"Alright I got the Log"
ComboFix 12-01-23.02 - Lis 01/25/2012 21:53:23.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.577 [GMT -6:00]
Running from: c:\documents and settings\Lis\My Documents\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Internet Security 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Lis\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
c:\windows\system32\Cache
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c17612172034f293.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
.
c:\windows\system32\drivers\usbehci.sys . . . is missing!!
.
.
((((((((((((((((((((((((( Files Created from 2011-12-26 to 2012-01-26 )))))))))))))))))))))))))))))))
.
.
2012-01-25 22:27 . 2012-01-25 22:27 388096 ----a-r- c:\documents and settings\Lis\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-01-25 22:27 . 2012-01-25 22:27 -------- d-----w- c:\program files\Trend Micro
2012-01-25 21:09 . 2011-12-10 21:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-25 21:09 . 2012-01-25 21:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-25 20:37 . 2012-01-25 20:45 -------- d-----w- c:\windows\SxsCaPendDel
2012-01-25 15:52 . 2012-01-25 15:53 -------- d-----w- c:\program files\Spybot - Search & Destroy
2012-01-23 23:29 . 2012-01-23 23:29 -------- d-----w- c:\program files\CCleaner
2012-01-23 03:02 . 2012-01-23 03:02 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E1FD07C2-F6E6-4DB5-80EE-81F14F32EA93}\MpKsl43d57b38.sys
2012-01-23 02:34 . 2012-01-23 02:34 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E1FD07C2-F6E6-4DB5-80EE-81F14F32EA93}\MpKsl306d9a7c.sys
2012-01-23 02:22 . 2012-01-23 02:22 29904 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E1FD07C2-F6E6-4DB5-80EE-81F14F32EA93}\MpKsl99a40312.sys
2012-01-23 02:11 . 2011-11-28 17:51 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-01-23 02:11 . 2011-11-28 17:53 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-01-23 02:11 . 2011-11-28 17:52 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-01-23 02:11 . 2011-11-28 17:52 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-01-23 02:11 . 2011-11-28 17:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-01-23 02:11 . 2011-11-28 17:52 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-01-23 02:11 . 2011-11-28 17:51 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-01-23 02:11 . 2011-11-28 17:48 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-01-23 02:10 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr
2012-01-23 02:10 . 2011-11-28 18:01 199816 ----a-w- c:\windows\system32\aswBoot.exe
2012-01-23 02:09 . 2012-01-23 02:09 -------- d-----w- c:\program files\AVAST Software
2012-01-23 02:09 . 2012-01-23 02:09 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-01-23 01:39 . 2012-01-23 01:39 92771 ----a-w- c:\documents and settings\All Users\Application Data\1327282435.bdinstall.bin
2012-01-23 01:29 . 2012-01-23 01:29 48211 ----a-w- c:\documents and settings\All Users\Application Data\1327282061.bdinstall.bin
2012-01-20 21:45 . 2009-06-25 19:20 1446264 ----a-w- c:\program files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
2012-01-12 00:20 . 2012-01-12 00:20 370958 ----a-w- c:\documents and settings\All Users\Application Data\1326326272.bdinstall.bin
2012-01-12 00:12 . 2012-01-12 00:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Bitdefender
2012-01-12 00:09 . 2008-11-08 00:55 16928 ------w- c:\windows\system32\spmsgXP_2k3.dll
2012-01-11 23:59 . 2012-01-11 23:59 -------- d-----w- c:\documents and settings\Lis\Application Data\QuickScan
2011-12-30 21:22 . 2011-12-30 21:22 -------- d-----w- c:\documents and settings\Lis\Local Settings\Application Data\SCE
2011-12-30 21:15 . 2011-12-30 21:15 -------- d-----w- c:\program files\Sony Online Entertainment
2011-12-30 21:15 . 2011-12-30 21:15 -------- d-----w- c:\documents and settings\Lis\Application Data\Sony Online Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-25 21:57 . 2008-11-27 04:45 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2008-11-27 04:45 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-21 10:47 . 2011-12-22 22:33 6823496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E1FD07C2-F6E6-4DB5-80EE-81F14F32EA93}\mpengine.dll
2011-11-21 10:47 . 2010-12-07 12:37 6823496 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-20 02:52 . 2011-08-20 14:44 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-18 12:35 . 2008-11-27 04:45 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2008-11-27 04:45 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2008-11-27 04:45 152064 ----a-w- c:\windows\system32\schannel.dll
2011-11-04 19:20 . 2008-11-27 04:45 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2008-11-27 04:45 43520 ------w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2008-11-27 04:45 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2008-11-27 04:45 385024 ------w- c:\windows\system32\html.iec
2011-11-03 15:28 . 2008-11-27 04:45 386048 ----a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2008-11-27 04:45 1292288 ------w- c:\windows\system32\quartz.dll
2011-11-01 16:07 . 2008-11-27 04:45 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2008-11-27 04:45 33280 ----a-w- c:\windows\system32\csrsrv.dll
2012-01-02 22:27 . 2012-01-02 22:27 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-08-14 2532576]
"nwiz"="nwiz.exe" [2002-08-08 372736]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [1/22/2012 8:11 PM 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1/22/2012 8:11 PM 314456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/22/2012 8:11 PM 20568]
R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [7/29/2011 2:18 PM 63448]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/25/2012 3:09 PM 652872]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [1/25/2012 3:09 PM 20464]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S1 MpKsl306d9a7c;MpKsl306d9a7c;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E1FD07C2-F6E6-4DB5-80EE-81F14F32EA93}\MpKsl306d9a7c.sys [1/22/2012 8:34 PM 29904]
S1 MpKsl6a7a04c1;MpKsl6a7a04c1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7065E4D5-A88D-4142-9ADA-F4EBCB9B8E05}\MpKsl6a7a04c1.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7065E4D5-A88D-4142-9ADA-F4EBCB9B8E05}\MpKsl6a7a04c1.sys [?]
