Hey broni i runned combofix and here's the log

ComboFix 11-09-08.01 - Hackingwite 09/09/2011 12:13:04.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.711 [GMT 5.5:30]
Running from: c:\documents and settings\Hackingwite.AKATSUKI-2F87D9\Desktop\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\admin\Application Data\updates
c:\documents and settings\admin\WINDOWS
c:\documents and settings\Ajay\Application Data\updates
c:\documents and settings\Hackingwite.AKATSUKI-2F87D9\Application Data\updates
c:\documents and settings\Hackingwite\Application Data\updates
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\desktop.ini
c:\program files\Internet Explorer\SET6DC.tmp
c:\program files\RegGenie
c:\program files\RegGenie\Backups\37987.0018952546
c:\program files\RegGenie\Backups\37987.0024786574
c:\program files\RegGenie\Backups\37987.0057213889
c:\program files\RegGenie\Backups\37987.0061727778
c:\program files\RegGenie\Backups\37987.0074312731
c:\program files\RegGenie\Backups\37987.0081004051
c:\program files\RegGenie\Backups\37987.0121504167
c:\program files\RegGenie\Backups\37987.0171590972
c:\program files\RegGenie\Backups\37987.0192928935
c:\program files\RegGenie\Backups\37987.0205501273
c:\program files\RegGenie\Backups\37987.0268565509
c:\program files\RegGenie\Backups\37987.0390096875
c:\program files\RegGenie\Backups\37987.0466596065
c:\program files\RegGenie\Backups\37987.0644871181
c:\program files\RegGenie\Backups\37987.096116169
c:\program files\RegGenie\Backups\37987.1176772222
c:\program files\RegGenie\Backups\37987.1759723958
c:\program files\RegGenie\Backups\39083.0113235995
c:\program files\RegGenie\IgnoredKeys.ini
c:\program files\RegGenie\IgnoredValues.ini
c:\program files\RegGenie\Logs\Scan on 1-1-2004 1-07-08 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 1-32-10 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-02-40 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-03-33 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-07-46 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-08-30 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-09-21 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-10-33 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-16-40 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-24-38 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-29-27 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-38-35 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 12-55-59 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 2-18-21 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 2-49-14 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2004 4-13-19 AM.txt
c:\program files\RegGenie\Logs\Scan on 1-1-2007 12-16-15 AM.txt
c:\program files\RegGenie\RegGenie.bim
c:\program files\RegGenie\RegGenie.bin
c:\program files\RegGenie\RegGenie.exe
c:\program files\RegGenie\RegGenie.ini
c:\program files\RegGenie\RegGenieOnReboot.exe
c:\program files\RegGenie\RegGenieOnRebootExpired.exe
c:\program files\RegGenie\RegGenieScheduler.exe
c:\program files\RegGenie\unins000.dat
c:\program files\RegGenie\unins000.exe
c:\program files\RegGenie\unins000.msg
c:\program files\Toolbar
c:\program files\Toolbar\3d_large_3.bmp
c:\program files\Toolbar\3d_largeHot_3.bmp
c:\program files\Toolbar\3d_small_3.bmp
c:\program files\Toolbar\3d_smallHot_3.bmp
c:\program files\Toolbar\3d_style_3.tbi
c:\windows\system32\drivers\78.exe
c:\windows\system32\drivers\937.exe
c:\windows\system32\mui\0816\lsaetsrv.dll
c:\windows\system32\qutbvfnvs0ktmky4n0q5.dll
c:\windows\TEMP\B8.tmp
.
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\userinit.exe
.
Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\explorer.exe
.
Infected copy of c:\windows\system32\cmd.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\cmd.exe
.
Infected copy of c:\windows\system32\expand.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\expand.exe
.
Infected copy of c:\windows\system32\findstr.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\findstr.exe
.
Infected copy of c:\windows\system32\freecell.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\freecell.exe
.
Infected copy of c:\windows\system32\magnify.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\magnify.exe
.
Infected copy of c:\windows\system32\mobsync.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\mobsync.exe
.
Infected copy of c:\windows\system32\mshearts.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\mshearts.exe
.
Infected copy of c:\windows\system32\narrator.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\narrator.exe
.
Infected copy of c:\windows\system32\net.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\net.exe
.
