Combofix did help me with hijack this so i am able to give all the info you needed..
Combofix Log:
ComboFix 09-08-28.05 - Main User 08/29/2009 9:03.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1659 [GMT -4:00]
Running from: c:\documents and settings\Main User\Desktop\Combo-fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\MAINUS~1\APPLIC~1\inst.exe
c:\documents and settings\Main User\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\Main User\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\nvorec.dll
c:\windows\system32\drivers\UACsvtioytpoa.sys
c:\windows\system32\resdll.dll
c:\windows\system32\UACfdcnddxcbi.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACowoojruetb.dll
c:\windows\system32\UACtjiydsdumt.dll
c:\windows\system32\UACtwdmelmdnx.dat
c:\windows\system32\UACynbforkcvn.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-29 )))))))))))))))))))))))))))))))
.
2009-08-28 21:26 . 2009-08-28 21:26 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-28 21:24 . 2009-08-28 21:26 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-28 21:24 . 2009-08-28 21:24 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\SUPERAntiSpyware.com
2009-08-28 21:24 . 2009-08-28 21:24 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-26 22:01 . 2009-08-26 22:02 -------- d-----w- c:\program files\LimeWire
2009-08-25 21:31 . 2009-08-25 21:31 -------- d-----w- c:\program files\iPod
2009-08-25 21:31 . 2009-08-25 21:31 -------- d-----w- c:\program files\iTunes
2009-08-25 21:31 . 2009-08-25 21:31 -------- d-----w- c:\program files\Common Files\Apple
2009-08-25 03:43 . 2009-08-25 03:43 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Malwarebytes
2009-08-24 21:23 . 2009-08-24 21:23 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-08-24 20:53 . 2009-08-24 20:53 49048 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-24 19:12 . 2009-08-24 19:12 -------- d-----w- c:\program files\Trend Micro
2009-08-24 19:08 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-24 19:08 . 2009-08-25 03:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-24 19:08 . 2009-08-24 19:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-24 19:08 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-24 02:26 . 2009-08-25 03:20 120 ----a-w- c:\windows\Sfimisukinasul.dat
2009-08-24 02:15 . 2009-08-24 02:15 -------- d-----w- c:\documents and settings\Main User\Local Settings\Application Data\{8D21BD41-08CC-40F4-9328-48574E97D92A}
2009-08-23 20:03 . 2009-08-23 20:03 27188 ---ha-w- c:\windows\system32\wildday.exe
2009-08-22 21:36 . 2009-08-24 21:00 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-22 04:45 . 2009-08-22 04:48 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-08-22 04:45 . 2009-08-22 04:48 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Uniblue
2009-08-22 02:17 . 2009-08-22 02:17 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-08-22 01:03 . 2009-08-22 01:03 -------- d-----w- c:\documents and settings\Administrator\Application Data\Ahead
2009-08-21 23:03 . 2009-08-21 23:03 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-21 21:56 . 2009-08-21 21:56 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\DriverCure
2009-08-21 21:55 . 2009-08-21 21:57 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverCure
2009-08-21 21:55 . 2009-08-21 21:55 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-08-21 21:52 . 2009-08-21 21:52 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Blitware
2009-08-21 21:41 . 2009-08-21 21:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-08-21 15:27 . 2009-08-21 15:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Ludia
2009-08-21 15:27 . 2009-08-21 15:27 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Ludia
2009-08-21 15:11 . 2009-08-21 15:11 -------- d-----w- c:\program files\Ubisoft
2009-08-21 05:24 . 2009-08-21 05:24 -------- d-----w- c:\program files\Hasbro
2009-08-21 03:04 . 2009-08-21 03:04 -------- d-----w- c:\documents and settings\Main User\Local Settings\Application Data\SupportSoft
2009-08-21 03:04 . 2009-08-21 03:04 -------- d-----w- c:\program files\Common Files\SupportSoft