S1 MpKsl8d4a12dc;MpKsl8d4a12dc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{62F3CDD5-3521-4367-9F6B-BB20BB3CEDF8}\MpKsl8d4a12dc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{62F3CDD5-3521-4367-9F6B-BB20BB3CEDF8}\MpKsl8d4a12dc.sys [?]
S1 MpKsl8f3aacff;MpKsl8f3aacff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3B6CEF36-23B5-47A5-9574-9A9633A4EA00}\MpKsl8f3aacff.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3B6CEF36-23B5-47A5-9574-9A9633A4EA00}\MpKsl8f3aacff.sys [?]
S1 MpKsl99a40312;MpKsl99a40312;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E1FD07C2-F6E6-4DB5-80EE-81F14F32EA93}\MpKsl99a40312.sys [1/22/2012 8:22 PM 29904]
S1 MpKsldf50c8cc;MpKsldf50c8cc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7964DAE1-46E0-4138-9E65-7034339ABA6C}\MpKsldf50c8cc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7964DAE1-46E0-4138-9E65-7034339ABA6C}\MpKsldf50c8cc.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/24/2009 10:27 PM 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/24/2009 10:27 PM 135664]
S3 kwndis;Kyocera Wireless NDIS Driver;c:\windows\system32\drivers\kwndis.sys [7/24/2007 11:58 PM 112512]
S3 NetWlan5;Symbol Based 802.11b Wireless LAN Card Driver;c:\windows\system32\drivers\NetWlan5.sys [3/15/2010 6:40 PM 132695]
S3 PTUMWBus;PANTECH USB Modem V2 Composite Device Driver;c:\windows\system32\DRIVERS\PTUMWBus.sys --> c:\windows\system32\DRIVERS\PTUMWBus.sys [?]
S3 PTUMWCDF;PANTECH USB Modem V2 Installation CD;c:\windows\system32\DRIVERS\PTUMWCDF.sys --> c:\windows\system32\DRIVERS\PTUMWCDF.sys [?]
S3 PTUMWFLT;PTUMWNET Filter Driver;c:\windows\system32\DRIVERS\PTUMWFLT.sys --> c:\windows\system32\DRIVERS\PTUMWFLT.sys [?]
S3 PTUMWMdm;PANTECH USB Modem V2 Modem Driver;c:\windows\system32\DRIVERS\PTUMWMdm.sys --> c:\windows\system32\DRIVERS\PTUMWMdm.sys [?]
S3 PTUMWNET;PANTECH USB Modem V2 WWAN Driver;c:\windows\system32\DRIVERS\PTUMWNET.sys --> c:\windows\system32\DRIVERS\PTUMWNET.sys [?]
S3 PTUMWVsp;PANTECH USB Modem V2 Diagnostic Port;c:\windows\system32\DRIVERS\PTUMWVsp.sys --> c:\windows\system32\DRIVERS\PTUMWVsp.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-25 04:26]
.
2012-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-25 04:26]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.7.254
DPF: {B94C2238-346E-4C5E-9B36-8CC627F35574}
FF - ProfilePath - c:\documents and settings\Lis\Application Data\Mozilla\Firefox\Profiles\l7k7u9im.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKCU-Run-LxrAutorun - c:\documents and settings\Lis\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-01-25 22:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\vsdatant]
"ImagePath"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(1656)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\SSSensor.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Sygate\SPF\smc.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\LxrSII1s.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2012-01-25 22:37:41 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-26 04:37
.
Pre-Run: 31,799,382,016 bytes free
Post-Run: 32,049,287,168 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30
.
- - End Of File - - 8097E5789B818DC7A4E66838261FA8F5