Here is the log from combofix:
ComboFix 10-08-19.02 - Sam 20/08/2010 21:59:52.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3069.1985 [GMT 1:00]
Running from: c:\users\Sam\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\st326017.dll
c:\windows\system32\st326162.dll
.
((((((((((((((((((((((((( Files Created from 2010-07-20 to 2010-08-20 )))))))))))))))))))))))))))))))
.
2010-08-20 21:11 . 2010-08-20 21:11 -------- d-----w- c:\users\TEMP.VP0021706BA0A8\AppData\Local\temp
2010-08-20 21:11 . 2010-08-20 21:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-19 16:37 . 2010-08-19 16:37 -------- d-----w- c:\program files\ERUNT
2010-08-14 19:42 . 2010-08-14 19:42 -------- d-----w- c:\users\Sam\AppData\Roaming\Malwarebytes
2010-08-14 19:42 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-14 19:42 . 2010-08-14 19:42 -------- d-----w- c:\programdata\Malwarebytes
2010-08-14 19:42 . 2010-08-14 19:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-14 19:42 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-13 21:37 . 2010-08-13 21:37 -------- d-----w- c:\users\Sam\AppData\Roaming\Auslogics
2010-08-13 21:37 . 2010-08-13 21:37 -------- d-----w- c:\program files\Auslogics
2010-08-12 17:25 . 2010-08-12 17:25 -------- d-----w- c:\programdata\IObit
2010-08-12 17:06 . 2010-08-17 19:25 -------- d-----w- c:\programdata\FLEXnet
2010-08-12 16:37 . 2010-08-12 16:37 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-08-12 15:17 . 2010-08-12 15:17 -------- d-----w- c:\users\Sam\AppData\Roaming\Juce VST Host
2010-08-12 10:17 . 2010-06-08 17:35 3600768 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-12 10:17 . 2010-06-08 17:35 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-08-12 10:17 . 2010-06-11 16:15 1248768 ----a-w- c:\windows\system32\msxml3.dll
2010-08-11 21:40 . 2010-08-11 21:40 -------- d-----w- c:\programdata\Research In Motion
2010-08-11 21:34 . 2010-08-11 21:39 102135128 ----a-w- c:\users\Sam\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\Extractor.exe
2010-08-08 22:07 . 2010-08-08 22:07 -------- d-----w- c:\users\Sam\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
2010-08-08 22:07 . 2010-08-08 22:07 -------- d-----w- c:\program files\TweetDeck
2010-08-06 11:29 . 2010-08-06 11:29 -------- d-----w- c:\users\Sam\AppData\Roaming\Blackberry Desktop
2010-08-03 20:38 . 2010-08-03 20:38 1821192 ----a-w- c:\users\Sam\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\vcredist_x86.exe
2010-08-03 20:38 . 2010-08-03 20:38 400728 ----a-w- c:\users\Sam\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\BBDesktopInstaller.exe
2010-08-03 20:38 . 2010-08-03 20:38 2959376 ----a-w- c:\users\Sam\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\dotnetfx35setup.exe
2010-08-03 20:38 . 2010-08-03 20:38 128472 ----a-w- c:\users\Sam\AppData\Roaming\Research In Motion\BlackBerry\Updates\5D17024E-6DC2-41aa-B38E-DA95AA158934\Helper.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-20 21:12 . 2009-01-26 15:47 -------- d-----w- c:\programdata\Kontiki
2010-08-20 11:16 . 2008-09-05 19:12 -------- d-----w- c:\programdata\Google Updater
2010-08-19 16:24 . 2008-09-05 14:21 7728 ----a-w- c:\users\Sam\AppData\Local\d3d9caps.dat
2010-08-19 15:03 . 2008-09-01 21:46 -------- d-----w- c:\program files\Microsoft Works
2010-08-18 22:58 . 2009-08-31 17:30 -------- d-----w- c:\users\Sam\AppData\Roaming\vlc
2010-08-17 15:25 . 2009-09-20 17:15 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-08-15 21:24 . 2009-11-08 19:30 -------- d-----w- c:\users\Sam\AppData\Roaming\FileZilla
2010-08-12 17:06 . 2008-09-04 12:14 86168 ----a-w- c:\users\Sam\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-12 16:45 . 2008-10-02 16:11 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-12 12:00 . 2008-09-06 23:39 -------- d-----w- c:\users\Sam\AppData\Roaming\Azureus
2010-08-12 11:53 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-11 22:09 . 2009-11-17 21:33 -------- d-----w- c:\users\Sam\AppData\Roaming\Research In Motion
2010-08-11 21:54 . 2009-11-17 21:29 -------- d-----w- c:\program files\Common Files\Research In Motion
2010-08-11 21:53 . 2009-11-17 21:48 -------- d-----w- c:\programdata\Roxio
2010-08-11 21:53 . 2008-09-01 21:33 -------- d-----w- c:\program files\Common Files\InstallShield
2010-08-11 21:52 . 2009-11-17 21:29 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-08-11 21:42 . 2009-11-17 21:29 -------- d-----w- c:\program files\Research In Motion
2010-08-04 14:44 . 2008-09-01 21:33 -------- d-----w- c:\program files\Common Files\Java
2010-08-04 14:41 . 2008-09-01 21:33 -------- d-----w- c:\program files\Java
2010-07-20 17:37 . 2010-06-22 11:25 -------- d-----w- c:\program files\iTunes
2010-07-20 17:36 . 2010-07-20 17:36 -------- d-----w- c:\program files\iPod
