I was able to run ComboFix with the instructions provided while in Safe mode with networking. I was unable to disable AVG before running ComboFix, but it still seemed to work just fine. The log is posted below.
ComboFix 09-09-11.05 - Muhammad 09/12/2009 15:32.1.1 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.351 [GMT -4:00]
Running from: c:\documents and settings\Muhammad\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\12015624
c:\documents and settings\All Users\Application Data\12015624\12015624
c:\documents and settings\All Users\Application Data\12015624\12015624.exe
c:\documents and settings\All Users\Application Data\12015624\pc12015624ins
c:\documents and settings\All Users\Application Data\jyty._sy
c:\documents and settings\All Users\Application Data\pape.inf
c:\documents and settings\All Users\Application Data\vidam.ban
c:\documents and settings\All Users\Documents\nonetuky.reg
c:\documents and settings\All Users\Documents\tecahefo.dll
c:\documents and settings\Muhammad\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Muhammad\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Muhammad\Application Data\rexikuny.dll
c:\documents and settings\Muhammad\Cookies\obos._dl
c:\documents and settings\Muhammad\Cookies\sigo.bin
c:\documents and settings\Muhammad\Cookies\symobasyzy.scr
c:\documents and settings\Muhammad\Cookies\xadaxafa.ban
c:\documents and settings\Muhammad\Cookies\xotofino.com
c:\documents and settings\Muhammad\Desktop\Advanced Virus Remover.lnk
c:\documents and settings\Muhammad\Desktop\AntivirusPro_2010.lnk
c:\documents and settings\Muhammad\Desktop\Total Security 2009.lnk
c:\documents and settings\Muhammad\Local Settings\Application Data\cuhebi.bat
c:\documents and settings\Muhammad\Local Settings\Application Data\vebapi.vbs
c:\documents and settings\Muhammad\Local Settings\Application Data\vyga.ban
c:\documents and settings\Muhammad\Local Settings\Application Data\ziry.vbs
c:\documents and settings\Muhammad\Start Menu\Advanced Virus Remover.lnk
c:\documents and settings\Muhammad\Start Menu\Programs\AntivirusPro_2010
c:\documents and settings\Muhammad\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Muhammad\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
c:\documents and settings\Muhammad\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
c:\documents and settings\Muhammad\Start Menu\Programs\Total Security
c:\documents and settings\Muhammad\Start Menu\Programs\Total Security\Total Security 2009.lnk
C:\kqbvc.exe
C:\p2hhr.bat
c:\program files\AdvancedVirusRemover
c:\program files\AdvancedVirusRemover\PAVRM.exe
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\AntivirusPro_2010\AVEngn.dll
c:\program files\AntivirusPro_2010\data\daily.cvd
c:\program files\AntivirusPro_2010\htmlayout.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\AntivirusPro_2010\pthreadVC2.dll
c:\program files\AntivirusPro_2010\Uninstall.exe
c:\program files\AntivirusPro_2010\wscui.cpl
c:\program files\Common Files\abyj.dl
c:\program files\Common Files\dokoci.bat
c:\program files\Mozilla Firefox\plc4.dll
c:\windows\Installer\21bf64.msp
c:\windows\Installer\21bf6e.msp
c:\windows\Installer\21bf79.msp
c:\windows\Installer\c1937f.msp
c:\windows\Installer\c19380.msp
c:\windows\Installer\c19381.msp
c:\windows\Installer\c19382.msp
c:\windows\Installer\c19383.msp
c:\windows\Installer\c19384.msp
c:\windows\Installer\c19385.msp
c:\windows\Installer\c19386.msp
c:\windows\Installer\c19387.msp
c:\windows\Installer\c6c407.msp
c:\windows\Installer\c6c408.msp
c:\windows\Installer\c6c409.msp
c:\windows\Installer\c6c40a.msp
c:\windows\Installer\c6c40b.msp
c:\windows\Installer\c6c40c.msp
c:\windows\Installer\c6c40d.msp
c:\windows\Installer\c6c40e.msp
c:\windows\Installer\c6c40f.msp
c:\windows\Installer\c6c410.msp
c:\windows\oqidetymyl.sys
c:\windows\system32\_scui.cpl
c:\windows\system32\~.exe
c:\windows\system32\41.exe
c:\windows\system32\ajyvyx.sys
c:\windows\system32\braviax.exe
c:\windows\system32\fyvano.dl
c:\windows\system32\gumunijo.dll
c:\windows\system32\lazahuji.exe
c:\windows\system32\lepefihi.exe
c:\windows\system32\metigime.dll
c:\windows\system32\mojujebu.dll
c:\windows\system32\nacukahe.bin
c:\windows\system32\sipudabube.inf
c:\windows\system32\taJF83ikdmf.dll
c:\windows\system32\tapi.nfo
c:\windows\system32\winhelper.dll
c:\windows\system32\winupdate.exe
c:\windows\system32\wisdstr.exe
c:\windows\system32\zohevanim.scr
c:\windows\xice.inf
c:\windows\ygycimi.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-08-12 to 2009-09-12 )))))))))))))))))))))))))))))))
.
