sorry for the late response, i've posted it in two parts. here it is:
ComboFix 09-11-20.05 - Tom 21/11/2009 19:04.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3071.2465 [GMT 0:00]
Running from: c:\documents and settings\Tom\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090919-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\desktop.ini
c:\documents and settings\Tom\Favorites\Download programs.url
c:\documents and settings\Tom\Favorites\Games.url
c:\documents and settings\Tom\Favorites\Translator.url
c:\documents and settings\Tom\Favorites\Videos.url
c:\documents and settings\Tom\Local Settings\Temporary Internet Files\mcc2F.tmp
c:\documents and settings\Tom\Local Settings\Temporary Internet Files\mcc75.tmp
c:\documents and settings\Tom\Start Menu\Programs\Download programs.url
c:\documents and settings\Tom\Start Menu\Programs\Games.url
c:\documents and settings\Tom\Start Menu\Programs\Security Tool.lnk
c:\documents and settings\Tom\Start Menu\Programs\Translator.url
c:\documents and settings\Tom\Start Menu\Programs\Videos.url
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\temp\vtmp2
c:\temp\vtmp2\ktnv33.log
c:\windows\Install.txt
c:\windows\rasqervy.dll
c:\windows\sdfinacs.dll
c:\windows\sdfixwcs.dll
c:\windows\system32\BReWErS.dll
c:\windows\system32\config\systemprofile\Application Data\Macromedia\Common
c:\windows\system32\config\systemprofile\Start Menu\Programs\Security Tool.lnk
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Install.txt
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\tdlcmd.dll
c:\windows\system32\tmp73.tmp
c:\windows\system32\tmp74.tmp
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
F:\Autorun.inf
F:\install.exe
Infected copy of c:\windows\system32\DRIVERS\nvgts.sys was found and disinfected
Restored copy from - Kitty ate it
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_npf
((((((((((((((((((((((((( Files Created from 2009-10-21 to 2009-11-21 )))))))))))))))))))))))))))))))
.
2009-11-21 18:55 . 2008-04-13 18:40 96512 -c--a-w- c:\windows\system32\drivers\atapi.sys
2009-11-21 18:55 . 2008-04-13 18:40 96512 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-18 17:56 . 2009-11-21 18:52 12800 ----a-w- c:\windows\system32\tdlclk.dll
2009-11-17 15:38 . 2009-11-17 15:39 -------- d-----w- c:\program files\iTunes
2009-11-17 15:32 . 2009-11-17 15:32 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-15 19:30 . 2009-11-15 19:30 -------- d-----w- c:\program files\Mouse fix
2009-11-14 23:21 . 2009-11-14 23:21 -------- d-----w- c:\documents and settings\Tom\Application Data\Malwarebytes
2009-11-14 23:21 . 2009-09-10 14:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-14 23:21 . 2009-11-14 23:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-14 23:21 . 2009-11-14 23:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-14 23:21 . 2009-09-10 14:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-13 17:10 . 2009-11-13 18:00 117760 ----a-w- c:\documents and settings\Tom\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-11-13 17:09 . 2009-11-13 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-11-13 17:08 . 2009-11-13 17:09 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-11-13 17:08 . 2009-11-13 17:08 -------- d-----w- c:\documents and settings\Tom\Application Data\SUPERAntiSpyware.com
2009-11-12 15:24 . 2009-11-21 16:09 -------- d-----w- c:\program files\Steam
2009-11-12 15:22 . 2009-09-04 17:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-11-12 15:22 . 2009-09-04 17:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-11-12 15:22 . 2009-09-04 17:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-11-12 15:22 . 2009-09-04 17:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-11-12 15:22 . 2009-09-04 17:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-11-12 15:22 . 2009-09-04 17:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-11-12 15:22 . 2009-09-04 17:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-11-08 13:58 . 2009-11-08 13:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Citrix
2009-11-08 13:57 . 2009-11-08 13:57 -------- d-----w- c:\documents and settings\Tom\Local Settings\Application Data\Citrix
2009-11-08 13:57 . 2009-11-08 13:57 61480 ----a-w- c:\documents and settings\Tom\GoToAssistDownloadHelper.exe
