Thanks for your further help. The ComboFix log fie saved is as follows:
ComboFix 09-03-26.03 - Owner 2009-03-28 12:02:34.1 - NTFSx86
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\RB1.tmp
c:\windows\ieocx.dll
c:\windows\system32\drivers\UACktlwowbp.sys
c:\windows\system32\mdm.exe
c:\windows\system32\system\
c:\windows\system32\UACapyhiymp.log
c:\windows\system32\UACaunmwvbf.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjxvimpqq.dll
c:\windows\system32\UAClnewswst.log
c:\windows\system32\UACnnbmtird.dll
c:\windows\system32\UACsrrojfwq.dll
c:\windows\system32\UACubobxthe.dat
c:\windows\system32\UACupafuxdu.dll
c:\windows\system32\UACxylqibqh.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-28 )))))))))))))))))))))))))))))))
.
2009-03-27 05:46 . 2009-03-27 05:47 <DIR> d-------- c:\windows\ERUNT
2009-03-27 05:14 . 2009-03-27 05:14 <DIR> d-------- c:\program files\Trend Micro
2009-03-27 04:33 . 2009-03-27 06:15 <DIR> d-------- C:\SDFix
2009-03-27 02:25 . 2009-03-27 04:13 <DIR> d-------- c:\program files\NVT Malware Remover Tool
2009-03-26 23:13 . 2009-03-26 23:13 <DIR> d-------- c:\program files\Raxco
2009-03-26 23:13 . 2009-03-26 23:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Raxco
2009-03-26 23:13 . 2008-08-28 13:16 71,184 --a------ c:\windows\system32\drivers\DefragFS.sys
2009-03-26 22:37 . 2009-03-26 22:37 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-26 22:37 . 2009-03-26 22:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-26 22:37 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 22:37 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-25 13:56 . 2009-03-25 13:59 16,832 --a------ c:\windows\system32\amcompat.tlb
2009-03-25 13:53 . 2009-03-28 12:02 <DIR> d-------- c:\windows\system32\CatRoot2
2009-03-20 19:03 . 2009-03-20 19:06 741 --a------ C:\iexplore.exe.lnk
2009-03-20 19:03 . 2009-03-20 19:19 546 --a------ C:\Mozilla Firefox.lnk
2009-03-18 18:37 . 2009-01-09 19:19 1,089,593 -----c--- c:\windows\system32\dllcache\ntprint.cat
2009-03-18 04:13 . 2009-03-18 04:13 <DIR> d-------- C:\e42c1aff98c4b84fb4d3540fb0
2009-03-14 21:45 . 2008-11-26 15:19 53,192 --a------ c:\windows\system32\drivers\rp_skt32.sys
2009-03-14 21:45 . 2008-08-06 21:20 48,384 --a------ c:\windows\system32\drivers\rp_pkt32.sys
2009-03-14 17:40 . 2009-03-14 17:40 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-03-14 17:28 . 2009-03-14 17:52 <DIR> d-------- c:\program files\NOS
2009-03-14 17:28 . 2009-03-14 17:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2009-03-07 16:38 . 2009-03-07 16:38 <DIR> d-------- c:\documents and settings\Owner\Application Data\DriverCure
2009-03-07 16:38 . 2009-03-07 16:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-03-07 16:38 . 2009-03-07 16:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\DriverCure
2009-03-06 21:10 . 2009-03-28 12:24 150,318 --a------ c:\windows\system32\oodbs.lor
2009-03-06 21:08 . 2009-03-14 16:19 <DIR> d-------- c:\windows\system32\oodag
2009-03-06 20:33 . 2009-03-06 20:33 <DIR> d-------- c:\program files\OO Software
2009-03-05 15:55 . 2009-03-05 15:55 <DIR> d-------- c:\documents and settings\Owner\Application Data\cs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-03-28 12:26 63,332,896 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-28 12:23 853,388 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-28 12:23 250,160 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-28 12:23 2,623,520 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-26 22:23 --------- d-----w c:\program files\Enigma Software Group