2010-07-20 17:36 . 2008-09-04 14:13 -------- d-----w- c:\program files\Common Files\Apple
2010-07-20 17:31 . 2010-07-20 17:31 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.4\SetupAdmin.exe
2010-07-17 04:00 . 2010-06-05 18:59 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-15 16:36 . 2010-07-15 16:36 53248 ----a-r- c:\users\Sam\AppData\Roaming\Microsoft\Installer\{3360D505-B0AA-4284-92DF-F872AF90A448}\ARPPRODUCTICON.exe
2010-07-14 22:16 . 2008-11-08 19:19 -------- d-----w- c:\users\Sam\AppData\Roaming\gtk-2.0
2010-07-01 11:07 . 2010-07-01 11:07 434176 ----a-w- c:\programdata\Trusteer\Rapport\store\exts\RapportMS\17053\RapportMS.dll
2010-06-29 17:47 . 2008-11-19 18:07 -------- d-----w- c:\program files\VstPlugins
2010-06-29 17:42 . 2009-05-30 15:53 -------- d-----w- c:\program files\Native Instruments
2010-06-26 06:05 . 2010-08-12 10:18 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-12 10:18 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-12 10:18 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-12 10:18 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-06-25 13:07 . 2008-09-23 08:08 -------- d-----w- c:\program files\Microsoft.NET
2010-06-22 11:20 . 2010-06-22 11:20 -------- d-----w- c:\program files\Bonjour
2010-06-21 13:37 . 2010-08-12 10:18 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-06-18 17:31 . 2010-08-12 10:18 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-06-18 15:04 . 2010-08-12 10:18 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-12 10:18 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-08-12 10:18 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-11 16:16 . 2010-08-12 10:18 274944 ----a-w- c:\windows\system32\schannel.dll
2010-06-08 12:15 . 2008-11-28 15:23 173 ----a-w- c:\users\Sam\AppData\Roaming\Azureus\restart.bat
2010-05-28 00:44 . 2010-05-28 00:43 145 --s-a-w- c:\users\Sam\AppData\Local\178776936.dat
2010-05-28 00:42 . 2010-05-28 00:42 4 ----a-w- c:\users\Sam\AppData\Roaming\ovczpx.dat
2010-05-27 20:08 . 2010-08-12 10:18 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-05-26 17:06 . 2010-06-11 11:59 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-11 11:59 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-08-20 11:15 . 2009-12-17 19:58 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
2008-09-01 21:47 . 2008-09-01 21:47 74 --sh--r- c:\windows\CT4CET.bin
2008-09-02 06:13 . 2008-09-02 06:13 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-16 483428]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-01-14 132392]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"Hercules DJ Series"="c:\program files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe" [2009-05-20 501032]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-20 30192]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-03-12 3563520]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-06-30 196608]
c:\users\Sam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-5-13 1058088]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-5-2 1211472]
VPNGuardUI.lnk - c:\program files\opswat\VPNGuard\VPNGuardUI.exe [2007-10-23 98304]
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-5-13 1058088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]
2007-04-23 11:23 1032640 ----a-w- c:\program files\Kontiki\KHost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-17 06:24 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-03-16 20:58 47392 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Webcam Central]
2008-06-03 14:54 446635 ------w- c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX5000 Series]
2006-09-22 04:01 139264 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIBVE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX5000 Series (Copy 1)]
2006-09-22 04:01 139264 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATIBVE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-09-04 16:25 133104 ----atw- c:\users\Sam\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-07-16 06:41 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
2007-04-23 11:23 1032640 ----a-w- c:\program files\Kontiki\KHost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2010-03-30 10:16 1820040 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 20:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SightSpeed]
2008-06-13 02:56 4758904 ----a-w- c:\program files\Dell Video Chat\DellVideoChat.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-27 20:24 1238352 ----a-w- c:\program files\Valve\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-09-01 21:42 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-10-06 22:09 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):ef,72,af,28,d6,0b,ca,01
