ok here it is
ComboFix 09-09-23.02 - James 09/24/2009 11:06.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2586 [GMT -4:00]
Running from: c:\documents and settings\James\Desktop\Combo-Fix.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((( Files Created from 2009-08-24 to 2009-09-24 )))))))))))))))))))))))))))))))
.
2009-09-24 13:45 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-24 13:45 . 2009-09-24 13:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-24 13:45 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-24 13:33 . 2009-09-24 13:33 -------- d-sh--w- c:\documents and settings\Administrator.JAMES-PC.000\IETldCache
2009-09-24 12:49 . 2009-09-24 12:49 -------- d-----w- c:\documents and settings\James\Application Data\Malwarebytes
2009-09-24 12:39 . 2009-09-24 12:39 -------- d-----w- c:\program files\ERUNT
2009-09-24 12:17 . 2009-09-24 14:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-24 12:17 . 2009-09-24 14:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-24 07:31 . 2009-09-24 07:31 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-24 07:30 . 2009-09-24 07:30 -------- d-----w- c:\documents and settings\Administrator.JAMES-PC\IETldCache
2009-09-24 07:30 . 2009-09-24 07:30 -------- d-s---w- c:\documents and settings\Administrator.JAMES-PC
2009-09-24 07:30 . 2009-09-24 07:30 -------- d-----w- c:\documents and settings\Administrator.JAMES-PC\Local Settings\Application Data\Microsoft
2009-09-23 12:32 . 2009-09-23 12:32 -------- d-----w- c:\documents and settings\James\Application Data\SUPERAntiSpyware.com
2009-09-23 11:27 . 2009-09-23 11:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-22 02:36 . 2009-09-22 02:36 -------- d-----w- c:\windows\Sun
2009-09-22 02:36 . 2009-09-22 02:35 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-22 02:35 . 2009-09-22 02:35 -------- d-----w- c:\program files\Java
2009-09-22 01:48 . 2009-09-22 01:48 -------- d-----w- c:\program files\7-Zip
2009-09-21 19:59 . 2009-09-21 19:59 -------- d-----w- c:\program files\Easy GIF Animator
2009-09-21 08:15 . 2001-08-17 19:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2009-09-21 08:15 . 2001-08-17 19:36 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2009-09-21 08:15 . 2001-08-17 19:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2009-09-21 08:15 . 2001-08-17 19:36 8192 ----a-w- c:\windows\system32\kbdkor.dll
2009-09-21 08:15 . 2001-08-17 11:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2009-09-21 08:15 . 2001-08-17 11:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2009-09-21 08:15 . 2001-08-17 11:55 6144 ----a-w- c:\windows\system32\kbd101c.dll
2009-09-21 08:15 . 2001-08-17 11:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
2009-09-21 08:15 . 2001-08-17 11:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2009-09-21 08:15 . 2001-08-17 11:55 5632 ----a-w- c:\windows\system32\kbd103.dll
2009-09-21 08:15 . 2008-04-14 09:39 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2009-09-21 08:15 . 2008-04-14 09:39 6144 ----a-w- c:\windows\system32\kbd106.dll
2009-09-14 13:36 . 2009-09-24 08:05 -------- d-----w- c:\documents and settings\James\Application Data\vlc
2009-09-14 13:34 . 2009-09-14 13:34 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Graboid_Inc
2009-09-14 13:34 . 2009-09-14 13:34 -------- d-----w- c:\documents and settings\James\Application Data\MozillaControl
2009-09-14 13:34 . 2009-09-14 13:37 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Graboid
2009-09-14 13:34 . 2009-09-14 13:34 -------- d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
2009-09-14 13:33 . 2009-09-14 13:33 -------- d-----w- c:\program files\VideoLAN
2009-09-14 13:31 . 2009-09-14 13:42 -------- d-----w- c:\program files\Graboid
2009-09-12 22:24 . 2009-09-12 22:24 -------- d-----w- c:\documents and settings\James\Application Data\NeroDigital™
2009-09-12 21:22 . 2009-09-12 21:22 -------- d-----w- c:\documents and settings\All Users\Application Data\SlySoft
