I ran combofix and below is the log report
ComboFix 10-02-01.05 - Bashiru Alabi 02/02/2010 15:45:46.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.482 [GMT -5:00]
Running from: c:\documents and settings\Bashiru Alabi\Desktop\ComboFix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\service
c:\windows\system32\service\02022010_TIS17_SfFniAU.log
c:\windows\system32\service\19122009_TIS17_SfFniAU.log
c:\windows\system32\service\31012010_TIS17_SfFniAU.log
.
((((((((((((((((((((((((( Files Created from 2010-01-02 to 2010-02-02 )))))))))))))))))))))))))))))))
.
2010-02-02 16:13 . 2010-02-02 16:13 -------- d-----w- c:\documents and settings\Kazeem Alabi\Application Data\Malwarebytes
2010-02-02 15:22 . 2010-02-02 15:22 -------- d-sh--w- c:\documents and settings\Kazeem Alabi\IECompatCache
2010-02-02 15:22 . 2010-02-02 16:11 -------- d-----w- c:\documents and settings\Kazeem Alabi\Application Data\RebateInformer
2010-02-02 15:21 . 2010-02-02 15:21 -------- d-----w- c:\documents and settings\Kazeem Alabi\Application Data\S300-S400 Series
2010-02-01 10:49 . 2010-02-01 10:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-01-31 23:23 . 2010-01-31 23:23 -------- d-----w- c:\documents and settings\Bashiru Alabi\Application Data\Malwarebytes
2010-01-31 23:23 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-31 23:23 . 2010-01-31 23:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-31 23:23 . 2010-01-31 23:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-31 23:23 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-29 13:14 . 2010-01-29 13:14 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-01-24 23:55 . 2010-01-24 23:55 -------- d-----w- c:\documents and settings\islamiah Alabi\Application Data\S300-S400 Series
2010-01-24 23:15 . 2010-01-24 23:31 -------- d-----w- c:\documents and settings\Bashiru Alabi\Application Data\S300-S400 Series
2010-01-24 23:12 . 2001-08-18 03:36 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-01-24 23:12 . 2001-08-18 03:36 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
2010-01-24 23:12 . 2008-04-13 19:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-01-24 23:12 . 2008-04-13 19:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-24 23:11 . 2010-01-24 23:11 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
2010-01-24 23:10 . 2009-04-17 10:52 49152 ----a-w- c:\windows\system32\LXEAPMON.DLL
2010-01-24 23:10 . 2009-04-17 10:52 32768 ----a-w- c:\windows\system32\LXEAFXPU.DLL
2010-01-24 23:10 . 2009-01-13 13:15 4485120 ----a-w- c:\windows\system32\LXEAoem.dll
2010-01-24 23:10 . 2008-03-05 03:12 98345 ----a-w- c:\windows\system32\IMHOST32.DLL
2010-01-24 23:10 . 2008-03-05 03:12 339968 ----a-w- c:\windows\system32\IMGMAN32.DLL
2010-01-24 23:09 . 2010-01-24 23:09 -------- d-----w- c:\documents and settings\All Users\Application Data\S300-S400 Series
2010-01-24 23:09 . 2010-01-24 23:09 -------- d-----w- c:\program files\Lexmark Tools for Office
2010-01-24 23:09 . 2009-04-24 19:47 213672 ----a-w- c:\windows\system32\LXEAwupd.exe
2010-01-24 23:09 . 2009-03-25 07:46 372736 ----a-w- c:\windows\system32\LXEAwupd.dll
2010-01-24 23:07 . 2010-01-24 23:07 -------- d-----w- c:\program files\Lexmark
2010-01-24 23:06 . 2010-01-31 23:21 -------- d-----w- c:\program files\Lexmark Toolbar
2010-01-24 23:02 . 2010-01-24 23:02 -------- d-----w- c:\program files\Lexmark Printable Web
2010-01-24 23:00 . 2010-01-24 23:30 -------- d-----w- c:\program files\Lexmark S300-S400 Series
2010-01-24 23:00 . 2009-02-20 13:48 23552 ----a-w- c:\windows\system32\lxeasmr.dll
2010-01-24 23:00 . 2009-02-20 13:48 299008 ----a-w- c:\windows\system32\lxeasm.dll
2010-01-23 11:09 . 2010-01-23 11:09 -------- d-----w- c:\documents and settings\islamiah Alabi\Local Settings\Application Data\Citrix
2010-01-23 11:08 . 2010-01-23 11:08 -------- d-sh--w- c:\documents and settings\islamiah Alabi\IECompatCache
2010-01-14 11:01 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-02 20:04 . 2004-08-04 05:00 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-02-02 18:30 . 2009-11-29 20:44 -------- d-----w- c:\program files\Trend Micro
2010-02-02 18:14 . 2009-05-26 04:56 -------- d-----w- c:\program files\Google
2010-02-02 18:09 . 2009-08-04 03:30 -------- d-----w- c:\program files\iWin.com
2010-02-01 12:03 . 2009-05-07 04:27 51808 ----a-w- c:\documents and settings\Bashiru Alabi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-01 01:37 . 2009-09-27 21:00 -------- d-----w- c:\program files\AVG
2010-01-29 04:59 . 2009-05-26 05:32 -------- d-----w- c:\program files\Yahoo!
