So I ran ComboFix the way that bleepingcomputer.com said to. I was able to run it after I renamed it funstuff.exe. Anyway, here is the log that came up. After it ran, my clock didn't restore to the original format, but the virus did not come up again on the system tray! I'm not sure if this means it's gone. Can you take a look at the log? Thank you so much!
ComboFix 08-12-07.04 - Al 2008-12-09 14:51:51.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.288 [GMT -8:00]
Running from: c:\documents and settings\Al\Desktop\funstuff.exe.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\brastk.exe
c:\windows\Downloaded Program Files\setup.inf
c:\windows\karna.dat
c:\windows\system32\brastk.exe
c:\windows\system32\bszip.dll
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\svchost.exe
c:\windows\system32\karna.dat
c:\windows\system32\kb2006a.exe
c:\windows\system32\usbmons.dll
c:\windows\system32\usbmons.exe
c:\windows\system32\wini10895.exe
D:\Autorun.inf
Infected copy of c:\windows\system32\drivers\beep.sys was found and disinfected
Restored copy from - c:\system volume information\_restore{8F041B17-D47B-4B07-8E2E-F5EB74D7F5B1}\RP270\A0018258.sys
.
((((((((((((((((((((((((( Files Created from 2008-11-09 to 2008-12-09 )))))))))))))))))))))))))))))))
.
2008-12-09 14:53 . 2008-12-09 14:53 4,224 --a------ c:\windows\system32\drivers\beep.sys
2008-12-03 07:58 . 2008-12-03 07:58 <DIR> d-------- c:\windows\system32\IOSUBSYS
2008-12-01 11:43 . 2008-12-01 11:43 <DIR> d-------- c:\documents and settings\Al\Application Data\Uniblue
2008-11-29 05:43 . 2001-08-17 13:56 7,552 --a------ c:\windows\system32\drivers\SONYPVU1.SYS
2008-11-29 05:43 . 2001-08-17 13:56 7,552 --a--c--- c:\windows\system32\dllcache\sonypvu1.sys
2008-11-17 12:04 . 2008-11-17 12:04 2,306,113 --a------ c:\windows\system32\GPhotos.scr
2008-11-12 05:40 . 2008-10-24 03:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 05:38 . 2008-09-04 09:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 22:56 --------- d-----w c:\documents and settings\Al\Application Data\OpenOffice.org2
2008-12-01 20:10 --------- d-----w c:\program files\Trend Micro
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 18:38 --------- d-----w c:\documents and settings\Al\Application Data\Nero
2008-10-16 18:20 --------- d-----w c:\documents and settings\All Users\Application Data\LightScribe
2008-10-16 18:15 --------- d-----w c:\program files\Common Files\LightScribe
2008-10-16 18:12 --------- d-----w c:\program files\Common Files\Nero
2008-10-16 18:08 --------- d-----w c:\program files\Nero
2008-10-16 18:08 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-10-16 14:22 --------- d-----w c:\program files\QuickTime
2007-11-13 20:01 3,395,343 ----a-w c:\program files\openofficeorg4.cab
2007-11-13 20:00 67,695,863 ----a-w c:\program files\openofficeorg3.cab
2007-11-13 19:49 17,646,967 ----a-w c:\program files\openofficeorg2.cab
2007-11-13 19:48 18,827,152 ----a-w c:\program files\openofficeorg1.cab
2007-11-13 19:47 4,364,800 ----a-w c:\program files\openofficeorg23.msi
2007-11-13 19:47 217 ----a-w c:\program files\setup.ini
2007-11-01 20:57 319,488 ----a-w c:\program files\setup.exe
2002-03-11 09:06 1,822,520 ----a-w c:\program files\instmsiw.exe
2002-03-11 08:45 1,708,856 ----a-w c:\program files\instmsia.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-09-19 455968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
c:\documents and settings\Al\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 393216]
Trend Micro Anti-Spyware.lnk - c:\program files\Trend Micro\Tmasy\Tmasy.exe [2008-01-14 1406480]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
hpoddt01.exe.lnk - c:\program files\HP\Digital Imaging\bin\hpotdd01.exe [2004-06-16 28672]
officejet 6100.lnk - c:\program files\HP\Digital Imaging\bin\hposol08.exe [2004-06-16 147456]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-02-27 972064]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2006\\QBDBMgrN.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2008-12-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-04-15 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1200428857.job
- c:\program files\HP\Digital Imaging\Bin\hpqfrucl.exe [2004-06-16 18:06]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Picasa Media Detector - c:\documents and settings\Al\My Documents\Picasa2\PicasaMediaDetector.exe
HKCU-Run-brastk - c:\windows\system32\brastk.exe
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-09 14:56:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\OpenOffice.org 2.3\program\soffice.exe
c:\program files\OpenOffice.org 2.3\program\soffice.bin
c:\program files\HP\Digital Imaging\bin\hpoevm08.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hposts08.exe
.
**************************************************************************
.
Completion time: 2008-12-09 15:03:17 - machine was rebooted [Al]
ComboFix-quarantined-files.txt 2008-12-09 23:02:46
Pre-Run: 61,298,364,416 bytes free
Post-Run: 61,241,290,752 bytes free
131 --- E O F --- 2008-11-13 05:00:29