Ok, it took forever but I finally got Combofix to run and here's the result:
ComboFix 09-10-19.04 - Mandi Mooney 10/20/2009 18:16.1.1 - NTFSx86
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\7969527279
c:\documents and settings\Administrator\Application Data\7969527279\7969527279.bat
c:\documents and settings\Administrator\Application Data\7969527279\7969527279.cfg
c:\documents and settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\10\AVGToolbarInstall.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\11\avgxch32.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\15\avg7api.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\15\avgmail.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\15\avgmvflx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\15\avgscanx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\15\avgscanx.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\15\avgvvx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\15\avgwdwsc.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\3\avgbat.bav
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\34\avgmfx64.sys
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\34\avgmfx86.sys
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\34\avgrsa.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\34\avgrssta.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\34\avgrsstx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\34\avgrsx.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\afuinst64.dat
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgabout.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgamnot.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgapix.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgcfgex.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgcfgx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgcmgr.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgdumpx.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgfrw.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avginet.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgiproxy.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgldx86.sys
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avglngx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avglogx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avglvex.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgnsx.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgpp.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgresf.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgsched.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgsrmax.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgsrmx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgssff.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgssie.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgtbapi.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgtdix.sys
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgtray.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgui.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avguiadv.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avguires.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgupd.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgupd.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgwd.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgwdsvc.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\avgxpl.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\dbghelp.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\fixcfg.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\setup.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\35\sporder.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\36\avgse.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\36\avgsea.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\4\avgcclix.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\4\avgclitx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\4\avgcorex.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\4\avgcrlpx.dll
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\4\avgcsrvx.exe
c:\documents and settings\Administrator\Local Settings\Temp\AVGDownloadManager\packages\7\avgoff2k.dll
c:\documents and settings\Administrator\Local Settings\Temp\is-90QMH.tmp\_isetup\_RegDLL.tmp
c:\documents and settings\Administrator\Local Settings\Temp\is-90QMH.tmp\_isetup\_shfoldr.dll
c:\documents and settings\Administrator\Local Settings\Temp\is-90QMH.tmp\mbam.dll
c:\documents and settings\Administrator\Local Settings\Temp\is-9MCT9.tmp\mbam-setup.tmp
c:\documents and settings\Administrator\Local Settings\Temp\is-LDLHG.tmp\mbam-setup.tmp
