OK - Here is the combo fix log. NEW HJT will be posted after.
ComboFix 09-11-06.03 - Owner 11/06/2009 23:30.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2395 [GMT -6:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Shared
c:\windows\system32\dulapiho.dll
c:\windows\system32\kepubiho.dll
c:\windows\system32\logon.exe
c:\windows\system32\tesiyuho.dll
c:\windows\system32\wovovipe.dll
I:\autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-10-07 to 2009-11-07 )))))))))))))))))))))))))))))))
.
2009-11-07 04:26 . 2009-09-10 20:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-07 04:26 . 2009-11-07 04:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-07 04:26 . 2009-09-10 20:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-03 22:40 . 2009-11-03 22:40 -------- d-----w- c:\documents and settings\Owner\Application Data\Amazon
2009-11-03 22:39 . 2009-11-03 22:39 -------- d-----w- c:\program files\Amazon
2009-11-01 17:52 . 2009-11-01 17:52 -------- d-----w- c:\program files\Flip Video
2009-11-01 17:52 . 2009-11-01 17:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Flip Video
2009-10-31 15:48 . 2009-10-31 15:50 -------- d-----w- C:\$AVG
2009-10-31 15:47 . 2009-10-31 15:47 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-10-29 03:36 . 2009-10-29 03:36 -------- d-----w- C:\rsit
2009-10-20 21:16 . 2009-10-20 21:16 -------- d-----w- c:\program files\Trend Micro
2009-10-17 21:46 . 2009-10-17 21:46 -------- d-----w- c:\documents and settings\Owner\DoctorWeb
2009-10-17 20:41 . 2009-10-17 22:32 -------- d-----w- c:\program files\bmtley
2009-10-16 15:40 . 2009-10-16 15:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-10-15 18:17 . 2009-10-15 18:17 -------- d-----w- c:\documents and settings\Owner\Application Data\Iomega Automatic Backup
2009-10-15 17:56 . 2009-10-15 17:56 -------- d-----w- c:\program files\Iomega
2009-10-15 17:55 . 2009-10-15 17:55 -------- d-----w- c:\windows\Downloaded Installations
2009-10-11 18:00 . 2009-10-11 21:28 -------- d-----w- c:\program files\iDump (Freeware)
2009-10-10 01:39 . 2009-10-10 01:39 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2009-10-09 16:47 . 2009-10-09 16:47 -------- d-----w- c:\program files\3ivx
2009-10-08 20:46 . 2009-10-09 21:35 -------- d-----w- c:\program files\Free Best Bulk Email Software
2009-10-08 20:46 . 2009-10-08 20:46 -------- d-----w- c:\windows\Free Best Bulk Email Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-07 05:40 . 2009-10-04 21:00 -------- d-----w- c:\program files\Dl_cats
2009-10-31 15:48 . 2009-10-02 14:58 -------- d-----w- c:\program files\AVG
2009-10-31 15:48 . 2009-10-02 14:59 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-31 15:48 . 2009-10-02 14:59 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-31 15:48 . 2009-10-02 14:59 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-31 15:48 . 2009-10-02 14:59 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-30 22:55 . 2009-10-03 15:42 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-16 22:34 . 2009-10-02 14:54 156592 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-15 17:55 . 2009-10-02 16:20 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-08 00:53 . 2009-10-08 00:53 -------- d-----w- c:\documents and settings\Owner\Application Data\DellFaxCtr
2009-10-07 01:16 . 2009-10-03 01:54 -------- d-----w- c:\program files\iTunes
2009-10-06 15:08 . 2009-10-02 16:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-05 00:01 . 2009-10-04 23:48 -------- d-----w- c:\program files\Microsoft Money Plus
2009-10-04 20:59 . 2009-10-04 20:52 -------- d-----w- c:\program files\Dell Photo AIO Printer 966
2009-10-04 20:57 . 2009-10-04 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-10-04 20:56 . 2009-10-04 20:56 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
2009-10-04 20:55 . 2009-10-04 20:55 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-10-04 20:55 . 2009-10-04 20:54 -------- d-----w- c:\program files\Dell PC Fax
2009-10-04 20:54 . 2009-10-04 20:54 -------- d-----w- c:\documents and settings\All Users\Application Data\DellFaxCtr
2009-10-04 20:36 . 2009-10-04 20:36 -------- d-----w- c:\program files\NETGEAR
2009-10-04 20:20 . 2009-10-01 22:42 -------- d-----w- c:\program files\microsoft frontpage
2009-10-04 20:11 . 2009-10-04 20:11 -------- d-----w- c:\documents and settings\Owner\Application Data\Leadertech
2009-10-03 17:36 . 2009-10-03 17:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2009-10-03 17:35 . 2009-10-03 17:35 -------- d-----w- c:\program files\Common Files\Macromedia Shared
2009-10-03 17:35 . 2009-10-03 17:35 -------- d-----w- c:\program files\Common Files\Macromedia
2009-10-03 17:35 . 2009-10-03 17:34 -------- d-----w- c:\program files\Macromedia
2009-10-03 15:44 . 2009-10-03 15:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Adobe Systems
2009-10-03 15:42 . 2009-10-03 15:42 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2009-10-03 02:07 . 2009-10-03 01:55 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-10-03 02:07 . 2009-10-03 01:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-10-03 01:55 . 2009-10-03 01:54 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-03 01:54 . 2009-10-03 01:54 -------- d-----w- c:\program files\iPod
2009-10-03 01:54 . 2009-10-03 01:53 -------- d-----w- c:\program files\Common Files\Apple
2009-10-03 01:54 . 2009-10-03 01:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-03 01:54 . 2009-10-03 01:54 -------- d-----w- c:\program files\Bonjour
2009-10-03 01:54 . 2009-10-03 01:54 -------- d-----w- c:\program files\QuickTime
2009-10-03 01:53 . 2009-10-03 01:53 -------- d-----w- c:\program files\Apple Software Update