2009-08-20 08:25 . 2009-08-21 05:23 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-20 08:24 . 2009-08-20 08:24 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\SpinTop
2009-08-15 21:55 . 2009-08-15 21:55 -------- d-----w- c:\documents and settings\All Users\Application Data\vsosdk
2009-08-14 07:03 . 2008-04-14 00:12 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-08-13 22:01 . 2009-08-13 22:01 -------- d-----w- c:\program files\Datel
2009-08-13 21:58 . 2001-05-07 10:56 19805 ----a-r- c:\windows\system32\drivers\usbio.sys
2009-08-13 07:11 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 01:03 . 2009-08-13 01:03 -------- d-----w- c:\windows\Sun
2009-08-11 19:53 . 2009-08-11 19:53 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-08-11 19:53 . 2009-08-25 22:06 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Vso
2009-08-11 19:53 . 2007-03-19 00:37 65602 ----a-w- c:\windows\system32\cook3260.dll
2009-08-11 19:53 . 2006-09-29 16:26 176165 ----a-w- c:\windows\system32\drv23260.dll
2009-08-11 19:53 . 2006-09-29 16:25 208935 ----a-w- c:\windows\system32\drv33260.dll
2009-08-11 19:53 . 2006-09-29 16:24 217127 ----a-w- c:\windows\system32\drv43260.dll
2009-08-11 19:53 . 2002-12-10 06:20 102439 ----a-w- c:\windows\system32\sipr3260.dll
2009-08-11 19:53 . 2006-05-20 20:16 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2009-08-11 19:53 . 2006-05-11 23:21 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2009-08-11 19:53 . 2009-08-11 19:53 -------- d-----w- c:\program files\VSO
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 10:54 . 2009-07-19 01:12 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\IMVU
2009-08-29 10:28 . 2009-07-25 03:05 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\BitTorrent
2009-08-29 10:19 . 2009-07-19 17:33 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\gtk-2.0
2009-08-28 22:14 . 2009-07-16 02:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-28 17:48 . 2009-07-19 05:16 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\vlc
2009-08-28 14:28 . 2009-07-19 04:46 8 ----a-w- c:\windows\system32\nvModes.dat
2009-08-28 02:08 . 2009-07-19 01:07 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\IMVUClient
2009-08-26 22:15 . 2009-07-21 17:23 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\LimeWire
2009-08-25 20:38 . 2009-07-19 00:31 -------- d-----w- c:\program files\Canon
2009-08-24 21:03 . 2009-07-16 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-18 00:34 . 2009-07-19 00:34 -------- d-----w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2009-08-15 20:32 . 2009-07-19 04:46 49048 ----a-w- c:\documents and settings\Main User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-11 19:53 . 2009-08-11 19:53 47360 ----a-w- c:\docume~1\MAINUS~1\APPLIC~1\pcouffin.sys
2009-08-10 20:58 . 2009-07-25 20:13 -------- d-----w- c:\program files\Common Files\Roxio Shared
2009-08-10 20:58 . 2009-07-25 20:13 -------- d-----w- c:\program files\Roxio
2009-08-10 20:57 . 2009-07-25 20:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2009-08-05 09:01 . 2004-08-12 14:01 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-27 18:54 . 2009-07-22 18:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-07-26 07:00 . 2009-07-26 07:00 -------- d-----w- c:\program files\MSXML 4.0
2009-07-25 22:08 . 2009-07-16 01:47 -------- d-----w- c:\program files\Ahead
2009-07-25 21:09 . 2009-07-25 21:05 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Roxio
2009-07-25 21:05 . 2009-07-25 21:05 -------- d-----w- c:\documents and settings\LocalService\Application Data\Roxio
2009-07-25 20:16 . 2009-07-25 20:16 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-07-25 20:16 . 2009-07-25 20:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Sonic
2009-07-25 20:16 . 2009-07-18 23:35 -------- d-----w- c:\program files\Common Files\SureThing Shared
2009-07-25 20:13 . 2009-07-16 00:35 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-22 18:38 . 2009-07-22 18:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-07-22 18:37 . 2009-07-22 18:36 -------- d-----w- c:\program files\Yahoo!