2009-03-24 22:06 --------- dc-h--w c:\documents and settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}
2009-03-23 16:30 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-21 18:01 --------- d-----w c:\documents and settings\Owner\Application Data\Apple Computer
2009-03-20 12:31 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-03-17 20:35 --------- d-----w c:\documents and settings\Owner\Application Data\Radialpoint
2009-03-17 20:32 --------- d-----w c:\program files\Radialpoint
2009-03-17 20:30 --------- d-----w c:\documents and settings\All Users\Application Data\Radialpoint
2009-03-17 20:18 --------- d-----w c:\program files\InstallShield Installation Information
2009-03-16 21:40 --------- d-----w c:\documents and settings\Owner\Application Data\Image Zone Express
2009-03-14 21:50 --------- d--h--w c:\documents and settings\Owner\Application Data\GTek
2009-03-14 21:50 --------- d--h--w c:\documents and settings\All Users\Application Data\GTek
2009-03-08 12:23 --------- d-----w c:\documents and settings\Owner\Application Data\alot
2009-03-08 07:02 --------- d-----w c:\program files\SmartShopper
2009-03-07 21:10 --------- d-----w c:\program files\ZumieSearch
2009-03-07 20:06 --------- d-----w c:\documents and settings\Owner\Application Data\SmartShopper
2009-02-23 20:05 37,896 ----a-w c:\windows\system32\drivers\oobctm.sys
2009-02-19 12:05 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-19 12:03 --------- d-----w c:\program files\Microsoft
2009-02-19 12:02 --------- d-----w c:\program files\Windows Live Toolbar
2009-02-19 12:02 --------- d-----w c:\program files\Windows Live
2009-02-19 12:01 --------- d-----w c:\program files\Microsoft Sync Framework
2009-02-18 15:37 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-11 21:55 --------- d-----w c:\program files\Windows Live SkyDrive
2009-02-11 21:46 --------- d-----w c:\program files\Common Files\Windows Live
2009-02-06 19:03 307,576 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 18:08 55,152 ----a-w c:\windows\system32\drivers\fssfltr_tdi.sys
2009-02-02 14:55 --------- d-----w c:\documents and settings\Owner\Application Data\Notepad++
2009-02-02 14:54 --------- d-----w c:\program files\Notepad++
2009-02-01 22:30 --------- d-----w c:\program files\Common Files\HP
2009-02-01 22:28 --------- d-----w c:\program files\Hewlett-Packard
2008-09-24 21:01 16,264,312 -c--a-w c:\program files\7zipfree_8675.exe
2008-05-27 23:37 2,400,784 ----a-w c:\program files\WLinstaller.exe
2008-03-24 02:22 2,585,872 ----a-w c:\program files\WindowsInstaller-KB893803-v2-x86.exe
2008-03-24 02:01 921,696 ----a-w c:\program files\WinQualifier.exe
2008-03-21 19:58 305,672 -c--a-w c:\program files\dxwebsetup.exe
1998-12-09 02:53 99,840 ----a-w c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 70,144 ----a-w c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 48,640 ----a-w c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 31,744 ----a-w c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 186,368 ----a-w c:\program files\Common Files\IRAREG.DLL
1998-12-09 02:53 17,920 ----a-w c:\program files\Common Files\IRASRIAL.DLL
2008-05-25 19:51 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052520080 526\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2BA1C226-EC1B-4471-A65F-D0688AC6EE3A}]
2008-02-05 17:20 1173024 --a------ c:\program files\SmartShopper\Bin\2.5.0\SmrtShpr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7}]
2008-10-31 19:05 759080 --a------ c:\program files\alot\bin\alot.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7}"= "c:\program files\alot\bin\alot.dll" [2008-10-31 759080]
