Here is the combofix log.
I haven't been using a flash drive for a while, but I do have one. Should I disinfect it?
I will continue with the other steps...
ComboFix 10-07-24.06 - Owner 08/01/2010 11:39:27.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2045.1391 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
.
- REDUCED FUNCTIONALITY MODE -
FILE ::
"c:\windows\system32\drivers\yxrurdkp.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\yxrurdkp.sys
c:\windows\system32\service
c:\windows\system32\service\01082010_TIS17_SfFniAU.log
.
((((((((((((((((((((((((( Files Created from 2010-07-01 to 2010-08-01 )))))))))))))))))))))))))))))))
.
2010-08-01 18:36 . 2010-08-01 18:36 -------- d-----w- c:\windows\LastGood
2010-08-01 04:41 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-25 17:26 . 2010-07-25 17:26 -------- d-----w- c:\program files\Microsoft
2010-07-25 17:26 . 2010-07-25 17:26 -------- d-----w- c:\program files\MSN Toolbar
2010-07-25 17:26 . 2010-07-25 17:26 -------- d-----w- c:\program files\MSN Toolbar Installer
2010-07-25 17:25 . 2010-07-25 17:25 61440 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3bc9a11a-n\decora-sse.dll
2010-07-25 17:25 . 2010-07-25 17:25 503808 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-13b88e8c-n\msvcp71.dll
2010-07-25 17:25 . 2010-07-25 17:25 499712 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-13b88e8c-n\jmc.dll
2010-07-25 17:25 . 2010-07-25 17:25 348160 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-13b88e8c-n\msvcr71.dll
2010-07-25 17:25 . 2010-07-25 17:25 12800 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3bc9a11a-n\decora-d3d.dll
2010-07-25 17:25 . 2010-06-22 11:36 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-25 09:23 . 2010-07-25 09:23 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-07-25 09:23 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-25 09:23 . 2010-07-25 09:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-25 09:23 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-25 09:23 . 2010-07-25 09:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-25 04:40 . 2010-07-25 04:59 -------- d-----w- c:\windows\system32\MpEngineStore
2010-07-25 04:33 . 2010-07-25 04:42 -------- d-----w- c:\program files\Windows Live Safety Center
2010-07-18 17:38 . 2010-07-18 17:39 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-18 17:34 . 2010-07-18 17:34 77184 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-07-16 01:03 . 2010-07-16 01:03 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-14 04:55 . 2010-07-14 04:55 -------- d-----w- c:\program files\iPod
2010-07-14 04:47 . 2010-07-14 04:47 -------- d-----w- c:\program files\Bonjour
2010-07-14 04:44 . 2010-07-14 04:44 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-25 17:29 . 2006-02-24 10:47 -------- d-----w- c:\program files\Java
2010-07-25 17:26 . 2006-02-24 10:47 -------- d-----w- c:\program files\Common Files\Java
2010-07-25 04:09 . 2008-12-02 06:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-18 17:35 . 2008-12-02 06:58 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-16 16:21 . 2008-06-23 22:31 -------- d-----w- c:\program files\Coupons
2010-07-16 01:03 . 2006-08-14 13:33 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-14 04:56 . 2009-08-09 17:26 -------- d-----w- c:\program files\iTunes
2010-07-14 04:55 . 2008-03-13 02:54 -------- d-----w- c:\program files\Common Files\Apple
2010-06-23 17:39 . 2010-06-23 17:39 501936 ----a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb31F.tmp.exe
2010-06-15 02:00 . 2008-07-15 02:23 -------- d-----w- c:\program files\Safari
2010-06-15 01:56 . 2010-06-15 01:56 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-14 14:31 . 2005-01-10 01:09 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-03 05:20 . 2006-11-10 15:09 12130 ----a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2010-05-18 23:35 . 2010-05-18 23:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-06 10:41 . 2005-01-09 23:48 916480 ----a-w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-07-26_18.00.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-01 18:29 . 2010-08-01 18:29 16384 c:\windows\Temp\Perflib_Perfdata_420.dat
+ 2010-08-01 18:29 . 2010-08-01 18:29 16384 c:\windows\Temp\Perflib_Perfdata_198.dat
- 2006-02-24 10:42 . 2010-06-10 06:16 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-02-24 10:42 . 2010-06-10 06:16 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-02-24 10:42 . 2010-06-10 06:16 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-02-24 10:42 . 2010-06-10 06:16 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-02-24 10:42 . 2010-06-10 06:16 4096 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 4096 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2010-08-01 18:37 . 2010-08-01 18:37 200192 c:\windows\Installer\591ec.msi
