Okay, done - here's the log:
ComboFix 11-07-24.03 - HP_Owner 25/07/2011 9:59.1.2 - x86
Running from: c:\documents and settings\HP_Owner\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions\{73e1e35c-27c2-44c5-90fa-cf9da6cbfec3}
c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions\{73e1e35c-27c2-44c5-90fa-cf9da6cbfec3}\chrome\xulcache.jar
c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions\{73e1e35c-27c2-44c5-90fa-cf9da6cbfec3}\defaults\preferences\xulcache.js
c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions\{73e1e35c-27c2-44c5-90fa-cf9da6cbfec3}\install.rdf
c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions\{b9452a5b-916c-404f-8479-850185ae13bc}
c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions\{b9452a5b-916c-404f-8479-850185ae13bc}\chrome\xulcache.jar
c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions\{b9452a5b-916c-404f-8479-850185ae13bc}\defaults\preferences\xulcache.js
c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\extensions\{b9452a5b-916c-404f-8479-850185ae13bc}\install.rdf
c:\documents and settings\HP_Owner\Application Data\PriceGong
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\1.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\a.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\b.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\c.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\d.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\e.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\f.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\g.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\h.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\i.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\J.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\k.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\l.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\m.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\n.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\o.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\p.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\q.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\r.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\s.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\t.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\u.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\v.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\w.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\x.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\y.xml
c:\documents and settings\HP_Owner\Application Data\PriceGong\Data\z.xml
c:\documents and settings\HP_Owner\Local Settings\Temporary Internet Files\mcc17.tmp
c:\documents and settings\HP_Owner\Local Settings\Temporary Internet Files\mcc1B.tmp
c:\documents and settings\HP_Owner\Local Settings\Temporary Internet Files\mccD.tmp
c:\documents and settings\HP_Owner\WINDOWS
c:\documents and settings\Sauerbraten\uninstall.exe
c:\program files\INSTALL.PIF
c:\windows\system32\config\systemprofile\WINDOWS
D:\Autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_USNJSVC
-------\Service_usnjsvc
.
.
((((((((((((((((((((((((( Files Created from 2011-06-25 to 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-21 23:53 . 2011-07-21 23:53 -------- d-----w- c:\program files\Dial-a-fix-v0.60.0.24
2011-07-21 21:58 . 2011-07-21 21:58 388096 ----a-r- c:\documents and settings\HP_Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-21 21:58 . 2011-07-21 21:58 -------- d-----w- c:\program files\Trend Micro
2011-07-21 21:50 . 2011-07-21 21:50 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-07-12 14:52 . 2007-04-10 02:06 8192 ----a-w- c:\windows\system32\E_DCINST.DLL
2011-07-12 14:51 . 2009-10-01 04:01 63488 ----a-w- c:\windows\system32\E_FD4BGXE.DLL
2011-07-12 14:51 . 2008-11-12 03:00 93696 ----a-w- c:\windows\system32\E_FLBGXE.DLL
2011-07-12 14:46 . 2011-07-12 14:46 -------- d-----w- c:\documents and settings\All Users\Application Data\UDL
2011-07-12 14:39 . 2011-07-13 08:25 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Epson
2011-07-12 14:38 . 2011-07-12 14:44 -------- d-----w- c:\program files\Epson Software
2011-07-12 14:38 . 2010-09-13 14:01 458129 ----a-w- c:\windows\system32\ensppui.dll
2011-07-12 14:38 . 2010-09-13 14:00 475410 ----a-w- c:\windows\system32\ensppmon.dll
2011-07-12 14:38 . 2008-06-18 10:49 249344 ----a-w- c:\windows\system32\enspres.dll
2011-07-12 14:38 . 2010-09-13 14:01 458129 ----a-w- c:\windows\system32\enppui.dll
2011-07-12 14:38 . 2010-09-13 14:00 475410 ----a-w- c:\windows\system32\enppmon.dll
2011-07-12 14:38 . 2008-06-18 10:49 249344 ----a-w- c:\windows\system32\enpres.dll
2011-07-12 14:38 . 2011-07-12 14:38 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\InstallShield
2011-07-12 14:36 . 2011-07-12 14:38 -------- d-----w- c:\program files\EpsonNet
2011-07-12 14:34 . 2011-07-12 14:52 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
2011-07-12 14:34 . 2009-10-15 23:00 132560 ----a-w- c:\windows\system32\esdevapp.exe
2011-07-12 14:34 . 2009-10-15 23:00 12800 ----a-w- c:\windows\system32\escdev.dll
2011-07-12 14:34 . 2009-09-16 23:00 342016 ----a-w- c:\windows\system32\eswiaud.dll
