I disabled everything before I started, hopefully nothing interfered with the process.
Here's the log:
ComboFix 08-08-04.07 - Owner 2008-08-05 11:11:51.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.84 [GMT -7:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner\Application Data\CURITY~1
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\84UKRT88\interclick.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\84UKRT88\interclick.com\ud.sol
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\Owner\My Documents\SSTEM3~1
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\fnts~1\F?nts\
C:\Program Files\Common Files\fnts~2
C:\WINNT\IA
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\pjerxowa.ini
C:\WINNT\system32\txusdorj.ini
.
((((((((((((((((((((((((( Files Created from 2008-07-05 to 2008-08-05 )))))))))))))))))))))))))))))))
.
2008-08-04 14:34 . 2008-08-05 07:35 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-04 13:38 . 2008-08-04 13:38 10,520 --a------ C:\WINNT\system32\avgrsstx.dll
2008-08-04 13:36 . 2008-08-04 13:47 <DIR> d-------- C:\WINNT\system32\drivers\Avg
2008-08-04 13:36 . 2008-08-04 13:36 <DIR> d-------- C:\Program Files\AVG
2008-08-04 13:36 . 2008-08-04 13:38 97,928 --a------ C:\WINNT\system32\drivers\avgldx86.sys
2008-08-04 13:36 . 2008-08-04 13:38 76,040 --a------ C:\WINNT\system32\drivers\avgtdix.sys
2008-08-04 12:46 . 2008-08-04 13:11 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-08-04 12:42 . 2008-07-30 20:07 38,472 --a------ C:\WINNT\system32\drivers\mbamswissarmy.sys
2008-08-04 12:32 . 2008-08-04 13:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-08-04 12:07 . 2008-08-04 12:07 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-08-04 08:33 . 2008-08-04 08:33 2 --a------ C:\WINNT\msoffice.ini
2008-08-04 08:02 . 2008-08-04 08:02 <DIR> d-------- C:\WINNT\ERUNT
2008-08-04 07:57 . 2008-08-04 08:25 <DIR> d-------- C:\SDFix
2008-08-01 15:40 . 2008-08-01 15:41 316,640 --a------ C:\WINNT\WMSysPr9.prx
2008-08-01 15:40 . 2008-04-14 05:42 221,184 --a------ C:\WINNT\system32\wmpns.dll
2008-08-01 15:05 . 2008-04-13 22:58 2,940,928 --------- C:\WINNT\system32\dllcache\wmploc.dll
2008-08-01 15:03 . 2006-12-29 00:31 19,569 --a------ C:\WINNT\
002470_.tmp
2008-08-01 15:02 . 2007-08-10 20:46 26,488 --a------ C:\WINNT\system32\spupdsvc.exe
2008-08-01 14:45 . 2008-04-14 02:30 103,424 --a------ C:\WINNT\system32\dpcdll.dll
2008-08-01 14:44 . 2008-08-01 15:07 <DIR> d-------- C:\WINNT\ServicePackFiles
2008-08-01 14:41 . 2002-06-14 18:46 19,274 --a------ C:\WINNT\
000001_.tmp
2008-08-01 12:44 . 2008-08-01 12:44 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-08-01 12:44 . 2008-08-01 12:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-08-01 12:44 . 2008-08-01 12:44 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-08-01 12:44 . 2008-08-01 12:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-08-01 11:55 . 2008-08-04 12:42 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-01 11:55 . 2008-08-01 11:55 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-08-01 11:55 . 2008-08-01 11:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-01 11:55 . 2008-07-30 20:07 17,144 --a------ C:\WINNT\system32\drivers\mbam.sys
2008-07-31 10:05 . 2008-07-31 10:05 105,472 --a------ C:\WINNT\system32\ywmivq.dll
2008-07-31 10:05 . 2008-07-31 10:05 105,472 --a------ C:\WINNT\system32\csibuesi.dll
2008-07-31 10:04 . 2008-08-01 12:21 91,648 --------- C:\WINNT\system32\tagyoogx.dll
2008-07-31 10:01 . 2008-08-05 11:20 105,408 --a------ C:\WINNT\system32\drivers\4593f830.sys
2008-07-30 10:02 . 2008-07-30 10:02 105,472 --a------ C:\WINNT\system32\yhcyuj.dll
