I have run the ATF Cleaner with no issues.
I have just run Combo Fix and the log file is below. I will await further instructions before proceeding. The next step would be the Hijack fix of winsys2.exe under safe mode. Please note that I do have an NVideo video adapter. Please advise how you would like me to proceed. Thanks!
ComboFix 10-03-01.04 - Administrator 03/02/2010 10:59:19.1.8 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3318.2963 [GMT -5:00]
Running from: c:\documents and settings\Administrator.HERITAGE\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100302-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-583907252-1659004503-1177238915-500
c:\windows\system32\MSIMRT.DLL
c:\windows\system32\MSIMRT32.DLL
c:\windows\system32\MSIMUSIC.DLL
.
((((((((((((((((((((((((( Files Created from 2010-02-02 to 2010-03-02 )))))))))))))))))))))))))))))))
.
2010-03-02 14:00 . 2010-03-02 14:00 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2010-02-26 23:06 . 2010-02-26 23:06 -------- d-----w- c:\program files\Trend Micro
2010-02-25 23:43 . 2010-02-25 22:55 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-02-25 22:54 . 2010-02-25 22:54 17480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-02-25 22:54 . 2010-02-25 22:54 961984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-02-25 22:54 . 2010-02-25 22:54 835312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-02-25 22:54 . 2010-02-25 22:54 842992 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-25 22:54 . 2010-02-25 22:54 1593320 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-02-25 22:54 . 2010-02-25 22:54 815184 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-02-25 22:54 . 2010-02-25 22:54 1229232 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-25 22:53 . 2010-02-25 22:53 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-25 22:53 . 2010-02-04 15:53 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-25 22:53 . 2010-02-25 22:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-02-25 22:53 . 2010-02-25 22:53 -------- d-----w- c:\program files\Lavasoft
2010-02-23 22:03 . 2010-02-23 22:03 -------- d-----w- c:\documents and settings\Administrator.HERITAGE\Application Data\Malwarebytes
2010-02-23 22:03 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 22:03 . 2010-02-23 22:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-23 22:03 . 2010-02-23 22:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 22:03 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 20:28 . 2010-02-23 20:43 -------- d-----w- C:\Feb2010
2010-02-22 22:45 . 2010-03-02 14:34 -------- d-----w- c:\documents and settings\Administrator.HERITAGE\Application Data\Spyware Terminator
2010-02-22 22:45 . 2010-02-26 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-02-22 22:45 . 2010-02-22 22:45 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-02-22 22:45 . 2010-02-22 22:45 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-02-22 22:45 . 2010-02-22 22:45 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-02-22 22:44 . 2010-03-02 14:34 -------- d-----w- c:\program files\Spyware Terminator
2010-02-22 21:00 . 2010-02-22 21:00 -------- d-----w- c:\windows\system32\wbem\Repository
2010-02-22 20:27 . 2010-02-22 20:27 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-15 22:09 . 2010-02-15 22:09 -------- d-----w- c:\program files\Citrix
2010-02-15 22:09 . 2010-02-15 22:09 60744 ----a-w- c:\documents and settings\Administrator.HERITAGE\g2mdlhlpx.exe
2010-02-12 14:51 . 2007-06-19 17:57 229888 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\HP1006S.DLL
2010-02-10 22:44 . 2010-02-10 22:44 -------- d-----w- c:\program files\Microsoft.NET
2010-02-10 22:43 . 2010-02-10 22:43 -------- d-----w- c:\program files\MSXML 6.0
2010-02-10 22:43 . 2010-02-10 22:45 -------- d-----w- c:\program files\Microsoft SQL Server
2010-02-10 22:41 . 2010-02-10 22:45 -------- d-----w- C:\Response
2010-02-10 22:25 . 2009-03-31 17:24 745472 ----a-w- c:\windows\system32\TAPIExCt.dll
2010-02-10 22:25 . 2006-01-07 14:56 143360 ----a-w- c:\windows\system32\SpectrumView.dll
2010-02-10 22:25 . 2010-02-10 22:25 -------- d-----w- c:\program files\Common Files\software fx shared