Infected copy of c:\windows\system32\net1.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\net1.exe
.
Infected copy of c:\windows\system32\netsh.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\netsh.exe
.
Infected copy of c:\windows\system32\notepad.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\notepad.exe
.
Infected copy of c:\windows\system32\osk.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\osk.exe
.
Infected copy of c:\windows\system32\route.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\route.exe
.
Infected copy of c:\windows\system32\rundll32.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\rundll32.exe
.
Infected copy of c:\windows\system32\sc.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\sc.exe
.
Infected copy of c:\windows\system32\sol.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\sol.exe
.
Infected copy of c:\windows\system32\sort.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\sort.exe
.
Infected copy of c:\windows\system32\spider.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\spider.exe
.
Infected copy of c:\windows\system32\taskmgr.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\taskmgr.exe
.
Infected copy of c:\windows\system32\utilman.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\utilman.exe
.
Infected copy of c:\windows\system32\winmine.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\winmine.exe
.
Infected copy of c:\windows\system32\wscntfy.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\wscntfy.exe
.
Infected copy of c:\windows\system32\wupdmgr.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\wupdmgr.exe
.
.
((((((((((((((((((((((((( Files Created from 2003-11-28 to 2003-12-31 )))))))))))))))))))))))))))))))
.
.
2011-09-09 01:29 . 2011-09-09 01:29 119808 --sh--w- C:\lsauplsa.dll
2011-09-09 01:08 . 2011-09-09 01:09 48984326 ----a-w- C:\35sp1.exe
2011-09-07 00:22 . 2011-09-07 00:22 -------- d-----w- C:\icytower1.5
2011-08-26 09:28 . 2011-09-06 00:21 -------- d-----w- C:\Evil
2011-07-12 07:01 . 2011-07-12 06:43 42887800 ----a-w- C:\Nokia_PC_Suite_eng_web.exe
2011-04-05 23:34 . 2011-09-04 18:43 -------- d-----w- C:\Ssd
2011-04-05 17:55 . 2011-04-05 17:55 -------- d-----w- C:\Virtuald DJ setup
2011-03-27 02:34 . 2004-01-01 00:07 -------- d-----w- C:\Video
2011-03-23 18:36 . 2003-12-31 18:32 -------- d-----w- C:\Intel
2011-03-23 18:25 . 2003-12-31 19:06 -------- d-----r- C:\MSOCache
2008-01-21 02:43 . 2008-01-21 02:43 -------- d-----w- C:\PerfLogs
2006-11-02 12:59 . 2006-11-02 12:59 -------- d-----we C:\Documents and Settings
2006-11-02 11:18 . 2003-12-31 19:09 -------- d-----w- C:\ProgramData
2006-11-02 11:18 . 2003-12-31 18:33 -------- d-----r- C:\Users
2004-01-01 09:34 . 2004-01-01 09:34 268435456 --sha-w- C:\WinPEpge.sys
2004-01-01 08:34 . 2003-12-31 19:41 -------- d-----w- C:\sankya
2004-01-01 08:16 . 2004-01-01 08:10 -------- d-----w- C:\OutputFolder
2004-01-01 08:12 . 2011-09-07 21:45 1350 ----a-w- C:\sdfeww.bat
2004-01-01 08:05 . 2011-09-05 22:02 1214800 ----a-w- C:\RegCure 1.5.0.0 Trial.exe
2004-01-01 08:05 . 2003-12-31 18:30 -------- d-----w- C:\CRACK
2004-01-01 08:05 . 2011-09-05 21:46 2262789 ----a-w- C:\RegCure.exe
2004-01-01 07:00 . 2004-01-01 07:00 -------- d-----w- C:\temp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2004-08-03 22:56 . 2011-09-09 06:13 150528 ----a-w- c:\windows\pchealth\UploadLB\Binaries\UploadM.exe
2004-08-03 22:56 . 2011-09-09 06:13 158208 ----a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe
2004-08-03 22:56 . 2011-09-09 06:13 18944 ----a-w- c:\windows\pchealth\helpctr\binaries\HscUpd.exe
