4F34-AFC4-05D1BAB28801} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/controls/yregucfg/2005_6_10_1/yregucfg.cab
DPF: {304171C0-65EA-4B51-B5D9-93A311E26EB1} - hxxp://217.126.211.198:1061/cgi-bin/MxPEG_ActiveX.cab?dummy=1528717
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-VTTimer - VTTimer.exe
HKLM-Run-AutoTBar - AUTOTBAR.EXE
Notify-dimsntfy - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-15 00:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\giffile\shell\Open\ddeexec]
@DACL=(02 0000)
@="\"file:%1\",,-1,,,,,"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1812)
c:\windows\system32\WININET.dll
c:\windows\system32\nView.dll
c:\windows\system32\NVWRSENG.DLL
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\nvwddi.dll
c:\progra~1\TEXTBR~1.0\Bin\TBMHOOK.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Lavasoft\Ad-Aware\AAWService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\AVG\AVG9\avgwdsvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\drivers\KodakCCS.exe
c:\program files\Kontiki\KService.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\System32\nvsvc32.exe
c:\program files\Streamload\MediaMax XL\StreamloadService.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\ALCXMNTR.EXE
c:\progra~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\windows\system32\taskmgr.exe
.
**************************************************************************
.
Completion time: 2010-04-15 01:11:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-15 00:11
Pre-Run: 78,526,001,152 bytes free
Post-Run: 78,491,938,816 bytes free
- - End Of File - - DD17EC5A638F09DB829AC0A8C9210E1B