2010-01-29 04:48 . 2009-09-27 21:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-01-29 04:48 . 2009-12-27 23:00 -------- d-----w- c:\program files\Norton Security Scan
2010-01-29 04:48 . 2009-10-30 22:02 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-24 23:14 . 2009-08-11 02:15 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-08 14:45 . 2009-08-14 12:02 -------- d-----w- c:\program files\Yahoo! Games
2010-01-08 14:40 . 2009-08-01 02:37 -------- d-----w- c:\program files\RealArcade
2010-01-08 02:08 . 2010-01-24 23:01 324264 ----a-w- c:\windows\system32\lxeaih.exe
2010-01-08 02:08 . 2010-01-24 23:01 598696 ----a-w- c:\windows\system32\lxeacoms.exe
2010-01-08 02:08 . 2010-01-24 23:01 373416 ----a-w- c:\windows\system32\lxeacfg.exe
2009-12-27 23:00 . 2009-09-27 21:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-21 19:14 . 2006-03-03 22:33 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-16 21:12 . 2009-12-16 21:12 438272 ----a-w- c:\windows\system32\lxeacoin.dll
2009-12-10 08:04 . 2009-05-07 04:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-10 00:47 . 2010-01-24 23:01 643072 ----a-w- c:\windows\system32\lxeapmui.dll
2009-12-10 00:43 . 2010-01-24 23:01 1048576 ----a-w- c:\windows\system32\lxeaserv.dll
2009-12-10 00:41 . 2010-01-24 23:01 688128 ----a-w- c:\windows\system32\lxeahbn3.dll
2009-12-10 00:40 . 2010-01-24 23:01 847872 ----a-w- c:\windows\system32\lxeausb1.dll
2009-12-10 00:37 . 2010-01-24 23:01 356352 ----a-w- c:\windows\system32\lxeahcp.dll
2009-12-10 00:36 . 2010-01-24 23:01 577536 ----a-w- c:\windows\system32\lxealmpm.dll
2009-12-10 00:35 . 2010-01-24 23:01 344064 ----a-w- c:\windows\system32\lxeaiesc.dll
2009-12-10 00:35 . 2010-01-24 23:01 802816 ----a-w- c:\windows\system32\lxeacomc.dll
2009-12-10 00:35 . 2010-01-24 23:01 364544 ----a-w- c:\windows\system32\lxeainpa.dll
2009-12-08 16:13 . 2009-12-08 15:56 -------- d-----w- c:\documents and settings\islamiah Alabi\Application Data\Inbox Toolbar
2009-12-08 15:56 . 2009-12-08 15:56 -------- d-----w- c:\documents and settings\islamiah Alabi\Application Data\RebateInformer
2009-11-29 20:42 . 2009-11-29 20:42 1223832 ----a-w- c:\windows\system32\drivers\vsapint.sys
2009-11-29 20:42 . 2009-11-29 20:45 50704 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2009-11-29 20:42 . 2009-11-29 20:45 158224 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-11-29 20:42 . 2009-11-29 20:42 89872 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2009-11-29 20:42 . 2009-11-29 20:42 36368 ----a-w- c:\windows\system32\drivers\tmpreflt.sys
2009-11-29 20:42 . 2009-11-29 20:42 339984 ----a-w- c:\windows\system32\drivers\TM_CFW.sys
2009-11-29 20:42 . 2009-11-29 20:42 225808 ----a-w- c:\windows\system32\drivers\tmxpflt.sys
2009-11-29 20:42 . 2009-11-29 20:45 59920 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2009-11-26 13:52 . 2010-01-24 23:01 86186 ----a-w- c:\windows\system32\lxeacfg.dll
2009-11-26 05:58 . 2009-11-26 05:58 1245321 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_DinerDash\IAF.dll
2009-11-21 15:51 . 2004-08-04 05:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-09 13:06 . 2010-01-24 23:01 106496 ----a-w- c:\windows\system32\lxeainsr.dll
2009-11-09 13:06 . 2010-01-24 23:01 36864 ----a-w- c:\windows\system32\lxeacur.dll