2004-08-03 22:56 . 2011-09-09 06:13 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\HelpSvc.exe
2004-08-03 22:56 . 2011-09-09 06:13 768512 ----a-w- c:\windows\pchealth\helpctr\binaries\HelpCtr.exe
2004-08-03 22:56 . 2004-08-03 22:56 279040 ----a-w- c:\windows\help\tshoot.dll
2004-08-03 22:56 . 2011-09-09 06:13 725566 ----a-w- c:\windows\srchasst\srchui.dll
2004-08-03 22:56 . 2011-09-09 06:13 58434 ----a-w- c:\windows\srchasst\srchctls.dll
2004-08-03 22:56 . 2011-09-09 06:13 38912 ----a-w- c:\windows\pchealth\helpctr\binaries\pchsvc.dll
2004-08-03 22:56 . 2011-09-09 06:13 102400 ----a-w- c:\windows\pchealth\helpctr\binaries\pchshell.dll
2004-08-03 22:56 . 2004-08-03 22:56 34816 ----a-w- c:\windows\help\sniffpol.dll
2004-08-03 22:56 . 2004-08-03 22:56 33280 ----a-w- c:\windows\help\sstub.dll
2004-08-03 22:56 . 2011-09-09 06:13 3166208 ----a-w- c:\windows\srchasst\msgr3en.dll
2004-08-03 22:56 . 2011-09-09 06:13 376320 ----a-w- c:\windows\pchealth\helpctr\binaries\msinfo.dll
2004-08-03 22:56 . 2004-08-03 22:56 450048 ----a-w- c:\windows\apppatch\AcLayers.dll
2004-08-03 22:56 . 2004-08-03 22:56 244736 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2004-08-03 22:56 . 2004-08-03 22:56 1852416 ----a-w- c:\windows\apppatch\AcGenral.dll
2004-08-03 22:56 . 2004-08-03 22:56 137728 ----a-w- c:\windows\apppatch\AcLua.dll
2004-08-03 22:56 . 2004-08-03 22:56 116224 ----a-w- c:\windows\apppatch\AcXtrnal.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2004-08-03 . 79E3761C72A658986693D9342E0EDADD . 138752 . . [5.4.3790.2180] . . c:\windows\system32\wuauclt.exe
[7] 2004-08-03 . 4126D27CECE4471E00E425411F7306B5 . 111104 . . [5.4.3790.2180] . . c:\windows\system32\dllcache\wuauclt.exe
.
[-] 2004-08-03 . 25855A1846BEF40E8184556301164194 . 52224 . . [5.1.2600.2180] . . c:\windows\system32\userinit.exe
[7] 2004-08-03 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\userinit.exe
.
.
[-] 2004-08-03 . AFA0CCC142CC304C7F56A4031AF41C6F . 120832 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\iexplore.exe
.
.
c:\windows\System32\ksuser.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2011-09-09 1500160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"System Intrusive"="\found.001\loglogms.dll" [2011-09-09 120832]
"4"="c:\documents and settings\Hackingwite.AKATSUKI-2F87D9\4.exe" [2011-09-09 42240]
"Microsoft Firewall 2.9"="c:\windows\system32\config\systemprofile\Application Data\WMPRWISE.EXE" [2011-09-09 132608]
"KB1013444.exe"="c:\documents and settings\Hackingwite.AKATSUKI-2F87D9\Application Data\KB1013444.exe" [2011-09-09 53248]
.
c:\documents and settings\Ajay\Start Menu\Programs\Startup\
4gww6ii.exe [2004-1-1 0]
avlhcc6oo.exe [2004-1-1 0]
ccxoojaa.exe [2004-1-1 0]
fwwrii0u.exe [2004-1-1 0]
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"Shell"= explorer.exe,RunDll32 "c:\windows\system32\svclsa.dll",Init
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-System Intrusive - c:\windows\system32\mui\0816\lsaetsrv.dll
HKU-Default-Run-engel - c:\documents and settings\Hackingwite.AKATSUKI-2F87D9\Application Data\updates\updates.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2004-01-01 00:01
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wscntfy.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Completion time: 2004-01-01 00:05:26 - machine was rebooted
ComboFix-quarantined-files.txt 2003-12-31 18:35
.
Pre-Run: 18,682,916,864 bytes free
Post-Run: 18,574,848,000 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin
multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Microsoft Windows XP Professional" =optin /fastdetect
.
- - End Of File - - D53E5E2AE9EBE09045151F600A504737