Yes, report is below.
ComboFix 09-12-02.05 - Rick Hyman 12/05/2009 22:43.8.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.402 [GMT -5:00]
Running from: c:\documents and settings\Rick Hyman\Desktop\Combo-Fix.exe
FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\cleanup.exe
.
---- Previous Run -------
.
c:\windows\system32\drivers\str.sys . . . . failed to delete
-- Previous Run --
Infected copy of c:\windows\system32\es.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\es.dll
--------
.
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.
2009-12-05 23:51 . 2009-08-12 21:48 270336 ----a-w- c:\windows\system32\cdg.dll
2009-12-05 23:51 . 2006-09-27 22:46 348160 ----a-w- c:\windows\system32\cdga.dll
2009-12-05 23:51 . 2006-07-18 02:42 14909 ----a-w- c:\windows\system32\A_reg.reg
2009-12-05 23:51 . 2009-12-05 23:51 -------- d-----w- c:\program files\Cucusoft
2009-12-05 17:27 . 2009-12-05 17:27 0 ----a-w- C:\backup.reg
2009-12-05 17:27 . 2009-12-05 17:27 574 ----a-w- C:\cleanup.bat
2009-12-05 17:27 . 2009-12-05 17:27 135168 ----a-w- C:\zip.exe
2009-12-04 00:52 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-12-04 00:42 . 2008-10-16 19:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-12-04 00:42 . 2008-10-16 19:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-12-04 00:42 . 2008-10-16 19:13 202776 ----a-w- c:\windows\system32\wuweb.dll
2009-12-04 00:42 . 2008-10-16 19:13 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-12-04 00:42 . 2008-10-16 19:12 323608 ----a-w- c:\windows\system32\wucltui.dll
2009-12-04 00:42 . 2008-10-16 19:09 92696 ----a-w- c:\windows\system32\cdm.dll
2009-12-04 00:42 . 2008-10-16 19:09 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-12-03 09:11 . 2009-08-07 00:24 327896 ----a-w- c:\windows\system32\dllcache\wucltui.dll
2009-12-03 09:11 . 2009-08-07 00:24 209632 ----a-w- c:\windows\system32\dllcache\wuweb.dll
2009-12-03 09:11 . 2009-08-07 00:24 53472 ----a-w- c:\windows\system32\dllcache\wuauclt.exe
2009-12-03 09:11 . 2009-08-07 00:23 1929952 ----a-w- c:\windows\system32\dllcache\wuaueng.dll
2009-12-03 09:11 . 2009-08-07 00:24 96480 ----a-w- c:\windows\system32\dllcache\cdm.dll
2009-12-01 09:37 . 2009-12-01 09:37 79488 ----a-w- c:\documents and settings\Rick Hyman\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-27 19:42 . 2009-10-10 07:07 38208 ----a-w- c:\documents and settings\Rick Hyman\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe2009-11-27 19:41 . 2009-11-27 19:44 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-27 19:40 . 2009-11-27 19:40 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-11-27 19:39 . 2009-11-27 19:39 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-27 19:39 . 2009-12-01 02:48 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-27 16:37 . 2008-10-16 19:09 43544 ----a-w- c:\windows\system32\wups2.dll
2009-11-27 16:37 . 2008-10-16 19:08 34328 ----a-w- c:\windows\system32\wups.dll
2009-11-27 16:36 . 2008-10-16 19:12 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-11-22 01:05 . 2009-11-22 01:05 -------- d-----w- c:\program files\iPod
2009-11-22 01:05 . 2009-11-22 01:05 -------- d-----w- c:\program files\iTunes
2009-11-22 00:26 . 2009-11-22 00:26 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-19 11:55 . 2009-11-19 11:55 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-11-16 10:26 . 2004-08-10 10:00 57398 ----a-w- c:\windows\system32\dllcache\imjpdadm.exe
2009-11-15 19:56 . 2009-12-04 01:03 -------- d-----w- c:\windows\LastGood
2009-11-12 12:06 . 2009-11-12 12:06 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-11-12 12:06 . 2009-11-12 12:06 93360 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2009-11-12 12:06 . 2009-11-12 12:06 554280 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2009-11-12 12:06 . 2009-11-21 05:43 537576 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-11-12 12:06 . 2009-11-12 12:06 283944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Vipre.dll
2009-11-12 12:06 . 2009-11-12 12:06 212480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-11-12 12:06 . 2009-11-12 12:06 1223976 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2009-11-12 12:06 . 2009-11-12 12:06 242984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-11-12 12:05 . 2009-11-12 12:05 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-12 12:05 . 2009-10-03 08:15 2924848 -c--a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-11-06 23:39 . 2009-12-06 03:39 664 ----a-w- c:\windows\system32\d3d9caps.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-05 17:32 . 2009-01-25 08:09 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2009-12-05 17:32 . 2009-01-25 08:09 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2009-12-05 17:32 . 2009-01-25 08:09 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2009-12-05 17:32 . 2009-01-25 08:09 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2009-12-05 17:32 . 2009-01-25 08:09 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2009-12-05 17:32 . 2009-01-25 08:09 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2009-12-05 17:32 . 2009-01-25 08:09 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2009-12-05 17:32 . 2009-01-25 08:09 439158 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2009-12-02 00:53 . 2008-11-16 12:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-27 03:21 . 2006-12-03 22:28 19178 -c--a-w- c:\documents and settings\Rick Hyman\Application Data\wklnhst.dat