2009-11-06 23:26 . 2009-11-06 23:26 -------- d-----w- c:\program files\Trend Micro
2009-11-06 20:19 . 2009-11-02 20:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-06 20:13 . 2009-11-06 20:13 -------- d-----w- c:\program files\Windows Defender
2009-11-06 15:49 . 2009-10-25 13:55 2064152 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-11-05 21:58 . 2009-11-08 16:20 -------- d-----w- c:\documents and settings\Tom\Local Settings\Application Data\AskToolbar
2009-11-04 16:34 . 2009-11-04 16:34 21419 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-11-04 16:33 . 2009-11-04 16:33 -------- d-----w- c:\program files\802.11 Wireless LAN
2009-11-02 19:51 . 2009-11-02 20:10 -------- d-----w- c:\program files\Cheat Engine
2009-11-02 15:28 . 2009-10-25 13:55 2025752 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-11-01 10:50 . 2009-11-01 10:50 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Office Genuine Advantage
2009-10-31 22:17 . 2009-11-06 19:15 -------- d-----w- c:\program files\Ask.com
2009-10-31 20:05 . 2009-10-31 20:05 -------- d-----w- c:\program files\Common Files\xing shared
2009-10-31 20:04 . 2009-10-31 20:04 -------- d-----w- c:\program files\real
2009-10-26 11:59 . 2009-10-26 11:59 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-26 02:07 . 2009-10-26 02:07 -------- d-----w- c:\documents and settings\Tom\Application Data\Jasc
2009-10-26 02:06 . 2009-10-26 02:06 -------- d-----w- c:\program files\Jasc Software Inc
2009-10-25 20:59 . 2009-10-25 20:59 3584 ----a-r- c:\documents and settings\Tom\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2009-10-25 20:59 . 2009-10-25 20:59 -------- d-----w- c:\program files\Windows Installer Clean Up
2009-10-23 17:39 . 2009-11-17 15:38 -------- d-----w- c:\program files\iPod
2009-10-23 17:39 . 2009-10-23 17:39 -------- d-----w- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 21:09 . 2009-06-04 21:13 4536608 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-11-21 21:01 . 2009-06-04 21:13 96149792 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-11-21 19:23 . 2009-06-04 21:13 429320 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-11-21 19:23 . 2009-06-04 21:13 1291472 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-11-21 19:23 . 2009-04-06 23:08 3887208 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-21 17:46 . 2008-08-09 10:59 -------- d-----w- c:\documents and settings\Tom\Application Data\DMCache
2009-11-21 17:32 . 2009-11-01 01:09 5632 --sha-w- c:\program files\Thumbs.db
2009-11-21 17:28 . 2009-04-05 20:54 -------- d-----w- c:\documents and settings\Tom\Application Data\uTorrent
2009-11-21 15:31 . 2009-05-28 19:56 -------- d-----w- c:\program files\MSECACHE
2009-11-17 15:38 . 2008-03-02 11:20 -------- d-----w- c:\program files\Common Files\Apple
2009-11-16 18:15 . 2008-04-12 16:14 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-14 23:01 . 2008-10-06 20:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-13 21:30 . 2009-09-01 18:42 -------- d-----w- c:\program files\Temp
2009-11-13 17:08 . 2008-09-28 10:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-13 16:47 . 2008-01-24 13:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-11 19:09 . 2009-02-13 22:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-11 17:36 . 2008-03-28 15:02 189104 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-11-11 16:50 . 2008-06-28 17:42 139584 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-06 20:44 . 2009-09-02 21:36 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-11-01 10:32 . 2009-04-05 20:54 -------- d-----w- c:\program files\uTorrent
2009-10-31 22:17 . 2009-04-05 20:10 -------- d-----w- c:\program files\BitComet
2009-10-31 20:05 . 2008-03-24 19:22 -------- d-----w- c:\program files\Common Files\Real
2009-10-31 11:33 . 2008-03-02 11:25 73984 -c--a-w- c:\documents and settings\Tom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 14:04 . 2009-02-13 22:38 -------- d-----w- c:\program files\Microsoft Works
2009-10-27 21:28 . 2009-04-09 09:37 -------- d-----w- c:\program files\Xvid
2009-10-27 21:28 . 2009-04-02 18:38 -------- d-----w- c:\program files\WorldOfGoo
2009-10-27 21:28 . 2008-01-25 09:44 -------- d-----w- c:\program files\Windows Media Connect 2
2009-10-27 21:28 . 2009-05-09 23:15 -------- d-----w- c:\program files\RegCure
