Post that log (Combofix.txt) in your next reply.
ComboFix 10-12-23.01 - Lubnah 24/12/2010 5:53.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.511.217 [GMT 11:00]
Running from: c:\documents and settings\Lubnah\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Lubnah\Desktop\CFScript.txt
AV: BP Security Anti-Virus *Disabled/Outdated* {2565CEEE-6BDB-4A6D-AD6D-F682F2695014}
FW: BP Security Firewall *Disabled* {38254411-9AEC-4967-913E-F892C2A4DF89}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lubnah\Application Data\PriceGong
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Lubnah\Application Data\PriceGong\Data\z.xml
c:\windows\LMI3F.tmp
c:\windows\LMI43.tmp
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_DFBCFDBA
((((((((((((((((((((((((( Files Created from 2010-11-23 to 2010-12-23 )))))))))))))))))))))))))))))))
.
2010-12-22 04:15 . 2010-12-22 04:15 -------- d-----w- C:\spoolerlogs
2010-12-16 19:00 . 2010-12-16 19:01 -------- d-----w- C:\680c114bc681db10c7
2010-12-16 04:27 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-16 04:27 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2010-12-11 15:40 . 2010-12-11 15:40 -------- d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
2010-12-11 15:34 . 2010-12-11 15:34 -------- d-----w- c:\program files\VideoLAN
2010-12-11 15:34 . 2010-12-11 15:40 -------- d-----w- c:\program files\Graboid
2010-12-06 00:29 . 2010-11-29 06:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-06 00:29 . 2010-11-29 06:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-05 23:21 . 2010-08-17 13:17 58880 -c--a-w- c:\windows\system32\dllcache\spoolsv.exe
2010-12-05 23:21 . 2010-08-17 13:17 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-12-05 21:38 . 2010-12-05 21:38 -------- d-----w- C:\found.002
2010-12-01 23:37 . 2010-12-06 00:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-24 04:07 . 2010-11-24 04:07 -------- d-----w- c:\documents and settings\All Users\Application Data\XoftSpySE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-23 17:56 . 2009-11-07 03:17 36352 ----a-w- c:\windows\system32\drivers\intelppm.sys
2010-11-18 18:12 . 2009-11-07 03:16 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-06 00:26 . 2007-06-25 05:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2009-11-07 03:15 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2009-11-07 03:16 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2009-11-07 03:15 1853312 ----a-w- c:\windows\system32\win32k.sys
2010-10-21 02:17 . 2009-08-17 18:30 40 ----a-w- C:\ZTWIN.BAT
2008-06-25 11:51 . 2008-06-25 11:51 118784 ----a-w- c:\program files\internet explorer\plugins\LV86ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 06:50 1197448 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-04-30 5472016]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-09-02 13351304]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-01-11 577536]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-08 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-08 81920]
"suScheduler"="c:\program files\ThinkVantage\SystemUpdate\UCLauncher.exe" [2005-08-01 40960]
"ESP"="c:\program files\bigpond\security\app\start.exe" [2009-11-02 62952]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-09-21 122368]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-07 2780432]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Lubnah\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Catalyst System Tray.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-8-12 45056]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RkHit.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ThinkVantage\\SystemUpdate\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP
xpsp2res.dll,-22009
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2/09/2009 6:20 PM 13360]
R2 AMP;AMP;c:\windows\system32\drivers\amp.sys [23/09/2009 10:41 AM 121896]
R2 AMPSE;AMPSE;c:\windows\system32\drivers\ampse.sys [23/09/2009 10:41 AM 956968]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2/09/2009 6:20 PM 69936]
R2 vseamps;vseamps;c:\program files\Common Files\Authentium\AntiVirus5\vseamps.exe [25/06/2009 6:17 PM 87328]
R2 vsedsps;vsedsps;c:\program files\Common Files\Authentium\AntiVirus5\vsedsps.exe [25/06/2009 6:17 PM 116000]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30/01/2010 3:23 PM 135664]
S2 SBAMSvc;AntiMalware;c:\program files\Common Files\Sunbelt\SBAMSvc.exe [8/09/2009 1:46 PM 1012040]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [5/08/2009 3:58 PM 93872]
S3 vbma012f;Virtual Bus for Microsoft ACPI-Compliant System; [x]
S3 XoftSpyService;XoftSpyService;"c:\program files\Common Files\XoftSpySE\6\xoftspyservice.exe" --> c:\program files\Common Files\XoftSpySE\6\xoftspyservice.exe [?]
.
Contents of the 'Scheduled Tasks' folder
2010-12-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]
2010-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 04:23]
2010-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 04:23]
2010-12-23 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 06:50]
2010-12-23 c:\windows\Tasks\User_Feed_Synchronization-{0D7654D3-C6AF-4895-B3E3-901C128F42A7}.job
- c:\windows\system32\msfeedssync.exe [2009-03-07 18:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2769726
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-klmdb.sys
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-24 06:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(676)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1896)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\bigpond\security\App\syssvcnt.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lkcitdl.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\National Instruments\MAX\nimxs.exe
c:\program files\National Instruments\Shared\Security\nidmsrv.exe
c:\program files\bigpond\security\app\Console.exe
c:\windows\system32\nisvcloc.exe
c:\program files\National Instruments\Shared\Tagger\tagsrv.exe
c:\windows\system32\HPZipm12.exe
c:\program files\ThinkVantage\SystemUpdate\UCLauncherService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2010-12-24 06:16:10 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-23 19:16
ComboFix2.txt 2010-12-23 11:30
ComboFix3.txt 2010-12-05 22:15
Pre-Run: 99,439,013,888 bytes free
Post-Run: 99,573,055,488 bytes free
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 42B27A7394A2C5C897CE01CB8300E301