2009-11-23 12:09 . 2008-10-03 23:20 -------- d-----w- c:\program files\QuickTime
2009-11-22 01:05 . 2007-10-17 10:40 -------- d-----w- c:\program files\Common Files\Apple
2009-11-21 14:04 . 2006-11-27 21:08 96696 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-12 12:06 . 2009-08-04 10:22 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-11-12 12:06 . 2009-08-04 10:22 5908024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-10-15 20:21 . 2009-10-15 20:21 -------- d-----w- c:\documents and settings\Jill Hyman\Application Data\Malwarebytes
2009-10-10 14:23 . 2009-09-22 21:12 3584 ----a-w- c:\documents and settings\Matthew Hyman\Application Data\Macromedia\Common\1223407419.exe
2009-10-09 22:41 . 2009-09-22 17:13 3584 ----a-w- c:\documents and settings\NetworkService\Application Data\Macromedia\Common\1223407419.exe
2009-10-05 21:01 . 2009-09-28 21:22 3584 ----a-w- c:\documents and settings\Danni Hyman\Application Data\Macromedia\Common\1223407419.exe
2009-09-29 01:24 . 2009-09-29 01:25 388608 ----a-w- c:\windows\system32\CF7074.exe
2009-09-29 00:19 . 2009-09-29 00:21 388608 ----a-w- c:\windows\system32\CF20058.exe
2009-09-28 23:21 . 2009-09-28 23:54 388608 ----a-w- c:\windows\system32\CF23298.exe
2009-09-28 19:47 . 2009-09-28 19:49 388608 ----a-w- c:\windows\system32\CF6897.exe
2009-09-24 02:44 . 2009-09-24 02:44 4045527 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-09-24 00:20 . 2009-09-24 00:20 17632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
2009-09-24 00:20 . 2009-03-28 21:15 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-09-24 00:20 . 2009-09-24 00:20 68640 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys
2009-09-24 00:20 . 2009-09-24 00:20 303976 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe
2009-09-24 00:19 . 2009-08-04 10:21 640760 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-09-14 23:07 . 2007-03-25 23:59 13278 -c--a-w- c:\documents and settings\Danni Hyman\Application Data\wklnhst.dat
2009-09-10 19:54 . 2008-11-16 12:31 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2008-11-16 12:31 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2008-06-08 12:15 . 2008-06-08 12:15 0 -c--a-w- c:\program files\uninstall.dat
2007-10-19 00:35 . 2006-12-04 01:58 88 -csh--r- c:\windows\system32\874376E414.sys
2007-10-19 00:36 . 2006-12-04 01:58 2828 -csha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-05-24 181488]
"cafw"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-08-28 771312]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-08-28 173296]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-08-28 259312]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-11-21 788880]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-07-24 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-27 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 19:30 79368 ----a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [3/19/2008 11:56 AM 93712]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/3/2009 7:52 PM 64288]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [3/21/2008 4:00 PM 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [3/21/2008 4:00 PM 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [3/19/2008 11:56 AM 115216]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/4/2008 12:27 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [3/21/2008 4:00 PM 66576]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 6:17 AM 1184912]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/18/2007 11:24 AM 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 11:24 AM 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [4/15/2008 12:50 PM 281104]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/25/2009 6:49 PM 24652]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [5/30/2008 4:56 PM 88816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-12-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 05:43]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.optimum.net/mStart Page =
hxxp://www.google.comuInternet Settings,ProxyOverride = *.local
DPF: {444785F1-DE89-4295-863A-D46C3A781394} -
hxxp://webplayer.unity3d.com/download_webplayer-2.x/UnityWebPlayer.cabDPF: {A5A76EA0-7B92-4707-9DBF-6F6FE56A6800} -
hxxp://scan.networkmagic.com/nmscan/download/WebDiag.4.5.8056.1-ship-WD.V1.cab.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - c:\program files\AIM6\aim6.exe
AddRemove-Ad-Aware - c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-atoysvfixkzwnqr - c:\windows\system32\atoysvfixkzwnqr.exe
AddRemove-cont_adsoftinc - c:\windows\system32\cont_adsoftinc-remove.exe
AddRemove-{E2883E8F-472F-4fb0-9522-AC9BF37916A7} - c:\program files\NOS\bin\getPlus_Helper.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-05 22:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
Completion time: 2009-12-05 23:00
ComboFix-quarantined-files.txt 2009-12-06 04:00
ComboFix2.txt 2008-11-23 15:35
Pre-Run: 216,634,572,800 bytes free
Post-Run: 216,602,234,880 bytes free
- - End Of File - - AE4BDEAB7342375E6524B2E6BD0E2428