2011-07-07 14:35 . 2011-07-06 18:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-07 14:34 . 2011-07-06 18:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-07 14:34 . 2011-07-17 08:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-03 13:50 . 2011-07-03 15:19 -------- d-----w- C:\Games
2011-06-30 11:04 . 2011-02-11 13:25 229888 ----a-w- c:\windows\system32\fxscover.exe
2011-06-30 10:49 . 2011-07-01 20:16 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Audacity
2011-06-29 09:24 . 2008-04-13 17:36 10240 ----a-w- c:\windows\system32\dllcache\compbatt.sys
2011-06-29 09:15 . 2001-08-17 12:51 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
2011-06-29 09:14 . 2008-04-13 17:46 13696 ----a-w- c:\windows\system32\dllcache\avcstrm.sys
2011-06-29 09:13 . 2001-08-17 21:36 462848 ----a-w- c:\windows\system32\dllcache\a3dapi.dll
2011-06-29 09:13 . 2001-08-17 12:52 23552 ----a-w- c:\windows\system32\dllcache\abp480n5.sys
2011-06-29 09:13 . 2001-08-17 21:36 98304 ----a-w- c:\windows\system32\dllcache\a3d.dll
2011-06-29 09:13 . 2001-08-17 13:55 38400 ----a-w- c:\windows\system32\dllcache\8514a.dll
2011-06-29 09:13 . 2008-04-13 17:46 48128 ----a-w- c:\windows\system32\dllcache\61883.sys
2011-06-29 09:13 . 2008-04-13 17:40 12288 ----a-w- c:\windows\system32\dllcache\4mmdat.sys
2011-06-29 09:13 . 2001-08-17 13:55 689216 ----a-w- c:\windows\system32\dllcache\3dfxvs.dll
2011-06-29 09:13 . 2001-08-17 12:28 762780 ----a-w- c:\windows\system32\dllcache\3cwmcru.sys
2011-06-29 09:13 . 2001-08-17 11:48 148352 ----a-w- c:\windows\system32\dllcache\3dfxvsm.sys
2011-06-29 09:13 . 2001-08-17 13:06 11264 ----a-w- c:\windows\system32\dllcache\1394vdbg.sys
2011-06-28 17:52 . 2011-06-28 17:52 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Unity
2011-06-28 17:43 . 2011-06-28 17:43 -------- d-----w- c:\documents and settings\HP_Owner\Local Settings\Application Data\Unity
2011-06-27 16:09 . 2011-06-30 10:49 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)
2011-06-25 18:10 . 2011-06-25 18:10 -------- d-----w- C:\Nexon
2011-06-25 18:10 . 2011-06-25 18:20 -------- d-----w- c:\documents and settings\All Users\Application Data\NexonEU
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-21 21:50 . 2010-04-27 14:54 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-06-22 17:10 . 2011-06-22 17:10 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
2011-06-19 10:32 . 2011-05-15 08:29 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 14:02 . 2004-08-04 11:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-17 14:55 . 2010-12-07 01:31 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-05-14 18:22 . 2011-05-14 18:22 53248 ----a-r- c:\documents and settings\HP_Owner\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-05-02 15:31 . 2004-08-04 11:00 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2004-08-04 11:00 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2004-08-04 11:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07 . 2004-08-04 11:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-26 11:07 . 2004-08-04 11:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2010-06-07 15:16 . 2010-08-11 09:14 3887480 ----a-w- c:\program files\procexp.exe
2009-12-01 10:53 . 2010-02-20 22:05 559992 ----a-w- c:\program files\autorunsc.exe
2009-11-24 13:15 . 2009-11-24 13:22 18665720 ----a-w- c:\program files\LimeWireWin.exe
2009-07-10 00:20 . 2009-07-10 00:19 347928562 ----a-w- c:\program files\sauerbraten_2009_05_04_trooper_edition_win32_setup.exe
2009-06-11 22:46 . 2009-07-07 12:05 172032 ----a-w- c:\program files\libpng13.dll
2009-04-12 19:22 . 2009-04-12 19:22 6237728 ----a-w- c:\program files\SUPERAntiSpyware.exe
2009-03-20 12:20 . 2009-03-20 12:20 573 ----a-w- c:\program files\xp_system32opens.vbs
2009-03-12 19:17 . 2009-09-30 11:27 5486113 ----a-w- c:\program files\DarkWave-Studio-2.4.exe
2009-03-12 15:43 . 2009-03-12 15:43 1971378 ----a-w- c:\program files\SetupImgBurn_2.4.2.0.exe
2009-02-22 21:35 . 2009-02-22 21:35 3171208 ----a-w- c:\program files\ccsetup216.exe
2009-02-21 13:50 . 2009-02-21 13:50 18638688 ----a-w- c:\program files\sdsetup.exe
2009-02-01 15:28 . 2009-07-07 12:05 45056 ----a-w- c:\program files\Launcher.exe
2009-01-30 18:13 . 2009-01-30 18:13 1053744 ----a-w- c:\program files\revosetup.exe
2009-01-03 20:33 . 2009-01-03 20:33 6832928 ----a-w- c:\program files\alzip.exe
2009-01-03 17:40 . 2009-01-03 17:40 939698 ----a-w- c:\program files\7z464.exe
2009-01-03 17:33 . 2009-01-03 17:33 8973608 ----a-w- c:\program files\zg603sui.exe
2008-12-09 15:01 . 2008-12-09 15:01 4399029 ----a-w- c:\program files\quickzip.exe
2008-11-19 17:48 . 2010-10-19 15:51 14709760 ----a-w- c:\program files\ClassActionKillers.msi
2008-11-19 17:48 . 2010-10-19 15:51 370176 ----a-w- c:\program files\setup.exe
2008-07-09 11:27 . 2008-07-09 11:27 820380 ----a-w- c:\program files\audacity-win-1.2.6.exe
2004-03-18 18:36 . 2009-07-07 12:05 401484 ----a-w- c:\program files\msvcrtd.dll
2011-06-22 14:57 . 2011-04-28 10:58 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 13:01 . 2010-04-22 18:23 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
2004-08-04 11:00 94784 --sha-w- c:\windows\twain.dll
2008-04-14 00:12 50688 --sha-w- c:\windows\twain_32.dll
2004-07-30 06:04 1216 --sha-w- c:\windows\Twunk_16.dll
2004-07-30 06:04 1216 --sha-w- c:\windows\Twunk_32.dll
2008-04-14 00:12 57344 --sha-w- c:\windows\system32\msvcirt.dll