2009-09-12 21:18 . 2009-09-12 21:18 -------- d-----w- c:\program files\SlySoft
2009-09-11 17:08 . 2009-09-11 17:08 24744 ----a-w- c:\windows\system32\drivers\ElbyCDIO.sys
2009-09-10 21:52 . 2009-09-10 21:52 104512 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-09-09 07:36 . 2009-09-09 07:36 0 ----a-w- c:\windows\nsreg.dat
2009-09-09 07:36 . 2009-09-09 07:36 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Mozilla
2009-09-07 20:52 . 2009-09-07 20:52 -------- d-----w- c:\program files\PFPortChecker
2009-09-07 19:00 . 2009-09-07 19:00 -------- d-----w- c:\program files\Port Forwarding Wizard
2009-09-06 17:09 . 2004-02-19 06:03 65536 ----a-w- c:\windows\system32\E_S00RP1.EXE
2009-09-06 16:05 . 2009-09-06 16:05 -------- d-----w- c:\program files\EPSON
2009-09-06 16:05 . 2003-05-21 06:27 64000 ----a-w- c:\windows\system32\E_FBCBAJA.DLL
2009-09-06 16:05 . 2004-11-25 09:07 79679 ----a-w- c:\windows\system32\E_FLMAJA.DLL
2009-09-06 16:05 . 2004-06-24 05:20 309760 ----a-w- c:\windows\system32\EAL32.DLL
2009-09-06 16:05 . 2004-03-12 05:30 82944 ----a-w- c:\windows\system32\EAL.EXE
2009-09-06 16:05 . 2000-06-07 05:01 34304 ----a-w- c:\windows\system32\E_FBCHAJA.DLL
2009-09-06 15:59 . 2009-09-06 15:59 -------- d-----w- c:\program files\ABBYY FineReader 5.0 Sprint
2009-09-06 15:59 . 2009-09-06 15:59 -------- d-----w- c:\program files\ABBYY FineReader 6.0
2009-09-06 15:58 . 2009-09-06 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-09-06 15:56 . 2008-04-14 04:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-09-06 15:56 . 2008-04-14 04:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-09-06 15:49 . 1997-04-09 00:08 299520 ----a-w- c:\windows\uninst.exe
2009-09-06 15:49 . 2009-09-06 15:49 -------- d-----w- c:\documents and settings\James\WINDOWS
2009-09-06 11:36 . 2009-09-06 11:36 -------- d-----w- c:\program files\ToGo Game
2009-09-04 08:24 . 2009-09-09 08:17 133912 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-03 20:39 . 2009-09-03 20:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-09-03 20:39 . 2009-09-21 09:31 -------- d-----w- c:\documents and settings\James\Application Data\Azureus
2009-09-03 20:38 . 2009-09-03 20:39 -------- d-----w- c:\program files\Vuze
2009-09-03 20:38 . 2009-09-03 20:38 -------- d-----w- c:\program files\Common Files\i4j_jres
2009-09-03 19:43 . 2009-09-03 19:44 -------- d-----w- c:\program files\Microsoft Digital Image 10
2009-09-03 01:56 . 2009-09-03 01:56 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-03 01:51 . 2009-09-03 01:51 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-09-03 01:47 . 2009-09-13 07:59 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Adobe
2009-09-03 01:47 . 2009-09-09 07:41 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-03 01:47 . 2009-09-03 01:47 -------- d-----w- c:\program files\NOS
2009-09-03 00:48 . 2009-09-23 17:40 -------- d-----w- c:\program files\PokerStars
2009-09-01 12:56 . 2009-09-01 12:56 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\WBFSManager
2009-09-01 12:48 . 2009-09-01 12:48 -------- d-----w- c:\program files\WBFS
2009-09-01 12:34 . 2009-09-22 08:39 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\MediaMonkey
2009-09-01 12:34 . 2009-09-01 12:34 -------- d-----w- c:\program files\MediaMonkey
2009-09-01 11:50 . 2009-09-01 11:50 -------- d-----w- C:\2105307cc9367b04d7be
2009-09-01 11:49 . 2009-09-01 11:49 -------- d-----w- c:\windows\system32\XPSViewer
2009-09-01 11:49 . 2009-09-01 11:49 -------- d-----w- c:\program files\MSBuild
2009-09-01 11:49 . 2009-09-01 11:49 -------- d-----w- c:\program files\Reference Assemblies
2009-09-01 11:48 . 2009-09-01 11:48 -------- d-----w- C:\91291f2f56351da1b0e2