2008-07-30 10:02 . 2008-07-30 10:02 105,472 --a------ C:\WINNT\system32\ewqndptq.dll
2008-07-30 10:00 . 2008-07-30 10:00 91,648 --a------ C:\WINNT\system32\cfchunpg.dll
2008-07-29 23:07 . 2008-07-29 23:05 4,286 --a------ C:\WINNT\system32\Jamster.ico
2008-07-29 12:20 . 2008-07-31 10:14 9,662 --a------ C:\WINNT\system32\ZoneAlarmIconUS.ico
2008-07-29 12:14 . 2008-07-29 12:14 <DIR> d-------- C:\WINNT\mkok
2008-07-29 12:14 . 2008-07-29 13:20 <DIR> d-------- C:\Program Files\Common Files\mkok
2008-07-28 17:37 . 2008-07-28 17:37 105,472 --a------ C:\WINNT\system32\psfbkt.dll
2008-07-28 17:37 . 2008-07-28 17:37 105,472 --a------ C:\WINNT\system32\jnbfmson.dll
2008-07-28 17:34 . 2008-07-28 17:34 91,648 --a------ C:\WINNT\system32\ekfjmlug.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-04 20:31 --------- d-----w C:\Program Files\Symantec
2008-08-04 20:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2004-03-23 22:49 55,832 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2003-03-07 04:17 2,765 ----a-w C:\Program Files\Common Files\AutoUpdate.rtf
2003-01-27 18:50 1,000,448 ----a-w C:\Program Files\Common Files\AutoUpdate.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-04 13:38 1235736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"OOBEDDDemise"="erase" [X]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2002-01-09 22:53:14 200704]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2002-08-26 09:04:52 83360]
ScreenArt.lnk - C:\Program Files\ScreenArt\WillowRd.exe [2008-01-24 14:04:18 339968]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R1 avgldx86;AVG AVI Loader Driver x86;C:\WINNT\system32\Drivers\avgldx86.sys [2008-08-04 13:38]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-04 13:38]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-04 13:38]
R2 avgtdix;AVG8 Network Redirector;C:\WINNT\system32\Drivers\avgtdix.sys [2008-08-04 13:38]
S1 27d8974d;27d8974d;C:\WINNT\system32\drivers\27d8974d.sys []
S3 AL101;Airlink101 802.11g PCI Driver;C:\WINNT\system32\DRIVERS\AL101.sys [2006-07-04 16:28]
S3 ALABULK;Fujifilm USB MemoryCard ReaderWriter device driver;C:\WINNT\system32\Drivers\ALABULK2.sys [2002-07-09 18:20]
S3 PCDRDRV;Pcdr Helper Driver;C:\Atf\Qctest\PCDoc\PCDRDRV.sys []
*Newly Created Service* - NMSCFG
*Newly Created Service* - NMSSVC
*Newly Created Service* - SYMTDI
.
Contents of the 'Scheduled Tasks' folder
2008-07-30 C:\WINNT\Tasks\HP Usg Daily.job
- C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe [2004-03-31 21:35]
2002-06-05 C:\WINNT\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2001-11-19 09:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Microsoft Works Update Detection - C:\Program Files\Microsoft Works\WkDetect.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8tkkxoj7.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
WWW.MYEMBARQ.COM
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-05 11:17:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
OOBEDDDemise = cmd /x /c erase C:\WINNT\System32\oobe\msoobe.exe????X?w???????tP??????????????????????????????v????????????????????????????????????s???????????????????P/??????????|??? ???????????|???????????????|???????????????????????P???P????????????????@??????????????????F??t????????????????????????????C
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINNT\system32\NMSSvc.Exe
C:\WINNT\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINNT\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-08-05 11:22:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-05 18:22:37
Pre-Run: 32,972,603,392 bytes free
Post-Run: 32,951,373,824 bytes free
152