Origin,
Loaded combo fix and executed here are the results.
ComboFix 09-05-26.02 - Administrator 05/26/2009 22:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3326.2848 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\ChkDisk.dll
c:\documents and settings\LocalService\Application Data\691447002.exe
c:\documents and settings\LocalService\Application Data\916653139.exe
c:\program files\ThunMail
c:\program files\ThunMail\testabd.dll
c:\windows\system32\AshEvtSvc.exe
c:\windows\system32\avast!Antivirus.exe
c:\windows\system32\drivers\ovfsthdevrtjrxjcxrrklpsgkfqpqbltkhaixd.sys
c:\windows\system32\glsetup.exe
c:\windows\system32\jhxm32.dll
c:\windows\system32\lklf32.dll
c:\windows\system32\lmn_setup.exe
c:\windows\system32\loader49.exe
c:\windows\system32\service-466.exe
c:\windows\system32\sft.res
c:\windows\system32\vp_setup.exe
c:\windows\system32\vp_setup.exe.bat
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\system32\init32.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASHEVTSVC
-------\Legacy_AVAST!ANTIVIRUS
-------\Service_AshEvtSvc
-------\Service_avast!Antivirus
-------\Service_ovfsthbpjwpktpuyxmynmyrobrrsdknovusmgi
((((((((((((((((((((((((( Files Created from 2009-04-27 to 2009-05-27 )))))))))))))))))))))))))))))))
.
2009-05-27 03:28 . 2009-05-27 03:28 -------- d-----w c:\documents and settings\Administrator\Application Data\AMS Services
2009-05-26 16:40 . 2009-05-26 16:40 57344 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-67e54663-n\Decora-SSE.dll
2009-05-26 16:40 . 2009-05-26 16:40 24064 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-525d10a6-n\Decora-D3D.dll
2009-05-26 16:40 . 2009-05-26 16:40 315392 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-71da985d-n\jogl.dll
2009-05-26 16:40 . 2009-05-26 16:40 20480 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-71da985d-n\jogl_awt.dll
2009-05-26 16:40 . 2009-05-26 16:40 20480 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-519bd469-n\gluegen-rt.dll
2009-05-26 16:40 . 2009-05-26 16:40 114688 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-71da985d-n\jogl_cg.dll
2009-05-26 16:40 . 2009-05-26 16:40 499712 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-5a710b2a-n\msvcp71.dll
2009-05-26 16:40 . 2009-05-26 16:40 499712 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-5a710b2a-n\jmc.dll
2009-05-26 16:40 . 2009-05-26 16:40 348160 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-5a710b2a-n\msvcr71.dll
2009-05-25 20:16 . 2009-05-27 03:28 95198 ----a-w c:\windows\system32\drivers\bf0d278.sys
2009-05-25 00:20 . 2009-05-25 00:20 -------- d-----w c:\program files\Trend Micro
2009-05-24 15:49 . 2009-05-24 15:49 10684866 ----a-w c:\documents and settings\Administrator\Application Data\Azureus\plugins\azump\mplayer.exe
2009-05-24 01:24 . 2009-05-24 01:24 23600 ----a-w c:\windows\system32\drivers\TVICHW32.SYS
2009-05-24 01:24 . 2009-05-24 01:24 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\eSupport.com
2009-05-24 00:45 . 2009-05-24 00:45 -------- d-----w c:\program files\AC3Filter
2009-05-24 00:30 . 2009-05-24 00:30 -------- d-----w c:\program files\ffdshow
2009-05-23 03:51 . 2009-05-23 03:51 -------- d-----w c:\documents and settings\Administrator\Application Data\Leadertech
2009-05-23 03:44 . 2009-05-23 03:44 -------- d-----w c:\program files\Atari
2009-05-22 16:12 . 2009-05-22 16:12 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\AMS Services, Inc
2009-05-22 16:08 . 2009-05-27 03:28 -------- d-----w c:\documents and settings\Administrator\Application Data\OA
2009-05-22 16:08 . 2009-05-22 16:08 -------- d-----w c:\program files\AMS Services
2009-05-22 15:38 . 2009-05-22 15:38 -------- d-----w c:\program files\Common Files\Business Objects
2009-05-22 15:38 . 2008-08-25 22:05 2134016 ----a-r c:\windows\system32\cdintf251.dll
2009-05-22 15:38 . 2009-05-22 15:38 -------- d-----w c:\program files\AMS Services, Inc
2009-05-22 15:36 . 2009-05-22 15:36 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\assembly
2009-05-08 14:59 . 2009-05-08 14:59 1915520 ----a-w c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe2009-05-07 17:53 . 2009-05-07 17:53 -------- d-----w c:\program files\Citrix
2009-05-07 17:53 . 2009-05-07 17:53 60744 ----a-w c:\documents and settings\Administrator\g2mdlhlpx.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-27 03:28 . 2009-03-22 06:35 16608 ----a-w c:\windows\gdrv.sys
2009-05-26 23:51 . 2009-03-22 07:09 -------- d-----w c:\program files\PokerStars.NET
2009-05-26 00:24 . 2009-03-22 04:36 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-05-26 00:24 . 2009-03-22 04:36 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-25 22:39 . 2009-03-27 15:40 -------- d-----w c:\documents and settings\Administrator\Application Data\Azureus