2009-09-01 11:48 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-09-01 11:48 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-09-01 11:48 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-09-01 11:48 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-09-01 11:48 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-09-01 11:48 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-09-01 11:48 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-09-01 11:43 . 2009-08-18 17:48 348160 ----a-w- c:\windows\vncutil.exe
2009-09-01 11:43 . 2009-07-21 20:40 41472 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2009-09-01 11:43 . 2009-03-17 18:07 122880 ----a-w- c:\windows\RtkAudioService.exe
2009-09-01 11:20 . 2007-04-03 03:56 19456 -c--a-w- c:\windows\system32\dllcache\agt0411.dll
2009-09-01 11:20 . 2007-04-03 03:56 19456 -c--a-w- c:\windows\system32\dllcache\agt0404.dll
2009-09-01 11:20 . 2008-04-14 09:39 6144 -c--a-w- c:\windows\system32\dllcache\kbd106n.dll
2009-09-01 11:20 . 2008-04-14 09:39 6144 ----a-w- c:\windows\system32\kbd106n.dll
2009-09-01 11:20 . 2008-04-14 09:39 6144 -c--a-w- c:\windows\system32\dllcache\kbd101.dll
2009-09-01 11:20 . 2008-04-14 09:39 6144 ----a-w- c:\windows\system32\kbd101.dll
2009-09-01 11:20 . 2007-04-03 03:56 19456 -c--a-w- c:\windows\system32\dllcache\agt0804.dll
2009-09-01 11:20 . 2008-04-14 09:39 7168 -c--a-w- c:\windows\system32\dllcache\f3ahvoas.dll
2009-09-01 11:20 . 2008-04-14 09:39 7168 ----a-w- c:\windows\system32\f3ahvoas.dll
2009-09-01 11:20 . 2008-04-14 09:39 6144 -c--a-w- c:\windows\system32\dllcache\kbdlk41j.dll
2009-09-01 11:20 . 2008-04-14 09:39 6144 ----a-w- c:\windows\system32\kbdlk41j.dll
2009-09-01 11:19 . 2007-04-03 03:56 19456 -c--a-w- c:\windows\system32\dllcache\agt0412.dll
2009-09-01 11:19 . 2008-04-14 09:39 7168 -c--a-w- c:\windows\system32\dllcache\kbdibm02.dll
2009-09-01 11:19 . 2008-04-14 09:39 7168 ----a-w- c:\windows\system32\kbdibm02.dll
2009-09-01 11:19 . 2008-04-14 09:39 6656 -c--a-w- c:\windows\system32\dllcache\kbdlk41a.dll
2009-09-01 11:19 . 2008-04-14 09:39 6656 ----a-w- c:\windows\system32\kbdlk41a.dll
2009-09-01 11:19 . 2008-04-14 09:41 218112 -c--a-w- c:\windows\system32\dllcache\c_g18030.dll
2009-09-01 11:19 . 2008-04-14 09:41 218112 ----a-w- c:\windows\system32\c_g18030.dll
2009-09-01 11:19 . 2008-04-14 09:39 6144 -c--a-w- c:\windows\system32\dllcache\kbdax2.dll
2009-09-01 11:19 . 2008-04-14 09:39 6144 ----a-w- c:\windows\system32\kbdax2.dll
2009-09-01 10:56 . 2009-09-01 10:56 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2009-09-01 10:56 . 2009-09-01 11:07 -------- d-----w- c:\program files\RegCure
2009-09-01 10:11 . 2009-09-01 10:11 -------- d-----w- c:\documents and settings\James\Application Data\OtakuSoftware
2009-09-01 10:03 . 2009-09-01 10:03 -------- d-----w- c:\program files\ENT
2009-09-01 09:28 . 2009-09-01 09:34 -------- d-----w- C:\D
2009-09-01 07:00 . 2009-09-01 07:00 -------- d-----w- c:\program files\MSXML 4.0
2009-09-01 00:15 . 2009-09-24 11:37 -------- d-----w- c:\documents and settings\James\Application Data\UseNeXT
2009-09-01 00:15 . 2009-09-01 00:15 -------- d-----w- c:\program files\UseNeXT
2009-08-31 23:50 . 2009-08-31 23:50 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-08-31 22:16 . 2009-09-03 08:10 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Ahead
2009-08-31 22:16 . 2009-08-31 22:16 -------- d-----w- c:\program files\NeroInstall.bak
2009-08-31 22:12 . 2009-08-31 22:12 -------- d-----w- c:\documents and settings\James\Application Data\Nero
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-24 15:10 . 2009-08-31 20:41 171354656 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-24 14:58 . 2009-08-31 20:41 2293304 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-24 07:58 . 2009-08-31 20:42 52912 ----a-w- c:\documents and settings\James\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-24 07:24 . 2009-09-23 13:39 -------- d-----w- c:\program files\Common Files\PC Tools
2009-09-24 07:24 . 2009-09-23 21:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan
2009-09-24 07:00 . 2009-09-24 07:00 -------- d-----w- c:\documents and settings\James\Application Data\STOPzilla!
