Hi,
I tried to follow instructions to disable real time antispyware protection but I couldn't find the option so I thought maybe I didn't have that. Anyway here is my log, thanks so much:
ComboFix 08-03-03.12 - 2008-03-03 10:36:05.1 - NTFSx86
Running from: C:\Documents and Settings\\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\DriveCleaner
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\DriveCleaner\DriveCleaner Manual.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\DriveCleaner\DriveCleaner on the Web.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\DriveCleaner\DriveCleaner.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\DriveCleaner\Feedback on Support Quality.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\DriveCleaner\Report Software Defect.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\DriveCleaner\Request for Instructions.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\DriveCleaner\Share Your Suggestions.lnk
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\DriveCleaner\Uninstall DriveCleaner.lnk
C:\Documents and Settings\Application Data\DriveCleaner
C:\Documents and Settings\Application Data\DriveCleaner\activator_info.txt
C:\Documents and Settings\Application Data\DriveCleaner\Logs\Activate.log
C:\Documents and Settings\Application Data\DriveCleaner\Logs\update.log
C:\Documents and Settings\Application Data\searchtoolbarcorp
C:\Documents and Settings\Application Data\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\Application Data\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\Documents and Settings\Desktop\DriveCleaner.lnk
C:\Documents and Settings\err.log
C:\Program Files\Common Files\drivecleaner free
C:\Program Files\mediapipe
C:\Program Files\mediapipe\Agent.dll
C:\Program Files\mediapipe\altpayments_terms.txt
C:\Program Files\mediapipe\api.exe
C:\Program Files\mediapipe\insdl.dll
C:\Program Files\mediapipe\install.log
C:\Program Files\mediapipe\MediaPipe.ini
C:\Program Files\mediapipe\p2pinst.exe
C:\Program Files\mediapipe\p2pl.exe
C:\Program Files\mediapipe\register.dll
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\AlConfig.xml
C:\Program Files\p2pnetworks\alp2plib.log
C:\Program Files\p2pnetworks\install.log
C:\Program Files\p2pnetworks\mpp2pl.exe
C:\Program Files\p2pnetworks\p2pnetworks.exe
C:\Program Files\p2pnetworks\sp2p.cache
C:\Program Files\p2pnetworks\uninst.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2008-02-03 to 2008-03-03 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 21:12 --------- d-----w C:\Program Files\NCH Software
2008-02-02 20:41 --------- d-----w C:\Program Files\NCH Swift Sound
2008-02-02 20:41 --------- d-----w C:\Documents and Settings Wayne\Application Data\NCH Swift Sound
2005-12-16 04:21 26,958 ----a-w C:\Program Files\Movieland Terms.html
2007-09-28 00:38 2,111,112 --sh--w C:\WINDOWS\system\vbxfa.bak1
2007-11-23 19:31 457,500 --sh--w C:\WINDOWS\system\vbxfa.bak2
2007-01-11 23:46 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85168A35-7651-4691-BC91-EF17845FA98C}]
2004-08-04 06:00 100864 --a------ C:\WINDOWS\system32\dmstyl.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2006-01-17 12:03 135168]
"combofix"="C:\WINDOWS\system32\CF12131.exe" [2004-08-04 06:00 388608]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"SFCDisable"=dword:00000004
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 Spssys;Toshiba SPS Service;C:\WINDOWS\system32\drivers\spssys.sys [2004-05-07 20:56]
R0 uqvvudjb;uqvvudjb;C:\WINDOWS\system32\drivers\gjyxibyp.dat []
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-03 10:43:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-03-03 10:47:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-03 15:47:50
.
2008-02-24 06:24:22 --- E O F ---