[HKEY_CLASSES_ROOT\clsid\{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\
0autocheck autochk *\
0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Radialpoint Security Services]
@="Service"
path=
backup=
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^StarOffice 8.lnk]
backup=c:\windows\pss\StarOffice 8.lnkStartup
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\StarOffice 8.lnk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMM2007RT
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\B'sCLiP]
--a------ 2003-05-22 19:20 1310720 c:\progra~1\B'SCLI~1\Win2K\BsCLiP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fssui]
--a------ 2007-12-17 10:12 243240 c:\program files\Windows Live\Family Safety\fssui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2009-02-06 18:51 3885408 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-12-19 21:49 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-15 20:02 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"xmlprov"=3 (0x3)
"usnjsvc"=3 (0x3)
"SysmonLog"=2 (0x2)
"SwPrv"=3 (0x3)
"SNMPTRAP"=3 (0x3)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"SCardSvr"=3 (0x3)
"RSVP"=3 (0x3)
"RDSessMgr"=3 (0x3)
"RasAuto"=3 (0x3)
"PNRPSvc"=3 (0x3)
"p2pimsvc"=3 (0x3)
"p2pgasvc"=3 (0x3)
"ose"=3 (0x3)
"iPod Service"=3 (0x3)
"hkmsvc"=3 (0x3)
"HidServ"=2 (0x2)
"GoogleDesktopManager-022208-143751"=3 (0x3)
"Dot3svc"=3 (0x3)
"dmserver"=3 (0x3)
"AppMgmt"=2 (0x2)
"ZumieSearch Service"=2 (0x2)
"TapiSrv"=3 (0x3)
"seclogon"=2 (0x2)
"PDEngine"=3 (0x3)
"idsvc"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"PDAgent"=2 (0x2)
"SeaPort"=2 (0x2)
"PD91Engine"=3 (0x3)
"PD91Agent"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"p2psvc"=3 (0x3)
"O&O Defrag"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dlcccoms.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
R3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
R3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [2008-09-22 910600]
R3 Radialpoint Security Services;Radialpoint Security Services;c:\program files\Radialpoint\Radialpoint Security Services\RpsSecurityAwareR.exe [2009-03-02 170736]
R4 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-07-13 29744]
R4 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S0 BsStor;B.H.A Storage Helper Driver; [x]
S2 BsUDF;B.H.A UDF Filesystem; [x]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssflt r_tdi.sys [2009-02-06 55152]
S2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [2008-09-22 693512]
S2 RadialpointSafeConnectAgent;Radialpoint Security Services SafeConnectAgent; [x]
S3 RadialpointSafeConnectDriver;RadialpointSafeConnec tDriver;c:\program files\Radialpoint\Radialpoint Security Services\SafeConnect\Driver\platform_XP\SafeConnec tDriver.sys [2008-11-14 161304]
S3 RadialpointSafeConnectFilter;RadialpointSafeConnec tFilter;c:\program files\Radialpoint\Radialpoint Security Services\SafeConnect\Driver\platform_XP\SafeConnec tFilter.sys [2008-11-14 29720]
S3 RadialpointSafeConnectShim;RadialpointSafeConnectS him;c:\program files\Radialpoint\Radialpoint Security Services\SafeConnect\Driver\platform_XP\SafeConnec tShim.sys [2008-11-14 27376]
--- Other Services/Drivers In Memory ---
*Deregistered* - AFD
*Deregistered* - aspnet_state
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - Bonjour Service
*Deregistered* - BsUDF
*Deregistered* - Cdfs
*Deregistered* - COMSysApp
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - DefragFS
*Deregistered* - Dhcp
*Deregistered* - dlcc_device