2009-09-23 15:47 . 2009-09-23 13:39 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-23 12:31 . 2009-08-31 20:34 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-22 01:54 . 2009-08-31 20:50 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-18 05:19 . 2009-08-31 20:39 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-09-06 15:58 . 2009-09-06 15:57 -------- d-----w- c:\program files\Lexmark X6100 Series
2009-09-06 15:58 . 2009-08-31 20:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-05 18:50 . 2009-08-31 20:53 -------- d-----w- c:\program files\Microsoft IntelliType Pro
2009-08-31 21:19 . 2009-08-31 21:19 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-08-31 21:19 . 2009-08-31 21:19 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-08-31 20:55 . 2009-08-31 20:54 -------- d-----w- c:\program files\Microsoft IntelliPoint
2009-08-31 20:51 . 2009-08-31 20:51 -------- d-----w- c:\program files\Realtek
2009-08-31 20:49 . 2009-08-31 20:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Pure Networks
2009-08-31 20:48 . 2009-08-31 20:48 -------- d-----w- c:\program files\Pure Networks
2009-08-31 20:47 . 2009-08-31 20:47 -------- d-----w- c:\program files\WebEx
2009-08-31 20:47 . 2009-08-31 20:47 8892928 ----a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2009-08-31 20:47 . 2009-08-31 20:47 -------- d-----w- c:\program files\Common Files\Pure Networks Shared
2009-08-31 20:43 . 2009-08-31 20:43 -------- d-----w- c:\documents and settings\James\Application Data\MailFrontier
2009-08-31 20:39 . 2009-08-31 20:39 -------- d-----w- c:\program files\Zone Labs
2009-08-31 20:34 . 2009-08-31 20:34 -------- d-----w- c:\program files\AGEIA Technologies
2009-08-31 20:17 . 2009-08-31 20:17 -------- d-----w- c:\program files\microsoft frontpage
2009-08-31 20:12 . 2009-08-31 20:12 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-31 20:12 . 2009-08-31 20:12 -------- d-----w- c:\program files\Unlocker
2009-08-31 20:12 . 2009-08-31 20:12 -------- d-----w- c:\program files\Microsoft PowerToys
2009-08-31 20:12 . 2009-08-31 20:12 -------- d-----w- c:\program files\HashTab Shell Extension
2009-08-31 20:07 . 2009-08-31 20:07 -------- d-----w- c:\program files\Windows Media Connect 2
2009-08-18 21:32 . 2009-08-31 20:51 5884416 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2009-08-14 18:08 . 2009-08-31 20:51 18702336 ----a-w- c:\windows\RTHDCPL.EXE
2009-08-05 20:10 . 2009-08-31 20:50 831488 ----a-w- c:\windows\RtlExUpd.dll
2009-08-05 09:01 . 2008-04-13 22:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 18:31 . 2009-08-31 20:51 2170880 ----a-w- c:\windows\MicCal.exe
2009-07-29 04:37 . 2008-04-13 22:42 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2008-04-13 22:41 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-17 19:01 . 2008-04-13 22:41 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2008-06-03 06:57 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-07 18:48 . 2009-08-31 20:47 25392 ----a-w- c:\windows\system32\drivers\pnarp.sys
2009-07-07 18:48 . 2009-08-31 20:47 26672 ----a-w- c:\windows\system32\drivers\purendis.sys
2009-07-03 17:09 . 2008-06-03 07:41 915456 ------w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-03-31 982408]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2009-08-31 472112]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"Lexmark X6100 Series"="c:\program files\Lexmark X6100 Series\lxbfbmgr.exe" [2003-09-23 57344]
"\\JAMES-CINDI-PC\EPSON Stylus Photo R340 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE" [2005-04-26 98304]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-09-10 420176]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
[HKLM\~\startupfolder\C:^Documents and Settings^James^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
path=c:\documents and settings\James\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
backup=c:\windows\pss\ERUNT AutoBackup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^James^Start Menu^Programs^Startup^YzShadow.lnk]
backup=c:\windows\pss\YzShadow.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe"= c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet,0.0.0.0/255.255.255.255:Enabled:Pure Networks Platform Service
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [6/3/2008 5:07 AM 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [6/3/2008 5:07 AM 53248]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/24/2009 9:45 AM 269648]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/24/2009 9:45 AM 19160]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [8/31/2009 4:51 PM 1684736]
S3 getPlusHelper;getPlus® Helper;c:\windows\System32\svchost.exe -k getPlusHelper [4/13/2008 6:42 PM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-24 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 10:57]
2009-09-24 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 10:57]
2009-09-24 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 10:57]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\James\Application Data\Mozilla\Firefox\Profiles\b67kwki6.default\
FF - plugin: c:\documents and settings\James\Application Data\Mozilla\Firefox\Profiles\b67kwki6.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-24 11:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1848)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Completion time: 2009-09-24 11:11
ComboFix-quarantined-files.txt 2009-09-24 15:11
Pre-Run: 458,324,996,096 bytes free
Post-Run: 458,301,558,784 bytes free
287 --- E O F --- 2009-09-09 07:02