2009-10-27 21:28 . 2009-04-09 09:37 -------- d-----w- c:\program files\AoA DVD Ripper
2009-10-27 21:28 . 2009-05-30 10:59 -------- d-----w- c:\program files\Heli Traffic 2009
2009-10-27 21:28 . 2008-03-27 19:23 -------- d-----w- c:\program files\Incomplete
2009-10-27 21:28 . 2008-10-29 09:50 -------- d-----w- c:\program files\FlashGet
2009-10-26 16:54 . 2009-02-18 16:30 588392 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-10-25 19:53 . 2009-06-28 11:54 58884 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-24 21:51 . 2008-06-27 19:25 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-10-21 15:49 . 2009-10-21 15:49 -------- d-----w- c:\documents and settings\Tom\Application Data\Mael
2009-10-21 15:40 . 2009-10-21 15:40 -------- d-----w- c:\program files\HxD
2009-10-18 16:22 . 2009-10-18 16:22 -------- d-----w- c:\documents and settings\Tom\Application Data\Flight One Software
2009-10-18 15:26 . 2009-10-18 15:26 1032192 ----a-w- c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\ucsn8dxp.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
2009-10-14 15:38 . 2009-09-24 20:25 -------- d-----w- c:\documents and settings\Tom\Application Data\IDM
2009-10-08 21:59 . 2009-09-26 17:27 -------- d-----w- c:\program files\Registry Easy
2009-10-08 20:13 . 2008-09-28 11:18 -------- d-----w- c:\program files\NVIDIA Corporation
2009-10-06 18:54 . 2009-02-18 16:41 5922816 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2009-10-06 16:34 . 2009-02-18 16:40 18750976 ----a-w- c:\windows\RTHDCPL.EXE
2009-10-06 07:12 . 2007-01-29 16:27 823936 ----a-w- c:\windows\system32\drivers\rtl8185.sys
2009-10-02 14:41 . 2009-10-02 14:41 -------- d-----w- c:\documents and settings\Tom\Application Data\Office Genuine Advantage
2009-09-29 18:38 . 2009-06-20 19:44 352256 ----a-w- c:\windows\vncutil.exe
2009-09-28 19:49 . 2009-09-28 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-09-28 15:08 . 2008-08-16 12:44 -------- d-----w- c:\program files\Yahoo!
2009-09-28 15:08 . 2009-09-28 15:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-09-27 18:22 . 2009-09-27 18:22 -------- d-----w- c:\program files\BTHomeHub
2009-09-25 15:17 . 2008-08-06 23:24 -------- d-----w- c:\documents and settings\Tom\Application Data\Media Player Classic
2009-09-25 14:34 . 2009-09-25 14:33 198064 ----a-w- c:\documents and settings\Tom\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-09-25 14:34 . 2009-01-29 18:31 -------- d-----w- c:\program files\Internet Download Manager
2009-09-23 16:41 . 2009-09-23 16:41 8704 ----a-w- c:\documents and settings\Tom\cpuxp.sys
2009-09-23 16:17 . 2008-05-22 14:34 -------- d-----w- c:\documents and settings\Tom\Application Data\Skype
2009-09-23 15:39 . 2008-05-22 14:42 -------- d-----w- c:\documents and settings\Tom\Application Data\skypePM
2009-09-22 18:45 . 2008-01-25 10:01 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-21 16:47 . 2009-06-20 19:44 41472 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2009-09-11 14:18 . 2004-08-03 23:56 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-03 23:56 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 17:44 . 2009-05-04 11:48 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-03 21:37 . 2009-09-03 21:32 6110 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2009-09-03 21:37 . 2009-09-03 21:37 67021 ----a-w- c:\windows\BricoPackUninst.cmd
2009-09-03 21:36 . 2004-08-03 23:56 218624 ----a-w- c:\windows\system32\uxtheme.dll
2009-09-02 21:36 . 2009-09-02 21:36 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-02 21:36 . 2009-09-02 21:36 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-02 21:36 . 2009-09-02 21:36 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-02 21:36 . 2009-09-02 21:36 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-02 10:58 . 2009-09-20 11:40 1107200 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-08-29 07:36 . 2004-08-03 23:56 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2009-07-11 11:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2004-08-03 23:56 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-27 12:57 . 2009-07-18 17:21 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-08-26 08:00 . 2004-08-03 23:56 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-05-01 21:16 . 2009-05-01 21:16 61 --sh--w- c:\windows\cnerolf.bin
.
