Here's the log from COMBOFIX
ComboFix 09-08-21.02 - Julianna Marie 08/22/2009 14:42.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1526.810 [GMT -4:00]
Running from: c:\documents and settings\Julianna Marie\Desktop\ComboFix.exe
AV: ZoneAlarm Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-3868997124-911790988-508925577-500
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Installer\236763.msp
c:\windows\Installer\5fd3ee9f.msp
c:\windows\kb913800.exe
c:\windows\run.log
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
c:\windows\system32\drivers\hjgruiwferdiph.sys
c:\windows\system32\hjgruilmkmsiol.dll
c:\windows\system32\hjgruirsbqaete.dat
c:\windows\system32\hjgruiseqxtkbc.dll
c:\windows\system32\hjgruiwroklpdl.dll
c:\windows\system32\hjgruixcekuybu.dat
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_hjgruiyqdtunbe
-------\Legacy_hjgruiyqdtunbe
((((((((((((((((((((((((( Files Created from 2009-07-22 to 2009-08-22 )))))))))))))))))))))))))))))))
.
2009-08-21 16:05 . 2009-08-21 16:05 127872 ----a-w- c:\documents and settings\Julianna Marie\Application Data\Move Networks\uninstall.exe
2009-08-19 13:46 . 2009-08-19 13:46 -------- d-----w- c:\program files\Coupons
2009-08-13 21:34 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 01:07 . 2009-08-10 01:07 -------- d-----w- c:\documents and settings\Julianna Marie\Application Data\Otto
2009-08-10 01:07 . 2009-08-10 01:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Otto
2009-08-08 01:49 . 2009-08-08 11:44 -------- d-----w- c:\documents and settings\Julianna Marie\.housecall6.6
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-22 18:55 . 2007-01-29 17:02 3921692 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-22 18:55 . 2007-01-29 17:02 350481184 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-22 18:24 . 2007-01-29 16:57 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-08-21 16:05 . 2008-03-10 23:42 -------- d-----w- c:\documents and settings\Julianna Marie\Application Data\Move Networks
2009-08-21 16:05 . 2009-06-16 06:35 4183416 ----a-w- c:\documents and settings\Julianna Marie\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-08-20 23:51 . 2009-08-20 23:52 401408 ----a-w- c:\windows\Internet Logs\xDB15.tmp
2009-08-20 16:18 . 2008-08-25 12:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-12 11:04 . 2009-08-12 11:21 920576 ----a-w- c:\windows\Internet Logs\xDB13.tmp
2009-08-12 11:04 . 2009-08-12 11:21 3432448 ----a-w- c:\windows\Internet Logs\xDB14.tmp
2009-08-08 01:12 . 2007-03-01 14:45 -------- d--h--w- c:\documents and settings\All Users\Application Data\yahoo!
2009-08-07 01:54 . 2009-07-28 11:02 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-07 01:54 . 2006-02-16 09:28 -------- d-----w- c:\program files\Java
2009-08-07 01:53 . 2009-08-07 01:53 152576 ----a-w- c:\documents and settings\Julianna Marie\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-07 01:50 . 2009-03-18 20:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-07 00:57 . 2009-02-13 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-07 00:57 . 2009-02-13 21:29 -------- d-----w- c:\program files\NOS
2009-08-06 20:48 . 2009-08-06 20:48 -------- d-----w- c:\program files\THQ
2009-08-06 20:48 . 2006-02-15 16:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-05 09:01 . 2006-02-15 14:03 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 21:41 . 2009-08-04 21:41 687104 ----a-w- c:\windows\is-BESLF.exe
2009-08-04 12:44 . 2009-08-04 12:44 2855 ----a-w- c:\windows\system32\desot.PIF
