here is the error message I still have onscreen it popped during the end of combo fix...what do i do click ok or cancel?
---------------------------
pev.3XE - Application Error
---------------------------
The instruction at "0x0070005f" referenced memory at "0x0070005f". The memory could not be "read".
Click on OK to terminate the program
Click on CANCEL to debug the program
---------------------------
OK Cancel
---------------------------
combofixlog
ComboFix 12-04-05.06 - Administrator 04/07/2012 15:05:43.1.2 - x86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1509.1243 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\antivirus 3 steps\b.exe
AV: avast! antivirus 4.8.1368 [VPS 120404-1] *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Online Armor Firewall *Enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator.NP\WINDOWS
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
c:\documents and settings\Berny\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Eliz\WINDOWS
c:\documents and settings\Owner\3320-enu-win2k_xp.exe
c:\documents and settings\Owner\Application Data\Island
c:\documents and settings\Owner\Application Data\Island\space.rgt
c:\documents and settings\Owner\Application Data\PriceGong
c:\documents and settings\Owner\Application Data\PriceGong\Data\1.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\4489.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\a.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\b.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\c.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\d.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\e.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\f.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\g.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\h.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\i.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\j.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\k.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\l.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\m.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Owner\Application Data\PriceGong\Data\n.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\o.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\p.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\q.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\r.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\s.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\t.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\u.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\v.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\w.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\wlu.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\x.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\y.txt
c:\documents and settings\Owner\Application Data\PriceGong\Data\z.txt
c:\documents and settings\Owner\Application Data\TMInc
c:\documents and settings\Owner\Application Data\TMInc\game.cfg
c:\documents and settings\Owner\Application Data\TMInc\user1.sav
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\6644nQ6.jpg
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\bPXsAg.jpg
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\Jbh5v.jpg
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\P0rk1aXa3.jpg
c:\documents and settings\Owner\System
c:\documents and settings\Owner\System\win_qs8.jqx
c:\documents and settings\Owner\WINDOWS
c:\windows\system32\_000023_.tmp.dll
c:\windows\system32\_000024_.tmp.dll
c:\windows\system32\_000025_.tmp.dll
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\DC120fc7_32.dll
c:\windows\system32\dds_trash_log.cmd
.
.
((((((((((((((((((((((((( Files Created from 2012-03-07 to 2012-04-07 )))))))))))))))))))))))))))))))
.
.
2012-04-07 13:10 . 2012-04-07 13:20 -------- d-----w- C:\b
2012-04-07 00:27 . 2012-04-07 00:27 -------- d-----w- c:\program files\HitmanPro
2012-04-07 00:26 . 2012-04-07 00:26 -------- d-----w- c:\documents and settings\All Users\Application Data\HitmanPro
2012-04-07 00:23 . 2010-10-24 11:06 598528 ----a-w- c:\windows\system32\ztv7z.dll
2012-04-07 00:23 . 2010-10-24 11:06 178176 ----a-w- c:\windows\system32\ztvunrar39.dll
2012-04-07 00:23 . 2006-06-19 17:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2012-04-07 00:23 . 2006-05-25 19:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2012-04-07 00:23 . 2005-08-26 05:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2012-04-07 00:23 . 2003-02-03 00:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2012-04-07 00:23 . 2002-03-06 05:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2012-04-07 00:23 . 2012-04-07 00:23 -------- d-----w- c:\program files\Trojan Remover
2012-04-07 00:23 . 2012-04-07 00:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
2012-04-06 14:56 . 2012-04-06 19:25 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2012-04-05 22:21 . 2012-04-05 22:21 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2012-04-05 22:19 . 2012-04-05 22:21 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-04-05 22:19 . 2012-04-05 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-04-05 22:15 . 2012-04-05 22:15 -------- d-----w- C:\TDSSKiller_Quarantine
