Yes it warned me about disabling AVAST, and I went to AVAST opened and stopped it, however maybe working only in safe mode it didn't work.I don't know, but I couldn't get it to close at that time. Thought I did till it ran the report.
Here is the new log.
ComboFix 10-01-16.04 - Lyn Moreno 01/18/2010 21:35:42.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.614 [GMT -5:00]
Running from: c:\documents and settings\Lyn Moreno\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Lyn Moreno\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\411BDSM
c:\program files\411BDSM\411BDSMToolbarHelper.exe
c:\program files\411BDSM\INSTALL.LOG
c:\program files\411BDSM\tb4110.dll
c:\program files\411BDSM\tb4111.dll
c:\program files\411BDSM\tb411B.dll
c:\program files\411BDSM\toolbar.cfg
c:\program files\411BDSM\UNWISE.EXE
.
((((((((((((((((((((((((( Files Created from 2009-12-19 to 2010-01-19 )))))))))))))))))))))))))))))))
.
2010-01-18 15:19 . 2009-12-24 16:58 6515976 ---ha-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\in00000\setup.exe
2010-01-18 15:19 . 2009-12-24 16:54 730032 ---ha-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\ar00000\install.exe
2010-01-18 15:19 . 2008-02-29 12:42 386496 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\ar00000\magicJackSplash.exe
2010-01-18 02:49 . 2010-01-18 02:49 -------- d-----w- C:\823e6988869b6f29baeefc
2010-01-17 04:47 . 2010-01-18 15:49 -------- d-----w- c:\documents and settings\Lyn Moreno\Local Settings\Application Data\PMB Files
2010-01-17 04:47 . 2010-01-17 04:47 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PMB Files
2010-01-17 03:30 . 2007-12-30 10:01 307200 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\Mozilla\Firefox\Profiles\4ass787b.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\psftp.exe
2010-01-17 03:30 . 2007-12-30 10:01 172032 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\Mozilla\Firefox\Profiles\4ass787b.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\puttygen.exe
2010-01-17 03:30 . 2007-12-30 10:01 90112 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\Mozilla\Firefox\Profiles\4ass787b.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
2010-01-05 11:57 . 2009-12-24 16:58 6515976 ---ha-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\Upgrade\setup2.exe
2010-01-05 11:57 . 2009-12-24 16:54 730032 ---ha-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\Upgrade\install2.exe
2010-01-05 11:56 . 2010-01-05 11:56 -------- d-----w- c:\documents and settings\Lyn Moreno\Local Settings\Application Data\magicJack
2010-01-02 08:19 . 2010-01-04 13:50 -------- d-----w- c:\documents and settings\Lyn Moreno\Application Data\Coby Media Manager
2010-01-02 08:19 . 2010-01-02 08:19 50098 ----a-r- c:\documents and settings\Lyn Moreno\Application Data\Microsoft\Installer\{3643EF5F-D28D-4B25-9FA1-8859FC303710}\controlPanelIcon.exe
2010-01-02 08:19 . 2010-01-02 08:19 10134 ----a-r- c:\documents and settings\Lyn Moreno\Application Data\Microsoft\Installer\{3643EF5F-D28D-4B25-9FA1-8859FC303710}\SystemFolder_msiexec.exe
2010-01-02 08:19 . 2010-01-02 08:19 -------- d-----w- c:\program files\Coby
2009-12-25 21:55 . 2009-12-25 21:55 -------- d-----w- c:\documents and settings\Lyn Moreno\Application Data\AnvSoft
2009-12-25 21:55 . 2009-12-25 21:55 -------- d-----w- c:\program files\AnvSoft
2009-12-24 16:59 . 2009-12-24 16:59 93016 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\ug00000\magicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 6515976 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\ug00000\setup.exe
2009-12-24 16:58 . 2009-12-24 16:58 416328 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\magicJackLoader.exe
2009-12-24 16:58 . 2009-12-24 16:58 480608 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\octvqe1_apiw.dll
2009-12-24 16:58 . 2009-12-24 16:58 214360 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\TjVista.dll
2009-12-24 16:58 . 2009-12-24 16:58 337240 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\TjIpSys.dll
2009-12-24 16:58 . 2009-12-24 16:58 607600 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\SJHandsetMagicJack.dll
2009-12-24 16:58 . 2009-12-24 16:58 87384 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\st00000\mjsetup.exe
2009-12-24 16:57 . 2009-12-24 16:57 93016 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\st00000\magicJack.dll
2009-12-24 16:57 . 2009-12-24 16:57 93016 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\magicJack.dll
2009-12-24 16:55 . 2009-12-24 16:55 12482904 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\magicJack.exe
2009-12-24 16:54 . 2009-12-24 16:54 730032 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\ug00000\install.exe
2009-12-24 16:53 . 2009-12-24 16:53 87384 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\in00000\mjsetup.exe
2009-12-24 16:53 . 2009-12-24 16:53 93016 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\in00000\magicJack.dll
