i uninstalled avg it before i ran combodfix and it still says it was running here is the log if i need to do it again let me know
ComboFix 12-04-13.01 - ecp 04/13/2012 10:13:54.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2551.2276 [GMT -7:00]
Running from: c:\documents and settings\ecp\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\ipconfig.txt
.
---- Previous Run -------
.
c:\documents and settings\ecp\Application Data\dplaysvr.exe
c:\documents and settings\NetworkService\Application Data\Adobe\sp.DLL
C:\ipconfig.txt
c:\windows\system32\ccflic0.dll
c:\windows\system32\dds_trash_log.cmd
c:\windows\system32\roxmediadb9.dll
c:\windows\system32\se45mdfl.dll
c:\windows\system32\sisagp.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_A88XENC
-------\Legacy_DNWHODISP
-------\Legacy_IAIMTV0
-------\Legacy_ZTEUSBMDM6K
-------\Service_A88xEnc
-------\Service_dnwhodisp
-------\Service_iaimtv0
-------\Service_SPService
-------\Service_ZTEusbmdm6k
-------\Legacy_A88XENC
-------\Legacy_DNWHODISP
-------\Legacy_IAIMTV0
-------\Legacy_ZTEUSBMDM6K
.
.
((((((((((((((((((((((((( Files Created from 2012-03-13 to 2012-04-13 )))))))))))))))))))))))))))))))
.
.
2012-04-11 23:59 . 2012-04-11 23:59 -------- d-----w- c:\documents and settings\ecp\Application Data\Malwarebytes
2012-04-11 23:58 . 2012-04-11 23:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-04-11 23:58 . 2012-04-11 23:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-04-11 23:58 . 2012-04-04 22:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-11 18:29 . 2012-04-11 18:29 -------- d-----w- C:\TDSSKiller_Quarantine
2012-04-07 12:17 . 2006-02-28 12:00 74752 ----a-w- c:\windows\system32\drivers\ipsec.sys
2012-04-06 14:40 . 2012-04-12 00:23 -------- d-----w- c:\program files\Trojan Guarder Gold Version
2012-04-05 13:22 . 2012-04-05 13:22 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-05 13:03 . 2012-04-05 13:03 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2012-04-05 12:59 . 2012-04-05 12:59 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Sun
2012-03-18 12:19 . 2012-03-18 12:19 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-03-18 12:19 . 2012-03-18 12:19 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-11 18:30 . 2006-02-28 12:00 454016 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-04-05 13:22 . 2011-08-31 02:16 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-04 14:35 . 2012-02-04 14:35 637848 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-02-04 14:35 . 2011-10-26 12:01 567184 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-04 14:35 . 2011-10-26 12:01 141312 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-18 12:19 . 2011-08-31 02:50 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-07_12.32.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-13 17:20 . 2012-04-13 17:20 16384 c:\windows\Temp\Perflib_Perfdata_70c.dat
+ 2006-02-28 12:00 . 2012-04-13 17:22 39992 c:\windows\system32\perfc009.dat
- 2006-02-28 12:00 . 2012-04-07 12:22 39992 c:\windows\system32\perfc009.dat
+ 2006-02-28 12:00 . 2012-04-13 17:22 311604 c:\windows\system32\perfh009.dat
- 2006-02-28 12:00 . 2012-04-07 12:22 311604 c:\windows\system32\perfh009.dat
+ 2012-04-11 16:17 . 2012-04-11 16:17 5138944 c:\windows\Installer\52324c.msi
+ 2012-04-07 13:02 . 2012-04-07 13:02 5136896 c:\windows\Installer\1a2713.msi
+ 2012-04-08 15:13 . 2012-04-08 15:13 2208768 c:\windows\Installer\107140b.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-03-03 740216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-02-26 65024]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-09-30 252296]
"ExpressFiles"="c:\program files\ExpressFiles\ExpressFiles.exe" [2012-02-06 424568]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-02-28 53760]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin 11Mbps Wireless Desktop Network Card Monitor.lnk - c:\windows\system32\BelkinMonitor.exe [2011-8-30 372736]
Billeo.lnk - c:\qoobox\Quarantine\C\Program Files\Billeo\billeo.exe.vir [2011-10-19 1490768]
Trojan Guarder Gold Version.lnk - c:\program files\Trojan Guarder Gold Version\Trojan Guarder.exe [2012-4-6 713728]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Program Files\\ExpressFiles\\ExpressFiles.exe"=
"c:\\Program Files\\ExpressFiles\\ExpressDL.exe"=
"c:\\Documents and Settings\\ecp\\My Documents\\Downloads\\uTorrent(1).exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [4/11/2012 4:58 PM 654408]
R3 anvsnddrv;AnvSoft Virtual Sound Device;c:\windows\system32\drivers\anvsnddrv.sys [2/4/2012 7:17 AM 32896]
R3 BEL6001P;Belkin 11Mbps Wireless Desktop Adapter (F5D6001 V.2);c:\windows\system32\drivers\BEL6001P.sys [8/30/2011 7:22 PM 78720]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [4/11/2012 4:58 PM 22344]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/5/2012 6:22 AM 253600]
S3 pcand5bk;PCAND5BK PCANDIS5 Protocol Driver;c:\windows\system32\PCAND5BK.SYS [8/30/2011 7:22 PM 15104]
.