2009-08-03 17:36 . 2008-08-25 12:21 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 17:36 . 2008-08-25 12:21 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-03 14:28 . 2009-08-03 14:33 3334656 ----a-w- c:\windows\Internet Logs\xDB12.tmp
2009-08-03 12:17 . 2007-03-08 23:04 14647178 ----a-w- c:\windows\Internet Logs\tvDebug.zip
2009-08-03 02:40 . 2007-07-22 15:58 -------- d-----w- c:\program files\FlashGet
2009-08-03 02:11 . 2009-08-03 02:23 2699776 ----a-w- c:\windows\Internet Logs\xDB11.tmp
2009-08-03 02:06 . 2009-08-03 02:06 35633 ----a-w- c:\windows\Internet Logs\zlclient_2nd_2009_08_02_21_27_45_small.dmp.zip
2009-08-01 15:01 . 2008-12-24 13:31 -------- d-----w- c:\program files\Safari
2009-08-01 14:56 . 2007-12-19 14:19 -------- d-----w- c:\program files\iTunes
2009-08-01 14:56 . 2009-08-01 14:56 -------- d-----w- c:\program files\iPod
2009-08-01 14:56 . 2007-12-19 14:16 -------- d-----w- c:\program files\Common Files\Apple
2009-08-01 14:50 . 2009-08-01 14:50 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-28 11:02 . 2006-05-13 23:44 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-07-22 23:57 . 2006-02-18 15:56 -------- d-----w- c:\program files\Google
2009-07-17 19:01 . 2006-02-15 14:02 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2006-02-15 14:05 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2006-02-15 14:04 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2006-02-15 14:02 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2006-02-15 14:02 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-26 20:14 . 2006-02-16 10:39 -------- d-----w- c:\program files\Microsoft Works
2009-06-18 11:42 . 2009-06-18 11:43 2336256 ----a-w- c:\windows\Internet Logs\xDB10.tmp
2009-06-16 14:36 . 2006-02-15 14:04 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2006-02-15 14:02 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 06:35 . 2009-06-16 06:35 97144 ----a-w- c:\documents and settings\Julianna Marie\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-12 12:31 . 2006-02-15 14:04 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2006-02-15 14:04 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2006-02-15 14:02 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2006-02-15 15:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2006-02-15 14:04 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-05 15:42 . 2009-05-01 14:46 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 15:42 . 2007-12-19 14:17 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-03 19:09 . 2006-02-15 14:03 1291264 ----a-w- c:\windows\system32\quartz.dll
2008-05-28 23:15 . 2008-05-28 23:15 0 ----a-w- c:\program files\temp01
2007-07-15 22:57 . 2007-07-15 22:57 774144 ----a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 23:24 . 2008-02-22 23:24 1098 c:\program files\FlashGet\bak\fgbhocfg.ini
2007-07-22 15:59 . 2007-07-22 15:59 1098 c:\program files\FlashGet\fgbhocfg.ini
2008-02-22 23:24 . 2008-08-12 00:09 673 c:\program files\FlashGet\bak\fgres1.ini
2007-07-22 15:59 . 2008-01-30 22:49 684 c:\program files\FlashGet\fgres1.ini
2008-02-22 23:24 . 2009-02-09 00:52 20 c:\program files\FlashGet\bak\FGUpdate1.ini
2007-07-22 15:59 . 2008-01-29 16:58 20 c:\program files\FlashGet\FGUpdate1.ini
2008-02-22 23:24 . 2008-08-12 11:19 20 c:\program files\FlashGet\bak\FGUpdate2.ini
2007-07-22 15:59 . 2008-01-29 16:58 20 c:\program files\FlashGet\FGUpdate2.ini
2008-02-22 23:24 . 2009-02-09 00:52 275 c:\program files\FlashGet\bak\FGUpdate3.ini
