Done that. It has removed the Antivirus XP 2008 program. Here are the logs:
ComboFix 08-08-14.05 - Iain 2008-08-15 19:15:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1547 [GMT 1:00]
Running from: C:\Documents and Settings\Iain\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
C:\Documents and Settings\Iain\Application Data\rhca9fj0e19v
C:\Documents and Settings\Kirsty\Cookies\
[email protected][1].txt
C:\Documents and Settings\Kirsty\Cookies\
[email protected][1].txt
C:\Documents and Settings\Kirsty\Cookies\
[email protected][3].txt
C:\Documents and Settings\Kirsty\Cookies\kirsty@chtah[2].txt
C:\Documents and Settings\Kirsty\Cookies\
[email protected][2].txt
C:\Documents and Settings\Kirsty\Cookies\kirsty@fastclick[1].txt
C:\Documents and Settings\Kirsty\Cookies\
[email protected][1].txt
C:\Documents and Settings\Kirsty\Cookies\kirsty@revsci[2].txt
C:\Documents and Settings\Kirsty\Cookies\kirsty@serving-sys[2].txt
C:\Documents and Settings\Kirsty\Cookies\kirsty@tsw0[3].txt
C:\Documents and Settings\Kirsty\Cookies\
[email protected][2].txt
C:\Documents and Settings\Kirsty\Cookies\
[email protected][1].txt
C:\Documents and Settings\Kirsty\Cookies\
[email protected][1].txt
C:\Documents and Settings\Kirsty\Cookies\
[email protected][1].txt
C:\Documents and Settings\Kirsty\Cookies\
[email protected][2].txt
C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\#SharedObjects\XMT9YWLM\interclick.com
C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\#SharedObjects\XMT9YWLM\interclick.com\ud.sol
C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Susanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Susanne\Cookies\
[email protected][1].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][3].txt
C:\Documents and Settings\Susanne\Cookies\susanne@ebay[3].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][2].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][2].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][1].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][1].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][2].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][1].txt
C:\Documents and Settings\Susanne\Cookies\susanne@tsw0[2].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][2].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][3].txt
C:\Documents and Settings\Susanne\Cookies\susanne@web-stat[2].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][3].txt
C:\Documents and Settings\Susanne\Cookies\
[email protected][1].txt
C:\Program Files\rhca9fj0e19v
C:\WINDOWS\system32\blphce9fj0e19v.scr
C:\WINDOWS\system32\ffsfmpnc.ini
C:\WINDOWS\system32\lphce9fj0e19v.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\phce9fj0e19v.bmp
C:\WINDOWS\system32\pphce9fj0e19v.exe
C:\WINDOWS\system32\PYIllUvw.ini
C:\WINDOWS\system32\PYIllUvw.ini2
C:\WINDOWS\system32\wimllcoh.ini
.
((((((((((((((((((((((((( Files Created from 2008-07-15 to 2008-08-15 )))))))))))))))))))))))))))))))
.
2008-07-21 01:29 . 2008-07-22 01:05 <DIR> d-------- C:\Program Files\PokerTracker 3
2008-07-18 15:15 . 2008-07-18 15:16 <DIR> d-------- C:\nav_update
2008-07-18 15:01 . 2008-07-18 15:01 <DIR> d-------- C:\Program Files\AvantGo Connect
2008-07-18 15:01 . 2008-07-18 15:01 2,464 --a------ C:\WINDOWS\$_hpcst$.hpc
2008-07-18 14:59 . 2008-07-18 14:59 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-07-18 13:02 . 2004-12-06 14:07 104,064 --a------ C:\WINDOWS\system32\drivers\wceusbsh.sys
2008-07-18 13:02 . 2004-12-06 14:07 104,064 --a--c--- C:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-07-18 12:21 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-07-18 12:21 . 2004-08-03 22:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-15 01:03 --------- d-----w C:\Program Files\McAfee
2008-08-10 21:40 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-10 21:39 --------- d-----w C:\Program Files\Full Tilt Poker
2008-08-10 21:30 --------- d-----w C:\Program Files\PokerStars
2008-08-07 18:57 --------- d-----w C:\Program Files\UltimateBet1
2008-08-05 23:17 --------- d-----w C:\Documents and Settings\Iain\Application Data\LimeWire
2008-07-19 17:31 --------- d-----w C:\Program Files\Java
2008-07-18 16:44 --------- d-----w C:\Program Files\Poker Tracker V2
2008-07-18 14:01 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-07-14 03:31 --------- d-----w C:\Documents and Settings\Iain\Application Data\Microgaming
2008-07-09 21:11 --------- d-----w C:\Program Files\Absolute Poker
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-05 18:58 --------- d-----w C:\Program Files\TryMedia
2008-07-05 15:51 --------- d-----w C:\Documents and Settings\Iain\Application Data\SpinTop
2008-07-03 18:26 --------- d-----w C:\Program Files\_uninstallation_info
2008-07-03 18:10 --------- d-----w C:\Program Files\Bodog Poker
2008-07-03 18:04 --------- d-----w C:\Program Files\MGS FF Helper
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-22 19:06 --------- d-----w C:\Program Files\MSN Messenger
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 14:56 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-04 11:50 405583]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 05:42 1164576]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"lxdimon.exe"="C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 17:54 434864]
"lxdiamon"="C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 17:54 25264]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 15:42 1404928]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 22:05 344064]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-07 19:37 185632]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-12 14:56 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
"C:\\WINDOWS\\system32\\lxdicfg.exe"=
"C:\\WINDOWS\\system32\\lxdicoms.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdiwbgw.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R2 lxdi_device;lxdi_device;C:\WINDOWS\system32\lxdicoms.exe [2007-06-11 15:14]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe [2007-06-11 15:14]
R2 pgsql-8.2;PostgreSQL Database Server 8.2;C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe runservice -w -N pgsql-8.2 -D C:\Program Files\PostgreSQL\8.2\data\ []
S0 TfFsMon;TfFsMon;C:\WINDOWS\system32\drivers\TfFsMon.sys []
S0 TfSysMon;TfSysMon;C:\WINDOWS\system32\drivers\TfSysMon.sys []
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
S3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-05-30 01:06]
S3 TfNetMon;TfNetMon;C:\WINDOWS\system32\drivers\TfNetMon.sys []
.
Contents of the 'Scheduled Tasks' folder
2008-06-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-RRT-Auto - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for RRT.zip\RRT.exe
HKLM-Run-lphce9fj0e19v - C:\WINDOWS\system32\lphce9fj0e19v.exe
HKLM-Run-SMrhca9fj0e19v - C:\Program Files\rhca9fj0e19v\rhca9fj0e19v.exe
SSODL-KernelCD-{ed9f547e-7725-46f4-a938-95c4abb21edf} - C:\WINDOWS\Resources\KernelCD.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Iain\Application Data\Mozilla\Firefox\Profiles\s6en2zv2.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.yahoo.co.uk**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-15 19:19:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdiserv.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\PostgreSQL\8.2\bin\pg_ctl.exe
C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
C:\Program Files\PostgreSQL\8.2\bin\postgres.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-08-15 19:21:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-15 18:21:31
Pre-Run: 225,899,708,416 bytes free
Post-Run: 226,272,829,440 bytes free
213 --- E O F --- 2008-08-13 17:11:02