Okay I did run it a second time and it has worked. Please see log below:
ComboFix 11-10-23.01 - David 23/10/2011 17:32:59.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.767.270 [GMT 1:00]
Running from: c:\documents and settings\David\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\2BB
c:\documents and settings\All Users\Application Data\2BB\{5EA53F4A-210A-44AD-BDEF-A1881C2690DF}.swf
c:\documents and settings\All Users\Favorites\Thumbs.db
c:\documents and settings\David\Application Data\Desktopicon
c:\documents and settings\David\Application Data\Desktopicon\config.ini
c:\documents and settings\David\Application Data\Toolbar4
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\1a06816a192357f4189197196943329e
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\1c76e82ec54cd18a4ded0139fc7b9347
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\26aaf652b3ae60696a4875f485da2f86
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\27c746d432b7a753a0af8d7c033b46fe
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\2b4ad282984708f7b89800e17a257476
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\2bcdd36f73e915f5e3956b0e359e2b94
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\35db787c9ed332998cf35cd592dad718
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\3b194b7303d1532b1f5d39dea9b3ec11
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\44567846e0387d6a62062ab4dbf9ae96
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\52b66d6979ef2abcea9a736d1b4dbc82
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\62bc30f25d3fdeb4649ec65be608739b
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\639a4accf0b15e07ffc3e66029266ccf
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\6f11d3f57222d8d4ba62f45aa5ca79b4
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\757a20d7a75ae93435ac64a6095eab39
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\89c35566d3dfdce78572ff8c2a627ad2
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\9840cd5f73490a37d4f3e47107ced675
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\9956734e872eec3ea3e17f52e84dc6cc
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\9d810aab3f7bcbacb07c241f8d726714
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\acfc834035dccfb94e7f9067f5d48a83
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\c48c9e27c16419ab995d48b077a802ff
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\c594d37e13c887da6ddc9975fa9aae82
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\c99af55cb1bc0fa21b04e4d18edaf729
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\cddda81bc855c2246ff278cf02b589c2
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\dcd16c0f4842bc19d648b261e3cf263d
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\df4570be347a68121d038aa7552d3745
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\fb95fd1b987bd4ffbcb67783e51679ec
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\1dfcc21cb058972d1a78f2572e74c3c9
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\2b1e48aafe5ac3b69f54a1e1e58e8419
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\48799e6132058471ea57d8066e8938b0
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\6cd49849edf124481f2c7d2f2ec60f1f
c:\documents and settings\David\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\8d35ea89b743df255e7e9d41f61f157d
c:\documents and settings\David\WINDOWS
c:\documents and settings\Susan Smart\Application Data\Toolbar4
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\1a06816a192357f4189197196943329e
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\1c76e82ec54cd18a4ded0139fc7b9347
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\27c746d432b7a753a0af8d7c033b46fe
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\2b4ad282984708f7b89800e17a257476
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\2bcdd36f73e915f5e3956b0e359e2b94
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\35db787c9ed332998cf35cd592dad718
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\36eaa177f2d8f2bfa896ffe0bad8da4c
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\44567846e0387d6a62062ab4dbf9ae96
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\52b66d6979ef2abcea9a736d1b4dbc82
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\62bc30f25d3fdeb4649ec65be608739b
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\639a4accf0b15e07ffc3e66029266ccf
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\6f11d3f57222d8d4ba62f45aa5ca79b4
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\757a20d7a75ae93435ac64a6095eab39
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\89c35566d3dfdce78572ff8c2a627ad2
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\9840cd5f73490a37d4f3e47107ced675
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\9956734e872eec3ea3e17f52e84dc6cc
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\9d810aab3f7bcbacb07c241f8d726714
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\acfc834035dccfb94e7f9067f5d48a83
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\c48c9e27c16419ab995d48b077a802ff
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\c594d37e13c887da6ddc9975fa9aae82
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\c99af55cb1bc0fa21b04e4d18edaf729
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\cddda81bc855c2246ff278cf02b589c2
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\dcd16c0f4842bc19d648b261e3cf263d
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\df4570be347a68121d038aa7552d3745
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\cache\fb95fd1b987bd4ffbcb67783e51679ec
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\1dfcc21cb058972d1a78f2572e74c3c9
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\2b1e48aafe5ac3b69f54a1e1e58e8419
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\48799e6132058471ea57d8066e8938b0
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\8d35ea89b743df255e7e9d41f61f157d
c:\documents and settings\Susan Smart\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\include_files\ed9007ba2da4365786024dbbc1251478
c:\program files\Burn4Free DB Toolbar\tbHElper.dll
c:\program files\Common Files\Uninstall
c:\windows\WindowsXP-KB822603-x86.exe
c:\windows\XSxS
.
.
((((((((((((((((((((((((( Files Created from 2011-09-23 to 2011-10-23 )))))))))))))))))))))))))))))))
.
.
