Here is the combofix log:
ComboFix 09-11-06.03 - Administrator 11/06/2009 22:35.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.184 [GMT -6:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: VirusRescue 3.0 *On-access scanning enabled* (Updated) {BED2903C-5EE3-4973-9679-828AE087DAE6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\Administrator\Application Data\Starware316
c:\documents and settings\Administrator\Application Data\Starware316\BrowserSearch\BrowserSearch.xml
c:\documents and settings\Administrator\Application Data\Starware316\BrowserSearch\BrowserSearch.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Configurator\Configurator.xml
c:\documents and settings\Administrator\Application Data\Starware316\Configurator\Configurator.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\ErrorSearch\ErrorSearchOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\ErrorSearch\ErrorSearchOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Free_Credit_Score\Free_Credit_ScoreOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\Free_Credit_Score\Free_Credit_ScoreOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Free_Music\Free_MusicOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\Free_Music\Free_MusicOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Layouts\ToolbarLayout.xml
c:\documents and settings\Administrator\Application Data\Starware316\Layouts\ToolbarLayout.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Manager\ManagerOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\Manager\ManagerOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Reference\ReferenceOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\Reference\ReferenceOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\RelatedSearch\RelatedSearchOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\RelatedSearch\RelatedSearchOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Ringtones\RingtonesOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\Ringtones\RingtonesOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Screensavers\ScreensaversOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\Screensavers\ScreensaversOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Toolbar\TBProductsOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\Toolbar\TBProductsOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\ToolbarLogo\ToolbarLogoOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\ToolbarLogo\ToolbarLogoOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\ToolbarSearch\ToolbarSearchOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\ToolbarSearch\ToolbarSearchOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\TravelSearch\TravelSearchOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\TravelSearch\TravelSearchOptions.xml.backup
c:\documents and settings\Administrator\Application Data\Starware316\Weather\AlertArchive.xml
c:\documents and settings\Administrator\Application Data\Starware316\Weather\WeatherOptions.xml
c:\documents and settings\Administrator\Application Data\Starware316\Weather\WeatherOptions.xml.backup
c:\documents and settings\All Users\Application Data\Starware316
c:\documents and settings\All Users\Application Data\Starware316\buttons\775_button_1b_def.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\FindIt.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\FindItHot.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\findithotxp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\finditxp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\Free_Credit_Score0.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\Free_Music0.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\logo.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\logoxp.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\Reference.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\ReferenceHot.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\referencehotxp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\referencexp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\Ringtones0.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\Screensavers0.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\Weather.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\WeatherHot.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\weatherhotxp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\weatherxp.png
c:\documents and settings\All Users\Application Data\Starware316\contexts\error.xml
c:\documents and settings\All Users\Application Data\Starware316\contexts\Related.xml
c:\documents and settings\All Users\Application Data\Starware316\contexts\Travel.xml
c:\documents and settings\All Users\Application Data\Starware316\images\walertXP.bmp
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\ProductMessagingConfig.xml
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\ProductMessagingConfig.xml.backup
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\SimpleUpdateConfig.xml
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\SimpleUpdateConfig.xml.backup
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\TimerManagerConfig.xml
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\TimerManagerConfig.xml.backup
c:\program files\Common Files\companion wizard
c:\program files\Common Files\companion wizard\log.txt
c:\program files\Common Files\companion wizard\WapCHK{4CB50401-D16A-410B-B91D-68BC91141254}.dll
c:\program files\Helper
c:\program files\Starware316
c:\program files\Starware316\icons\star_16.ico
c:\program files\Starware316\Starware316Config.xml
c:\program files\Starware316\Starware316Uninstall.exe
C:\resycled
c:\resycled\boot.com
C:\WA6P
c:\wa6p\mxfilerelatedcache.mxc2
c:\windows\bemark2.dat
c:\windows\f49f4daa.dat
c:\windows\fmark2.dat
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\ieupdates.exe.tmp
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\stera.log
c:\windows\system32\tmp.reg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FOPN
-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_NWCWORKSTATION
-------\Service_gaopdxserv.sys
-------\Service_NWCWorkstation
((((((((((((((((((((((((( Files Created from 2009-10-07 to 2009-11-07 )))))))))))))))))))))))))))))))
.
