Thanks for the help. Here is my new ComboFix log:
ComboFix 09-03-19.02 - Jimmy 2009-03-20 16:27:43.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.768.454 [GMT -7:00]
Running from: c:\documents and settings\Jimmy.VALUED-20606295\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jimmy.VALUED-20606295\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090320-0] *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\system32\55.scr
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\_OTMoveIt
c:\_otmoveit\MovedFiles\
03202009_145043.log
c:\_otmoveit\MovedFiles\
03202009_145043.res
c:\documents and settings\Jimmy.VALUED-20606295\DoctorWeb
c:\documents and settings\Jimmy.VALUED-20606295\DoctorWeb\CureIt.log
c:\windows\system\svhost.exe
c:\windows\system32\55.scr
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WINDOWSTELEPHONY
-------\Service_WindowsTelephony
((((((((((((((((((((((((( Files Created from 2009-02-20 to 2009-03-20 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-20 22:50 --------- d-----w c:\program files\PS TO USB CONVERTOR
2009-03-20 05:50 --------- d-----w c:\documents and settings\Jimmy.VALUED-20606295\Application Data\Azureus
2009-03-17 21:04 --------- d-----w c:\documents and settings\Jimmy.VALUED-20606295\Application Data\vlc
2009-01-31 01:51 --------- d-----w c:\program files\Java
2009-01-29 05:54 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-29 05:54 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-29 05:54 --------- d-----w c:\documents and settings\Jimmy.VALUED-20606295\Application Data\InstallShield
2009-01-29 05:54 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2009-01-29 05:05 --------- d-----w c:\program files\Teamspeak2_RC2
2009-01-29 05:05 --------- d-----w c:\documents and settings\Jimmy.VALUED-20606295\Application Data\teamspeak2
2009-01-21 06:08 --------- d-----w c:\program files\LibUSB-Win32-0.1.10.1
2009-01-16 06:56 4 --sh--r c:\documents and settings\All Users\Application Data\sysqcl0.dat
2008-12-18 07:53 604 ---ha-w c:\program files\STLL Notifier
2008-08-18 07:56 784 ----a-w c:\documents and settings\Jimmy.VALUED-20606295\Application Data\mpauth.dat
2008-02-18 20:25 35,184 ----a-w c:\documents and settings\Jimmy.VALUED-20606295\Application Data\GDIPFONTCACHEV1.DAT
2006-10-21 18:38 147,456 ----a-w c:\program files\mozilla firefox\plugins\CDVDiso.dll
2006-01-15 13:38 231,064 ----a-w c:\program files\mozilla firefox\plugins\CDVDisoEFP.dll
2005-05-14 15:04 151,040 ----a-w c:\program files\mozilla firefox\plugins\CDVDisolinuz.dll
2006-01-15 13:38 54,289 ----a-w c:\program files\mozilla firefox\plugins\CDVDlinuz.dll
2005-05-14 15:04 6,656 ----a-w c:\program files\mozilla firefox\plugins\CDVDnull.dll
2005-04-20 08:21 86,016 ----a-w c:\program files\mozilla firefox\plugins\cdvdPeops.dll
2005-05-14 15:04 6,656 ----a-w c:\program files\mozilla firefox\plugins\DEV9null.dll
2005-05-16 08:41 21,732 ----a-w c:\program files\mozilla firefox\plugins\FWnull.dll
2006-03-13 09:34 565,248 ----a-w c:\program files\mozilla firefox\plugins\GSdx9 sse2.dll
2006-03-13 16:33 602,112 ----a-w c:\program files\mozilla firefox\plugins\GSdx9.dll
2006-09-04 00:08 18,944 ----a-w c:\program files\mozilla firefox\plugins\PadSSSPSX.dll
2005-05-14 15:04 372,892 ----a-w c:\program files\mozilla firefox\plugins\PADwin.dll
2006-11-04 09:20 94,208 ----a-w c:\program files\mozilla firefox\plugins\spu2PeopsSound.dll
2005-05-14 15:04 9,728 ----a-w c:\program files\mozilla firefox\plugins\USBnull.dll
2006-11-17 22:06 7,892,992 ----a-w c:\program files\mozilla firefox\plugins\ZeroGS KOSMOS 0.96 non sse2.dll
2006-11-18 14:50 7,892,992 ----a-w c:\program files\mozilla firefox\plugins\ZeroGS KOSMOS 0.96 sse2.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-03-20_15.59.32.71 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-20 23:31:57 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_52c.dat
+ 2009-03-20 23:32:09 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_f8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools\daemon.exe" [2008-04-01 486856]
"AlcoholAutomount"="d:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-22 203720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"avast!"="d:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"lxdimon.exe"="d:\program files\Lexmark 3500-4500 Series\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 434864]
"lxdiamon"="d:\program files\Lexmark 3500-4500 Series\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 25264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-07-16 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-06-24 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 d:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= sonymjpg.dll
"vidc.ffds"= d:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Lexmark 3500-4500 Series\\Lexmark 3500-4500 Series\\lxdimon.exe"=
"d:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
"c:\\WINDOWS\\system32\\lxdicoms.exe"=
"d:\\Program Files\\Lexmark 3500-4500 Series\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
"d:\\Program Files\\Lexmark 3500-4500 Series\\Lexmark 3500-4500 Series\\App4R.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-07 114768]
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [2006-10-10 5632]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2007-02-27 32256]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-08-06 20560]
R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service --> c:\windows\system32\lxdicoms.exe -service [?]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [2002-04-24 175232]
S2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdiserv.exe [2008-03-18 99248]
S3 HFXLowerFilter;HFXLowerFilter;c:\windows\system32\drivers\hfx_lfd.sys [2006-06-21 21632]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2007-08-19 33792]
S3 LucentSoftModem;Lucent Technologies Soft Modem;c:\windows\system32\drivers\LTSM.sys [2002-04-24 807917]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096]
S3 SMBE;Sony MPEG2 Encoder Board (WDM);c:\windows\system32\drivers\Smbe.sys [2002-04-24 594668]
S3 XDva008;XDva008;\??\c:\windows\System32\XDva008.sys --> c:\windows\System32\XDva008.sys [?]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.ca/uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {ADCC68D4-AAEA-4338-817D-1F261D9FB759} -
hxxp://www.dragongemworld.com/Active_X/ENetLauncher.cabFF - ProfilePath - c:\documents and settings\Jimmy.VALUED-20606295\Application Data\Mozilla\Firefox\Profiles\skwmol9v.default\
FF - plugin: d:\program files\VideoLAN\VLC\npvlc.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-20 16:33:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(588)
d:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
d:\program files\Alwil Software\Avast4\aswUpdSv.exe
d:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxdicoms.exe
c:\windows\system32\wscntfy.exe
d:\program files\Alwil Software\Avast4\ashMaiSv.exe
d:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-03-20 16:41:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-20 23:40:12
ComboFix2.txt 2009-03-20 23:03:15
Pre-Run: 6,294,315,008 bytes free
Post-Run: 6,283,218,944 bytes free
Current=2 Default=2 Failed=1 LastKnownGood=5 Sets=1,2,3,4,5
165