here my combofix.txt:
ComboFix 08-11-28.02 - Grant 2008-11-28 19:35:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.444 [GMT -7:00]
Running from: c:\documents and settings\Grant\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Danah Miles\Application Data\addon.dat
c:\documents and settings\Grant\Application Data\addon.dat
c:\documents and settings\Guest\Favorites\Online Security Test.url
c:\windows\system32\skinboxer43.dll
c:\windows\system32\unsvchosts.lzma
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\winlogon.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-29 )))))))))))))))))))))))))))))))
.
2008-11-27 20:07 . 2008-11-27 20:07
d-------- c:\documents and settings\All Users\Application Data\Uniblue
2008-11-27 20:07 . 2008-10-26 02:01 20,232 --a------ c:\windows\SYSTEM32\AntiSpyNative64.exe
2008-11-27 20:07 . 2008-10-26 02:01 16,648 --a------ c:\windows\SYSTEM32\AntiSpyNative32.exe
2008-11-26 18:24 . 2008-11-26 18:25 d-------- c:\documents and settings\Danah Miles\Application Data\U3
2008-11-26 17:39 . 2007-09-05 23:22 289,144 --a------ c:\windows\SYSTEM32\VCCLSID.exe
2008-11-26 17:39 . 2006-04-27 16:49 288,417 --a------ c:\windows\SYSTEM32\SrchSTS.exe
2008-11-26 17:39 . 2008-10-01 14:51 87,552 --a------ c:\windows\SYSTEM32\VACFix.exe
2008-11-26 17:39 . 2008-10-10 07:58 82,944 --a------ c:\windows\SYSTEM32\o4Patch.exe
2008-11-26 17:39 . 2008-05-18 20:40 82,944 --a------ c:\windows\SYSTEM32\IEDFix.exe
2008-11-26 17:39 . 2008-10-10 07:58 82,944 --a------ c:\windows\SYSTEM32\IEDFix.C.exe
2008-11-26 17:39 . 2008-08-18 11:19 82,432 --a------ c:\windows\SYSTEM32\404Fix.exe
2008-11-26 17:39 . 2004-07-31 17:50 51,200 --a------ c:\windows\SYSTEM32\dumphive.exe
2008-11-26 17:39 . 2007-10-03 23:36 25,600 --a------ c:\windows\SYSTEM32\WS2Fix.exe
2008-11-26 17:39 . 2008-11-26 17:39 980 --a------ c:\windows\SYSTEM32\tmp.reg
2008-11-26 00:56 . 2008-11-26 00:56 2,002 --a------ c:\windows\Sysvxd.exe
2008-11-12 03:00 . 2008-11-12 03:00 d-------- c:\program files\MSXML 4.0
2008-11-10 12:57 . 2008-11-10 12:57 d-------- c:\program files\KORG Legacy
2008-11-10 12:57 . 2008-11-10 12:57 d-------- c:\program files\Common Files\KORG
2008-11-10 12:57 . 2008-11-10 12:57 d-------- c:\documents and settings\All Users\Application Data\KORG
2008-11-01 21:47 . 2008-11-01 21:47 d-------- c:\documents and settings\Grant\WINDOWS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-29 02:38 502,272 ----a-w c:\windows\SYSTEM32\winlogon.exe
2008-11-29 02:38 502,272 ----a-w c:\windows\SYSTEM32\DLLCACHE\winlogon.exe
2008-11-28 05:25 --------- d-----w c:\program files\Trillian
2008-11-27 05:00 --------- d-----w c:\program files\Google
2008-11-26 06:21 --------- d-----w c:\documents and settings\Grant\Application Data\Applied Acoustics Systems
2008-11-26 06:21 --------- d-----w c:\documents and settings\Grant\Application Data\Apple Computer
2008-11-26 06:21 --------- d-----w c:\documents and settings\Grant\Application Data\Amazon
2008-11-26 06:21 --------- d-----w c:\documents and settings\Grant\Application Data\AdobeUM
2008-11-26 06:21 --------- d-----w c:\documents and settings\Grant\Application Data\.csound
2008-11-26 06:17 295,424 ----a-w c:\windows\SYSTEM32\termsrv.dll
2008-11-23 18:38 --------- d-----w c:\program files\VstPlugins
2008-11-23 18:37 --------- d-----w c:\program files\Native Instruments
2008-11-23 17:27 --------- d-----w c:\program files\Cycling '74
2008-11-23 17:27 --------- d-----w c:\program files\Common Files\Cycling '74
2008-11-22 04:45 --------- d-----w c:\program files\Common Files\Native Instruments
2008-11-21 00:41 --------- d-----w c:\documents and settings\Grant\Application Data\uTorrent
2008-11-17 02:52 --------- d-----w c:\program files\Soulseek
2008-10-27 22:13 --------- d-----w c:\program files\PSP SpringVerb CM
2008-10-27 22:12 286,720 ----a-w c:\windows\iun506.exe
2008-10-26 06:28 --------- d-----w c:\documents and settings\Grant\Application Data\FabFilter
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ----a-w c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-10-23 03:32 --------- d-----w c:\documents and settings\Grant\Application Data\OpenOffice.org2