2009-10-23 18:13 . 2009-10-23 18:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Amazon
2009-10-23 18:10 . 2009-10-23 18:10 -------- d-----w- c:\program files\Amazon
2009-10-15 14:35 . 2009-10-15 14:35 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\PCHealth
2009-10-10 02:41 . 2009-10-10 02:41 -------- d-----w- c:\program files\SystemRequirementsLab
2009-10-08 20:24 . 2009-10-08 20:24 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-10-08 20:24 . 2009-10-08 20:24 -------- d-----w- c:\documents and settings\Administrator\Application Data\No Company Name
2009-10-08 12:30 . 2009-10-08 12:31 -------- d-----w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2009-10-08 12:30 . 2009-10-08 12:30 -------- d-----w- c:\program files\SmartSound Software
2009-10-08 12:29 . 2009-10-08 12:29 38208 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\
http://www.macromedia.com\bin\airapp...pinstaller.exe
2009-10-08 12:28 . 2009-10-08 12:28 -------- d-----w- c:\program files\Common Files\Macrovision Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-28 23:42 . 2009-01-07 06:04 1 ----a-w- c:\documents and settings\Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-10-08 20:26 . 2006-10-02 22:43 34352 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-08 12:33 . 2006-10-01 22:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-08 12:28 . 2007-06-27 17:04 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-08 12:08 . 2009-10-08 01:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\Download Manager
2009-09-29 21:38 . 2009-09-29 21:38 -------- d-----w- c:\program files\GoldWave
2009-09-29 21:12 . 2009-09-29 21:11 -------- d-----w- c:\program files\u-he
2009-09-29 21:12 . 2009-09-29 21:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Celemony Software GmbH
2009-09-29 21:11 . 2009-09-29 21:11 -------- d-----w- c:\program files\Common Files\Digidesign
2009-09-29 21:11 . 2009-09-29 21:11 -------- d-----w- c:\program files\Celemony
2009-09-28 03:29 . 2009-09-28 03:29 -------- d-----w- c:\program files\Microsoft
2009-09-28 03:29 . 2009-09-28 03:29 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-28 03:29 . 2008-07-01 01:45 -------- d-----w- c:\program files\Windows Live
2009-09-27 04:44 . 2009-09-27 04:42 -------- d-----w- c:\program files\SpywareBlaster
2009-09-27 04:42 . 2009-09-27 04:42 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-23 16:05 . 2006-10-20 00:29 -------- d-----w- c:\program files\Yahoo!
2009-09-23 16:05 . 2008-12-27 12:44 -------- d--h--r- c:\documents and settings\Administrator\Application Data\yahoo!
2009-09-23 16:05 . 2007-07-01 22:53 -------- d--h--r- c:\documents and settings\All Users\Application Data\yahoo!
2009-09-22 15:57 . 2009-09-22 15:57 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-22 15:56 . 2009-09-22 15:56 152576 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-09-21 04:50 . 2009-09-21 04:50 -------- d-----w- c:\program files\MSBuild
2009-09-21 04:49 . 2009-09-21 04:49 -------- d-----w- c:\program files\Reference Assemblies
2009-09-21 03:13 . 2008-06-15 15:25 -------- d-----w- c:\program files\Alwil Software
2009-09-21 00:38 . 2009-05-31 23:29 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-21 00:16 . 2009-09-21 00:16 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-09-21 00:16 . 2009-09-21 00:16 -------- d-----w- c:\program files\Linksys Wireless-G PCI Wireless Network Monitor
2009-09-11 14:18 . 2004-08-10 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-06 10:48 . 2009-09-06 10:48 1586528 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Elements Organizer\8.0\Flash Galleries\Dynamic\flashplayer\windows\SAFlashPlayer.exe
2009-09-06 10:48 . 2009-09-06 10:48 83296 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Elements Organizer\8.0\Slideshow Templates\yahoomap\resources\AuthSWF.exe
2009-09-04 21:03 . 2004-08-10 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:36 . 2004-08-10 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2004-08-10 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2004-08-10 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2004-08-10 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2007-06-05 03:22 . 2007-06-05 03:23 774144 ----a-w- c:\program files\RngInterstitial.dll
2007-05-09 21:06 . 2007-05-09 21:06 16 ---ha-w- c:\program files\Common Files\mxfilerelatedcache.mxc2
2007-05-09 21:06 . 2007-05-09 21:06 16 ---ha-w- c:\program files\mxfilerelatedcache.mxc2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"PC Pitstop Optimize Scheduler"="c:\program files\PCPitstop\Optimize\PCPOptimize.exe" [2006-10-27 1696768]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-17 86102]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-22 149280]
"combofix"="c:\combofix\CF2901.exe" [2009-11-07 389120]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe "
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\My Games\\SmallBall Baseball\\smallball.exe"=
"%windir%\\system32\\winav.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Adobe\\Elements Organizer 8.0\\AdobePhotoshopElementsMediaServer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 ACEDRV08;ACEDRV08;c:\windows\system32\drivers\ACEDRV08.sys [5/8/2007 8:50 PM 108768]
S2 Tmfilter;Tmfilter;c:\windows\system32\drivers\TmXPFlt.sys --> c:\windows\system32\drivers\TmXPFlt.sys [?]
S2 Tmntsrv;Trend NT Realtime Service;"c:\program files\Trend Micro\Antivirus\Tmntsrv.exe" --> c:\program files\Trend Micro\Antivirus\Tmntsrv.exe [?]
S2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys --> c:\windows\system32\drivers\Tmpreflt.sys [?]
S2 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Antivirus\tmproxy.exe --> c:\program files\Trend Micro\Antivirus\tmproxy.exe [?]
S3 Linksys3P;Wireless-G PCI Adapter with SRX400 Driver;c:\windows\system32\drivers\TMIMO31P.sys [10/1/2006 5:11 PM 780800]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys --> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [5/8/2007 8:44 PM 544768]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.yahoo.com
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.msn.com
uInternet Connection Wizard,ShellNext = iexplore
IE: &Search - ?p=ZKxdm176QPUS
TCP: {B33CE678-3EC8-44D9-BC7D-2A564AC4DD88} = 208.67.220.220,208.67.222.222
DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Windows Registry Repair Pro - c:\program files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe
HKCU-Run-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-06 22:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\program files\Dell AIO Printer A940\dlbabmon.exe
.
**************************************************************************
.
Completion time: 2009-11-07 22:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-07 04:49
Pre-Run: 57,516,347,392 bytes free
Post-Run: 59,044,704,256 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - BD60CEAC545B19D6C283E275F86A90EF