2009-12-24 16:52 . 2009-12-24 16:52 441704 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\st00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 441704 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\in00000\magicJackSplash.exe
2009-12-24 16:52 . 2009-12-24 16:52 50520 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\cdloader2.exe
2009-12-22 04:29 . 2009-12-22 05:05 69 ----a-w- c:\documents and settings\Lyn Moreno\jagex_runescape_preferences2.dat
2009-12-20 22:00 . 2009-12-20 22:02 -------- d-----w- c:\windows\system32\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-19 02:33 . 2006-05-18 16:34 -------- d-----w- c:\documents and settings\Lyn Moreno\Application Data\Skype
2010-01-18 15:19 . 2009-08-07 18:52 -------- d-----w- c:\documents and settings\Lyn Moreno\Application Data\mjusbsp
2010-01-17 20:57 . 2009-05-08 21:27 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-17 04:47 . 2006-06-21 01:34 -------- d-----w- c:\program files\Pando Networks
2010-01-15 05:01 . 2007-05-11 01:22 -------- d-----w- c:\program files\Windows Media Connect 2
2009-12-26 08:52 . 2006-05-29 23:11 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-12-26 08:52 . 2006-05-29 23:11 -------- d-----w- c:\program files\DVDVideoSoft
2009-12-22 04:58 . 2006-06-21 00:32 39 ----a-w- c:\documents and settings\Lyn Moreno\jagex_runescape_preferences.dat
2009-12-07 13:39 . 2009-12-18 13:08 57856 ----a-w- c:\documents and settings\Lyn Moreno\Application Data\Mozilla\Firefox\Profiles\4ass787b.default\extensions\{eecba28f-b68b-4b3a-b501-6ce12e6b8696}\platform\WINNT_x86-msvc\components\winprocess.dll
2009-12-04 05:22 . 2009-12-04 05:22 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PopCap
2009-12-03 05:06 . 2006-05-18 16:36 -------- d-----w- c:\documents and settings\Lyn Moreno\Application Data\skypePM
2009-11-26 22:26 . 2009-11-26 22:26 -------- d-----w- c:\program files\The Game Creators
2009-11-26 22:26 . 2005-05-22 07:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-26 21:51 . 2009-11-26 21:51 -------- d-----w- c:\program files\LG Electronics
2009-11-25 19:37 . 2009-11-25 19:37 -------- d-----w- c:\program files\Opera
2009-11-24 23:54 . 2009-04-30 20:52 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-04-30 20:53 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-04-30 20:53 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-04-30 20:53 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-04-30 20:53 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-04-30 20:53 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-04-30 20:53 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-04-30 20:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-04-30 20:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-21 15:51 . 2004-08-04 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-06 22:00 . 2009-04-30 21:15 836418 ----a-w- c:\windows\XSitePro2 Uninstaller.exe
2009-11-06 20:23 . 2009-04-30 21:25 36792 ----a-w- c:\documents and settings\Lyn Moreno\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 07:45 . 2004-08-04 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Lyn Moreno\Application Data\mjusbsp\cdloader2.exe" [2009-12-24 50520]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-01-17 2937528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F5D7050v3"="c:\program files\Belkin\F5D7050v3\Belkinwcui.exe" [2007-10-31 1654784]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-23 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-8-26 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=
"c:\\Program Files\\AIM\\AIM Pro\\aimpro.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\Lyn Moreno\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Lyn Moreno\\Application Data\\mjusbsp\\magicJack.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57582:TCP"= 57582:TCP:Pando Media Booster
"57582:UDP"= 57582:UDP:Pando Media Booster
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/30/2009 3:53 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/30/2009 3:53 PM 20560]
S3 Mouhpsgaiwx;Mouhpsgaiwx; [x]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Lyn Moreno\Application Data\Mozilla\Firefox\Profiles\4ass787b.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/FF - prefs.js: keyword.URL -
hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=FF - component: c:\documents and settings\Lyn Moreno\Application Data\Mozilla\Firefox\Profiles\4ass787b.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\documents and settings\Lyn Moreno\Application Data\Mozilla\Firefox\Profiles\4ass787b.default\extensions\{eecba28f-b68b-4b3a-b501-6ce12e6b8696}\platform\WINNT_x86-msvc\components\winprocess.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-411BDSM Toolbar - c:\progra~1\411BDSM\UNWISE.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-18 21:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
Completion time: 2010-01-18 21:48:40
ComboFix-quarantined-files.txt 2010-01-19 02:48
ComboFix2.txt 2010-01-18 06:04
Pre-Run: 14,972,645,376 bytes free
Post-Run: 14,953,185,280 bytes free
- - End Of File - - 7A9B5DB85ED5DBAED31E23FCF421C003