2007-07-22 15:59 . 2008-01-29 16:58 275 c:\program files\FlashGet\FGUpdate3.ini
2008-12-26 15:11 . 2008-12-26 15:11 0 c:\program files\FlashGet\bak\FlashGet-000A94CD.dmp
2008-12-26 15:11 . 2008-12-26 15:11 715 c:\program files\FlashGet\bak\FlashGet-000A94CD.rpt
2008-12-26 15:11 . 2008-12-26 15:11 0 c:\program files\FlashGet\bak\FlashGet-000AFFFA.dmp
2008-12-26 15:11 . 2008-12-26 15:11 715 c:\program files\FlashGet\bak\FlashGet-000AFFFA.rpt
2008-12-26 15:11 . 2008-12-26 15:11 0 c:\program files\FlashGet\bak\FlashGet-000B51A4.dmp
2008-12-26 15:11 . 2008-12-26 15:11 715 c:\program files\FlashGet\bak\FlashGet-000B51A4.rpt
2008-12-26 22:42 . 2008-12-26 22:42 0 c:\program files\FlashGet\bak\FlashGet-00101D00.dmp
2008-12-26 22:42 . 2008-12-26 22:42 715 c:\program files\FlashGet\bak\FlashGet-00101D00.rpt
2008-03-11 22:20 . 2008-03-11 22:20 0 c:\program files\FlashGet\bak\FlashGet-001CCC40.dmp
2008-03-11 22:20 . 2008-03-11 22:20 715 c:\program files\FlashGet\bak\FlashGet-001CCC40.rpt
2008-03-11 22:23 . 2008-03-11 22:23 0 c:\program files\FlashGet\bak\FlashGet-001F6C01.dmp
2008-03-11 22:23 . 2008-03-11 22:23 715 c:\program files\FlashGet\bak\FlashGet-001F6C01.rpt
2008-03-13 15:19 . 2008-03-13 15:19 0 c:\program files\FlashGet\bak\FlashGet-08AD4BBB.dmp
2008-03-13 15:19 . 2008-03-13 15:19 714 c:\program files\FlashGet\bak\FlashGet-08AD4BBB.rpt
2008-02-23 16:06 . 2008-02-23 16:06 0 c:\program files\FlashGet\bak\FlashGet-0E09CB1B.dmp
2008-02-23 16:06 . 2008-02-23 16:06 714 c:\program files\FlashGet\bak\FlashGet-0E09CB1B.rpt
2008-02-23 16:06 . 2008-02-23 16:06 0 c:\program files\FlashGet\bak\FlashGet-0E0A048A.dmp
2008-02-23 16:06 . 2008-02-23 16:06 714 c:\program files\FlashGet\bak\FlashGet-0E0A048A.rpt
2008-02-23 20:38 . 2008-02-23 20:38 0 c:\program files\FlashGet\bak\FlashGet-0E0A9EC7.dmp
2008-02-23 20:38 . 2008-02-23 20:38 714 c:\program files\FlashGet\bak\FlashGet-0E0A9EC7.rpt
2008-02-28 13:46 . 2008-02-28 13:46 0 c:\program files\FlashGet\bak\FlashGet-0E94A38A.dmp
2008-02-28 13:46 . 2008-02-28 13:46 714 c:\program files\FlashGet\bak\FlashGet-0E94A38A.rpt
2008-02-28 13:47 . 2008-02-28 13:47 0 c:\program files\FlashGet\bak\FlashGet-0E950707.dmp
2008-02-28 13:47 . 2008-02-28 13:47 714 c:\program files\FlashGet\bak\FlashGet-0E950707.rpt
2008-02-28 15:22 . 2008-02-28 15:22 0 c:\program files\FlashGet\bak\FlashGet-0E9626B0.dmp
2008-02-28 15:22 . 2008-02-28 15:22 714 c:\program files\FlashGet\bak\FlashGet-0E9626B0.rpt
2008-02-28 17:12 . 2008-02-28 17:12 0 c:\program files\FlashGet\bak\FlashGet-0F514BFD.dmp
2008-02-28 17:12 . 2008-02-28 17:12 714 c:\program files\FlashGet\bak\FlashGet-0F514BFD.rpt
2008-02-28 17:56 . 2008-02-28 17:56 0 c:\program files\FlashGet\bak\FlashGet-0F51762A.dmp
2008-02-28 17:56 . 2008-02-28 17:56 714 c:\program files\FlashGet\bak\FlashGet-0F51762A.rpt
2008-02-28 21:11 . 2008-02-28 21:11 0 c:\program files\FlashGet\bak\FlashGet-0F7B4123.dmp
2008-02-28 21:11 . 2008-02-28 21:11 714 c:\program files\FlashGet\bak\FlashGet-0F7B4123.rpt
2008-03-10 23:42 . 2008-03-10 23:42 0 c:\program files\FlashGet\bak\FlashGet-0F9357B4.dmp
2008-03-10 23:42 . 2008-03-10 23:42 714 c:\program files\FlashGet\bak\FlashGet-0F9357B4.rpt
2008-02-28 22:55 . 2008-02-28 22:55 0 c:\program files\FlashGet\bak\FlashGet-102BBDED.dmp
2008-02-28 22:55 . 2008-02-28 22:55 714 c:\program files\FlashGet\bak\FlashGet-102BBDED.rpt
2008-02-29 01:41 . 2008-02-29 01:41 0 c:\program files\FlashGet\bak\FlashGet-10B237B5.dmp
2008-02-29 01:41 . 2008-02-29 01:41 714 c:\program files\FlashGet\bak\FlashGet-10B237B5.rpt