R2 gupdate1c9865d669d927e;Google Update Service (gupdate1c9865d669d927e);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 133104]
R2 HerculesDJControlMP3;Hercules DJ Control MP3;c:\program files\Hercules\Audio\DJ Console Series\HerculesDJControlMP3.EXE [2007-11-21 17408]
R2 SIMUL8Parallel;SIMUL8 Parallel Processor;c:\progra~1\SIMUL8\SIMUL8_ParallelSVC.exe [2007-03-29 502272]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-20 30192]
R3 HDJCtrl;Hercules DJ Control MP3 Service;c:\windows\system32\Drivers\HDJCtrl.sys [2009-05-20 24064]
R3 HDJMidi;Hercules DJ Control MP3 MIDI;c:\windows\system32\DRIVERS\HDJMidi.sys [2009-05-20 122368]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-04-05 1029456]
R3 P0630VID;Creative WebCam Live!;c:\windows\system32\DRIVERS\P0630Vid.sys [2004-04-14 91797]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-09-06 717296]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-06-05 64160]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [2009-03-16 81920]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-04-28 161048]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2010-03-08 62496]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2008-03-13 203264]
S3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\DRIVERS\OA001Ufd.sys [2009-03-06 133632]
S3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\DRIVERS\OA001Vid.sys [2009-03-08 280096]
S3 VPNGuardService;VPNGuardService;c:\program files\OPSWAT\VPNGuard\VPNGuardService.exe [2007-10-23 299008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-08-20 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 12:11]
2010-08-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-01 15:05]
2010-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0ceb245f0d00.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 00:13]
2010-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 00:13]
2010-08-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1596938837-54953107-2832527327-1000Core.job
- c:\users\Sam\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-04 16:25]
2010-08-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1596938837-54953107-2832527327-1000UA.job
- c:\users\Sam\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-04 16:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.facebook.com/home.php
uInternet Settings,ProxyOverride = <local>;*.local
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
FF - ProfilePath - c:\users\Sam\AppData\Roaming\Mozilla\Firefox\Profiles\0a3jjibc.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLC\npvlc.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Sam\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\Sam\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-BlackBerryAutoUpdate - c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
MSConfigStartUp-dscactivate - c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
AddRemove-Free Audio Editor - c:\progra~1\Free Audio Editor\UNWISE.EXE
AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\Sam\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\octoshape\octoshape.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2010-08-20 22:12
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1596938837-54953107-2832527327-1000\Software\G*e*n*i*e*"!\FM Genie Scout 2009 XE]
"GameDir"="c:\\Users\\Sam\\Documents\\Sports Interactive\\Football Manager 2009\\games"
"ShortlistDir"="c:\\Users\\Sam\\Documents\\Sports Interactive\\Football Manager 2009\\shortlists"
"ScreenshotsDir"="c:\\Users\\Sam\\Documents\\Sports Interactive\\Football Manager 2009"
"SaveDir"="c:\\Users\\Sam\\Documents\\Sports Interactive\\Football Manager 2009\\"
"HistoryDir"="c:\\Users\\Sam\\Desktop\\fm_genie_scout_2009_xe\\FM Genie Scout 2009 XE\\History Points"
"LangDB"=""
"LastSaveGame"=""
"Language"="English"
"LoadLangDB"=dword:00000000
"CompressHistoryPoints"=dword:00000000
"HighlightedAttributes"=dword:00000000
"MinCondition"=dword:00000050
"SkinName"="Champions League"
"LastUpdateCheck"=dword:00000000
"HighQualityGUI"=dword:00000001
"AutomaticallyUpdateCheck"=dword:00000001
"AdvancedGeneration"=dword:00000000
"TranslateStaffSkills"=dword:00000001
"TranslatePlayerSkills"=dword:00000001
"TranslatePositions"=dword:00000001
"ShowHistory"=dword:00000001
"Version"=dword:00000066
"UniqueID"="B5-A280-E07F"
"Currency"=dword:00000056
"UseProxy"=dword:00000000
"ProxyHost"=""
"ProxyPort"=""
"UseAuthentication"=dword:00000000
"UserName"=""
"UserPassword"=""
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-08-20 22:16:51
ComboFix-quarantined-files.txt 2010-08-20 21:16
Pre-Run: 101,974,974,464 bytes free
Post-Run: 101,984,174,080 bytes free
- - End Of File - - 52FFD25E82A73F5EC3AD4701E24801C5