2009-10-03 01:31 . 2009-10-03 01:31 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-10-03 01:30 . 2009-10-03 01:30 -------- d-----w- c:\program files\Microsoft.NET
2009-10-02 16:20 . 2009-10-02 16:20 -------- d-----w- c:\program files\Analog Devices
2009-10-02 15:09 . 2009-10-02 15:09 -------- d-----w- c:\program files\MSXML 4.0
2009-10-02 14:59 . 2009-10-02 14:59 -------- d-----w- c:\documents and settings\Owner\Application Data\Nero
2009-10-02 14:58 . 2009-10-02 14:56 -------- d-----w- c:\program files\Common Files\Nero
2009-10-02 14:56 . 2009-10-02 14:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-10-02 14:56 . 2009-10-02 14:56 -------- d-----w- c:\program files\Nero
2009-10-02 14:54 . 2009-10-02 14:54 -------- d-----w- c:\program files\Windows Defender
2009-10-02 14:53 . 2009-10-02 14:53 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-10-02 14:53 . 2009-10-02 14:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-02 14:53 . 2009-10-02 14:53 -------- d-----w- c:\program files\XP Codec Pack
2009-10-01 23:41 . 2009-10-01 23:41 -------- d-----w- c:\program files\Windows Media Connect 2
2009-10-01 23:08 . 2009-10-01 22:41 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-01 22:39 . 2009-10-01 22:39 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-01 15:29 . 2009-10-03 06:40 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-21 22:09 . 2009-09-21 22:09 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
2009-08-29 00:42 . 2009-10-03 01:53 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-29 00:42 . 2009-10-03 01:53 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-07 03:07 . 2009-08-07 03:07 39424 --sha-w- c:\windows\system32\wevotozu.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Iomega Automatic Backup"="c:\program files\Iomega\Iomega Automatic Backup\ibackup.exe" [2002-10-15 3014656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2007-06-29 312560]
"dlcqmon.exe"="c:\program files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 292080]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 966\memcard.exe" [2007-06-29 304368]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLCQCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-16 106496]
"Iomega Automatic Backup 1.0.1"="c:\program files\Iomega\Iomega Automatic Backup\ibackup.exe" [2002-10-15 3014656]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-10-31 2010904]
"combofix"="c:\combofix\CF1941.exe" [2009-11-07 389120]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2009-10-3 25214]
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe logon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-31 15:48 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDef end]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dlcqcoms.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"c:\\Program Files\\Internet Explorer\\iexplore.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\WINDOWS\\explorer.exe"=
"c:\\WINDOWS\\system32\\logonui.exe"=
"c:\\WINDOWS\\system32\\winlogon.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"20001:UDP"= 20001:UDP:MicroSAN
"80:TCP"= 80:TCP:Web
R0 ZetSFD;ZetSFD;c:\windows\system32\drivers\ZetSFD.sys [10/4/2009 2:36 PM 12800]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/2/2009 8:59 AM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/2/2009 8:59 AM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/31/2009 9:47 AM 285392]
R2 SFSZ;DataPlow SFS for Zetera Storage Devices;c:\windows\system32\drivers\sfsz.sys [10/4/2009 2:36 PM 345984]
R2 Z-SANService;Z-SAN Service;c:\program files\NETGEAR\NETGEAR Storage Central Manager Utility\Z-SANService.exe [10/4/2009 2:36 PM 376891]
R3 ZetBus;Zetera Virtual Bus;c:\windows\system32\drivers\ZetBus.sys [10/4/2009 2:36 PM 15488]
R3 ZetMPD;ZetMPD;c:\windows\system32\drivers\ZetMPD.sys [10/4/2009 2:36 PM 5120]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [10/1/2009 5:25 PM 20160]
S3 ADM851X;ADM851X USB To Fast Ethernet Adapter;c:\windows\system32\drivers\ADM851X.SYS [10/27/2004 3:05 PM 22144]
S4 Imdflpp6cwnf;Imdflpp6cwnf; [x]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*NewlyCreated* - ZETSFD
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-11-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-11-06 c:\windows\Tasks\User_Feed_Synchronization-{5EB36B48-E061-4477-9395-25A423B004BD}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.flashmobrocks.com/
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
Filter: text/html - {824b3c6a-dc66-4378-a47b-69fe13abb636} -
.
- - - - ORPHANS REMOVED - - - -
BHO-{79d31472-a0b0-4760-825d-8109a1c0ec65} - kepubiho.dll
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
HKLM-Run-tokinobuz - c:\windows\system32\dulapiho.dll
HKLM-Run-<NO NAME> - (no file)
HKLM-Run-hawikazodo - wovovipe.dll
SharedTaskScheduler-{45c46334-457d-4032-8b77-463c6feb9996} - c:\windows\system32\dulapiho.dll
SSODL-zokubonen-{45c46334-457d-4032-8b77-463c6feb9996} - c:\windows\system32\dulapiho.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-06 23:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???? ??????????????????????????????????????????????????????????????????????????? ??????????????????????????????????????????????????????????????????????????? ?????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlcqcoms.exe
c:\progra~1\Iomega\System32\AppServices.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-11-07 23:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-07 05:43
Pre-Run: 449,352,101,888 bytes free
Post-Run: 450,272,636,928 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 38E9E4EB0DFDD5D08A33B42A2B014D28