2008-03-04 22:45 . 2008-03-04 22:45 0 c:\program files\FlashGet\bak\FlashGet-111FA188.dmp
2008-03-04 22:45 . 2008-03-04 22:45 714 c:\program files\FlashGet\bak\FlashGet-111FA188.rpt
2008-03-17 15:26 . 2008-03-17 15:26 0 c:\program files\FlashGet\bak\FlashGet-1D4C52D3.dmp
2008-03-17 15:26 . 2008-03-17 15:26 714 c:\program files\FlashGet\bak\FlashGet-1D4C52D3.rpt
2008-03-17 15:26 . 2008-03-17 15:26 0 c:\program files\FlashGet\bak\FlashGet-1D4CA97E.dmp
2008-03-17 15:26 . 2008-03-17 15:26 714 c:\program files\FlashGet\bak\FlashGet-1D4CA97E.rpt
2008-03-07 15:44 . 2008-03-07 15:44 0 c:\program files\FlashGet\bak\FlashGet-1F11D239.dmp
2008-03-07 15:44 . 2008-03-07 15:44 714 c:\program files\FlashGet\bak\FlashGet-1F11D239.rpt
2008-02-22 23:24 . 2008-08-08 18:38 8961 c:\program files\FlashGet\bak\FlashGet_LOGO.gif
2007-10-05 21:53 . 2008-01-18 19:37 22619 c:\program files\FlashGet\FlashGet_LOGO.gif
2008-02-05 13:47 . 2008-02-05 13:47 117 c:\program files\FlashGet\bak\Config\BITS.ini
2008-10-22 23:01 . 2008-12-26 22:57 5189 c:\program files\FlashGet\bak\Config\DHTTable.dat
2008-10-22 22:46 . 2008-12-26 22:54 184 c:\program files\FlashGet\bak\Config\UPnP.ini
2008-02-05 13:47 . 2009-08-03 02:40 2931 c:\program files\FlashGet\bak\FGMule\config\core.cfg
2008-02-05 19:04 . 2008-12-27 01:51 1221 c:\program files\FlashGet\bak\FGMule\config\core.ed2k.svr
2008-02-05 13:47 . 2009-08-03 01:17 37 c:\program files\FlashGet\bak\FGMule\config\FGEMCORE.cfg
2008-02-05 19:04 . 2009-08-03 02:40 704 c:\program files\FlashGet\bak\FGMule\log\stat.db
2008-10-22 22:46 . 2008-10-12 09:32 14468 c:\program files\FlashGet\bak\Torrent\prono.torrent
2008-10-22 22:47 . 2008-10-22 23:38 390 c:\program files\FlashGet\bak\Torrent\prono.torrent.bits
2008-10-22 22:46 . 2008-10-22 23:38 291 c:\program files\FlashGet\bak\Torrent\prono.torrent.filelist
2008-10-22 23:38 . 2008-10-22 23:38 347 c:\program files\FlashGet\bak\Torrent\prono.torrent.seeds
2008-10-22 23:38 . 2008-10-22 23:38 0 c:\program files\FlashGet\bak\Torrent\prono.torrent.~tmp
2008-12-17 17:02 . 2008-11-06 21:49 56785 c:\program files\FlashGet\bak\Torrent\Transsiberian[2008]DvDrip-aXXo.torrent
2008-12-17 17:02 . 2008-12-19 23:04 1098 c:\program files\FlashGet\bak\Torrent\Transsiberian[2008]DvDrip-aXXo.torrent.bits
2008-12-17 17:02 . 2008-12-19 23:04 613 c:\program files\FlashGet\bak\Torrent\Transsiberian[2008]DvDrip-aXXo.torrent.filelist
2005-11-28 19:41 . 2005-11-28 19:41 602182 c:\program files\Intel\Wireless\Bin\bak\ifrmewrk.exe
2005-12-05 20:37 . 2005-12-05 20:37 667718 c:\program files\Intel\Wireless\Bin\bak\ZCfgSvc.exe
2007-12-11 17:10 . 2007-12-11 17:10 267048 c:\program files\iTunes\bak\iTunesHelper.exe
2009-07-13 18:03 . 2009-07-13 18:03 292128 c:\program files\iTunes\iTunesHelper.exe
2006-11-01 08:04 . 2006-11-01 08:04 321088 c:\program files\Pure Networks\Network Magic\bak\nmapp.exe
2008-01-18 14:32 . 2008-01-18 14:32 451896 c:\program files\Pure Networks\Network Magic\nmapp.exe
2007-12-11 15:56 . 2007-12-11 15:56 286720 c:\program files\QuickTime\bak\QTTask.exe
2009-05-26 21:18 . 2009-05-26 21:18 413696 c:\program files\QuickTime\QTTask.exe
2006-02-26 10:29 . 2005-12-16 08:32 761945 c:\program files\Synaptics\SynTP\bak\SynTPEnh.exe
2006-02-26 10:29 . 2005-12-16 08:34 82009 c:\program files\Synaptics\SynTP\bak\SynTPLpr.exe
2006-02-15 16:25 . 2006-01-05 22:02 352256 c:\program files\TOSHIBA\TOSHIBA Applet\bak\thotkey.exe
2006-02-16 09:27 . 2005-04-27 00:13 122880 c:\program files\TOSHIBA\TOSHIBA Zooming Utility\bak\SmoothView.exe