c:\documents and settings\Administrator\Local Settings\Temp\is-M5G8N.tmp\_isetup\_RegDLL.tmp
c:\documents and settings\Administrator\Local Settings\Temp\is-M5G8N.tmp\_isetup\_shfoldr.dll
c:\documents and settings\Administrator\Local Settings\Temp\is-M5G8N.tmp\mbam.dll
c:\documents and settings\Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\Q7STOROP\mbam-setup[1].exe
c:\documents and settings\Administrator\ntuser.dll
c:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.dll
c:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.lnk
c:\documents and settings\All Users\Application Data\46935229
c:\documents and settings\All Users\Application Data\46935229\46935229.bat
c:\documents and settings\All Users\Application Data\62102617
c:\documents and settings\All Users\Application Data\62102617\62102617.bat
c:\documents and settings\Mandi Mooney\ntuser.dll
c:\documents and settings\Mandi Mooney\Start Menu\Programs\Startup\scandisk.dll
c:\documents and settings\Mandi Mooney\Start Menu\Programs\Startup\scandisk.lnk
c:\program files\Common
c:\program files\Common\_helper.sig
c:\program files\maqonv
c:\program files\maqonv\iygrsysguard.exe
c:\program files\Shared
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\iyufuloh.dll
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\run.log
c:\windows\system32\11478.exe
c:\windows\system32\13782.exe
c:\windows\system32\14044.exe
c:\windows\system32\15724.exe
c:\windows\system32\16771.exe
c:\windows\system32\16827.exe
c:\windows\system32\17853.exe
c:\windows\system32\18029.exe
c:\windows\system32\18151.exe
c:\windows\system32\18467.exe
c:\windows\system32\18803.exe
c:\windows\system32\18841.exe
c:\windows\system32\19169.exe
c:\windows\system32\19226.exe
c:\windows\system32\20498.exe
c:\windows\system32\21095.exe
c:\windows\system32\21551.exe
c:\windows\system32\22033.exe
c:\windows\system32\22557.exe
c:\windows\system32\22581.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\24695.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\27961.exe
c:\windows\system32\28145.exe
c:\windows\system32\29358.exe
c:\windows\system32\29479.exe
c:\windows\system32\30146.exe
c:\windows\system32\30945.exe
c:\windows\system32\3199.exe
c:\windows\system32\3625.exe
c:\windows\system32\3956.exe
c:\windows\system32\41.exe
c:\windows\system32\5705.exe
c:\windows\system32\5935.exe
c:\windows\system32\6334.exe
c:\windows\system32\6471.exe
c:\windows\system32\652.exe
c:\windows\system32\7135.exe
c:\windows\system32\724.exe
c:\windows\system32\8221.exe
c:\windows\system32\8801.exe
c:\windows\system32\9961.exe
c:\windows\system32\AVR09.exe
c:\windows\system32\bincd32.dat
c:\windows\system32\biyogali.dll
c:\windows\system32\bodihovi.dll
c:\windows\system32\calc.dll
c:\windows\system32\config\systemprofile\Application Data\6221912618
c:\windows\system32\config\systemprofile\Application Data\6221912618\6221912618.bat
c:\windows\system32\config\systemprofile\Application Data\6221912618\6221912618.cfg
c:\windows\system32\config\systemprofile\Application Data\6221912618\6221912618.exe
c:\windows\system32\config\systemprofile\Application Data\lizkavd.exe
c:\windows\system32\config\systemprofile\Application Data\seres.exe
c:\windows\system32\config\systemprofile\Application Data\svcst.exe
c:\windows\system32\config\systemprofile\ntuser.dll
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
c:\windows\system32\drivers\SKYNETqvxduymi.sys
c:\windows\system32\gikuseju.dll
c:\windows\system32\gomonoye.dll
c:\windows\system32\hizupoye.dll
c:\windows\system32\iehelper.dll
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\janufini.dll
c:\windows\system32\juyiwune.dll
c:\windows\system32\ketisuli.dll
c:\windows\system32\kogujiru.dll
c:\windows\system32\lojerawu.dll
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\mipasowu.dll
c:\windows\system32\mosanemi.dll
c:\windows\system32\mscomct2.dat
c:\windows\system32\msCOrewr.dll
c:\windows\system32\pump.exe
c:\windows\system32\sepajimo.exe
c:\windows\system32\skynet.dat
c:\windows\system32\SKYNETalnqjlct.dll
c:\windows\system32\SKYNETdkdffbym.dll
c:\windows\system32\SKYNETfqxoqmqi.dll
c:\windows\system32\SKYNEThxvrjbav.dll
c:\windows\system32\SKYNETjgymnkvy.dll
c:\windows\system32\SKYNETqhrrjenk.dll
c:\windows\system32\SKYNETvwqtahht.dat
c:\windows\system32\SKYNETymqfuivm.dat
c:\windows\system32\sonhelp.htm
c:\windows\system32\winupdate.exe
c:\windows\system32\wispex.html
c:\windows\system32\yizofuyu.dll
c:\windows\system32\yovimuti.dll
c:\windows\system32\zeselufu.dll
c:\windows\Temp\3749436016.exe
c:\windows\Temp\418741962.exe
c:\windows\wf3.dat
c:\windows\wf4.dat
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETodablrmy
-------\Legacy_SKYNETodablrmy
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-09-21 to 2009-10-21 )))))))))))))))))))))))))))))))
.