2008-10-23 03:30 410,976 ----a-w c:\windows\SYSTEM32\deploytk.dll
2008-10-23 03:30 --------- d-----w c:\program files\Java
2008-10-15 16:57 332,800 ----a-w c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-13 20:52 --------- d-----w c:\program files\u-he
2008-10-03 17:41 6,066,176 ------w c:\windows\SYSTEM32\DLLCACHE\ieframe.dll
2008-09-30 23:43 1,286,152 ----a-w c:\windows\SYSTEM32\msxml4.dll
2008-09-15 11:57 1,846,016 ----a-w c:\windows\SYSTEM32\win32k.sys
2008-09-15 11:57 1,846,016 ----a-w c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2008-09-04 16:42 1,106,944 ----a-w c:\windows\SYSTEM32\msxml3.dll
2008-09-04 16:42 1,106,944 ----a-w c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
2008-06-17 03:58 23,741 ---h--w c:\documents and settings\Danah Miles\Application Data\svchost.dat
2008-06-14 21:56 23,741 ---h--w c:\documents and settings\Grant\Application Data\svchost.dat
2005-08-10 03:05 184,808 ----a-w c:\documents and settings\Danah Miles\Application Data\shb.dat
2005-02-21 21:24 4,086 -c--a-w c:\program files\uninstal.log
2006-11-30 05:01 848 -csha-w c:\windows\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"HPsetm"="c:\documents and settings\Grant\Application Data\Google\ijdkq13324484.exe" [2008-11-25 102912]
"Uniblue SpyEraser"="c:\program files\Uniblue\SpyEraser\SpyEraser.exe" [2008-10-26 1431816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-22 136600]
c:\documents and settings\Grant\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-09-21 3444008]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-01-25 98304]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-01-25 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdcamon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WinDefend"=2 (0x2)
"SiteAdvisor Service"=2 (0x2)
"lxdc_device"=2 (0x2)
"lxdcCATSCustConnectService"=2 (0x2)
"Adobe LM Service"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-08-21 97928]
R1 vcdrom;Virtual CD-ROM Device Driver;\??\c:\windows\SYSTEM32\DRIVERS\VCdRom.sys [2001-12-19 8576]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-08-21 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-08-21 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-08-21 76040]
S3 FileObjInfo;STFileDriver; []
S3 UKS11LDR;M-Audio USB Keystation Loader; []
S3 USBKT1X1;M-Audio USB Keystation; []
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0C6CD287-8014-A45C-118B-A96EBA6516BF}]
c:\windows\system32\system32\vtimer.exe s
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{46F6B9DE-ADD7-1BA7-6004-DD50BAA263AD}]
c:\windows\system32\setup\svchost.exe s
.
Contents of the 'Scheduled Tasks' folder
2008-11-29 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2008-11-24 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-08-16 08:02]
2008-08-26 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-08-16 08:02]
2008-11-28 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2008-10-26 02:01]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_02\bin\jusched.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Grant\Application Data\Mozilla\Firefox\Profiles\egt2p3sd.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
FF -: plugin - c:\program files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\mozilla firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\mozilla firefox\plugins\npitunes.dll
FF -: plugin - c:\program files\mozilla firefox\plugins\npmusicn.dll
FF -: plugin - c:\program files\mozilla firefox\plugins\npunagi2.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-28 19:41:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Windows Defender\MsMpEng.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\SYSTEM32\IMAPI.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\SYSTEM32\snmp.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\SYSTEM32\WSCNTFY.EXE
.
**************************************************************************
.
Completion time: 2008-11-28 19:47:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-29 02:46:55
Pre-Run: 4,561,821,696 bytes free
Post-Run: 4,875,825,152 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
222 --- E O F --- 2008-11-27 21:29:00