2006-02-15 16:41 . 2005-11-30 20:25 73728 c:\program files\TOSHIBA\Tvs\bak\TvsTray.exe
2006-02-16 09:19 . 2005-03-18 01:37 151552 c:\toshiba\IVP\ISM\bak\pinger.exe
2006-02-16 17:03 . 2005-08-05 21:56 64512 c:\windows\ehome\bak\ehtray.exe
2006-02-16 17:03 . 2005-08-05 21:56 64512 c:\windows\ehome\ehtray.exe
2006-02-15 14:04 . 2004-08-10 12:00 15360 c:\windows\system32\bak\ctfmon.exe
2006-02-15 14:04 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe
2006-02-18 15:57 . 2005-11-28 05:52 77824 c:\windows\system32\bak\hkcmd.exe
2006-02-18 15:57 . 2005-11-28 05:55 118784 c:\windows\system32\bak\igfxpers.exe
2006-02-18 15:57 . 2005-11-28 05:55 98304 c:\windows\system32\bak\igfxtray.exe
2006-02-16 10:18 . 2005-10-06 13:20 122940 c:\windows\system32\DLA\bak\DLACTRLW.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-22 39408]
"Uniblue RegistryBooster 2009"="c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe" [N/A]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-01-08 451896]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-01-18 451896]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-03-31 982408]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-05 122368]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-07 149280]
"TFncKy"="TFncKy.exe" [N/A]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-15 88203]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [N/A]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-15 155648]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Julianna Marie^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\Julianna Marie\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Pure Networks\\Network Magic\\WebServer\\bin\\nmraapache.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"67:UDP"= 67:UDP:DHCP Discovery Service
S3 IO_Memory;IO_Memory;\??\c:\sysprep\Drivers\ioport.sys --> c:\sysprep\Drivers\ioport.sys [?]
S3 SVRPEDRV;SVRPEDRV;\??\c:\sysprep\PEDrv.sys --> c:\sysprep\PEDrv.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-08-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
2009-08-22 c:\windows\Tasks\ZoneAlarm Security.job
- c:\progra~1\ZONELA~1\ZONEAL~1\zlclient.exe [2008-04-29 23:20]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
uInternet Connection Wizard,ShellNext = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxp://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371420.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-22 14:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1584)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\ZoneLabs\avsys\ScanningProcess.exe
c:\windows\system32\ZoneLabs\avsys\ScanningProcess.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\system32\dllhost.exe
c:\program files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
c:\program files\Pure Networks\Network Magic\WebServer\bin\rotatelogs.exe
c:\program files\Pure Networks\Network Magic\WebServer\bin\rotatelogs.exe
c:\program files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
c:\program files\Pure Networks\Network Magic\WebServer\bin\rotatelogs.exe
c:\program files\Pure Networks\Network Magic\WebServer\bin\rotatelogs.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\TPSBattM.exe
.
**************************************************************************
.
Completion time: 2009-08-22 15:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-22 19:13
Pre-Run: 111,774,031,872 bytes free
Post-Run: 114,753,925,120 bytes free
375 --- E O F --- 2009-08-13 23:18