2009-11-09 13:06 . 2010-01-24 23:01 57344 ----a-w- c:\windows\system32\lxeajswr.dll
2009-11-09 13:06 . 2010-01-24 23:01 262144 ----a-w- c:\windows\system32\lxeainsb.dll
2009-11-09 13:06 . 2010-01-24 23:01 90112 ----a-w- c:\windows\system32\lxeacub.dll
2009-11-09 13:06 . 2010-01-24 23:01 208896 ----a-w- c:\windows\system32\lxeagrd.dll
2009-11-09 13:06 . 2010-01-24 23:01 253952 ----a-w- c:\windows\system32\lxeacu.dll
2009-11-09 13:05 . 2010-01-24 23:01 323584 ----a-w- c:\windows\system32\lxeains.dll
2009-11-09 12:59 . 2009-11-09 12:59 86016 ----a-w- c:\windows\system32\lxeagcfg.dll
2009-11-08 19:48 . 2009-05-13 00:50 52200 ----a-w- c:\documents and settings\islamiah Alabi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-08-20 1368064]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2008-08-20 1191936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-11-29 1020248]
"lxeamon.exe"="c:\program files\Lexmark S300-S400 Series\lxeamon.exe" [2009-04-29 766632]
"EzPrint"="c:\program files\Lexmark S300-S400 Series\ezprint.exe" [2009-04-29 139944]
"Lexmark S300-S400 Series Fax Server"="c:\program files\Lexmark S300-S400 Series\fm3032.exe" [2009-04-29 316072]
c:\documents and settings\Kazeem Alabi\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\documents and settings\Bashiru Alabi\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-05-15 03:39 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-03-31 00:00 162584 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2007-03-31 00:00 138008 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
2008-08-20 20:09 1191936 ----a-w- c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2008-02-26 14:57 128296 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-03-30 23:59 138008 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2007-05-10 14:22 405504 ----a-w- c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-03 23:20 866584 ----a-w- c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R2 lxea_device;lxea_device;c:\windows\system32\lxeacoms.exe -service --> c:\windows\system32\lxeacoms.exe -service [?]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [11/29/2009 3:42 PM 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [11/29/2009 3:42 PM 339984]
R3 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [11/29/2009 3:45 PM 50704]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [11/29/2009 3:46 PM 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [11/29/2009 3:46 PM 689416]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - KLMDB
*Deregistered* - klmd21
*Deregistered* - klmdb
.
Contents of the 'Scheduled Tasks' folder
2010-02-02 c:\windows\Tasks\User_Feed_Synchronization-{DDF01372-B27E-4748-80DA-A4EC0E2C9519}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
------- Supplementary Scan -------
.
mSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-02 15:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1280)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
c:\windows\system32\igfxdev.dll
.
Completion time: 2010-02-02 15:50:42
ComboFix-quarantined-files.txt 2010-02-02 20:50
Pre-Run: 65,673,531,392 bytes free
Post-Run: 65,710,505,984 bytes free
- - End Of File - - 58131B365519BA1291E96206B4D9022B