Like before, I will send the report in two parts, here is the first:
ComboFix 09-08-04.04 - Rocio 08/06/2009 14:53.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3062.2339 [GMT -4:00]
Running from: c:\documents and settings\Rocio\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Rocio\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Windows Live OneCare *On-access scanning disabled* (Updated) {427ADFC3-B354-4A51-BE34-A9D4218E45C4}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
FW: Windows Live OneCare Firewall *disabled* {A3899D22-27E6-4A7E-AE4E-2C106646DAAB}
.
((((((((((((((((((((((((( Files Created from 2009-07-06 to 2009-08-06 )))))))))))))))))))))))))))))))
.
2009-08-04 20:48 . 2009-08-04 20:48 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-04 20:47 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 20:47 . 2009-08-04 20:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-04 20:47 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-04 20:06 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-08-04 16:03 . 2009-08-04 16:06 626720 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-04 15:14 . 2009-08-04 16:54 -------- d-----w- c:\program files\Microsoft Windows OneCare Live
2009-08-04 14:23 . 2009-08-04 14:23 -------- d-----w- c:\documents and settings\Rocio\Local Settings\Application Data\Mozilla
2009-08-04 14:22 . 2009-08-04 16:54 -------- d-----w- c:\program files\Mozilla Firefox(2)
2009-08-03 14:44 . 2009-08-03 14:44 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2009-08-03 14:44 . 2009-08-03 14:44 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060}
2009-08-03 14:04 . 2007-08-04 04:34 35720 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-03 14:04 . 2007-08-04 04:23 -------- d-----w- c:\documents and settings\Administrator\Application Data\GTek
2009-08-03 14:04 . 2009-08-03 14:43 -------- d-----w- c:\documents and settings\Administrator
2009-08-03 13:29 . 2009-08-03 14:43 -------- d-----w- c:\program files\Windows Live Safety Center
2009-08-03 12:41 . 2009-08-03 12:41 18880 ----a-w- c:\documents and settings\All Users\Application Data\rotimaje.pif
2009-08-03 12:41 . 2009-08-03 12:41 16418 ----a-w- c:\documents and settings\Rocio\Local Settings\Application Data\lyvohac.reg
2009-08-02 12:58 . 2009-08-02 12:58 18365 ----a-w- c:\program files\Common Files\zeba.sys
2009-08-02 12:58 . 2009-08-02 12:58 13068 ----a-w- c:\documents and settings\Rocio\Local Settings\Application Data\pogosinoc.bat
2009-08-01 15:54 . 2009-08-01 15:54 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-08-01 15:27 . 2009-08-01 15:27 -------- d-----w- c:\documents and settings\Rocio\Local Settings\Application Data\ESET
2009-08-01 14:51 . 2009-08-01 14:51 -------- d-----w- c:\documents and settings\Rocio\Application Data\ESET
2009-08-01 14:50 . 2009-08-01 14:50 -------- d-----w- c:\program files\ESET
2009-08-01 14:50 . 2009-08-01 14:50 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-07-22 12:55 . 2009-07-22 12:55 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-22 12:51 . 2009-07-22 12:51 152576 ----a-w- c:\documents and settings\Rocio\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-06 18:56 . 2008-08-31 14:29 -------- d-----w- c:\documents and settings\Rocio\Application Data\Skype
2009-08-06 13:56 . 2008-08-31 14:32 -------- d-----w- c:\documents and settings\Rocio\Application Data\skypePM
2009-08-04 20:06 . 2004-08-10 16:51 407040 ----a-w- c:\windows\system32\netlogon.dll
2009-08-04 16:06 . 2009-08-04 16:03 8420 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-04 15:18 . 2009-04-16 12:47 -------- d-----w- c:\program files\AhnLab
2009-08-03 14:43 . 2009-06-10 16:13 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-03 12:45 . 2009-07-06 15:42 -------- d-----w- c:\program files\Trend Micro
2009-08-03 12:41 . 2009-08-03 12:41 19723 ----a-w- c:\documents and settings\Rocio\Application Data\ytenuj.dat
2009-07-22 12:55 . 2007-08-04 04:18 -------- d-----w- c:\program files\Java
2009-07-07 13:50 . 2007-08-04 04:26 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-07 13:33 . 2008-04-11 14:13 -------- d-----w- c:\program files\Norton 360
2009-07-07 13:32 . 2008-04-11 14:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-03 17:09 . 2004-08-10 16:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-02 13:06 . 2007-08-09 14:11 685400 ----a-w- c:\documents and settings\Louis\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-01 19:56 . 2009-07-01 19:56 -------- d-----w- c:\documents and settings\Rocio\Application Data\Malwarebytes
2009-07-01 19:56 . 2009-07-01 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-30 14:36 . 2009-05-26 13:05 -------- d-----w- c:\documents and settings\Rocio\Application Data\BitZipper
2009-06-18 15:05 . 2009-06-18 15:05 -------- d-----w- c:\program files\Art Explosion
2009-06-18 15:05 . 2007-08-04 04:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-18 12:15 . 2007-10-09 14:13 964 ----a-w- c:\documents and settings\Rocio\Application Data\wklnhst.dat
2009-06-16 14:36 . 2004-08-10 16:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-10 16:51 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-10 21:20 . 2007-08-04 04:31 -------- d-----w- c:\program files\Microsoft Works