*Deregistered* - Dnscache
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - fssfltr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - gusvc
*Deregistered* - HTTP
*Deregistered* - ip6fw
*Deregistered* - IpFilterDriver
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - Kbdclass
*Deregistered* - KLIF
*Deregistered* - KSecDD
*Deregistered* - mdmxsdk
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - MSDTC
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - OMCI
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PCIIde
*Deregistered* - PD91Agent
*Deregistered* - PD91Engine
*Deregistered* - PfModNT
*Deregistered* - Pml Driver HPZ12
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RadialpointSafeConnectAgent
*Deregistered* - RadialpointSafeConnectDriver
*Deregistered* - RadialpointSafeConnectFilter
*Deregistered* - RadialpointSafeConnectShim
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RP_FWS
*Deregistered* - RpcSs
*Deregistered* - RPPKT
*Deregistered* - RPSKT
*Deregistered* - SamSs
*Deregistered* - SimpTcp
*Deregistered* - SNMP
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - tunmp
*Deregistered* - Udfs
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - WS2IFSL
*Deregistered* - WZCSVC
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{203eb6de-7ba7-11dd-95a2-806d6172696f}]
\Shell\AutoRun\command - D:\Install.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-28 c:\windows\Tasks\Antispyware Scheduled Scan.job
- c:\program files\AntiSpywareApp\AntiSpyware.exe []
2009-03-28 c:\windows\Tasks\Antispyware Scheduled Scan.job
- c:\program files\AntiSpywareApp []
2009-03-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-03-26 c:\windows\Tasks\ErrorFix Scan.job
- c:\program files\ErrorFix\ErrorFix.exe []
2009-03-26 c:\windows\Tasks\ErrorFix Scan.job
- c:\program files\ErrorFix []
2009-03-27 c:\windows\Tasks\ErrorSmart Scheduled Scan.job
- c:\program files\ErrorSmart\ErrorSmart.exe []
2009-03-27 c:\windows\Tasks\ErrorSmart Scheduled Scan.job
- c:\program files\ErrorSmart []
2009-03-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 17:31]
2009-03-27 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll []
2009-03-28 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe []
2009-03-27 c:\windows\Tasks\RegClean Scheduled Scan.job
- c:\program files\RegClean\RegClean.exe []
2009-03-27 c:\windows\Tasks\RegClean Scheduled Scan.job
- c:\program files\RegClean []
.
- - - - ORPHANS REMOVED - - - -
BHO-{06ec6572-7280-485a-a712-c380526bc048} - c:\windows\ieocx.dll
Toolbar-SITEguard - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-OneCareUI - c:\program files\Microsoft Windows OneCare Live\winssnotify.exe
MSConfigStartUp-sysav - c:\documents and settings\Owner\Application Data\pcdefender.exe
.
------- Supplementary Scan -------
.
mStart Page = hxxp://in.rediff.com/index.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
IE: Add to Windows &Live Favorites -
Add to Windows Live Favorites
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: {{3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - {2260D608-C844-435d-90FD-DC16CFA577F2} - c:\program files\SmartShopper\Bin\2.5.0\SmrtShpr.dll
IE: {{3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - {BCEB373D-A35A-4200-BD43-8586CD9DFAE7} - c:\program files\SmartShopper\Bin\2.5.0\SmrtShpr.dll
Trusted Zone: barclays.co.uk\
www.personal
Trusted Zone: co-operativebank.co.uk\welcome26
Trusted Zone: landregistry.gov.uk\www1
Trusted Zone: microsoft.com\
www.update
Trusted Zone: msn.com\www
Trusted Zone: radialpoint.com\www
