here is the combo fix notepad file
ComboFix 09-07-14.07 - ensign 07/14/2009 21:19.3.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.2045.1303 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 )))))))))))))))))))))))))))))))
.
2009-07-14 14:23 . 2009-07-14 17:38 ——– d—–w- c:\users\ensign\AppData\Local\Adobe
2009-07-12 00:54 . 2009-07-12 00:55 ——– d—–w- c:\program files\Windows Live Safety Center
2009-07-09 21:36 . 2009-07-12 03:50 ——– d—–w- c:\users\ensign\AppData\Roaming\pridl
2009-06-27 08:05 . 2009-06-27 08:05 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-06-23 21:53 . 2008-11-04 07:30 30568 —-a-w- c:\windows\system32\mdimon.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-02 00:30 . 2009-06-03 21:54 ——– d—–w- c:\users\ensign\AppData\Roaming\Skype
2009-07-01 20:00 . 2009-06-03 22:01 ——– d—–w- c:\users\ensign\AppData\Roaming\skypePM
2009-06-23 21:54 . 2008-06-14 09:42 ——– d—–w- c:\programdata\Microsoft Help
2009-06-11 02:39 . 2009-06-11 02:39 ——– d—–w- c:\users\ensign\AppData\Roaming\ATI
2009-06-11 02:33 . 2009-06-11 02:33 ——– d—–w- c:\program files\SigmaTel
2009-06-11 02:33 . 2008-06-14 10:12 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-11 02:33 . 2009-06-11 02:33 ——– d—–w- c:\program files\Common Files\InstallShield
2009-06-11 02:30 . 2009-06-11 02:27 ——– d—–w- c:\program files\ATI Technologies
2009-06-11 02:27 . 2009-06-11 02:27 ——– d—–w- c:\program files\ATI
2009-06-11 02:17 . 2009-06-11 02:17 ——– d—–w- c:\program files\Intel
2009-06-03 22:01 . 2009-06-03 22:01 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-06-03 21:53 . 2009-06-03 21:53 ——– d—–w- c:\program files\Common Files\Skype
2009-06-03 21:53 . 2009-06-03 21:53 ——– d—–r- c:\program files\Skype
2009-06-03 21:53 . 2009-06-03 21:53 ——– d—–w- c:\programdata\Skype
2009-05-31 21:23 . 2009-05-31 21:23 ——– d—–w- c:\users\ensign\AppData\Roaming\PeerNetworking
2009-05-25 17:51 . 2008-06-13 17:16 100256 —-a-w- c:\users\ensign\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-25 17:40 . 2008-06-14 09:46 ——– d—–w- c:\program files\Microsoft Works
2009-05-19 00:36 . 2009-05-19 00:36 ——– d—–w- c:\programdata\WindowsSearch
2009-05-16 00:25 . 2009-05-16 00:25 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-12 14:04 . 2009-05-12 14:04 34062 —-a-w- c:\users\ensign\AppData\Roaming\Move Networks\ie_bin\Uninst.exe
2009-05-09 05:50 . 2009-06-11 01:47 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-11 01:47 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-04-30 12:37 . 2009-06-13 21:27 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-04-30 12:37 . 2009-06-13 21:27 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-04-23 12:43 . 2009-06-11 01:24 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-11 01:34 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-11 01:44 2033152 —-a-w- c:\windows\system32\win32k.sys
2006-11-22 14:58 . 2006-11-22 14:58 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-07-15_00.26.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-06-13 21:17 . 2009-07-15 01:16 41004 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:03 . 2009-07-15 01:16 62952 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:00 . 2009-07-14 23:49 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:00 . 2009-07-15 01:16 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:00 . 2009-07-15 01:16 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:00 . 2009-07-14 23:49 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:00 . 2009-07-14 23:49 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:00 . 2009-07-15 01:16 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-13 18:02 . 2009-07-15 01:16 9642 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4225793217-963442044-4212106655-1000_UserData.bin
- 2009-07-14 14:55 . 2009-07-15 00:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-07-15 01:14 . 2009-07-15 01:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-07-15 01:14 . 2009-07-15 01:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 14:55 . 2009-07-15 00:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-07-15 01:22 598350 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-07-15 00:23 598350 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-07-15 01:22 101988 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-07-15 00:23 101988 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 169264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-05-06 405504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C40920AC-DB07-490B-A8E4-6DE7D7E0ACA6}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{2E869305-F402-484B-8428-8479C7F1BD45}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{61B4DDB1-8E0D-44FD-AA5A-67CEB23870AE}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{701BE77C-A7E0-459B-8896-C8196A6C630D}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{1881B864-D50B-4410-A762-557DAE8B523A}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{B98F6DC0-8441-46D7-AFED-6C0A38AC6EB5}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{F0D0ED47-E81C-470F-A5C3-50B39C658885}"= c:\program files\Skype\Phone\Skype.exe:Skype
R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\System32\drivers\tmlwf.sys [7/29/2008 12:06 PM 145424]
R2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [1/15/2008 10:28 AM 204800]
R2 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [7/29/2008 12:06 PM 50192]
R2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [1/18/2009 10:34 AM 497008]
R2 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [3/19/2009 9:23 AM 36368]
R2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [1/18/2009 10:34 AM 677128]
R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\System32\drivers\tmwfp.sys [7/29/2008 12:06 PM 256528]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-14 21:27
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-07-15 21:28
ComboFix-quarantined-files.txt 2009-07-15 01:28
Pre-Run: 149,629,210,624 bytes free
Post-Run: 149,609,496,576 bytes free
135 — E O F — 2009-06-24 07:00