2009-10-20 22:19 . 2009-10-20 22:19 -------- d-----w- c:\documents and settings\Mandi Mooney\Local Settings\Application Data\{14F1623B-F81D-4FD8-8AC7-CABBB18179E4}
2009-10-18 14:59 . 2009-10-20 22:13 0 ----a-r- c:\windows\Pgogi.bin
2009-10-18 14:59 . 2009-10-20 22:13 120 ----a-w- c:\windows\Shaqaxu.dat
2009-10-18 14:59 . 2009-10-18 14:59 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\{4DBAD962-922E-4BE4-BDB6-BAF4699DF0C5}
2009-10-17 01:58 . 2009-10-20 22:22 0 ----a-r- c:\windows\win32k.sys
2009-10-15 22:37 . 2009-10-20 22:49 744 ----a-w- c:\windows\system32\wininit.dll
2009-10-05 17:13 . 2009-10-05 22:04 131731 ----a-w- c:\windows\system32\dbsinit.exe
2009-10-05 17:01 . 2009-10-05 17:01 5120 ----a-w- C:\pmyro.exe
2009-10-05 00:13 . 2009-10-05 00:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-17 01:57 . 2009-09-11 00:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-18 23:31 . 2009-09-18 23:31 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-18 23:31 . 2009-09-18 23:31 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-18 23:31 . 2009-09-18 23:31 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-18 23:31 . 2009-09-18 23:31 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-18 23:30 . 2009-09-18 23:30 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-09-18 23:30 . 2009-09-18 23:30 -------- d-----w- c:\program files\AVG
2009-09-18 23:30 . 2009-09-18 23:30 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-18 23:26 . 2009-09-18 23:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\AVG8
2009-09-18 23:06 . 2009-09-18 23:06 -------- d-----w- c:\program files\Trend Micro
2009-09-13 13:19 . 2009-09-13 13:19 163840 ----a-w- c:\windows\svchasts.exe
2009-09-13 03:04 . 2009-09-13 03:03 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-09-13 03:03 . 2009-09-13 03:03 -------- d-----w- c:\program files\Common Files\Cisco Systems
2009-09-13 03:03 . 2009-09-13 03:02 -------- d-----w- c:\program files\McAfee
2009-09-13 03:02 . 2009-09-13 03:02 -------- d-----w- c:\program files\Common Files\McAfee
2009-09-11 01:12 . 2009-09-11 01:12 -------- d-----w- c:\documents and settings\Mandi Mooney\Application Data\Malwarebytes
2009-09-11 01:02 . 2009-09-02 10:22 7 ----a-w- c:\windows\system32\nar.bin
2009-09-11 00:18 . 2009-09-11 00:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-09-11 00:18 . 2009-09-11 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-03 18:36 . 2009-09-11 00:18 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2009-09-11 00:18 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2005-10-31 02:09 . 2005-10-31 02:06 20921040 ----a-w- c:\program files\AdbeRdr705_enu_full.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="c:\program files\AIM\aim.exe" [2005-08-05 67160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-07-28 4841472]
"WCOLOREAL"="c:\program files\COMPAQ\Coloreal\coloreal.exe" [2002-01-22 131072]
"CPQEASYACC"="c:\program files\Compaq\Easy Access Button Support\StartEAK.exe" [2001-12-14 32768]
"srmclean"="c:\cpqs\Scom\srmclean.exe" [2001-07-24 36864]
"Smapp"="c:\program files\Analog Devices\SoundMAX\Smtray.exe" [2001-10-12 69632]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-09-28 26112]
"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2000-07-13 311350]
"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [2000-07-13 28739]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-02-10 1420560]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-01-15 267048]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-08-03 1295632]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-10-17 111952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2007-10-25 136512]
"CARPService"="carpserv.exe" - c:\windows\system32\carpserv.exe [2002-07-08 4608]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-07-28 323584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil9f.exe" [2008-03-25 218496]
c:\documents and settings\Mandi Mooney\Start Menu\Programs\Startup\
Adobe Media Player.lnk - c:\program files\Adobe Media Player\Adobe Media Player.exe [2008-9-24 260096]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2008-4-15 303104]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-7-13 24633]
office.exe [2009-10-16 102678]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli msninte2.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
R1 EACMOS;EACMOS;c:\windows\system32\drivers\EACMOS.SYS [x]
R2 srmsvc;srmsvc;c:\windows\srmsvc.exe [x]
R4 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [2006-02-10 45840]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-09-18 335240]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-09-18 108552]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-09-18 297752]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 C4C_BSC2;C4C_BSC2;c:\windows\system32\DRIVERS\C4C_BSC2.sys [2002-07-08 84788]
.