2009-09-11 07:08 . 2009-09-11 07:08 -------- d-----w- c:\documents and settings\Muhammad\Application Data\U3
2009-09-10 01:32 . 2009-09-10 01:32 17470 ----a-w- c:\windows\qotedo.com
2009-09-10 01:32 . 2009-09-10 01:32 15478 ----a-w- c:\windows\yworolymo.dat
2009-09-10 01:26 . 2009-09-12 19:46 80256 ----a-w- c:\windows\system32\drivers\d4f31910.sys
2009-09-10 01:24 . 2009-09-10 01:24 49664 ----a-w- C:\scmhux.exe
2009-09-10 01:24 . 2009-09-10 01:24 22016 ----a-w- C:\udtcnn.exe
2009-08-28 21:28 . 2009-06-25 08:25 54272 -c----w- c:\windows\system32\dllcache\wdigest.dll
2009-08-28 21:28 . 2009-06-25 08:25 301568 -c----w- c:\windows\system32\dllcache\kerberos.dll
2009-08-28 21:28 . 2009-06-25 08:25 136192 -c----w- c:\windows\system32\dllcache\msv1_0.dll
2009-08-28 21:28 . 2009-06-24 11:18 92928 -c----w- c:\windows\system32\dllcache\ksecdd.sys
2009-08-24 21:07 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-24 21:07 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-24 21:07 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-24 21:07 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-24 21:07 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-24 21:07 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-24 21:07 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-24 21:07 . 2009-08-24 21:07 -------- d-----w- C:\fbcd292a309e8114d9b8a77e
2009-08-24 17:40 . 2009-08-24 17:40 -------- d-----w- c:\windows\system32\wbem\Repository
2009-08-21 07:12 . 2009-08-24 21:08 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-21 07:12 . 2009-08-21 07:12 -------- d-----w- c:\program files\MSBuild
2009-08-21 07:12 . 2009-08-21 07:12 -------- d-----w- c:\program files\Reference Assemblies
2009-08-13 21:30 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-12 19:47 . 2008-05-13 07:27 65857824 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-12 19:13 . 2008-05-18 03:23 -------- d-----w- c:\documents and settings\Muhammad\Application Data\Move Networks
2009-09-12 07:12 . 2008-05-13 07:27 882980 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-10 01:32 . 2009-06-10 01:32 88576 --sha-w- c:\windows\system32\gabuwuwo.dll
2009-09-10 01:32 . 2009-09-10 01:32 16233 ----a-w- c:\documents and settings\Muhammad\Application Data\wavuvykatu.dat
2009-09-10 01:32 . 2009-09-10 01:32 10566 ----a-w- c:\program files\Common Files\terevalyzu._sy
2009-09-10 01:30 . 2008-05-16 18:07 -------- d-----w- c:\documents and settings\Muhammad\Application Data\OpenOffice.org2
2009-08-26 04:59 . 2008-06-05 05:17 21168 ----a-w- c:\documents and settings\Muhammad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-24 17:35 . 2008-05-13 11:44 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 01:05 . 2009-07-15 01:05 -------- d-----w- c:\program files\MSECache
2009-07-14 03:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2004-08-04 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2004-08-04 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 12:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 12:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 12:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 12:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-22 02:24 . 2008-05-17 05:06 664 ----a-w- c:\documents and settings\Muhammad\Local Settings\Application Data\d3d9caps.dat
2009-06-16 14:36 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-10 01:25 . 2009-06-10 01:25 49664 --sha-w- c:\windows\system32\vajozesi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1f4734c9-393c-42c7-8d37-eb2c26d9530e}]
2009-06-10 01:25 49664 --sha-w- c:\windows\system32\vajozesi.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"Google Update"="c:\documents and settings\Muhammad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-26 133104]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-05-04 2356088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-10-09 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-10-09 126976]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"zowuhidot"="c:\windows\system32\gabuwuwo.dll" [2009-09-10 88576]
c:\documents and settings\Admin\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
c:\documents and settings\Muhammad\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{da0d7c43-fe69-4ce3-8ced-c9bb76fda2ca}"= "c:\windows\system32\gabuwuwo.dll" [2009-09-10 88576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"gudarobad"= {da0d7c43-fe69-4ce3-8ced-c9bb76fda2ca} - c:\windows\system32\gabuwuwo.dll [2009-09-10 88576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-21 02:09 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Muhammad\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Muhammad\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/13/2008 7:44 AM 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/13/2008 7:44 AM 108552]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe --> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe --> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
.
Contents of the 'Scheduled Tasks' folder
2009-08-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1897051121-682003330-1006Core.job
- c:\documents and settings\Muhammad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-26 03:57]
2009-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1897051121-682003330-1006UA.job
- c:\documents and settings\Muhammad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-26 03:57]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.commStart Page =
hxxp://www.google.comFF - ProfilePath - c:\documents and settings\Muhammad\Application Data\Mozilla\Firefox\Profiles\gldkb2wh.default\
FF - prefs.js: browser.startup.homepage -
hxxp://go.microsoft.com/fwlink/?LinkId=69157FF - plugin: c:\documents and settings\Muhammad\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Muhammad\Application Data\Move Networks\plugins\npqmp071504000001.dll
FF - plugin: c:\documents and settings\Muhammad\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Muhammad\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
HKLM-Run-12015624 - c:\documents and settings\All Users\Application Data\12015624\12015624.exe
HKLM-Run-tenasunume - metigime.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-12 15:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\d4f31910]
"ImagePath"="\SystemRoot\System32\drivers\d4f31910.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1456)
c:\windows\system32\WININET.dll
c:\windows\system32\gabuwuwo.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\logishrd\LVCOMSER\LVComSer.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\iPod\bin\iPodService.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Common Files\logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2009-09-12 15:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-12 19:50
Pre-Run: 15,446,548,480 bytes free
Post-Run: 16,023,154,688 bytes free
284 --- E O F --- 2009-09-02 00:10