2011-10-23 16:02 . 2011-10-23 16:02 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{044C8358-E453-4220-A2C2-3797E6A0EF1A}\offreg.dll
2011-10-23 16:00 . 2011-10-23 16:00 -------- d-sh--w- c:\documents and settings\Administrator.HOME-96DDBCAEEA\IETldCache
2011-10-23 14:43 . 2011-10-23 14:48 -------- d-----w- c:\documents and settings\New
2011-10-22 12:02 . 2007-03-09 10:25 2321288 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-10-22 12:02 . 2011-10-18 01:28 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{044C8358-E453-4220-A2C2-3797E6A0EF1A}\mpengine.dll
2011-10-22 12:02 . 2011-05-24 18:14 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-10-22 11:59 . 2011-10-22 11:59 -------- d-----w- c:\program files\Windows Defender
2011-10-21 19:22 . 2010-07-16 13:59 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2011-10-21 19:22 . 2010-07-16 13:59 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2011-10-21 19:21 . 2010-11-25 09:42 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-10-21 19:21 . 2011-10-23 12:50 -------- d-----w- c:\program files\PC Tools Security
2011-10-21 19:21 . 2011-10-21 19:21 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2011-10-21 19:21 . 2011-10-21 19:21 -------- d-----w- c:\documents and settings\David\Application Data\PC Tools
2011-10-21 18:23 . 2011-10-21 18:23 -------- d-----w- c:\program files\BEARSH~1
2011-10-21 18:11 . 2011-10-22 12:48 -------- d-----w- c:\program files\Enigma Software Group
2011-10-21 18:11 . 2011-10-22 12:45 -------- d-----w- C:\sh4ldr
2011-10-21 18:11 . 2011-10-22 12:44 -------- d-----w- c:\windows\D3F93A5A7A5D4867B2A16F46500D006C.TMP
2011-10-21 18:10 . 2011-10-21 18:10 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-10-20 17:18 . 2011-10-23 15:42 -------- d-----w- c:\program files\Common Files\Research In Motion
2011-10-20 17:18 . 2011-10-22 18:00 -------- d-----w- c:\program files\Research In Motion
2011-10-18 14:30 . 2011-10-18 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2011-10-18 13:45 . 2011-10-03 04:06 476904 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-10-18 13:45 . 2011-10-03 04:06 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-18 13:41 . 2011-10-18 13:41 -------- d-----w- c:\documents and settings\UpdatusUser
2011-10-18 13:41 . 2011-10-18 13:41 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2011-10-18 13:40 . 2011-08-03 11:49 253952 ----a-w- c:\windows\system32\nvrsth.dll
2011-10-18 13:40 . 2011-08-03 11:49 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-10-18 13:39 . 2011-10-18 13:39 280276 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-10-18 13:39 . 2011-10-18 13:39 280276 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-10-18 13:39 . 2011-10-18 13:39 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-10-18 13:38 . 2011-08-03 11:49 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-10-18 13:38 . 2011-08-03 11:49 875112 ----a-w- c:\windows\system32\nvgenco32.dll
2011-10-18 13:38 . 2011-08-03 11:49 914024 ----a-w- c:\windows\system32\nvdispco32.dll
2011-10-18 13:38 . 2011-08-03 11:49 5427200 ----a-w- c:\windows\system32\nvcuda.dll
2011-10-18 13:38 . 2011-08-03 11:49 2387560 ----a-w- c:\windows\system32\nvcuvid.dll
2011-10-18 13:38 . 2011-08-03 11:49 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-10-18 13:38 . 2011-08-03 11:49 17186816 ----a-w- c:\windows\system32\nvcompiler.dll
2011-10-18 13:38 . 2011-10-18 13:41 -------- d-----w- c:\program files\NVIDIA Corporation
2011-10-18 13:31 . 2011-10-20 10:53 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-17 17:28 . 2009-09-02 12:44 626688 ----a-w- c:\windows\system32\vp7vfw.dll
2011-10-17 16:43 . 2011-10-17 16:58 -------- d-----w- C:\My DVD
2011-10-17 16:41 . 2011-10-17 16:41 -------- d-----w- c:\program files\XviD
2011-10-17 16:41 . 2004-07-26 11:12 187904 ----a-w- c:\windows\system32\Lame.exe
2011-10-17 16:41 . 2011-10-17 16:41 641021 ----a-w- c:\windows\unins000.exe
2011-10-17 16:41 . 2004-07-26 11:12 166912 ----a-w- c:\windows\system32\Lame_enc.dll
2011-10-17 16:40 . 2011-10-17 17:31 -------- d-----w- c:\program files\EasyDVDRip
2011-10-16 13:23 . 2010-11-19 17:04 892928 ----a-w- c:\windows\system32\iconv.dll
2011-10-16 13:23 . 2010-11-19 17:04 675840 ----a-w- c:\windows\system32\ac3filter.ax
2011-10-16 13:23 . 2004-12-20 10:10 61440 ----a-w- c:\windows\system32\xvid.ax
2011-10-16 13:23 . 2011-10-16 20:49 -------- d-----w- c:\program files\Wondershare
2011-10-15 14:19 . 2011-10-15 14:19 21361 ----a-w- c:\windows\system32\drivers\AegisP.sys
2011-10-15 14:19 . 2011-10-15 14:19 -------- d-----w- c:\program files\EDIMAX
2011-10-15 14:19 . 2008-07-29 23:44 619136 ----a-w- c:\windows\system32\drivers\rt2870.sys
2011-10-15 14:19 . 2008-07-29 23:43 217088 ----a-w- c:\windows\system32\RaCoInst.dll
2011-10-15 14:19 . 2008-06-15 22:57 4096 ----a-w- c:\windows\system32\drivers\rt2870.bin
2011-10-15 14:19 . 2011-10-15 14:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Edimax Driver
2011-10-12 16:57 . 2011-10-22 12:56 -------- d-----w- c:\documents and settings\David\Application Data\AVG2012
2011-10-12 16:52 . 2011-10-12 16:52 -------- d-----w- c:\documents and settings\Susan Smart\Application Data\AVG2012
2011-10-12 16:50 . 2011-10-22 12:56 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG2012
2011-09-27 09:35 . 2011-09-27 09:35 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Trusteer