------- Sigcheck -------
[-] 2009-06-03 . 7EE936A57B5901D6B1C4AF9A9E6C500A . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2009-06-03 . 7EE936A57B5901D6B1C4AF9A9E6C500A . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 10:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-02 14:56 1175944 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2008-08-18 106496]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-02 2028312]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-12 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-31 198160]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2008-09-05 159744]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-28 141600]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-10-06 18750976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\Shell ExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-09-19 21:12 16680 ----a-w- c:\program files\Citrix\GoToAssist\570\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-02 21:36 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDef end]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^My applications^Tibia Client.exe]
backup=c:\windows\pss\Tibia Client.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless Configuration Utility HW.15.lnk]
backup=c:\windows\pss\Wireless Configuration Utility HW.15.lnkCommon Startup
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility HW.15.lnk
[HKLM\~\startupfolder\C:^Documents and Settings^Tom^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=c:\windows\pss\MagicDisc.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ParetoLogic Anti-Virus PLUS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=2 (0x2)
"GoToAssist"=2 (0x2)
".norton2009Reset"=2 (0x2)
"usnjsvc"=2 (0x2)
"IDriverT"=3 (0x3)
"UpdateCenterService"=2 (0x2)
"prfldsvc"=2 (0x2)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"McciCMService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=2 (0x2)
"McAfee SiteAdvisor Service"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"f:\\Call Of Duty Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Safari\\Safari.exe"=
"f:\\Call of Duty WAW\\CoDWaWmp.exe"=
"c:\\Documents and Settings\\Tom\\My Documents\\My Games saves\\Left 4 Dead\\left4dead.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21/03/2009 20:30 114768]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [02/09/2009 21:36 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [02/09/2009 21:36 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [11/11/2009 10:44 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/11/2009 10:44 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21/03/2009 20:30 20560]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [02/09/2009 21:36 297752]
R2 Prvflder;Prvflder;c:\windows\system32\drivers\prvflder.sys [21/04/2006 07:22 70912]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
R3 bfturboh;BUFFALO TurboUSB for HD Filter;c:\windows\system32\drivers\bfturboh.sys [27/12/2008 17:40 17152]
R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [04/10/2008 07:42 22784]
S0 NVStrap;NVStrap;c:\windows\system32\drivers\NVStrap.sys [03/12/2008 22:28 4224]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [18/02/2009 16:40 1684736]
S3 cpuxp;cpuxp;c:\documents and settings\Tom\cpuxp.sys [23/09/2009 16:41 8704]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/11/2009 10:44 7408]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [06/04/2009 12:19 23064]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [02/10/2002 09:57 13532]
S4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [28/07/2008 23:12 210216]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28/01/2008 09:14 721904]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
BtwSrv
.
Contents of the 'Scheduled Tasks' folder
2009-02-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-11-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1383384898-2147175445-1003Core.job
- c:\documents and settings\Tom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 19:38]
2009-11-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1383384898-2147175445-1003UA.job
- c:\documents and settings\Tom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 19:38]
2009-11-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2009-11-21 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
2009-11-21 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 08:20]
2009-07-05 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 08:20]
2009-11-14 c:\windows\Tasks\Schedule Task Weekly.job
- c:\program files\Registry Easy\RE.exe [2009-09-26 15:43]
2009-11-21 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-09-02 14:56]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://www.bt.com/gta
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*
http://uk.search.yahoo.com/
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\idmmbc.dll
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://138.237.46.59/activex/AMC.cab
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-*{2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)
HKLM-Run-81640726 - c:\docume~1\ALLUSE~1\APPLIC~1\81640726\81640726.exe
MSConfigStartUp-Comrade - (no file)
AddRemove-Aircraft Factory F4u Corsair - f:\micros~3\\UNWISE.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-21 21:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.