Trusted Zone: redbridge.gov.uk\planning
Trusted Zone: removal-instructions.com\www
Trusted Zone: sch.uk\folders.canonpalmer.redbridge
Trusted Zone: sch.uk\webmail.canonpalmer.redbridge
Trusted Zone: studentfinancedirect.co.uk\secure
Trusted Zone: themass.com\www
Trusted Zone: virginmedia.com\help2
Trusted Zone: virginmedia.com\www
Trusted Zone: windowsupdate.com\download
Trusted Zone: worldofsu.com\www
Trusted Zone: worldpay.com\select
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\magk1fxb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-28 12:26:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Curr entVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="C258B1F49BFA2731 E692076951478541711A10CAC0BF629195884AAA8317210E51 B3D842166D2D1B7FE6CB0F72F30AE4FDED7BC443E1F76F68F5 F30F9C3AA606D8B5EE9DCDE07471C26E5F0B417D448059B187 8866AF5EDD04862BDEB593E33E644E42423A1AD2547086C7EC 32A5911915D01518C0889A68ED53473325BE2AE50CE241FA11 0F8036CD02AED600DF358845A9240BAB7C1A6C2968C438070B 2C7F644D032B4F6B1CDF2428E2FE26D555F9058FDD0DC5512A 9B44C444ADBAF8FEBC9E127BECC74CFEBC9E127BECC74CFEBC 9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E 127BECC74CA6A0AC4980AC79335D575E7D6A3B9808A2D97226 D213B5559DB7CE019D40AA5CFB8BD99B2548D65B3C886E5723 606E39DB8B9C1929E1526F496C67B1B4044EBEDE5726055BC5 AA7CFDE53CE4352BED5BCC04DC40D9D1297C6E2DE39C65CC53 D6D8F1BD6699D6C066BAD1D80685D417B8E86230D63D24633B E348E05AA93C3560E98152CA5F1ECD9619F8E7738994DF0DA0 F6CAE165465AC286D1C35B4C964BF075FA9931CE52CDBF25D6 0FD95D3603C448E265D986B82ADC1031F2063BB034D0C02FCC 0EAFC07D454E3F79D7C21B8183981EB9AB7912B10C25A2DCB4 087551FBF4BCAAC66CC6DF42E7D5D5029CB79D9FADF208B9BB 7A9781C9B4F0356763C624A298733793583A03A9145760F193 DD24888094D76DAF42A6664C2549358BFCAC3B8B6DADD8FC18 8A2ECA346FEFCA8ECE8C392750D3825E164A21F0A6EE96232E 9533626D1450460DF499A69EE58E3E1282630A5ED858DB9EA5 BED1F8363CA975E97F9F2F3D00577462766E53C7A2BF95979A 8E3487AAEE458E85C75C51CBC483D9B5F79BF450A25FBC2BCC E32DDEAB335A4D07771108103F7DA8D7E42928EE0C66EDBFD2 7F19C09D30D5099C52B05B79C1BE4CBECC107BFBD02F8B16CB 47E3F8751651E6C04590B54BE7ED3D18966F2BA385B99930F7 3096C9F5EDEBEB32266553ED89E0C6D3B36103274A7B80A749 3EBE0B2E09DA09F2E50DAC9054DF89FAA1AB894BB83E58110E AD2D6FFDB409115D32118E7F8CA24C6FA5D687AF9F7DE93312 D3FA617A79D1DB856937E080F833E78227C0E82A33096F7ECB 6CD54B55C0527D09033AF2F2E4A22C9B78B45447DC6F173632 203B41B756EAB8DA11A26B91EB4838519C4294FC692459147D C158023A3EF6D078EFE6AD46A09B741D8DAC311FAFC75652A7 410FF0D48E6C3283A3D943A7FA12B496500317B6C95DAD949D 38C258EF091C85EF562789F667C0F336DF3A67A2EB0F253E13 552DE93E6965D2845DC5BD622BE2AB4F3471A5F08792305200 F6275BB33487FDBF64F7C268D3F637ABE41160A66A143E7021 01F65A054634AC3190DFC480952949A0451EB954C8349F8221 832A6BDC27E90EBFEB821240CE08D6BE"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1740)
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Radialpoint\Radialpoint Security Services\Fws.exe
c:\windows\system32\dlcccoms.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Radialpoint\Radialpoint Security Services\SafeConnect\bin\SanaAgent.exe
c:\windows\system32\verclsid.exe
.
************************************************** ************************
.
Completion time: 2009-03-28 12:33:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-28 12:33:19
Pre-Run: 21,912,813,568 bytes free
Post-Run: 22,264,266,752 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Micro soft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
446 --- E O F --- 2009-03-18 17:00:11
THank you very much for your most kind help.
Kind regards
Edcondi