2010-02-10 22:24 . 2010-02-10 22:24 -------- d-----w- c:\program files\CoLinear
2010-02-10 22:22 . 2010-02-10 22:22 -------- d-----w- C:\response10_demo
2010-02-10 22:22 . 2010-02-10 22:05 107513175 ----a-w- C:\response10_demo.zip
2010-02-01 15:56 . 2006-12-14 15:00 110592 ----a-w- c:\documents and settings\Administrator.HERITAGE\Application Data\U3\temp\cleanup.exe
2010-02-01 15:56 . 2010-02-01 15:56 -------- d-----w- C:\LightPics
2010-02-01 15:55 . 2007-02-12 22:46 3096576 ---ha-w- c:\documents and settings\Administrator.HERITAGE\Application Data\U3\temp\Launchpad Removal.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-19 20:22 . 2009-12-07 19:03 161 ----a-w- c:\windows\daa.bat
2010-02-10 22:24 . 2009-10-22 15:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-10 22:23 . 2009-12-01 20:07 20736 ----a-w- c:\documents and settings\Administrator.HERITAGE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-04 15:53 . 2010-02-25 22:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-02-01 15:56 . 2009-12-24 20:48 -------- d-----w- c:\documents and settings\Administrator.HERITAGE\Application Data\U3
2010-01-05 10:00 . 2008-04-14 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2008-04-14 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2008-04-14 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-12-07 20:29 . 2009-12-07 19:09 165 ----a-w- c:\windows\mmm.bat
2009-12-02 20:56 . 2009-10-21 21:05 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
1998-12-09 02:53 . 1998-12-09 02:53 99840 ----a-w- c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 . 1998-12-09 02:53 70144 ----a-w- c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 . 1998-12-09 02:53 48640 ----a-w- c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 . 1998-12-09 02:53 31744 ----a-w- c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 . 1998-12-09 02:53 186368 ----a-w- c:\program files\Common Files\IRAREG.DLL
1998-12-09 02:53 . 1998-12-09 02:53 17920 ----a-w- c:\program files\Common Files\IRASRIAL.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"WinSys2"="c:\windows\system32\winsys2.exe" [2008-01-18 208896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-19 149280]
"nwiz"="nwiz.exe" [2009-03-28 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 17:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater6]
2009-01-08 12:36 2521464 ----a-w- c:\program files\Common Files\Adobe\Updater6\Adobe_Updater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-04-27 17:08 17881088 ----a-w- c:\windows\RTHDCPL.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/25/2010 5:55 PM 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11/19/2009 11:03 AM 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2/22/2010 5:45 PM 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/19/2009 11:03 AM 20560]
R2 MSSQL$RESPONSE;SQL Server (RESPONSE);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2/10/2007 8:29 AM 29178224]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [10/22/2009 10:49 AM 159400]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [10/22/2009 10:47 AM 1684736]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 10:52 AM 1229232]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-03-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 22:54]
.
.
------- Supplementary Scan -------
.
TCP: {4827466B-3510-4DE9-93E6-A47FF92C1C54} = 192.168.0.150,192.168.0.100
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2010-03-02 11:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys >>UNKNOWN [0x8A68F8C8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba10cf28
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\atapi -> atapi.sys @ 0xb9f14b3a
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Intel(R) 82578DC Gigabit Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xb9e1dbb0
PacketIndicateHandler -> NDIS.sys @ 0xb9e2aa21
SendHandler -> NDIS.sys @ 0xb9e0887b
user & kernel MBR OK
**************************************************************************
.
Completion time: 2010-03-02 11:02:39
ComboFix-quarantined-files.txt 2010-03-02 16:02
Pre-Run: 383,995,555,840 bytes free
Post-Run: 383,960,973,312 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 772DA2979139C3308038DDDF8F3078B0