here is my combo fix log
ComboFix 09-06-03.04 - HP_Administrator 06/04/2009 9:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3006.2498 [GMT -7:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
AV: Prevx 2.0 *On-access scanning disabled* (Updated) {557C3342-BC52-4508-AC25-4441BDF5C04C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Internet Explorer\2.exe
c:\program files\Internet Explorer\setupapi.dll
c:\program files\Mozilla Firefox\setupapi.dll
c:\windows\IE4 Error Log.txt
c:\windows\Install.txt
c:\windows\KBPK090531.log
c:\windows\system32\3361
c:\windows\system32\3361\mlog
c:\windows\system32\drivers\13cde429.sys
c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
c:\windows\system32\drivers\Msft_Kernel_zumbus_01005.Wdf
c:\windows\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
c:\windows\system32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
c:\windows\system32\drivers\qwco.sys
c:\windows\system32\drivers\zkzucdc.sys
c:\windows\system32\dxnnmnir.ini
c:\windows\system32\kdfinj.dll
c:\windows\system32\kungsfcbvukcek.dat
c:\windows\system32\kungsfvxiombcf.dat
c:\windows\system32\rnoyohcl.ini
c:\windows\system32\srqss.ini2
c:\windows\system32\xbadd.ini
c:\windows\system32\xbadd.ini2
----- BITS: Possible infected sites -----
hxxp://binuser.fileave.com
Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected
Restored copy from - The cat ate it

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_avast!antivirus
-------\Legacy_ias
-------\Legacy_msncache
-------\Legacy_ntalme
-------\Legacy_PERFMONS
-------\Legacy_ROUTING
-------\Legacy_sopidkc
-------\Service_ias
-------\Service_kungsfhhbutmne
((((((((((((((((((((((((( Files Created from 2009-05-04 to 2009-06-04 )))))))))))))))))))))))))))))))
.
2009-06-03 06:20 . 2009-06-03 17:57 -------- d-----w- c:\documents and settings\HP_Administrator\DoctorWeb
2009-06-02 09:36 . 2009-06-02 09:36 117760 ----a-w- c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-02 09:36 . 2009-06-02 09:36 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-02 09:36 . 2009-06-02 09:36 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com
2009-06-02 09:35 . 2009-06-02 09:35 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-02 08:43 . 2009-06-02 08:44 19500 ----a-w- c:\windows\hpqins13.dat
2009-06-02 05:54 . 2009-06-02 05:54 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-06-02 05:25 . 2009-06-02 05:25 -------- d-----w- C:\SystemRoot
2009-06-02 05:23 . 2009-06-02 05:23 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\WinBatch
2009-06-01 22:16 . 2009-06-02 00:07 -------- d-----w- c:\program files\RegCure
2009-06-01 18:27 . 2009-06-01 18:27 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-01 18:22 . 2006-05-24 01:05 110592 ----a-w- c:\documents and settings\Administrator\Application Data\U3\temp\cleanup.exe
2009-06-01 18:14 . 2009-06-01 18:17 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-06-01 18:06 . 2009-06-01 18:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\U3
2009-06-01 11:51 . 2009-06-01 11:51 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-06-01 11:51 . 2009-06-01 11:51 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-06-01 11:49 . 2007-12-27 02:08 302600 ----a-w- c:\windows\system32\drivers\pxfsf.sys
2009-06-01 11:49 . 2007-12-27 02:07 23048 ----a-w- c:\windows\system32\drivers\PxRD.sys
2009-06-01 11:49 . 2009-06-01 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Prevx
2009-06-01 04:28 . 2009-06-01 11:51 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-06-01 01:41 . 2009-06-04 16:48 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-05-31 16:21 . 2009-06-04 17:03 99422 ----a-w- c:\windows\system32\drivers\7291365f.sys
2009-05-31 15:35 . 2009-05-31 15:35 3371383 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-31 15:35 . 2009-05-31 15:35 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-05-31 15:35 . 2009-05-26 20:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-31 15:34 . 2009-05-26 20:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-31 15:34 . 2009-05-31 15:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-31 15:34 . 2009-05-31 15:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-31 15:23 . 2009-05-31 15:40 -------- d-----w- c:\windows\dhcp
2009-05-14 05:15 . 2009-05-14 05:15 -------- d-----w- c:\program files\MSECache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-04 16:58 . 2006-07-19 00:43 182656 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-06-04 16:13 . 2007-05-29 22:07 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Azureus
2009-06-04 08:42 . 2008-11-09 07:31 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\GrabIt
