I ran Combofix and now when I try to sign on to IE I get a message that I can't because something in the registry is to be deleted. So I am in safe mode sending this to you.
ComboFix 12-03-22.01 - D 03/24/2012 20:34:25.9.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1981.1295 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-02-25 to 2012-03-25 )))))))))))))))))))))))))))))))
.
.
2012-03-25 00:39 . 2012-03-25 00:39 ——– d—–w- c:\users\D\AppData\Local\temp
2012-03-25 00:39 . 2012-03-25 00:39 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-03-14 07:26 . 2012-02-02 15:16 2044416 —-a-w- c:\windows\system32\win32k.sys
2012-03-14 07:26 . 2012-02-14 15:45 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-03-14 07:26 . 2012-02-14 15:45 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-03-14 07:26 . 2012-02-13 14:12 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-03-14 07:26 . 2012-02-13 13:47 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-03-14 07:26 . 2012-02-13 13:44 1068544 —-a-w- c:\windows\system32\DWrite.dll
2012-03-14 07:26 . 2012-01-31 10:59 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-03-14 07:22 . 2012-01-09 15:54 613376 —-a-w- c:\windows\system32\rdpencom.dll
2012-03-14 07:22 . 2012-01-09 13:58 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-09 04:57 . 2012-03-09 04:57 ——– d—–w- c:\program files\VS Revo Group
2012-03-09 03:36 . 2012-03-09 03:36 ——– d—–w- c:\users\D\AppData\Roaming\Malwarebytes
2012-03-09 03:36 . 2012-03-09 03:36 ——– d—–w- c:\programdata\Malwarebytes
2012-03-09 03:36 . 2012-03-09 03:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-03-09 03:36 . 2011-12-10 20:24 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-03-09 03:19 . 2012-03-09 03:20 ——– d—–w- c:\program files\VideoConverter
2012-03-09 03:19 . 2012-03-09 03:19 1492 —-a-w- C:\user.js
2012-03-09 03:19 . 2012-03-09 03:19 ——– d—–w- c:\windows\system32\Extensions
2012-03-09 03:18 . 2012-03-09 03:20 ——– d—–w- c:\program files\AudioConverter
2012-03-05 02:17 . 2012-03-05 02:17 ——– d—–w- c:\users\D\AppData\Roaming\Macrovision
2012-03-05 02:17 . 2012-03-05 02:17 ——– d—–w- c:\users\D\AppData\Roaming\Zeon
2012-03-05 02:16 . 2012-03-05 02:16 ——– d—–w- c:\programdata\ScanSoft
2012-03-05 02:03 . 2012-03-05 02:06 ——– d—–w- c:\programdata\Nuance
2012-03-05 02:02 . 2012-03-05 02:02 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2012-03-05 02:02 . 2012-03-05 02:02 ——– d—–w- c:\programdata\zeon
2012-03-05 02:01 . 2012-03-05 02:01 ——– d—–w- C:\speech
2012-03-05 02:01 . 2012-03-05 02:01 ——– d—–w- c:\programdata\Macrovision
2012-03-05 02:01 . 2012-03-05 02:01 ——– d—–w- c:\program files\Nuance
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-05 00:23 . 2011-10-28 05:00 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-08 06:03 . 2011-11-10 13:41 6552120 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-01-31 12:44 . 2011-10-30 02:16 237072 ——w- c:\windows\system32\MpSigStub.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"PDFHook"="c:\program files\Nuance\PDF Professional 5\pdfpro5hook.exe" [2008-12-23 795936]
"PDF5 Registry Controller"="c:\program files\Nuance\PDF Professional 5\RegistryController.exe" [2008-12-23 58656]
"Nuance PDF Professional 5-reminder"="c:\program files\Nuance\PDF Professional 5\Ereg\Ereg.exe" [2008-11-03 54560]
.
c:\users\D\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-7-11 111376]
Microsoft Office Shortcut Bar.lnk - c:\program files\Microsoft Office\Office\MSOFFICE.EXE [1997-7-11 333824]
Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-7-11 51984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
——- Supplementary Scan ——-
.
uStart Page =
IE: Append the content of the link to existing PDF file - c:\program files\Nuance\PDF Professional 5\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Append the content of the selected links to existing PDF file - c:\program files\Nuance\PDF Professional 5\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
IE: Append to existing PDF file - c:\program files\Nuance\PDF Professional 5\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Create PDF file - c:\program files\Nuance\PDF Professional 5\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF file from the content of the link - c:\program files\Nuance\PDF Professional 5\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF files from the selected links - c:\program files\Nuance\PDF Professional 5\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: Open with PDF Converter 5.2 - c:\program files\Nuance\PDF Professional 5\cnvres_eng.dll /100
IE: Open with PDF Professional 5.2 - c:\program files\Nuance\PDF Professional 5\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
TCP: DhcpNameServer = 192.168.10.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-03-24 20:39
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2012-03-24 20:42:22
ComboFix-quarantined-files.txt 2012-03-25 00:42
ComboFix2.txt 2012-03-19 04:46
ComboFix3.txt 2012-03-19 02:51
.
Pre-Run: 113,272,025,088 bytes free
Post-Run: 113,252,163,584 bytes free
.
- - End Of File - - 62F3A5417A731D9A7257426409A6AA99