NETSVCS REQUIRES REPAIRS - current entries shown
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Messenger
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
oracleorahome92pagingserver
iAimFP5
AN983
hmonitor
aamqdispatcher
patrol_scheduler
tnbrlds
rwbackupsrv
ipsraidn
SED133x
p17
unrealircd
NIPALK
se44nd5
RTL8023xp
dktknsrv
mscsptisrv
w800mgmt
citrixxteserver
dkeysync
se2Bnd5
dot4ufd
mgisvr
co_mon
w22n51
ypcservice
atinrvxx
psasrv
issvc
G400DH
NetMsmqActivator
appnnode
AmdIde
qcmerced
aclient
DivisCTS
w550bus
es1371
incdfs
win32sl
amfilter
bthidenum
backupexecnamingservice
pnmsrv
sonicatheaterinstallerservice
SymIM
dtscsi
ageremodemaudio
ZDPSp50
W8100PCI
DSI_SiUSBXp_3_1
ql2100
kbfiltr
db2remotecmd
nvlddmkm
zntport
TOSHIBASoftModem
ATNT40K
ksthunk
guardian2
pinnaclesys.mediaserver
CAM1210
L6POD
nvnetbus
z525mgmt
se58bus
rpcnet
s117nd5
MXOFX
mod7700
arc
wdm_au8820
NxFsMon
websensecamreportserver
wusb54gv2svc
wpdusb
ZD1211BU(ZyDAS)
w810mdm
pdlndint
sandboxu
vet-filt
USBModem
pptchpad
ha10kx2k
MSW_USB
EL90X
w800mdfl
sifilter
s117bus
savrt
adpu320
AVerTV
BVRPMPR5
mfesmfk
nsm1serd
tcpip6
jsdaemon
pavagente
omniserv
comhost
toscosrv
sysmgmthp
Rasauto
Rasman
Remoteaccess
Schedule
Seclogon
SENS
Sharedaccess
SRService
Tapisrv
Themes
TrkWks
W32Time
WZCSVC
Wmi
WmdmPmSp
winmgmt
wscsvc
xmlprov
BITS
wuauserv
ShellHWDetection
helpsvc
WmdmPmSN
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 13:22]
.
2012-04-13 c:\windows\Tasks\Express Files Updater.job
- c:\program files\ExpressFiles\EFupdater.exe [2012-02-06 10:37]
.
2012-04-13 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-09-01 05:18]
.
.
------- Supplementary Scan -------
.
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\ecp\Application Data\Mozilla\Firefox\Profiles\war018ks.default\
FF - prefs.js: browser.startup.homepage - hxxp://forums.prowrestling.com/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20110910&q=
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-84839861.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-04-13 10:21
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\SOUNDMAN.EXE
.
**************************************************************************
.
Completion time: 2012-04-13 10:23:24 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-13 17:23
ComboFix2.txt 2012-04-11 14:17
ComboFix3.txt 2012-04-07 12:35
.
Pre-Run: 905,519,104 bytes free
Post-Run: 1,038,659,584 bytes free
.
- - End Of File - - 48AAE9D98294C758C4D745CD85E8FE6A