2009-06-03 06:03 . 2008-03-18 18:50 -------- d-----w- c:\program files\Trend Micro
2009-06-03 03:38 . 2007-06-11 05:12 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\U3
2009-06-02 05:57 . 2006-07-19 11:17 -------- d-----w- c:\program files\HP
2009-06-02 05:57 . 2006-07-19 11:35 -------- d-----w- c:\program files\Hewlett-Packard
2009-06-02 05:16 . 2005-01-25 00:30 139264 ----a-w- c:\windows\system32\hpzjrd01.dll
2009-05-06 05:17 . 2008-11-18 06:14 11148 ----a-w- c:\documents and settings\All Users\Application Data\DVDXStudio\CloneDVD4\MainApp.dll
2009-05-05 03:36 . 2009-05-04 23:46 -------- d-----w- c:\program files\CutStudio
2009-05-04 23:46 . 2009-05-04 23:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Roland DG Corporation
2009-05-04 23:46 . 2006-07-19 11:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-02 16:38 . 2009-05-02 16:38 1078 ----a-r- c:\documents and settings\HP_Administrator\Application Data\Microsoft\Installer\{6A5887F9-F17E-4905-B577-7956BF866C88}\_18be6784.exe
2009-05-02 16:38 . 2009-05-02 16:38 -------- d-----w- c:\program files\Callipygian 3D
2009-04-29 10:02 . 2008-04-24 16:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-27 13:28 . 2007-09-24 17:34 7114736 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Azureus\plugins\azemp\azmplay.exe
2009-04-27 13:25 . 2007-06-05 19:20 -------- d-----w- c:\program files\Azureus
2009-04-27 02:39 . 2008-07-04 05:25 -------- d-----w- c:\program files\FlexiSIGN-PRO 8.1v1
2009-04-24 22:15 . 2008-01-21 03:07 256 ----a-w- c:\windows\system32\pool.bin
2009-04-24 22:10 . 2009-04-24 22:10 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Apple Computer
2009-04-15 03:43 . 2009-04-15 03:42 -------- d-----w- c:\program files\QuickTime
2009-04-15 03:42 . 2009-04-15 03:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-15 03:41 . 2009-04-15 03:41 -------- d-----w- c:\program files\Apple Software Update
2009-04-15 03:41 . 2009-04-15 03:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-03-27 04:44 . 2006-07-19 11:28 317224 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-10 06:44 . 2008-03-18 05:31 2516 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-03-10 06:44 . 2008-03-18 05:31 2516 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2008-07-31 07:35 . 2008-07-31 07:35 13661 ----a-w- c:\program files\uninstal.log
2005-01-21 00:53 . 2007-08-17 17:31 45056 ------r- c:\program files\SetAttrib.exe
2003-11-04 00:07 . 2004-04-24 00:06 499712 ----a-w- c:\program files\msvcp71.dll
2003-11-04 00:07 . 2004-04-24 00:06 348160 ----a-w- c:\program files\msvcr71.dll
2003-05-30 16:22 . 2003-09-08 16:09 344064 ----a-r- c:\program files\msvcr70.dll
2002-01-05 10:40 . 2003-09-08 16:09 487424 ----a-w- c:\program files\msvcp70.dll
2008-03-29 02:44 . 2008-03-29 02:44 27976 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-03-29 02:44 . 2008-03-29 02:44 125848 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-03-29 02:44 . 2008-03-29 02:44 46408 ----a-w- c:\program files\mozilla firefox\plugins\atmccli.dll
2007-06-22 02:38 . 2007-06-22 02:38 30280 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2007-06-22 02:38 . 2007-06-22 02:38 79432 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2007-06-22 02:38 . 2007-06-22 02:38 71240 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2007-06-22 02:38 . 2007-06-22 02:38 140872 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2007-06-22 02:39 . 2007-06-22 02:39 38472 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2007-06-22 02:39 . 2007-06-22 02:39 46664 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2008-03-29 02:44 . 2008-03-29 02:44 98712 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2007-06-22 02:39 . 2007-06-22 02:39 34376 ----a-w- c:\program files\mozilla firefox\plugins\logging.dll
2007-06-22 02:39 . 2007-06-22 02:39 685640 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2007-06-22 02:40 . 2007-06-22 02:40 30280 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2008-11-18 06:35 . 2008-11-18 06:27 24 --sh--w- c:\windows\S66670E06.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\MCX1\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-11-13 27136]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0>
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlackBerry Desktop Redirector.lnk]
backup=c:\windows\pss\BlackBerry Desktop Redirector.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Extender Resource Monitor.lnk]
backup=c:\windows\pss\Extender Resource Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Program Neighborhood Agent.lnk]