2009-07-22 18:37 . 2009-07-22 18:37 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Yahoo!
2009-07-21 18:20 . 2009-07-21 18:20 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Apple Computer
2009-07-21 18:20 . 2009-07-21 18:19 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-21 18:19 . 2009-07-21 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-07-21 18:19 . 2009-07-21 18:19 -------- d-----w- c:\program files\Bonjour
2009-07-21 18:19 . 2009-07-21 18:18 -------- d-----w- c:\program files\QuickTime
2009-07-21 18:18 . 2009-07-21 18:18 -------- d-----w- c:\program files\Apple Software Update
2009-07-21 18:17 . 2009-07-21 18:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-07-20 22:47 . 2009-07-20 22:46 -------- d-----w- c:\program files\Super Mario World
2009-07-20 16:45 . 2009-07-18 23:00 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Ahead
2009-07-20 09:19 . 2009-07-20 09:19 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Windows Search
2009-07-19 21:54 . 2009-07-19 21:54 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-07-19 18:35 . 2009-07-19 18:35 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\IMVU Previewer
2009-07-19 05:15 . 2009-07-19 05:15 -------- d-----w- c:\program files\VideoLAN
2009-07-19 04:56 . 2009-07-19 04:56 -------- d-----w- c:\program files\Gimp-2.0
2009-07-19 04:37 . 2009-07-19 04:37 -------- d-----w- c:\program files\ImvuTools2
2009-07-19 00:29 . 2009-07-19 00:29 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonBJ
2009-07-18 23:35 . 2009-07-18 23:35 -------- d-----w- c:\program files\Memorex exPressit Label Design Studio
2009-07-18 22:23 . 2009-07-18 22:23 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-07-18 03:05 . 2009-07-18 03:05 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\OpenOffice.org
2009-07-18 02:56 . 2009-07-16 01:57 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-17 19:01 . 2004-08-12 13:55 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 02:07 . 2009-07-16 02:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-16 01:59 . 2009-07-16 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-07-16 01:57 . 2009-07-16 01:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-16 01:57 . 2009-07-16 01:57 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-07-16 01:57 . 2009-07-16 01:57 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-16 01:57 . 2009-07-16 01:57 -------- d-----w- c:\program files\AVG
2009-07-16 01:48 . 2009-07-16 01:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2009-07-16 01:48 . 2009-07-16 01:48 -------- d-----w- c:\program files\Common Files\Nero
2009-07-16 01:47 . 2009-07-16 01:47 -------- d-----w- c:\program files\Common Files\Ahead
2009-07-16 01:46 . 2009-07-16 01:46 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\CyberLink
2009-07-16 01:45 . 2009-07-16 01:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2009-07-16 01:45 . 2009-07-16 01:45 -------- d-----w- c:\program files\CyberLink
2009-07-16 01:45 . 2009-07-16 00:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-16 01:41 . 2009-07-16 01:41 -------- d-----w- c:\program files\JRE
2009-07-16 01:41 . 2009-07-16 01:41 -------- d-----w- c:\program files\OpenOffice.org 3
2009-07-16 01:41 . 2009-07-16 01:38 -------- d-----w- c:\program files\Java
2009-07-16 01:38 . 2009-07-16 01:38 0 ----a-w- c:\windows\nsreg.dat
2009-07-16 01:38 . 2009-07-16 01:38 -------- d-----w- c:\program files\Common Files\Java
2009-07-16 01:37 . 2009-07-16 01:37 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-16 01:31 . 2009-07-16 01:22 -------- d-----w- c:\program files\Windows Desktop Search
2009-07-16 01:24 . 2009-07-16 01:24 -------- d-----w- c:\program files\MSBuild
2009-07-16 01:24 . 2009-07-16 01:24 -------- d-----w- c:\program files\Reference Assemblies
2009-07-16 01:22 . 2009-07-16 01:22 -------- d-----w- c:\docume~1\MAINUS~1\APPLIC~1\Windows Desktop Search
2009-07-16 01:21 . 2009-07-16 01:21 -------- d-----w- c:\program files\Windows Media Connect 2
2009-07-16 00:57 . 2009-07-16 00:27 77423 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-16 00:39 . 2009-07-16 00:39 -------- d-----w- c:\program files\Broadcom
2009-07-16 00:38 . 2009-07-16 00:38 -------- d-----w- c:\program files\CONEXANT