2012-04-05 17:14 . 2012-04-05 19:49 -------- d-----w- c:\documents and settings\Administrator.NP
2012-03-18 22:05 . 2012-03-18 22:05 -------- d-----w- c:\program files\Jewel Quest Solitaire III
2012-03-18 22:05 . 2012-03-18 22:05 -------- d--h--w- c:\windows\PIF
2012-03-10 20:23 . 2012-03-10 20:23 -------- d-----w- c:\program files\Ashampoo Burning Studio 2012
2012-03-10 19:32 . 2012-03-10 19:32 -------- d-----w- c:\documents and settings\Owner\Application Data\Ashampoo
2012-03-10 00:06 . 2012-03-10 00:06 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\temp
2012-03-10 00:05 . 2012-03-10 19:32 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\ashampoo
2012-03-10 00:05 . 2012-03-10 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ashampoo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-03 09:22 . 2008-03-04 21:46 1860096 ----a-w- c:\windows\system32\win32k.sys
2012-01-11 19:06 . 2012-02-15 10:46 3072 ------w- c:\windows\system32\iacenc.dll
2012-01-09 16:20 . 2008-03-04 21:46 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2003-07-12 00:04 . 2008-09-21 17:51 46592 -c--a-w- c:\program files\KeyGen.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2009-12-05 923336]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\acaptuser32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
backup=c:\windows\pss\BigFix.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 -c--a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 15:50 155648 -c--a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2012-03-07 21:27 3905920 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
2012-04-03 20:36 1238800 ----a-w- c:\program files\Trojan Remover\Trjscan.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"High Definition Audio Property Page Shortcut"=HDAudPropShortcut.exe
"SunKistEM"=c:\program files\Digital Media Reader\shwiconem.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"HPDJ Taskbar Utility"=c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"IgfxTray"=c:\windows\system32\igfxtray.exe
"Babylon Client"=c:\program files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"SoundMan"=SOUNDMAN.EXE
"AlcWzrd"=ALCWZRD.EXE
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Persistence"=c:\windows\system32\igfxpers.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\Kyodai Mahjongg 2006\\kmj.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
.
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [2011-08-11 116608]
S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2010-01-31 114768]
S1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2009-12-25 223312]
S1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2009-12-25 24656]
S1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [2009-12-25 29776]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2011-07-22 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-01-31 20560]
S2 BackupService;BackupService;c:\documents and settings\Owner\Application Data\HP SimpleSave Application\uUACTokenSvc.exe [2010-12-31 83512]
S2 HitmanProScheduler;HitmanPro Scheduler;c:\program files\HitmanPro\hmpsched.exe [2012-04-06 90952]
S2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [2009-12-25 1282248]
S2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [2009-12-25 3291336]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [2011-06-02 11336]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
atkkeyboardservice
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43eca3e4-1519-11e0-961f-0011116e4d04}]
\Shell\AutoRun\command - J:\HPLauncher.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uSearchMigratedDefaultURL = hxxp://www.cherche.us/Result.php?cx=partner-pub-0420647136319153%3A5n6ugpjrdrh&cof=GIMP%3ACCCCCC%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A10%3BDIV%3A%23FFFFF0%3B&q={searchTerms}
mStart Page = hxxp://www.google.com
Trusted Zone: chat-land.org
Trusted Zone: francite.net
Trusted Zone: gamezebo.com\www
Trusted Zone: realtor.com\www
TCP: DhcpNameServer = 24.200.241.37 24.201.245.77 24.200.243.189
DPF: {C2B78FF1-6E5A-4854-AC24-E09A0E2411BA} - hxxp://static1.meetupstatic.com/applet/MeetUploader_200909.cab
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{7ac1cacf-43d3-4b2b-861c-219bda77ecf1} - (no file)
Toolbar-{7ac1cacf-43d3-4b2b-861c-219bda77ecf1} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{7AC1CACF-43D3-4B2B-861C-219BDA77ECF1} - (no file)
SafeBoot-11586904.sys
MSConfigStartUp-Internet Security - c:\documents and settings\All Users\Application Data\isecurity.exe
AddRemove-WhiteSmoke - c:\program files\WhiteSmoke\Uninst.exe
AddRemove-{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113217220} - c:\program files\Gamenext\Brainiversity\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-04-07 16:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(208)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'explorer.exe'(1728)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2012-04-07 16:13:54 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-07 20:13
.
Pre-Run: 35,713,564,672 bytes free
Post-Run: 36*053*635*072 bytes free
.
- - End Of File - - 2FF15DC1CDC841E8322B72FF11AFE6D6