OK, this is what I got. I really appreciate you helping me with this!
ComboFix 10-02-05.01 - Owner 02/05/2010 13:21:35.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.401 [GMT -5:00]
Running from: E:\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Application Data\Desktopicon
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.
2010-02-05 18:09 . 2010-02-05 18:09 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2010-02-04 21:42 . 2010-02-04 21:42 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\AVG Security Toolbar
2010-02-04 18:03 . 2010-02-04 18:03 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AVG Security Toolbar
2010-02-04 18:03 . 2010-02-04 18:03 -------- d-----w- c:\documents and settings\Administrator\Application Data\Search Settings
2010-02-04 18:03 . 2010-02-04 18:03 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-02-04 17:31 . 2010-02-04 17:34 -------- d-----w- c:\program files\Unlocker
2010-02-04 16:58 . 2010-02-04 16:58 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2010-02-04 15:19 . 2010-02-04 15:19 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-02-04 14:45 . 2010-02-04 14:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-02-04 14:42 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-04 14:42 . 2010-02-04 19:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-04 14:42 . 2010-02-04 14:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-04 14:42 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-04 13:23 . 2010-02-05 18:09 -------- d-----w- c:\documents and settings\Administrator
2010-02-04 12:47 . 2001-08-17 18:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2010-02-04 12:47 . 2001-08-17 18:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-02-02 03:09 . 2010-02-04 15:30 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-02-02 02:45 . 2010-02-02 03:09 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-02-02 02:45 . 2010-02-02 02:45 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-02-02 01:57 . 2010-02-02 01:57 -------- d-----w- c:\documents and settings\Owner\Application Data\AVG8
2010-02-02 00:06 . 2010-02-02 00:06 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-18 23:56 . 2010-01-18 23:56 -------- d-----w- c:\program files\Scholastic
2010-01-07 00:15 . 2010-01-07 00:15 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Unity
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 17:58 . 2008-09-02 18:13 -------- d-----w- c:\program files\Java
2010-02-04 22:04 . 2009-12-05 16:52 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-04 16:49 . 2010-02-04 14:45 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-02-02 20:02 . 2009-11-11 13:00 79488 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-02 00:10 . 2008-08-30 21:52 -------- d-----w- c:\program files\Trillian
2010-02-01 23:37 . 2009-12-14 00:50 0 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\prvlcl.dat
2010-01-30 23:21 . 2008-09-15 15:45 -------- d-----w- c:\program files\Dl_cats
2010-01-22 08:21 . 2009-11-29 20:32 -------- d-----w- c:\program files\Microsoft Silverlight
2009-12-25 13:26 . 2009-07-29 20:09 -------- d-----w- c:\program files\sz8058
2009-12-25 03:18 . 2009-04-17 03:07 36928 -c-ha-w- c:\windows\system32\mlfcache.dat
2009-12-25 03:07 . 2009-12-25 02:44 -------- d-----w- c:\program files\iTunes
2009-12-25 02:59 . 2008-08-31 15:04 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-12-25 02:46 . 2009-12-25 02:44 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-25 02:44 . 2008-08-31 15:00 -------- d-----w- c:\program files\iPod
2009-12-25 02:44 . 2009-03-07 13:16 -------- d-----w- c:\program files\Common Files\Apple
2009-12-25 02:41 . 2009-12-25 02:41 -------- d-----w- c:\program files\Bonjour
2009-12-25 02:39 . 2008-08-31 15:03 -------- d-----w- c:\program files\QuickTime
2009-12-21 19:14 . 2009-12-21 19:14 2148220 ----a-w- c:\windows\system32\orarevapi.dll
2009-12-21 19:14 . 2006-03-04 03:33 916480 ------w- c:\windows\system32\wininet.dll
2009-12-14 19:15 . 2009-12-14 19:15 2146304 ----a-w- c:\windows\system32\GPhotos.scr
2009-12-08 21:29 . 2008-10-06 12:18 43528 -c--a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-25 18:02 . 2010-02-02 03:12 1230080 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-11-21 15:51 . 2004-08-04 10:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-13 22:57 . 2009-11-13 22:57 922112 ------w- c:\windows\system32\imapi2fs.dll
2009-11-13 22:57 . 2009-11-13 22:57 426496 ------w- c:\windows\system32\imapi2.dll
2009-11-12 22:07 . 2009-11-12 22:07 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{01E04581-4EEE-11D0-BFE9-00AA005B4383}"= "c:\windows\system32\browseui.dll" [2008-04-14 1025024]
"{0E5CBF21-D15F-11D0-8301-00AA005B4383}"= "c:\windows\system32\SHELL32.dll" [2008-06-17 8461312]
"{21FA44EF-376D-4D53-9B0F-8A89D3229068}"= "c:\program files\Windows Live\Toolbar\wltcore.dll" [2009-02-06 1068904]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{01e04581-4eee-11d0-bfe9-00aa005b4383}]
[HKEY_CLASSES_ROOT\clsid\{0e5cbf21-d15f-11d0-8301-00aa005b4383}]
[HKEY_CLASSES_ROOT\clsid\{21fa44ef-376d-4d53-9b0f-8a89d3229068}]
[HKEY_CLASSES_ROOT\TypeLib\{182E05A4-F4FF-4F73-8C84-D36B87D915AF}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-10-17 4347120]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"P17Helper"="P17.dll" [2005-05-03 64512]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"DLBTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-09 69632]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [11/29/2009 3:31 PM 54752]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2/1/2010 9:45 PM 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2/1/2010 9:45 PM 30104]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://msn.com/uDefault_Search_URL =
hxxp://www.google.com/ieuInternet Settings,ProxyServer = http=127.0.0.1:9090
uInternet Settings,ProxyOverride = *.local
uSearchAssistant =
hxxp://www.google.com/ieIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: adobe.com\get
Trusted Zone: adobe.com\www
Trusted Zone: cvs.com\cvslearnet.com
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\rprqk1d5.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.bing.com/search?FORM=IEFM1&q=FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://sn102w.snt102.mail.live.com/default.aspx?wa=wsignin1.0|https://www.facebook.com/frankielaz?v=feed&story_fbid=190504792087#/home.php?ref=home|https://harmonia.dmv.state.ny.us/regrenewal/rrnenterreginfo.cfm|http://www.google.com/FF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 9090
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\rprqk1d5.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-*{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
WebBrowser-{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
HKLM-Run-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-05 13:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: error reading MBR
called modules: ntoskrnl.exe >>UNKNOWN [0x83475F93]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf76dbf28
\Driver\ACPI -> ACPI.sys @ 0xf764ecb8
\Driver\atapi -> atapi.sys @ 0xf7606852
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Intel(R) PRO/100 VE Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf74fabb0
PacketIndicateHandler -> NDIS.sys @ 0xf7507a21
SendHandler -> NDIS.sys @ 0xf74e587b
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\_VOIDd.sys]
"imagepath"="\systemroot\system32\drivers\_VOIDxwysoqmnjy.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1344)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\Rundll32.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\logitech\quickcam\lu\lulnchr.exe
c:\program files\logitech\quickcam\lu\LogitechUpdate.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2010-02-05 13:37:35 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-05 18:37
ComboFix2.txt 2010-02-04 16:25
ComboFix3.txt 2010-02-04 14:34
Pre-Run: 2,665,562,112 bytes free
Post-Run: 3,184,685,056 bytes free
- - End Of File - - F5E940123E25D4FFE22A27A8B25E4C8E