2009-05-23 04:02 . 2009-03-22 06:36 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-23 03:44 . 2009-05-17 02:07 -------- d-----w c:\program files\VUGames
2009-05-20 21:56 . 2009-05-20 21:56 -------- d-----w c:\program files\CCleaner
2009-05-17 03:46 . 2009-03-22 13:20 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-17 03:46 . 2009-05-17 03:46 2967799 ----a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-17 02:16 . 2009-05-17 02:16 43520 ----a-w c:\windows\system32\CmdLineExt03.dll
2009-05-16 22:27 . 2009-05-16 22:27 -------- d-----w c:\documents and settings\All Users\Application Data\NOS
2009-05-16 22:27 . 2009-05-16 22:27 -------- d-----w c:\program files\NOS
2009-05-15 23:46 . 2009-03-22 13:18 -------- d-----w c:\documents and settings\Administrator\Application Data\LimeWire
2009-04-21 18:02 . 2009-03-27 15:40 -------- d-----w c:\program files\Vuze
2009-04-17 02:25 . 2009-04-01 17:35 349184 ----a-w c:\documents and settings\Administrator\Application Data\SanDisk\Sansa Updater\SansaUpdaterInstall.exe
2009-04-17 02:25 . 2009-04-17 02:25 79872 ----a-w c:\documents and settings\Administrator\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
2009-04-17 02:25 . 2009-04-17 02:25 541696 ----a-w c:\documents and settings\Administrator\Application Data\SanDisk\Sansa Updater\SansaUpdater.exe
2009-04-06 20:32 . 2009-03-22 13:20 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 20:32 . 2009-03-22 13:20 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-03 23:44 . 2009-03-28 14:53 107888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-04-03 23:36 . 2009-03-22 06:36 -------- d-----w c:\program files\Common Files\InstallShield
2009-04-01 17:35 . 2009-04-01 17:35 -------- d-----w c:\documents and settings\Administrator\Application Data\SanDisk
2009-03-28 14:42 . 2009-03-28 14:42 -------- d-----w c:\program files\AGEIA Technologies
2009-03-28 14:42 . 2009-03-28 14:42 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-27 16:10 . 2009-03-27 16:10 413696 ----a-w c:\windows\system32\wrap_oal.dll
2009-03-27 16:10 . 2009-03-27 16:10 110592 ----a-w c:\windows\system32\OpenAL32.dll
2009-03-24 23:31 . 2009-03-24 23:31 245 ----a-w c:\windows\PowerReg.dat
2009-03-24 23:23 . 2009-03-24 23:23 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-03-24 21:45 . 2009-03-22 05:22 68456 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-23 01:57 . 2009-03-22 04:34 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-22 07:07 . 2009-03-22 07:07 0 ----a-w c:\windows\ativpsrm.bin
2009-03-22 07:03 . 2009-03-22 07:03 9158 ----a-r c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}\ARPPRODUCTICON.exe
2009-03-22 06:58 . 2009-03-22 06:58 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-22 06:57 . 2009-03-22 06:57 152576 ----a-w c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-22 06:40 . 2009-03-22 06:40 319488 ----a-w c:\windows\HideWin.exe
2009-03-22 05:21 . 2009-03-22 05:21 0 ----a-w c:\windows\nsreg.dat
2009-03-22 04:32 . 2009-03-22 04:32 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-22 04:28 . 2009-03-22 04:37 4127 ----a-w c:\windows\mozver.dat
2009-03-16 19:18 . 2009-04-15 17:36 69448 ----a-w c:\windows\system32\XAPOFX1_3.dll
2009-03-16 19:18 . 2009-04-15 17:36 517448 ----a-w c:\windows\system32\XAudio2_4.dll
2009-03-16 19:18 . 2009-04-15 17:36 235352 ----a-w c:\windows\system32\xactengine3_4.dll
2009-03-16 19:18 . 2009-04-15 17:36 22360 ----a-w c:\windows\system32\X3DAudio1_6.dll
2009-03-09 20:27 . 2009-04-15 17:36 453456 ----a-w c:\windows\system32\d3dx10_41.dll
2009-03-09 20:27 . 2009-04-15 17:36 4178264 ----a-w c:\windows\system32\D3DX9_41.dll
2009-03-09 20:27 . 2009-04-15 17:36 1846632 ----a-w c:\windows\system32\D3DCompiler_41.dll
2009-03-03 19:53 . 2009-05-16 22:27 17464 ----a-w c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9ujw7fip.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}\chrome\content\getPlus_Adobe_reg.exe
2009-03-03 19:53 . 2009-05-16 22:27 12792 ----a-w c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9ujw7fip.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}\chrome\content\getPlus_Adobe_reg_bootstrap.exe
2009-03-03 19:53 . 2009-05-16 22:27 109420 ----a-w c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9ujw7fip.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}\plugins\np_gp.dll
.
------- Sigcheck -------
Do you guys have a recommendation for anti virus ? Is one better than the other? I use spybot for spyware but would like to know what the wizards of the web recommend. Thanks so much!