2011-09-25 18:00 . 2011-09-25 18:00 56336 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-03 01:37 . 2008-01-30 19:29 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-26 10:41 . 2008-07-29 19:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 2004-08-04 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 10:41 . 2004-08-04 12:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-13 05:30 . 2010-09-07 02:48 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-09-09 09:12 . 2004-08-04 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2004-08-04 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2008-07-22 11:58 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-08 05:08 . 2010-09-07 02:48 40016 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2011-08-03 11:49 . 2007-07-24 10:55 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-08-03 11:49 . 2007-07-24 10:54 4210816 ----a-w- c:\windows\system32\nv4_disp.dll
2011-08-03 11:49 . 2006-10-22 11:22 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-08-03 11:49 . 2006-10-22 11:22 2404864 ----a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:49 . 2006-10-22 11:22 16191488 ----a-w- c:\windows\system32\nvoglnt.dll
2011-08-03 11:49 . 2006-10-22 11:22 146024 ----a-w- c:\windows\system32\nvsvc32.exe
2011-08-03 11:49 . 2006-10-22 11:22 13892200 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:49 . 2006-10-22 11:22 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-10-01 11:24 . 2011-03-23 20:47 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"C-Media Mixer"="Mixer.exe" [2004-08-11 1228800]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]
"NvMediaCenter"="NvMCTray.dll" [2011-08-03 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1632360]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2011-10-15 1601536]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 04:42 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2006-04-09 09:19 634880 ----a-w- c:\program files\Eraser\eraser.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-14 20:17 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 04:42 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 17:36 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemTray]
2004-08-04 12:00 3072 ----a-w- c:\windows\system32\systray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"vsmon"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\BitLord 1.2\\Bitlord files\\bitlord.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [13/09/2010 15:27 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [07/09/2010 03:48 32592]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [14/02/2010 22:42 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [21/10/2011 20:22 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [21/10/2011 20:22 656320]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [08/12/2010 04:12 229840]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [12/11/2010 13:19 295248]
R1 RapportCerberus_32029;RapportCerberus_32029;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\32029\RapportCerberus32_32029.sys [18/10/2011 12:50 227312]
R1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [25/09/2011 19:00 70416]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [25/09/2011 19:00 161936]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [18/10/2011 14:41 2255464]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [25/09/2011 18:59 919352]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [03/08/2010 15:23 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [03/08/2010 15:23 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [03/08/2010 15:23 16720]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\David\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys --> c:\docume~1\David\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [?]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [04/08/2004 13:00 14336]
S3 Pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [22/07/2009 18:31 47360]
S3 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [25/09/2011 19:00 56336]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [13/02/2011 14:13 27064]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [31/07/2009 10:03 86696]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [31/07/2009 10:03 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [31/07/2009 10:03 114472]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [31/07/2009 10:03 108328]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [31/07/2009 10:03 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [31/07/2009 10:03 104616]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [31/07/2009 10:03 109736]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [21/10/2011 20:21 366840]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2011-10-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://www.bigseekpro.com/burn4free/{D5D17671-56EE-4057-99F5-BE822D7EF593}
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*
Yahoo! SearchBar Home Page
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
Trusted Zone: saynoto0870.com\www
TCP: DhcpNameServer = 192.168.1.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\fak05eg6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://www.bigseekpro.com/search/toolbar/burn4free/{D646C6BE-FF2C-4457-B8AB-97DC8B64FD73}?q=
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
user_pref(network.http.accept.default,text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5,application/x-tsmxml);
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
MSConfigStartUp-PCSuiteTrayApplication - c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_07\bin\jusched.exe
MSConfigStartUp-WinUtilities Memory Optimizer - c:\program files\WinUtilities\ToolMemoryOptimizer.exe
MSConfigStartUp-ZoneAlarm Client - c:\program files\Zone Labs\ZoneAlarm\zlclient.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2011-10-23 17:45
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(796)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
Completion time: 2011-10-23 17:49:42
ComboFix-quarantined-files.txt 2011-10-23 16:49
.
Pre-Run: 16,207,069,184 bytes free
Post-Run: 16,710,262,784 bytes free
.
- - End Of File - - 9218F1D01E0C142CE0DD2827C63DF946