Contents of the 'Scheduled Tasks' folder
2009-10-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-02-10 21:27]
2005-10-03 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\System32\OOBE\oobebaln.exe [2001-08-18 07:56]
2005-09-28 c:\windows\Tasks\Registration reminder 2.job
- c:\windows\System32\OOBE\oobebaln.exe [2001-08-18 07:56]
2005-10-13 c:\windows\Tasks\Registration reminder 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2001-08-18 07:56]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
mSearch Bar = hxxp://rd.yahoo.com/customize/yessentials_cq/defaults/sb/*http://www.yahoo.com/search/ie.html
uInternet Connection Wizard,ShellNext = hxxp://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
LSP: c:\windows\system32\vaOICKwyOu.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: Yahoo! Euchre - hxxp://origin.games.yahoo.net/games/clients/y/et3_x.cab
.
- - - - ORPHANS REMOVED - - - -
BHO-{a50a9cb4-78e3-2cdf-2c42-0ec7e8950ed2} - c:\windows\iyufuloh.dll
WebBrowser-{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
HKLM-Run-AVG7_CC - c:\progra~1\Grisoft\AVGFRE~1\avgcc.exe
HKLM-Run-AOLDialer - c:\program files\Common Files\AOL\ACS\AOLDial.exe
HKLM-Run-lomesujin - c:\windows\system32\bodihovi.dll
HKLM-Run-Xjatubi - c:\windows\iyufuloh.dll
HKLM-Run-AutoLogon - (no file)
HKU-Default-Run-AVG7_Run - c:\progra~1\Grisoft\AVGFRE~1\avgw.exe
HKU-Default-Run-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKU-Default-Run-system tool - c:\program files\maqonv\iygrsysguard.exe
HKU-Default-Run-calc - c:\windows\system32\config\SYSTEM~1\ntuser.dll
HKU-Default-Run-Microsoft uptime Service - sysuptime.exe
SharedTaskScheduler-{8178829f-3c09-4ba6-91d5-646db1b3a77d} - c:\windows\system32\bodihovi.dll
SSODL-pejuwesaw-{8178829f-3c09-4ba6-91d5-646db1b3a77d} - c:\windows\system32\bodihovi.dll
SafeBoot-EACMOS.SYS
AddRemove-AVG7Uninstall - c:\program files\Grisoft\AVG Free\setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-20 19:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(672)
c:\windows\msninte2.dll
- - - - - - - > 'explorer.exe'(3904)
c:\windows\msninte2.dll
c:\windows\system32\browselc.dll
c:\program files\McAfee\VirusScan Enterprise\Scriptcl.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\windows\system32\nvsvc32.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\windows\system32\wdfmgr.exe
c:\combofix\CF10059.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
c:\program files\Compaq\Easy Access Button Support\CPQEADM.EXE
c:\compaq\EAKDRV\EAUSBKBD.EXE
c:\progra~1\Compaq\EASYAC~1\BttnServ.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\program files\iPod\bin\iPodService.exe
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-21 19:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-21 00:13
Pre-Run: 60,048,687,104 bytes free
Post-Run: 63,186,464,768 bytes free
- - End Of File - - 88DD1BEBAA60A9C60A5B5ECBBBE46C92
AS A NOTE: After I ran ComboFix, my internet stopped working. I've checked with my local provider and they've advised that it's a problem on my end. Can you advise what I need to do to restore connections?