2009-06-10 17:56 . 2008-01-14 17:59 -------- d-----w- c:\program files\Full Tilt Poker
2009-06-10 17:11 . 2007-08-09 15:23 -------- d-----w- c:\program files\Common Files\PDFView
2009-06-10 17:11 . 2009-06-10 17:11 -------- d-----w- c:\program files\NewSoft
2009-06-10 17:10 . 2009-06-10 17:10 -------- d-----w- c:\documents and settings\Rocio\Application Data\ScanSoft
2009-06-10 17:10 . 2007-08-09 15:21 -------- d-----w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-06-10 17:10 . 2009-06-10 17:10 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2009-06-10 17:09 . 2009-06-10 17:09 -------- d-----w- c:\program files\ScanSoft
2009-06-10 17:06 . 2009-06-10 17:06 -------- d-----w- c:\program files\ArcSoft
2009-06-10 17:05 . 2007-08-09 14:27 -------- d-----w- c:\program files\Canon
2009-06-10 16:45 . 2008-03-04 20:43 -------- d-----w- c:\documents and settings\Rocio\Application Data\NewSoft
2009-06-10 16:36 . 2009-06-10 16:09 -------- d-----w- c:\program files\Windows Live
2009-06-10 16:24 . 2007-08-10 13:32 685400 ----a-w- c:\documents and settings\Rocio\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-10 16:12 . 2009-06-10 16:10 -------- d-----w- c:\program files\Microsoft
2009-06-10 16:12 . 2009-06-10 16:12 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-06-10 16:10 . 2009-06-10 16:10 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-06-10 16:04 . 2009-06-10 16:04 -------- d-----w- c:\program files\Common Files\Windows Live
2009-06-10 14:49 . 2008-03-31 19:14 -------- d-----w- c:\program files\SmartFTP Client 3.0 Setup Files
2009-06-03 19:09 . 2004-08-10 16:51 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-14 19:49 . 2009-05-14 19:49 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2009-05-14 19:49 . 2009-05-14 19:49 33096 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2009-05-14 19:49 . 2009-05-14 19:49 133000 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-05-14 19:47 . 2009-05-14 19:47 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-05-14 19:41 . 2009-05-14 19:41 114472 ----a-w- c:\windows\system32\drivers\eamon.sys
.
(((((((((((((((((((((((((((((
SnapShot@2009-08-04_20.09.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-06 13:52 . 2009-08-06 13:52 16384 c:\windows\Temp\Perflib_Perfdata_35c.dat
+ 2009-08-05 17:46 . 2009-08-05 17:46 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-05-02 198704]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-08-11 21741864]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-12 2356088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mailstation Assistant"="c:\program files\Pitney Bowes\mailstation 2\mailstationAssistant minimize" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2007-08-04 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"PDUiP6700DMon"="c:\program files\Canon\Memory Card Utility\iP6700D\PDUiP6700DMon.exe" [2006-03-16 61440]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-22 1191936]
"CnwiDeviceAgent"="c:\program files\Canon\GAROStatusMonitor\cnwida.exe" [2006-07-27 65536]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"PrintPack dispatcher"="c:\program files\Software602\Print2PDF\PrnPack.exe" [2007-11-23 73728]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 155648]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-22 148888]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-07-24 282624]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
GARO Status Monitor.lnk - c:\program files\Canon\GAROStatusMonitor\cnwism.exe [2007-8-10 348160]
Logo Calibration Loader.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\CalibrationLoader\CalibrationLoader.exe [2005-2-2 708608]
OKI LPR Utility.lnk - c:\program files\Okidata\OKI LPR Utility\okilpr.exe [2009-2-12 151552]
ProfileReminder.lnk - c:\program files\GretagMacbeth\i1\Eye-One Match 3\ProfileReminder.exe [2005-2-2 954368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2007-11-27 20:13 10792 ----a-w- c:\program files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Canon\\imagePROGRAF Device Setup Utility\\cnwids.exe"=
"c:\\Program Files\\Canon\\GAROStatusMonitor\\cnwism.exe"=
"c:\\Program Files\\Canon\\GAROStatusMonitor\\cnwida.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3 DEMO\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3 DEMO\\support\\bin\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1947:TCP"= 1947:TCP:HASP SRM
"1947:UDP"= 1947:UDP:HASP SRM
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [5/14/2009 3:47 PM 731840]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 OnyxUpdaterService;Onyx Updater;c:\onyx\AutoUpdate\OnxUpdtService.exe [8/24/2007 11:18 AM 33280]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [4/11/2008 8:37 AM 14416]
S2 OcHealthMon;Windows Live OneCare Health Monitor;"c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe" --> c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [?]
S3 DM150Drv;DM150Drv;c:\windows\system32\drivers\DM150Drv.sys [11/7/2008 12:36 PM 20600]
S3 EyeOneDp;EyeOneDp;c:\windows\system32\drivers\EyeOneDp.sys [2/17/2003 4:24 PM 44344]
S3 i1;eye-one;c:\windows\system32\drivers\i1.sys [1/16/2003 2:46 PM 26045]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.