Alright. Put eventlog back on my machine and it starts up much faster now. Got ComboFix working as WinInit.com,and here are the results it gave.
ComboFix 09-09-12.A0 - HP_Administrator 09/13/2009 14:41.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.546 [GMT -4:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\WinInit.com.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\cleanup.exe
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator\Local Settings\Temp\IadHide5.dll
c:\recycler\NPROTECT
c:\recycler\S-1-5-21-527237240-179605362-725345543-500
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Installer\3e496f.msp
c:\windows\kb913800.exe
c:\windows\system32\41.exe
c:\windows\system32\drivers\2f76ae7a.sys
c:\windows\system32\drivers\hjgruibabanvxo.sys
c:\windows\system32\hjgruiawuwcdiy.dat
c:\windows\system32\hjgruibdecyext.dll
c:\windows\system32\hjgruibfnndrtc.dat
c:\windows\system32\hjgruibjtpexju.dll
c:\windows\system32\hjgruiboxvkyxj.dll
c:\windows\system32\hjgruibyprkltp.dll
c:\windows\system32\hjgruicnvtntkj.dll
c:\windows\system32\hjgruidibcrdpp.dat
c:\windows\system32\hjgruidtibciqx.dat
c:\windows\system32\hjgruiemddkpks.dat
c:\windows\system32\hjgruieqrxuwpc.dll
c:\windows\system32\hjgruifthieiey.dat
c:\windows\system32\hjgruifvrtcgif.dll
c:\windows\system32\hjgruigxuwpite.dat
c:\windows\system32\hjgruihwmcmdts.dat
c:\windows\system32\hjgruihxvrtfge.dat
c:\windows\system32\hjgruiivpucrlr.dll
c:\windows\system32\hjgruijismnwxb.dll
c:\windows\system32\hjgruimpftkpig.dll
c:\windows\system32\hjgruimstiwwoi.dll
c:\windows\system32\hjgruincbvttnq.dll
c:\windows\system32\hjgruioqxymycd.dll
c:\windows\system32\hjgruipdmexbyf.dll
c:\windows\system32\hjgruiphpfvrtf.dll
c:\windows\system32\hjgruipowidecb.dll
c:\windows\system32\hjgruiputoibiq.dat
c:\windows\system32\hjgruipymexjdi.dat
c:\windows\system32\hjgruiqbwtvxiq.dll
c:\windows\system32\hjgruiqhpylkdm.dll
c:\windows\system32\hjgruiqltupqjy.dat
c:\windows\system32\hjgruiqxnbmnri.dat
c:\windows\system32\hjgruirwetbqvn.dll
c:\windows\system32\hjgruirxeixnst.dll
c:\windows\system32\hjgruirxhtanei.dat
c:\windows\system32\hjgruisajqpjul.dll
c:\windows\system32\hjgruisirqogwt.dll
c:\windows\system32\hjgruitagbpetd.dll
c:\windows\system32\hjgruiufygyqob.dll
c:\windows\system32\hjgruiviwwoism.dll
c:\windows\system32\hjgruivtepuyav.dat
c:\windows\system32\hjgruivxsiwkcb.dat
c:\windows\system32\hjgruiwbvttbqp.dll
c:\windows\system32\hjgruiwkbwucbl.dat
c:\windows\system32\hjgruixegoidip.dat
c:\windows\system32\hjgruixobcqhti.dll
c:\windows\system32\hjgruiyxcdbxpp.dll
c:\windows\system32\lufuyuko.exe
c:\windows\system32\ps2.bat
c:\windows\system32\sumopuwu.dll
c:\windows\system32\wovageku.dll
D:\Autorun.inf
c:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_hjgruisxrkmuyy
-------\Legacy_SYS
-------\Legacy_SYSDRV
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_hjgruisxrkmuyy
-------\Service_sys
-------\Service_2f76ae7a
((((((((((((((((((((((((( Files Created from 2009-08-13 to 2009-09-13 )))))))))))))))))))))))))))))))
.