2009-07-16 00:36 . 2009-07-16 00:36 -------- d-----w- c:\program files\Analog Devices
2009-07-16 00:28 . 2009-07-16 00:28 -------- d-----w- c:\program files\microsoft frontpage
2009-07-16 00:25 . 2009-07-16 00:25 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-14 03:43 . 2004-08-12 14:10 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-13 18:22 . 2009-07-13 18:22 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-03 17:09 . 2004-08-12 14:09 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-12 14:08 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-12 14:04 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-12 14:04 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-12 14:01 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-12 13:59 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-12 13:58 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-12 13:58 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-12 14:07 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-12 13:57 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-14 20:07 . 2009-07-16 02:01 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-12 12:31 . 2004-08-12 14:07 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-12 13:55 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2009-07-16 00:24 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-12 14:09 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2004-08-12 14:03 1291264 ----a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-01-27 1381376]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-16 1948440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-18 1657376]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-16 01:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Main User\\Desktop\\BitTorrent\\bittorrent.exe"=
"c:\\Documents and Settings\\Main User\\Application Data\\IMVUClient\\IMVUClient.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/15/2009 9:57 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/15/2009 9:57 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/15/2009 9:57 PM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/15/2009 9:57 PM 298776]
S2 assert update;assert update;c:\windows\system32\wildday.exe [8/23/2009 4:03 PM 27188]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Main User\Start Menu\Programs\IMVU\Run IMVU.lnk
FF - ProfilePath - c:\docume~1\MAINUS~1\APPLIC~1\Mozilla\Firefox\Profiles\7wucojqp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.imvu.com/catalog/web_mypage.php?user=35573861
FF - HiddenExtension: XUL Cache: {8D21BD41-08CC-40F4-9328-48574E97D92A} - c:\documents and settings\Main User\Local Settings\Application Data\{8D21BD41-08CC-40F4-9328-48574E97D92A}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-29 09:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(636)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2009-08-29 9:09
ComboFix-quarantined-files.txt 2009-08-29 13:09
Pre-Run: 186,590,842,880 bytes free
Post-Run: 186,772,926,464 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
290 --- E O F --- 2009-08-26 21:49
Combofix uninstall list
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8
Apple Mobile Device Support
Apple Software Update
AVG Free 8.5
Bonjour
Broadcom Gigabit Integrated Controller
Conexant D850 56K V.9x DFVc Modem
ConvertXtoDVD 3.3.4.106e
Critical Update for Windows Media Player 11 (KB959772)
Dell ResourceCD
Gimp 2.6.2 Debug
Hell's Kitchen 1.1.5
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
iTunes
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 7
LimeWire 5.1.4
Malwarebytes' Anti-Malware
Memorex exPressit Label Design Studio
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Monopoly Here & Now Edition
Mozilla Firefox (3.0.13)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
Nero Suite
NVIDIA Drivers
OpenOffice.org 3.0
PIXMA Extended Survey Program
PowerDVD
QuickTime
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
SoundMAX
Spybot - Search & Destroy
Super Mario World
SUPERAntiSpyware Free Edition
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
VLC media player 1.0.0
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
WinRAR archiver
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar