Hi Gecko
Sorry for delay in replying - been away a few days.
I followed your instructions - downloaded and ran ComboFix, then downloaded updated and ran Malwarebytes [logs of both below].
Upon running ComboFix, an alert told me to disable NOD32 - I couldn't figure out a sure way of doing this [NOD32 wasn't supposed to be running at all, though it is my resident virus checker], so I just uninstalled it for now. Once this was done and registry cleaned, I clicked the 'OK' box for ComboFix to continue. The uninstallation process of NOD32 advised that a reboot was necessary, but I told it not to at that point to allow ComboFix to continue.
ComboFix said 'Windows Recovery Console' not installed, so I allowed it to download and succsesfully install.
I then ran Malwarebytes which came up with 14 suspected infections, which I assume you can see from the log. You did not say if I should 'Remove Selected', so for the moment I have left it in that state.
I will leave the computer and Malwarebytes on until you come back to me. Cheers for your help so far.
ComboFix 12-04-05.04 - Richard 05/04/2012 12:08:23.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2640 [GMT 1:00]
Running from: c:\documents and settings\Richard\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\DragToDiscUserNameE.txt
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
c:\documents and settings\Richard\Desktop\Setup.exe
c:\documents and settings\Richard\GZsfEIVz2
c:\documents and settings\Richard\Local Settings\Application Data\apnloiwf.log
c:\documents and settings\Richard\Local Settings\Application Data\hpgxdkkq.log
c:\documents and settings\Richard\Local Settings\Application Data\igklykrn.log
c:\documents and settings\Richard\Local Settings\Application Data\jgabwruh.log
c:\documents and settings\Richard\Local Settings\Application Data\mybsidbl.log
c:\documents and settings\Richard\Local Settings\Application Data\tieywave.log
c:\documents and settings\Richard\Local Settings\Application Data\vbuvjyah.log
c:\documents and settings\Richard\My Documents\~WRL0004.tmp
c:\documents and settings\Richard\WINDOWS
C:\sooi832.bin
c:\sooi832.bin\0325C0D55867C47
c:\sooi832.bin\CA0A4982943.exe
c:\windows\iun6002.exe
c:\windows\MTUn4572.exe
c:\windows\SET10EB.tmp
c:\windows\SETBE8.tmp
c:\windows\system32\ClientSyncLoader.htm
c:\windows\system32\ClientSyncLoaderDriver.htm
c:\windows\system32\html
c:\windows\system32\html\blank.htm
c:\windows\system32\html\bot.htm
c:\windows\system32\html\innerframeset.htm
c:\windows\system32\html\left.htm
c:\windows\system32\html\main.htm
c:\windows\system32\html\middle.htm
c:\windows\system32\html\rightframeset.htm
c:\windows\system32\html\top.htm
c:\windows\system32\html\website.htm
c:\windows\system32\images
c:\windows\system32\images\3models.gif
c:\windows\system32\images\but3_off.gif
c:\windows\system32\images\but3_on.gif
c:\windows\system32\images\main_bot.gif
c:\windows\system32\images\main_mid.gif
c:\windows\system32\images\main_top.gif
c:\windows\system32\images\model1.gif
c:\windows\system32\images\panel_bot.gif
c:\windows\system32\images\panel_top.gif
c:\windows\system32\images\pc.gif
c:\windows\system32\images\pcw_award_cover.gif
c:\windows\system32\images\pcwcover.gif
c:\windows\system32\images\Thumbs.db
c:\windows\system32\images\topoff.gif
c:\windows\system32\images\topon.gif
c:\windows\system32\images\webscreen.gif
c:\windows\system32\SET1009.tmp
c:\windows\system32\SET100D.tmp
c:\windows\system32\SET100F.tmp
c:\windows\system32\SET1010.tmp
c:\windows\system32\SET1011.tmp
c:\windows\system32\SET101B.tmp
c:\windows\system32\SET101F.tmp
c:\windows\system32\SET1024.tmp
c:\windows\system32\SET102A.tmp
c:\windows\system32\SET103A.tmp
c:\windows\system32\SET103B.tmp
c:\windows\system32\SET105A.tmp
c:\windows\system32\SET105D.tmp
c:\windows\system32\SET1060.tmp
c:\windows\system32\SET1065.tmp
c:\windows\system32\SET1067.tmp
c:\windows\system32\SET106E.tmp
c:\windows\system32\SET106F.tmp
c:\windows\system32\SET1070.tmp
c:\windows\system32\SET1072.tmp
c:\windows\system32\SET1073.tmp
c:\windows\system32\SET1074.tmp
c:\windows\system32\SET1077.tmp
c:\windows\system32\SET1079.tmp
c:\windows\system32\SET107A.tmp
c:\windows\system32\SET107C.tmp
c:\windows\system32\SET107F.tmp
c:\windows\system32\SET1081.tmp
c:\windows\system32\SET1086.tmp
c:\windows\system32\SET1087.tmp
c:\windows\system32\SET108F.tmp
c:\windows\system32\SET1096.tmp
c:\windows\system32\SET109B.tmp
c:\windows\system32\SET109E.tmp
c:\windows\system32\SET10A1.tmp
c:\windows\system32\SET10A3.tmp
c:\windows\system32\SET10A7.tmp
c:\windows\system32\SET10A9.tmp
c:\windows\system32\SET10AA.tmp
c:\windows\system32\SET10AB.tmp
c:\windows\system32\SET10AE.tmp
c:\windows\system32\SET10AF.tmp
c:\windows\system32\SET10B3.tmp
c:\windows\system32\SET10B4.tmp
c:\windows\system32\SET10B7.tmp
c:\windows\system32\SET10B9.tmp
c:\windows\system32\SET10BF.tmp
c:\windows\system32\SET10C2.tmp
c:\windows\system32\SET10C4.tmp
c:\windows\system32\SET10C7.tmp
c:\windows\system32\SET10CA.tmp
c:\windows\system32\SET10CC.tmp
c:\windows\system32\SET185B.tmp
c:\windows\system32\SET1863.tmp
c:\windows\system32\SET1867.tmp
c:\windows\system32\SET186E.tmp
c:\windows\system32\SET1895.tmp
c:\windows\system32\SET18B9.tmp
c:\windows\system32\SET1D5D.tmp
c:\windows\system32\SET1D65.tmp
c:\windows\system32\SET1D69.tmp
c:\windows\system32\SET1D70.tmp
c:\windows\system32\SET1D95.tmp
c:\windows\system32\SET1D97.tmp
c:\windows\system32\SET1DBB.tmp
c:\windows\system32\SET44.tmp
c:\windows\system32\SET50.tmp
c:\windows\system32\SET8A2.tmp
c:\windows\system32\SET8A3.tmp
c:\windows\system32\SET8A5.tmp
c:\windows\system32\SET8A7.tmp
c:\windows\system32\SET8A9.tmp
c:\windows\system32\SET8B0.tmp
c:\windows\system32\SET8B1.tmp
c:\windows\system32\SET8B4.tmp
c:\windows\system32\SET8B9.tmp
c:\windows\system32\SET8BA.tmp
c:\windows\system32\SET8BB.tmp
c:\windows\system32\SET8BD.tmp
c:\windows\system32\SET8BE.tmp
c:\windows\system32\SET8BF.tmp
c:\windows\system32\SET8C0.tmp
c:\windows\system32\SET8C1.tmp
c:\windows\system32\SET8C3.tmp
c:\windows\system32\SET8C4.tmp
c:\windows\system32\SET8C5.tmp
c:\windows\system32\SET8C6.tmp
c:\windows\system32\SET8C9.tmp
c:\windows\system32\SET8D0.tmp
c:\windows\system32\SET8D09.tmp
c:\windows\system32\SET8D1.tmp
c:\windows\system32\SET8D2.tmp
c:\windows\system32\SET8D3.tmp
c:\windows\system32\SET8D6.tmp
c:\windows\system32\SET8D8.tmp
c:\windows\system32\SET8DA.tmp
c:\windows\system32\SET8E1.tmp
c:\windows\system32\SET8E4.tmp
c:\windows\system32\SET8E5.tmp
c:\windows\system32\SET8E7.tmp
c:\windows\system32\SET8E8.tmp
c:\windows\system32\SET8E9.tmp
c:\windows\system32\SET8EC.tmp
c:\windows\system32\SET8EE.tmp
c:\windows\system32\SET8EF.tmp
c:\windows\system32\SET8F0.tmp
c:\windows\system32\SET8F1.tmp
c:\windows\system32\SET8F2.tmp
c:\windows\system32\SET8F8.tmp
c:\windows\system32\SET8FD.tmp
c:\windows\system32\SET8FE.tmp
c:\windows\system32\SET902.tmp
c:\windows\system32\SET905.tmp
c:\windows\system32\SET906.tmp
c:\windows\system32\SET90D.tmp
c:\windows\system32\SET90E.tmp
c:\windows\system32\SET911.tmp
c:\windows\system32\SET915.tmp
c:\windows\system32\SET91E.tmp
c:\windows\system32\SET91F.tmp
c:\windows\system32\SET922.tmp
c:\windows\system32\SET925.tmp
c:\windows\system32\SET926.tmp
c:\windows\system32\SET927.tmp
c:\windows\system32\SET928.tmp
c:\windows\system32\SET929.tmp
c:\windows\system32\SET939.tmp
c:\windows\system32\SET93E.tmp
c:\windows\system32\SET940.tmp
c:\windows\system32\SET942.tmp
c:\windows\system32\SET943.tmp
c:\windows\system32\SET944.tmp
c:\windows\system32\SET945.tmp
c:\windows\system32\SET947.tmp
c:\windows\system32\SET948.tmp
c:\windows\system32\SET94C.tmp
c:\windows\system32\SET94D.tmp
c:\windows\system32\SET951.tmp
c:\windows\system32\SET952.tmp
c:\windows\system32\SET958.tmp
c:\windows\system32\SET959.tmp
c:\windows\system32\SET95A.tmp
c:\windows\system32\SET961.tmp
c:\windows\system32\SET962.tmp
c:\windows\system32\SET968.tmp
c:\windows\system32\SET969.tmp
c:\windows\system32\SET96A.tmp
c:\windows\system32\SET96D.tmp
c:\windows\system32\SET97.tmp
c:\windows\system32\SET973.tmp
c:\windows\system32\SET97F.tmp
c:\windows\system32\SET981.tmp
c:\windows\system32\SET983.tmp
c:\windows\system32\SET984.tmp
c:\windows\system32\SET985.tmp
c:\windows\system32\SET988.tmp
c:\windows\system32\SET990.tmp
c:\windows\system32\SET992.tmp
c:\windows\system32\SET993.tmp
c:\windows\system32\SET996.tmp
c:\windows\system32\SET998.tmp
c:\windows\system32\SET99C.tmp
c:\windows\system32\SET9AD.tmp
c:\windows\system32\SET9AE.tmp
c:\windows\system32\SET9AF.tmp
c:\windows\system32\SET9B6.tmp
c:\windows\system32\SET9B7.tmp
c:\windows\system32\SET9BA.tmp
c:\windows\system32\SET9BB.tmp
c:\windows\system32\SET9BC.tmp
c:\windows\system32\SET9BD.tmp
c:\windows\system32\SET9BE.tmp
c:\windows\system32\SET9C0.tmp
c:\windows\system32\SET9C1.tmp
c:\windows\system32\SET9C2.tmp
c:\windows\system32\SET9C4.tmp
c:\windows\system32\SET9C5.tmp
c:\windows\system32\SET9C6.tmp
c:\windows\system32\SET9C9.tmp
c:\windows\system32\SET9CC.tmp
c:\windows\system32\SET9D1.tmp
c:\windows\system32\SET9D2.tmp
c:\windows\system32\SET9D3.tmp
c:\windows\system32\SET9D8.tmp
c:\windows\system32\SET9D9.tmp
c:\windows\system32\SET9DA.tmp
c:\windows\system32\SET9DC.tmp
c:\windows\system32\SETA00.tmp
c:\windows\system32\SETA02.tmp
c:\windows\system32\SETA03.tmp
c:\windows\system32\SETA06.tmp
c:\windows\system32\SETA07.tmp
c:\windows\system32\SETA0A.tmp
c:\windows\system32\SETA0D.tmp
c:\windows\system32\SETA0E.tmp
c:\windows\system32\SETA10.tmp
c:\windows\system32\SETA15.tmp
c:\windows\system32\SETA17.tmp
c:\windows\system32\SETA1A.tmp
c:\windows\system32\SETA1E.tmp
c:\windows\system32\SETA1F.tmp
c:\windows\system32\SETA20.tmp
c:\windows\system32\SETA21.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-03-05 to 2012-04-05 )))))))))))))))))))))))))))))))
.
.
2017-08-17 16:06 . 2017-08-17 16:06 -------- d-----w- c:\program files\proDAD
2012-03-30 13:12 . 2012-03-30 13:12 1409 ----a-w- c:\windows\QTFont.for
2012-03-29 14:02 . 2012-03-29 14:35 226304 ---ha-w- c:\windows\system32\GZsfEIVz2
2012-03-29 13:41 . 2012-03-29 13:41 -------- d-----w- c:\documents and settings\Richard\Application Data\iZotope
2012-03-29 12:36 . 2012-03-29 12:36 388096 ----a-r- c:\documents and settings\Richard\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-03-29 12:36 . 2012-03-29 12:36 -------- d-----w- c:\program files\Trend Micro
2012-03-28 13:29 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2012-03-28 13:28 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2012-03-28 13:24 . 2008-04-14 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2012-03-28 13:24 . 2008-04-14 12:00 81920 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2012-03-28 11:03 . 2001-08-17 21:36 38912 -c--a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2012-03-28 11:02 . 2008-04-14 12:00 18944 -c--a-w- c:\windows\system32\dllcache\cprofile.exe
2012-03-28 10:59 . 2008-04-14 12:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2012-03-28 10:59 . 2008-04-14 12:00 16384 ----a-w- c:\program files\Internet Explorer\Connection Wizard\isignup.exe
2012-03-28 10:32 . 2008-04-14 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2012-03-28 10:32 . 2008-04-14 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2012-03-28 10:32 . 2008-04-14 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2012-03-28 10:32 . 2008-04-14 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2012-03-28 10:32 . 2008-04-14 12:00 16535 ----a-r- c:\windows\SET16A.tmp
2012-03-28 10:31 . 2008-04-14 12:00 1088840 ----a-r- c:\windows\SET15E.tmp
2012-03-28 10:31 . 2008-04-14 12:00 1296669 ----a-r- c:\windows\SET15B.tmp
2012-03-27 02:11 . 2012-03-27 02:11 -------- d-----w- C:\i386
2012-03-17 17:36 . 2012-03-17 18:22 -------- d-----w- c:\documents and settings\Richard\Local Settings\Application Data\xilqrlve
2012-03-17 16:54 . 2012-03-17 16:54 592824 ----a-w- c:\program files\Mozilla Firefox\gkmedias.dll
2012-03-17 16:54 . 2012-03-17 16:54 44472 ----a-w- c:\program files\Mozilla Firefox\mozglue.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-25 17:27 . 2011-05-23 17:34 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-03 09:22 . 2008-04-14 12:00 1860096 ----a-w- c:\windows\system32\win32k.sys
2012-02-02 19:03 . 2012-02-02 19:07 8192 ----a-w- c:\windows\system32\E_DCINST.DLL
2012-02-02 19:03 . 2012-02-02 19:07 93696 ----a-w- c:\windows\system32\E_FLBHLE.DLL
2012-02-02 19:03 . 2012-02-02 19:07 63488 ----a-w- c:\windows\system32\E_FD4BHLE.DLL
2012-01-11 19:06 . 2012-02-15 11:43 3072 ------w- c:\windows\system32\iacenc.dll
2012-01-09 16:20 . 2008-11-05 03:10 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-17 16:54 . 2012-01-29 23:51 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2006-05-03 10:06 163328 --sha-r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 31232 --sha-r- c:\windows\system32\msfDX.dll
2007-12-17 13:43 27648 --sha-w- c:\windows\system32\Smab0.dll
2008-02-04 19:26 151040 --sha-w- c:\windows\system32\VistaUltm.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2011-12-19 . 21F8FEBD157A8A6BF7F0FB826111148A . 3087872 . . [6.00.2900.6182] . . c:\windows\SoftwareDistribution\Download\796a0f15940e7ad65a72532d85ac77d3\SP3QFE\mshtml.dll
[-] 2011-12-19 . 8DE666A743F3B961892338A2E15EA702 . 3087360 . . [6.00.2900.6182] . . c:\windows\SoftwareDistribution\Download\796a0f15940e7ad65a72532d85ac77d3\SP3GDR\mshtml.dll
[-] 2011-12-17 . A9259CD226283CD4F798C00909754A94 . 5979136 . . [8.00.6001.19190] . . c:\windows\SoftwareDistribution\Download\c1d540600ba9c34c5b3244c020eee491\SP3GDR\mshtml.dll
[-] 2011-12-17 . 49B88A833ECA99EFBFFC5AAE5CC998ED . 5980160 . . [8.00.6001.23286] . . c:\windows\$hf_mig$\KB2647516-IE8\SP3QFE\mshtml.dll
[-] 2011-12-17 . 49B88A833ECA99EFBFFC5AAE5CC998ED . 5980160 . . [8.00.6001.23286] . . c:\windows\SoftwareDistribution\Download\c1d540600ba9c34c5b3244c020eee491\SP3QFE\mshtml.dll
[-] 2011-11-04 . DD8D655E1881B70A5259A23A6018A6C2 . 5978112 . . [8.00.6001.19170] . . c:\windows\ie8updates\KB2647516-IE8\mshtml.dll
[-] 2011-11-04 . DD8D655E1881B70A5259A23A6018A6C2 . 5978112 . . [8.00.6001.19170] . . c:\windows\SoftwareDistribution\Download\a6632ea9734d3683d8cc4b4a30215873\SP3GDR\mshtml.dll
[-] 2011-11-04 . 699421E2E1313C18671A703953CAE14B . 5978624 . . [8.00.6001.23266] . . c:\windows\$hf_mig$\KB2618444-IE8\SP3QFE\mshtml.dll
[-] 2011-11-04 . 699421E2E1313C18671A703953CAE14B . 5978624 . . [8.00.6001.23266] . . c:\windows\SoftwareDistribution\Download\a6632ea9734d3683d8cc4b4a30215873\SP3QFE\mshtml.dll
[-] 2011-10-03 . 4963CB503600FC3BCBDBFBA51FBA1FAC . 5971456 . . [8.00.6001.19154] . . c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
[-] 2011-10-03 . 1240A6B7B470BED0AA6C9FEC7AB0EA26 . 5972992 . . [8.00.6001.23250] . . c:\windows\$hf_mig$\KB2586448-IE8\SP3QFE\mshtml.dll
[-] 2010-12-20 . 61FF8ABD55DBD6453B7DD81F6DD2D966 . 3078144 . . [6.00.2900.6058] . . c:\windows\$hf_mig$\KB2482017\SP3QFE\mshtml.dll
[-] 2010-11-05 . 17762D2C4468FF99EF33F597F9D34E6F . 3076608 . . [6.00.2900.6049] . . c:\windows\$hf_mig$\KB2416400\SP3QFE\mshtml.dll
[-] 2010-09-09 . 575FBCB3E2C6E848F0386F38AAF0E4ED . 3074560 . . [6.00.2900.6036] . . c:\windows\$hf_mig$\KB2360131\SP3QFE\mshtml.dll
[-] 2010-06-24 . E833C8A9918DA80DBE80ABD2917B9292 . 3073536 . . [6.00.2900.6003] . . c:\windows\$hf_mig$\KB2183461\SP3QFE\mshtml.dll
[-] 2010-05-06 . C7B7A88CC7D7ABA5C395145BF92F46F7 . 5950976 . . [8.00.6001.18928] . . c:\windows\SoftwareDistribution\Download\e9e3bc7b49018c1f53cc0d1bd73cad37\SP3GDR\mshtml.dll
[-] 2010-05-06 . 9BE28F749A7FE7F8F177C6AA2E9DA609 . 5953024 . . [8.00.6001.23019] . . c:\windows\SoftwareDistribution\Download\e9e3bc7b49018c1f53cc0d1bd73cad37\SP3QFE\mshtml.dll
[-] 2010-04-16 . 9574D5B0C784DA0FD8F6A9BB37936A52 . 3073536 . . [6.00.2900.5969] . . c:\windows\$hf_mig$\KB982381\SP3QFE\mshtml.dll
[-] 2010-02-26 . EE6B9880933172AE78A1146BE15D6D21 . 3073536 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3QFE\mshtml.dll
[-] 2009-12-22 . A758F0891A87EE005848A0BC740A5B96 . 3071488 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3GDR\mshtml.dll
[-] 2009-12-22 . AD17006339C1934D86449F335C241FF1 . 3073536 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\mshtml.dll
[-] 2009-10-29 . D1CF72C34BAF70C52797D1CB78D6EE92 . 3070976 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3GDR\mshtml.dll
[-] 2009-10-29 . DA551BFEC150760A38A9AD0C95A8A71C . 3073024 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\mshtml.dll
[-] 2009-10-29 . F3A9E882DF2F155C9395979FF9D7B0A7 . 3070976 . . [6.00.2900.3640] . . c:\windows\$NtUninstallKB978207_0$\mshtml.dll
[-] 2009-09-25 . 601E18A9A8F0D0ED39692B593212378F . 3070976 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3GDR\mshtml.dll
[-] 2009-09-25 . 37F578776552FA076EA6085F0365209C . 3072512 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\mshtml.dll
[-] 2009-04-29 . ABD8093E43E53AEA5898D2214B92E9BA . 3068928 . . [6.00.2900.5803] . . c:\windows\$hf_mig$\KB969897\SP3GDR\mshtml.dll
[-] 2009-04-29 . 06CF679E3D24C3DF270556456A0F1EDA . 3069440 . . [6.00.2900.5803] . . c:\windows\$hf_mig$\KB969897\SP3QFE\mshtml.dll
[-] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB2586448-IE8\mshtml.dll
[-] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\system32\mshtml.dll
[-] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\mshtml.dll
[-] 2009-02-20 . 2F70F2F74C40397D031016FA162981C2 . 3068416 . . [6.00.2900.5764] . . c:\windows\$hf_mig$\KB963027\SP3GDR\mshtml.dll
[-] 2009-02-20 . 1618A4A2C5DD8164B8295190C8EA6544 . 3068416 . . [6.00.2900.5764] . . c:\windows\$hf_mig$\KB963027\SP3QFE\mshtml.dll
[-] 2008-12-12 . 6D1D493622EA050DBAABD0C4C1DFADB5 . 3067392 . . [6.00.2900.3492] . . c:\windows\$NtUninstallKB963027_0$\mshtml.dll
[-] 2008-12-12 . B6DAA74E2ED36C71B502945589A683AE . 3067904 . . [6.00.2900.5726] . . c:\windows\$hf_mig$\KB960714\SP3QFE\mshtml.dll
[-] 2008-12-12 . C828AA1C5469E72251F3D367005E589F . 3067904 . . [6.00.2900.5726] . . c:\windows\$hf_mig$\KB960714\SP3GDR\mshtml.dll
[-] 2008-10-16 . CC5A2205D37AE67CE23AB7FD3E1FDACA . 3067904 . . [6.00.2900.5694] . . c:\windows\$hf_mig$\KB958215\SP3QFE\mshtml.dll
[-] 2008-10-16 . B846C2DE341CF32B42AD297437233742 . 3067904 . . [6.00.2900.5694] . . c:\windows\$hf_mig$\KB958215\SP3GDR\mshtml.dll
[-] 2008-08-20 . 20D44D1A5A406CD8E129D3D4F0B5717C . 3067392 . . [6.00.2900.3429] . . c:\windows\$NtUninstallKB960714_0$\mshtml.dll
[-] 2008-08-20 . 507BDA42F7DB8209C0F0B3556A043491 . 3067904 . . [6.00.2900.5659] . . c:\windows\$hf_mig$\KB956390\SP3GDR\mshtml.dll
[-] 2008-08-20 . BD45470B132A0F98596277323D9F2E5A . 3067904 . . [6.00.2900.5659] . . c:\windows\$hf_mig$\KB956390\SP3QFE\mshtml.dll
[-] 2008-06-25 . 04EEC0FF4DD3C7041628973CA6832C33 . 3067904 . . [6.00.2900.5626] . . c:\windows\$hf_mig$\KB953838\SP3QFE\mshtml.dll
[-] 2008-06-23 . 1FC693A4EE1D9D9CD78DDA6C87232F6F . 3067392 . . [6.00.2900.3395] . . c:\windows\$NtUninstallKB956390_0$\mshtml.dll
[-] 2008-06-23 . F433136C23D13B120412B300D1324A7E . 3067392 . . [6.00.2900.5626] . . c:\windows\$hf_mig$\KB953838\SP3GDR\mshtml.dll
[-] 2008-04-21 . 083B967E6B0B2BB539CE6B08D45D631F . 3066880 . . [6.00.2900.3354] . . c:\windows\$NtUninstallKB953838_0$\mshtml.dll
[-] 2008-04-21 . FE406DE0651C9E8201DCB0460609D739 . 3066880 . . [6.00.2900.5583] . . c:\windows\$hf_mig$\KB950759\SP3GDR\mshtml.dll
[-] 2008-04-21 . 46A61BA430110F00DD990D058AA3D054 . 3067392 . . [6.00.2900.5583] . . c:\windows\$hf_mig$\KB950759\SP3QFE\mshtml.dll
[7] 2008-04-14 . A706E122B398FE1AB85CB9B75D044223 . 3066880 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\mshtml.dll
[-] 2008-02-16 . 701A6798DDF875CAA3A5099EE75FD57F . 3066880 . . [6.00.2900.3314] . . c:\windows\$NtUninstallKB950759_0$\mshtml.dll
[-] 2007-12-07 . 8A4DD074DEC1B0C063C8493ABF654CBC . 3066368 . . [6.00.2900.3268] . . c:\windows\$NtUninstallKB947864$\mshtml.dll
[-] 2007-02-20 . 2991727809C7AC3A33E4178CC73244D8 . 3063296 . . [6.00.2900.3086] . . c:\windows\$NtUninstallKB944533$\mshtml.dll
[-] 2007-01-04 . 1C45525574EF206346FBAFCAAC7CC4A5 . 3062272 . . [6.00.2900.3059] . . c:\windows\$NtUninstallKB931768$\mshtml.dll
[-] 2006-10-23 . 88E1C15BB1A9ED3CBA4D6F2F408D5010 . 3061248 . . [6.00.2900.3020] . . c:\windows\$NtUninstallKB928090$\mshtml.dll
[-] 2006-09-14 . CEFEA1C301139A817931BE132F0359FE . 3058688 . . [6.00.2900.2995] . . c:\windows\$NtUninstallKB925454$\mshtml.dll
[-] 2006-07-28 . D251679BD9EF0250201FB899EC40FD32 . 3058176 . . [6.00.2900.2963] . . c:\windows\$NtUninstallKB922760$\mshtml.dll
[-] 2006-05-19 . 8687E029BE63C77D4919485068C54D77 . 3055104 . . [6.00.2900.2912] . . c:\windows\$NtUninstallKB918899$\mshtml.dll
[-] 2006-03-23 . ABCD123F888E4E97C8751378CCCC4F26 . 3055616 . . [6.00.2900.2873] . . c:\windows\$NtUninstallKB916281$\mshtml.dll
[-] 2005-10-05 . 3394299FBF1CD0B24089FC762611360B . 3017728 . . [6.00.2900.2769] . . c:\windows\$hf_mig$\KB896688\SP2QFE\mshtml.dll
[-] 2005-10-04 . 042AC20E084D21DD6BEE99B89CC30FB7 . 3015168 . . [6.00.2900.2769] . . c:\windows\$NtUninstallKB912812$\mshtml.dll
[-] 2004-08-04 . 376E0843B2356CA91CEC8D9837A56FF7 . 3003392 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB896688$\mshtml.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
.
c:\documents and settings\Richard\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\acaptuser32.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^blueyonder Instant Support Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\blueyonder Instant Support Tool.lnk
backup=c:\windows\pss\blueyonder Instant Support Tool.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2010-09-22 18:11 640440 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2011-09-07 14:53 40376 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\amd_dc_opt]
2007-07-23 11:06 180224 ----a-w- c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
2003-06-18 00:00 45056 ----a-w- c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
2006-12-12 09:46 19456 ----a-w- c:\windows\system32\CtHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
2006-12-12 09:46 20480 ----a-w- c:\windows\system32\Ctxfihlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
2006-05-22 13:26 694272 ----a-w- c:\program files\dvd43\DVD43_Tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 18:36 30040 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
2009-05-14 09:45 33624064 ----a-r- c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 15:24 54840 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
2006-07-13 05:22 57344 ----a-w- c:\program files\Lexmark 1200 Series\lxczbmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
2005-09-22 08:05 438359 ----a-w- c:\progra~1\BLUEYO~1\SMARTB~1\blueyonder-istnotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-16 22:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 16:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-10-16 11:04 13851752 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-10-16 11:04 110696 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2005-01-14 18:21 110744 ----a-w- c:\program files\CyberLink\PowerCinema\PCMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
2004-03-10 14:26 406016 ----a-w- c:\windows\system32\PSDrvCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
2005-03-23 14:34 1630303 ----a-w- c:\program files\CyberLink\Power2Go\Power2GoExpress.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ptipbmf]
2003-06-20 14:06 118784 ----a-w- c:\windows\system32\ptipbmf.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-12-11 10:56 286720 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RCSystem]
2005-06-16 17:25 49152 ----a-w- c:\program files\Creative\Shared Files\Module Loader\DLLML.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 13:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2005-11-25 09:19 151597 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 00:00 90112 ----a-w- c:\windows\Updreg.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
2005-07-11 10:34 122880 ----a-w- c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{1290A33C-85F5-4164-A1BE-7DD299D4986A}]
2004-06-08 18:33 69721 ----a-w- c:\program files\CyberLink\PowerBackup\PBKScheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=2 (0x2)
"PnkBstrB"=2 (0x2)
"PnkBstrA"=2 (0x2)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"LexBceS"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"CyberLink Media Library Service"=2 (0x2)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
"Adobe LM Service"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerCinema\\PowerCinema.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Avid\\Avid Liquid 7\\Program\\RM.exe"=
"c:\\Program Files\\Avid\\Avid Liquid 7\\Program\\StudioU.mod"=
"c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Ubisoft\\Crytek\\Far Cry\\Bin32\\FarCry.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26/04/2006 23:48 642560]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 11:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [17/02/2010 11:15 66632]
R3 Pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/07/2006 22:44 47360]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [31/03/2010 13:58 1358720]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [25/07/2006 15:56 16512]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [01/04/2010 16:38 79360]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [04/06/2009 02:46 171032]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [04/06/2009 02:46 171032]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [04/06/2009 02:46 1324056]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [04/06/2009 02:46 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [04/06/2009 02:46 72728]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [04/06/2009 02:46 72728]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [17/02/2010 11:15 12872]
S4 m5287;m5287;c:\windows\system32\drivers\m5287.sys [25/11/2005 17:44 85888]
S4 m5289;m5289;c:\windows\system32\drivers\m5289.sys [25/11/2005 17:44 51840]
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-04-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-716800117-3360742898-1720601440-1006Core.job
- c:\documents and settings\Richard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-02 18:00]
.
2012-04-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-716800117-3360742898-1720601440-1006UA.job
- c:\documents and settings\Richard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-02 18:00]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.co.uk/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Tiscali Internet Access
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Download all with Free Download Manager -
file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager -
file://c:\program files\Free Download Manager\dlselected.htm
IE: Download web site with Free Download Manager -
file://c:\program files\Free Download Manager\dlpage.htm
IE: Download with Free Download Manager -
file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Richard\Application Data\Mozilla\Firefox\Profiles\6i2xrjmt.default\
FF - prefs.js: browser.startup.homepage -
hxxp://en-GB.start.mozilla.com/firefox? ... B:official.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-UJ7J2I3X8GVFVFXER - c:\sooi832.bin\CA0A4982943.exe
MSConfigStartUp-egui - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
AddRemove-MadTracker 2 - c:\windows\MTUn4572.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-04-05 12:21
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-716800117-3360742898-1720601440-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-716800117-3360742898-1720601440-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0561C98C-9C16-1528-CD53-D97A84E0A2A9}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iagieijlkfgcacekbi"=hex:6b,61,64,6a,62,6a,6f,62,6b,61,6f,63,62,61,66,6c,6e,6b,
6f,6b,70,6b,00,00
"haeihkmblmajfidb"=hex:6b,61,63,6a,67,67,65,6a,6b,6c,6f,69,6d,67,6f,67,62,65,
69,68,6e,61,00,00
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(936)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
- - - - - - - > 'explorer.exe'(2196)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\windows\system32\CTsvcCDA.EXE
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\wscntfy.exe
c:\windows\SYSTEM32\CTXFISPI.EXE
.
**************************************************************************
.
Completion time: 2012-04-05 12:30:21 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-05 11:30
ComboFix2.txt 2008-12-23 16:13
.
Pre-Run: 19,649,327,104 bytes free
Post-Run: 20,385,021,952 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - F89FE7ACB09BB4DA153E29B092A0BFBC
--------------------------------------------------Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.orgDatabase version: v2012.04.05.04
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 6.0.2900.5512
Richard :: RAPSCALLION [administrator]
05/04/2012 12:38:02
mbam-log-2012-04-05 (17-26-50).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 657553
Time elapsed: 2 hour(s), 57 minute(s), 14 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 14
C:\Program Files\Acoustica CD Label Maker\GZsfEIVz2 (Virus.Ramnit) -> No action taken.
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\GZsfEIVz2 (Virus.Ramnit) -> No action taken.
C:\Program Files\Mozilla Firefox\GZsfEIVz2 (Virus.Ramnit) -> No action taken.
C:\Program Files\Avid\Avid Liquid 7\Program\GZsfEIVz2 (Virus.Ramnit) -> No action taken.
C:\Qoobox\Quarantine\C\Documents and Settings\Richard\GZsfEIVz2.vir (Virus.Ramnit) -> No action taken.
C:\System Volume Information\_restore{54C7A4C0-672A-400F-89D3-264781F4E928}\RP13\A0005903.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{54C7A4C0-672A-400F-89D3-264781F4E928}\RP15\A0006035.exe (Trojan.Agent.CK) -> No action taken.
C:\System Volume Information\_restore{54C7A4C0-672A-400F-89D3-264781F4E928}\RP2\A0001066.exe (Trojan.SpyEyes.H) -> No action taken.
C:\System Volume Information\_restore{54C7A4C0-672A-400F-89D3-264781F4E928}\RP5\A0004028.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{54C7A4C0-672A-400F-89D3-264781F4E928}\RP9\A0005263.exe (Trojan.SpyEyes.H) -> No action taken.
C:\WINDOWS\system32\GZsfEIVz2 (Virus.Ramnit) -> No action taken.
C:\Documents and Settings\Richard\Desktop\GABLE\GZsfEIVz2 (Virus.Ramnit) -> No action taken.
C:\Documents and Settings\Richard\Desktop\ORGANIZING\SOUND&MUSIC\GZsfEIVz2 (Virus.Ramnit) -> No action taken.
C:\Documents and Settings\Richard\Desktop\ORGANIZING\TOOLS\GZsfEIVz2 (Virus.Ramnit) -> No action taken.
(end)