2009-09-13 18:32 . 2009-09-13 18:15 55808 ----a-w- c:\windows\system32\eventlog.dll
2009-09-13 18:32 . 2009-09-13 18:15 55808 ----a-w- c:\windows\system32\dllcache\eventlog.dll
2009-09-12 19:14 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-12 19:14 . 2009-09-12 19:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-12 19:14 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-12 17:21 . 2009-09-12 17:21 574 ----a-w- C:\cleanup.bat
2009-09-12 17:21 . 2009-09-12 17:21 135168 ----a-w- C:\zip.exe
2009-09-09 22:41 . 2009-09-12 18:59 1559 ----a-w- c:\windows\system32\olgdjlba.dat
2009-09-09 22:37 . 2009-09-09 22:37 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Viewpoint
2009-08-21 23:06 . 2009-08-21 23:06 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-21 23:06 . 2009-08-21 23:06 -------- d-----w- c:\program files\MSBuild
2009-08-21 23:06 . 2009-08-21 23:06 -------- d-----w- c:\program files\Reference Assemblies
2009-08-21 23:05 . 2009-08-21 23:06 -------- d-----w- C:\1aa9a6127fb447cef54cbc
2009-08-21 23:05 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-21 23:05 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-21 23:05 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-21 23:05 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-21 23:05 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-21 23:05 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-21 23:05 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-21 23:01 . 2009-08-21 23:01 -------- d-----w- c:\program files\MSXML 6.0
2009-08-19 15:47 . 2009-08-19 15:47 -------- d-----w- c:\program files\iTunes
2009-08-15 02:30 . 2009-08-15 02:30 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2009-08-14 23:02 . 2009-08-14 23:02 -------- d-----w- c:\windows\ServicePackFiles
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-12 18:45 . 2009-06-12 18:44 49664 --sha-w- c:\windows\system32\zudeyuwi.dll
2009-08-31 18:09 . 2008-09-02 01:38 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-23 22:45 . 2006-08-24 23:51 -------- d-----w- c:\program files\AIM
2009-08-23 03:04 . 2008-09-02 01:38 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-23 03:04 . 2008-09-02 01:38 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-23 03:04 . 2008-09-02 01:38 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-22 04:11 . 2006-03-12 06:48 63696 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-21 22:12 . 2006-09-23 05:35 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\BitTorrent
2009-08-19 15:47 . 2006-07-03 20:49 -------- d-----w- c:\program files\iPod
2009-08-19 15:47 . 2007-11-28 06:24 -------- d-----w- c:\program files\Common Files\Apple
2009-08-14 05:38 . 2006-09-29 01:46 4620 ----a-w- c:\windows\XChange.dat
2009-08-12 19:53 . 2009-08-12 19:53 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-12 19:53 . 2009-08-12 19:53 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-12 19:53 . 2009-08-12 19:53 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2009-08-12 19:52 . 2008-09-02 01:19 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-12 18:46 . 2009-08-12 18:46 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-08-12 18:46 . 2009-08-12 18:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-05 09:11 . 2004-08-09 21:00 204800 ------w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55 . 2004-08-09 21:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 14:08 . 2004-08-09 21:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-11 22:45 . 2009-07-11 22:45 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-07-11 22:45 . 2009-07-11 22:45 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-06-26 15:59 . 2004-08-09 21:00 668160 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 15:59 . 2004-08-09 21:00 81920 ------w- c:\windows\system32\ieencode.dll
2009-06-25 18:36 . 2004-08-09 21:00 95744 ----a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2004-08-09 21:00 661504 ----a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2004-08-09 21:00 517120 ----a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2004-08-09 21:00 48640 ----a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2004-08-09 21:00 471552 ----a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2004-08-09 21:00 47104 ----a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2004-08-09 21:00 225280 ----a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2004-08-09 21:00 186880 ----a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2004-08-09 21:00 177152 ----a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2004-08-09 21:00 16896 ----a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2004-08-09 21:00 138240 ----a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2004-08-09 21:00 123392 ----a-w- c:\windows\system32\mqrtdep.dll
2009-06-22 11:49 . 2004-08-09 21:00 19968 ----a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2004-08-09 21:00 117248 ----a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2004-08-09 21:00 4608 ----a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2004-08-09 21:00 91776 ----a-w- c:\windows\system32\drivers\mqac.sys
2009-06-16 14:55 . 2004-08-09 21:00 82432 ------w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-09 21:00 119808 ------w- c:\windows\system32\t2embed.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-06-12 18:45 . 2009-06-12 18:45 49664 --sha-w- c:\windows\system32\jehodini.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f74c0501-f644-4968-91f9-6939587f6aa4}]
2009-06-12 18:45 49664 --sha-w- c:\windows\system32\jehodini.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [2006-09-21 43520]
"AWMON"="c:\program files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 517632]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 143360]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-04 7307264]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"DMAScheduler"="c:\program files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe" [2005-11-01 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 249856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"ViewMgr"="c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [2007-01-04 112336]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-11-04 1519616]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-01-11 15961088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-3-12 27136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-3-12 36903]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-23 03:04 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Games\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/1/2008 9:38 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/1/2008 9:38 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/1/2008 9:38 PM 297752]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 8:59 PM 24652]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/1/2008 9:38 PM 908056]
S2 giyqy;giyqy;c:\windows\system32\drivers\irxffg.sys --> c:\windows\system32\drivers\irxffg.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
USBDriver
.
Contents of the 'Scheduled Tasks' folder
2009-08-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2008-09-02 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-09-02 21:26]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.insightbb.com/default.aspxuDefault_Search_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktopmStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktopmSearch Bar =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktopIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: {3CBA13C3-58C7-47F1-9758-D4B255A50D51} -
file://e:\html\search\ses_ocx\sessearch.ocxFF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\xaasg3ln.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.insightbb.com/default.aspxFF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DISCover - c:\program files\DISC\DISCover.exe
HKLM-Run-DiscUpdateManager - c:\program files\DISC\DiscUpdateMgr.exe
HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-PCDrProfiler - (no file)
HKLM-Run-gevodimoye - wovageku.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-13 15:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(840)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(1012)
c:\windows\system32\nview.dll
c:\windows\system32\nvwddi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2009-09-13 15:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-13 19:07
Pre-Run: 24,405,716,992 bytes free
Post-Run: 27,025,350,656 bytes free
321 --- E O F --- 2009-09-08 02:19
Should I run malwarebytes again, or are there any more steps I should take before that?