backup=c:\windows\pss\Program Neighborhood Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
backup=c:\windows\pss\Service Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\12cfg515-k641-55sf-n66p
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\12zfg94-f641-2sf-k31p-5n1er6h6l2
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagnostic manager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dr watson32
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ec96556f
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\malware doctor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nzdflkioezncfiunfindiuchiuenfcdc
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrProfiler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrevxOne
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\reader_s
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\shv
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sysldtray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"<NO NAME>"=
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 AladdinUsbFilter;AladdinUsbFilterService;c:\windows\system32\drivers\AladdinUsbFilter.sys [8/22/2008 12:09 AM 484352]
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [12/17/2008 1:04 PM 283520]
R0 MDPMGRNT;MacDrive partition driver;c:\windows\system32\drivers\MDPMGRNT.SYS [12/23/2008 3:15 PM 19456]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [6/1/2009 4:51 AM 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [6/1/2009 4:51 AM 27656]
R1 prevxtdi;PREVX TDI filter;c:\windows\system32\drivers\pxtdi.sys [6/1/2009 4:49 AM 28040]
R2 MacDriveService;MacDrive service;c:\program files\Mediafour\MacDrive 7\MacDriveService.exe [11/26/2008 10:23 AM 150528]
R2 trysftnt;trysftnt;c:\windows\system32\drivers\TRYSFTNT.SYS [8/21/2008 9:34 PM 39136]
S1 13cde429;13cde429;c:\windows\system32\drivers\13cde429.sys --> c:\windows\system32\drivers\13cde429.sys [?]
S1 3c45c201;3c45c201;c:\windows\system32\drivers\3c45c201.sys --> c:\windows\system32\drivers\3c45c201.sys [?]
S1 sasdifsv;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 saskutil;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 csiscanner;CSIScanner; [x]
S3 CH341SER;CH341SER;c:\windows\system32\drivers\CH341SER.SYS [2/24/2008 12:07 PM 35824]
S3 prevxemulator;PREVX Emulator driver;c:\windows\system32\drivers\PxEmu.sys [6/1/2009 4:49 AM 107912]
S3 sasenum;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS --> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder
2009-05-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-06-04 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 22:02]
2009-06-04 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 22:02]
.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-MacDrive Volume Icons - (no file)
SafeBoot-procexp90.sys
MSConfigStartUp-a00f2c6d3561 - (no file)
MSConfigStartUp-a00f2c6df035 - (no file)
MSConfigStartUp-svchost - (no file)
MSConfigStartUp-UfSeAgnt - (no file)
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\74ad0fl7.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7171
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJPI150_14.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npBattlerapPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-04 10:02
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\7291365f]
"ImagePath"="\SystemRoot\System32\drivers\7291365f.sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:74,37,aa,0d,59,26,d9,41,14,89,21,4c,a8,2f,7f,09,af,44,59,dd,e4,
9e,06,7e,8f,29,cb,04,47,c4,f9,b5,54,2b,63,1a,bb,60,b8,47,1d,ae,71,d4,1b,9c,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:74,37,aa,0d,59,26,d9,41,14,89,21,4c,a8,2f,7f,09,af,44,59,dd,e4,
9e,06,7e,8f,29,cb,04,47,c4,f9,b5,54,2b,63,1a,bb,60,b8,47,1d,ae,71,d4,1b,9c,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(624)
c:\windows\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(1884)
c:\program files\Mediafour\MacDrive 7\MDVolumeIcons.dll
c:\program files\Mediafour\MacDrive 7\MACDRAPI.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Citrix\ICA Client\ssonsvr.exe
c:\windows\system32\ati2evxx.exe
c:\windows\arservice.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\spool\drivers\w32x86\3\HPZIPM12.EXE
c:\windows\system32\PSIService.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\ehome\RMSvc.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\ehome\McrdSvc.exe
c:\program files\Zune\ZuneNss.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-04 10:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-04 17:10
Pre-Run: 25,939,533,824 bytes free
Post-Run: 31,212,089,344 bytes free
329 --- E O F --- 2009-05-14 10:03