It looks like combofix died a valiant death, it took some with it. But there is more, possibly a rootkit involved.
Please delete the copy of combofix.exe you have and down load a new one. Don’t run it yet.
Open Spybot and make sure teatimer is disabled. To do so do the following
Click mode
click Advanced mode
if you get a warning answer “yes”
click tools
click resident
uncheck resident “teatimer” and SDHelper if installed
click allow change
reboot
Open OTMOVEIT and kill these files
C:\WINDOWS\system32\hlvbfwoq
C:\WINDOWS\F?nts
C:\Program Files\winupdate
C:\WINDOWS\system32\drivers\ctl_w32.sys
I really need you to submit these files to www.virustotal.com and the results posted here. It will go along way in resolving this.
C:\Install
C:-2132482456
C:\WINDOWS\system32\xpdx.sys
C:\WINDOWS\4k98lr8i
C:\WINDOWS\ivtrm74h
C:\WINDOWS\system32\drivers\Fub04.sys
Download and run ERUNT http://www.larshederer.homepage.t-online.de/erunt/
(the download link is server1 or server2, or server3)
Start ERUNT, confirm the Welcome message.
Type in the name of a restore folder where the backed up registry
files should be saved, or click “…” to browse your computer’s drives
and select a folder. You can also simply leave the default, which is a
folder named ERDNT inside your Windows folder, the advantage being
that you have access to this folder from the Windows Recovery Console
in case Windows does not boot anymore.
Next, select the backup options:
Click “OK” and wait until the backup process is complete. (Note that
depending on your system configuration this may take some time, and
that the first bar is NOT a progress bar, just an indicator that the
program is still running.) The ERDNT program for later restoration of
the registry is automatically copied to the restore folder.
REGISTRY FIX
REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zima]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winupdate]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\p2pnetworking]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dszyvsla]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bunebkbk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9a7adf1a.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\80e4e6c7]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\09b4ff53.exe]
Next you will need to create the repair registry fix to do that copy and paste ALL of the above in the quote box to a notepad file. Ensure there is no space above the REGEDIT4.
Then in notepad click FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES
Then in the FILE NAME box type fix.reg
make sure the box at the top is set to save in Desktop
This will create a fix.reg file on your desktop
http://img127.imageshack.us/img127/433/regtg8.jpg
To use this file you will need to right click the icon and select merge, accept the warning if it appears and you are done.
Okay we’ll give combofix another go.
Close all browsers and windows and run combofix. Let it run undisturbed, your desktop may appear frozen that’s normal, watch for hardrive activityof any kind. Do not move the mouse, just let it run.
Let me know if you encounter any problems with the any of the above. Please do all the steps in order that they where posted.
In your next reply please include the OTMOVEIT results, the virustotal results, and the combofix log.