- 2006-02-24 10:42 . 2010-06-10 06:16 409600 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 409600 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 286720 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-02-24 10:42 . 2010-06-10 06:16 286720 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-02-24 10:42 . 2010-06-10 06:16 249856 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 249856 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-02-24 10:42 . 2010-06-10 06:16 794624 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 794624 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2006-02-24 10:42 . 2010-08-01 18:38 135168 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2006-02-24 10:42 . 2010-06-10 06:16 135168 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2010-05-25 18:45 . 2010-05-25 18:45 8445440 c:\windows\Installer\591ff.msp
+ 2010-07-01 05:52 . 2010-07-01 05:52 5522944 c:\windows\Installer\591c9.msp
+ 2006-07-21 03:42 . 2010-07-02 19:39 34045896 c:\windows\system32\MRT.exe
- 2006-07-21 03:42 . 2010-07-02 19:39 34045896 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-16 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-04-03 389120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-01-26 1020248]
"showwnd"="showwnd.exe" [2003-09-19 36864]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-08-27 139264]
"QuickFinder Scheduler"="c:\program files\Corel\WordPerfect Office X4\Programs\QFSCHD140.EXE" [2008-03-21 83232]
"nwiz"="nwiz.exe" [2005-07-09 1519616]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-09 7110656]
"NBCUniversal Media Manager Tray"="c:\program files\Entriq\MediaSphere\Bin\EntriqMediaTray.exe" [2006-09-07 372736]
"ledpointer"="CNYHKey.exe" [2004-03-03 5576704]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2005-10-28 8740864]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"HPHmon03"="c:\windows\system32\hphmon03.exe" [2006-01-13 311296]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2006-01-13 196608]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"EntriqMediaTray"="c:\program files\Entriq\MediaSphere\EntriqMediaTray.exe" [2006-05-01 122880]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"CHotkey"="mHotkey.exe" [2004-12-09 550912]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe" [2010-02-12 240992]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2004-8-10 17408]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MetaFrame Password Manager Agent Background Process.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\MetaFrame Password Manager Agent Background Process.lnk
backup=c:\windows\pss\MetaFrame Password Manager Agent Background Process.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 --sh--w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:*

isabled:Remote Media Center Experience
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [10/25/2009 3:48 PM 36368]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/7/2010 10:17 AM 135664]
S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [7/16/2006 4:33 PM 18864]
S3 Net6IM;Net6;c:\windows\system32\DRIVERS\net6im51.sys --> c:\windows\system32\DRIVERS\net6im51.sys [?]
S3 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [10/25/2009 3:55 PM 50704]
S3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [10/25/2009 3:55 PM 689416]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - SEAPORT
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-06-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2010-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 17:17]
2010-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 17:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Open with WordPerfect - c:\program files\Corel\WordPerfect Office X4\Programs\WPLauncher.hta
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
DPF: {26B2A5DA-BFD6-422F-A89A-28A54C74B12B} - hxxp://www.costcophotocenter.com/upload/activex/v3_0_0_4/PhotoCenter_ActiveX_Control.cab
DPF: {A1662FB6-39BE-41BB-ACDC-0448FB1B5817} - hxxp://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_5/PhotoCenter_ActiveX_Control.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-01 11:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\program files\Citrix\MetaFrame Password Manager\SSOGina\SSOGina.DLL
c:\program files\Citrix\MetaFrame Password Manager\Plugin\EventMgr\EventReporter.dll
c:\program files\Citrix\MetaFrame Password Manager\resource.dll
.
Completion time: 2010-08-01 11:46:18
ComboFix-quarantined-files.txt 2010-08-01 18:46
ComboFix2.txt 2010-07-26 18:02
Pre-Run: 154,173,030,400 bytes free
Post-Run: 154,183,798,784 bytes free
- - End Of File - - 5EC34D72010B0CA70BFC2E22890E64BD