2008-04-14 00:12 413696 --sha-w- c:\windows\system32\msvcp60.dll
2008-04-14 00:12 343040 --sha-w- c:\windows\system32\msvcrt.dll
2011-02-08 13:33 978944 --sha-w- c:\windows\system32\OLDCC.tmp
2010-12-20 17:32 551936 --sh--w- c:\windows\system32\oleaut32.dll
2008-04-14 00:12 84992 --sh--w- c:\windows\system32\olepro32.dll
2008-04-14 00:12 11776 --sh--w- c:\windows\system32\regsvr32.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ad708c09-d51b-45b3-9d28-4eba2681febf}"= "c:\program files\Download_Energy\prxtbDow0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ad708c09-d51b-45b3-9d28-4eba2681febf}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ad708c09-d51b-45b3-9d28-4eba2681febf}"= "c:\program files\Download_Energy\prxtbDow0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ad708c09-d51b-45b3-9d28-4eba2681febf}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{AD708C09-D51B-45B3-9D28-4EBA2681FEBF}"= "c:\program files\Download_Energy\prxtbDow0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ad708c09-d51b-45b3-9d28-4eba2681febf}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-07-01 2424192]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ftutil2"="ftutil2.dll" [2004-06-07 106496]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"btbb_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" [2009-09-14 1584640]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-05-25 1306216]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-17 13529088]
"FUFAXSTM"="c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2009-12-02 847872]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-27 36975]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-06-12 273544]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-6-5 27136]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-06 09:58 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-04-02 15:11 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Vid\\Vid.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"=
.
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1ca3dc146c6f28a;Google Update Service (gupdate1ca3dc146c6f28a);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-25 133104]
R3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2011-06-08 73728]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-25 133104]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\DRIVERS\mfendisk.sys [2011-03-13 83688]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-03-13 85984]
R3 RTPP2K;RTPP2K;c:\windows\system32\DRIVERS\rtpp2k.sys [2001-04-30 87374]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-18 12872]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2011-03-13 89368]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-18 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2010-05-26 67656]
S2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2011-07-22 3029208]
S2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\Drivers\LBeepKE.sys [2010-08-24 10448]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2011-02-16 88176]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 214904]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-03-13 159832]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2011-03-13 148520]
S2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-04-01 428640]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-03-13 57432]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-03-13 337912]
S3 mfendiskmp;mfendiskmp;c:\windows\system32\DRIVERS\mfendisk.sys [2011-03-13 83688]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2009-06-18 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-08 18:23]
.
2011-07-25 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1157552183-2752306718-432289623-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 09:47]
.
2011-07-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1157552183-2752306718-432289623-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 09:47]
.
2011-03-21 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2011-03-18 13:53]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jvo1qb88.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/webhp?hl=en&source=hp&btnG=Google+Search
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-PCDrProfiler - (no file)
SafeBoot-Wdf01000.sys
AddRemove-Sauerbraten - c:\documents and settings\Sauerbraten\uninstall.exe
.
.
.
**************************************************************************
.
disk not found C:\
.
please note that you need administrator rights to perform deep scan
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(532)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2088)
c:\windows\system32\WININET.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
c:\program files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
c:\windows\system32\rundll32.exe
c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
.
**************************************************************************
.
Completion time: 2011-07-25 10:36:32 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-25 09:36
.
Pre-Run: 93,165,621,248 bytes free
Post-Run: 92,944,678,912 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 0415A439B65A3AE295F4D2ABBF72BDDC
Will now reboot clean and see what happens.