Here is the ComboFix log.
ComboFix 08-07-11.1 - mdg 2008-07-17 17:42:48.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.795 [GMT -4:00]
Running from: C:\Documents and Settings\mdg\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-17 to 2008-07-17 )))))))))))))))))))))))))))))))
.
2008-07-17 17:33 . 2008-07-17 17:33 <DIR> d-------- C:\Deckard
2008-07-17 11:57 . 2008-07-17 11:57 <DIR> d-------- C:\Program Files\Defraggler
2008-07-17 11:45 . 2008-07-17 11:46 <DIR> d-------- C:\Program Files\Smarty Uninstaller Pro
2008-07-17 11:45 . 2007-08-15 13:09 417,792 --a------ C:\WINDOWS\system32\vbalCmdBar6.ocx
2008-07-17 11:45 . 2007-08-15 13:09 262,144 --a------ C:\WINDOWS\system32\lst_v.ocx
2008-07-17 11:45 . 2004-03-09 00:00 212,240 --a------ C:\WINDOWS\system32\RICHTX32.OCX
2008-07-17 11:45 . 1999-02-09 21:40 188,928 --a------ C:\WINDOWS\system32\vbuzip10.DLL
2008-07-17 11:45 . 2007-08-15 13:09 159,744 --a------ C:\WINDOWS\system32\wt_menu.dll
2008-07-17 11:45 . 2007-08-15 13:09 94,208 --a------ C:\WINDOWS\system32\img_lst.ocx
2008-07-17 11:45 . 2007-08-15 13:09 40,960 --a------ C:\WINDOWS\system32\ssubtmr6.dll
2008-07-17 11:13 . 2008-07-17 11:16 <DIR> d-------- C:\Program Files\Unlocker
2008-07-17 11:13 . 2008-07-17 11:13 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\Desktopicon
2008-07-14 12:01 . 2008-07-14 12:01 <DIR> d-------- C:\Program Files\Sun
2008-07-14 12:01 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-14 11:35 . 2008-07-14 11:35 <DIR> d-------- C:\Program Files\TextPad 5
2008-07-14 11:35 . 2008-07-14 11:35 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\Helios
2008-07-12 21:33 . 2008-07-12 21:33 <DIR> d-------- C:\Program Files\HDD Health
2008-07-12 00:07 . 2008-07-12 00:08 <DIR> d-------- C:\Program Files\Opera
2008-07-10 22:44 . 2008-07-10 23:16 <DIR> d-------- C:\Program Files\Eusing Free Registry Cleaner
2008-07-10 22:38 . 2008-07-10 23:43 <DIR> d-------- C:\Program Files\RegCleaner
2008-07-10 15:50 . 2008-07-10 15:50 <DIR> d-------- C:\Nexon(0.58)
2008-07-10 15:46 . 2008-07-10 15:46 <DIR> d-------- C:\Nexon
2008-07-09 19:48 . 2008-07-11 16:10 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\MySQL
2008-07-09 19:44 . 2008-07-09 19:45 <DIR> d-------- C:\Program Files\MySQL
2008-07-08 22:25 . 2008-07-08 22:25 <DIR> d-------- C:\Documents and Settings\mdg\.netbeans-registration
2008-07-08 22:21 . 2008-07-08 22:24 <DIR> d-------- C:\Program Files\NetBeans 6.1
2008-07-08 16:49 . 2006-08-16 07:58 100,352 -----c--- C:\WINDOWS\system32\dllcache\6to4svc.dll
2008-07-08 13:16 . 2008-07-08 13:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-07-08 13:14 . 2008-07-08 13:23 <DIR> d-------- C:\Program Files\Common Files\Autodesk Shared
2008-07-08 13:14 . 2008-07-10 22:41 <DIR> d-------- C:\Program Files\Autodesk
2008-07-07 23:26 . 2008-07-07 23:26 <DIR> d-------- C:\Program Files\Common Files\Stardock
2008-07-07 23:26 . 2008-07-08 13:03 163,712 --a------ C:\WINDOWS\system32\drivers\vidstub.sys
2008-07-07 22:46 . 2008-07-07 22:46 <DIR> d--h-c--- C:\Documents and Settings\All Users\Application Data\{8CC5CF4A-124E-41BA-B58C-A41F05BE09CC}
2008-07-07 22:40 . 2008-07-07 23:26 <DIR> d-------- C:\Program Files\Stardock
2008-07-07 17:30 . 2008-07-07 17:30 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-07-06 13:47 . 2008-07-06 13:47 <DIR> d-------- C:\Program Files\Media Player Classic
2008-07-05 15:57 . 2008-07-05 21:55 <DIR> d-------- C:\DVDTemp
2008-07-05 15:56 . 2008-07-07 00:21 <DIR> d-------- C:\Program Files\Super_DVD_Creator_9.8
2008-07-05 09:44 . 2008-07-05 09:45 <DIR> d-------- C:\Documents and Settings\Kuzniak\Application Data\Hamachi
2008-07-05 09:32 . 2008-07-05 09:32 <DIR> d-------- C:\Documents and Settings\Kuzniak\Application Data\Comodo
2008-07-04 16:40 . 2008-07-04 16:40 <DIR> d-------- C:\Program Files\Hamachi
2008-07-04 15:58 . 2008-07-04 15:58 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\Media Player Classic
2008-07-04 11:55 . 2008-07-04 11:55 87,056 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-07-04 11:55 . 2008-07-04 11:55 24,208 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-07-04 10:54 . 2008-07-04 10:54 249,592 --a------ C:\WINDOWS\system32\cssdll32.dll
2008-07-04 10:53 . 2008-07-04 10:54 <DIR> d-------- C:\Program Files\COMODO
2008-07-04 10:53 . 2008-07-04 10:53 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\Comodo
2008-07-04 10:53 . 2008-07-04 20:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-07-04 10:53 . 2008-07-04 10:53 143,104 --a------ C:\WINDOWS\system32\guard32.dll1
2008-07-04 10:53 . 2008-07-04 11:55 143,104 --a------ C:\WINDOWS\system32\guard32.dll
2008-07-03 20:48 . 2008-07-03 20:50 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\Vso
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Program Files\PowerISO
2008-07-02 21:30 . 2008-07-02 21:29 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-02 17:54 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-02 17:54 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-07-02 17:54 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-07-02 17:54 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-02 17:54 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-02 17:54 . 2008-07-02 17:54 2,054 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-30 18:43 . 2008-07-14 16:14 <DIR> d-------- C:\Program Files\Uniblue
2008-06-30 18:43 . 2008-07-11 20:09 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\Uniblue
2008-06-29 23:13 . 2008-06-29 23:13 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\TrojanHunter
2008-06-29 20:33 . 2008-06-29 20:33 <DIR> d-------- C:\Program Files\TrojanHunter 5.0
2008-06-29 19:37 . 2008-06-29 19:37 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\McAfee
2008-06-29 17:25 . 2008-06-29 17:25 <DIR> d-------- C:\Program Files\Avira
2008-06-29 17:25 . 2008-06-29 17:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-06-28 13:51 . 2008-07-08 11:47 <DIR> d-------- C:\Documents and Settings\Kuzniak\Application Data\OpenOffice.org2
2008-06-28 13:18 . 2008-06-28 13:18 <DIR> d-------- C:\Documents and Settings\Kuzniak\Application Data\HPAppData
2008-06-26 23:33 . 2008-06-26 23:33 <DIR> d-------- C:\Program Files\Oxin's Style!
2008-06-26 19:49 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-06-26 19:49 . 2008-06-23 23:34 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-06-26 16:10 . 2008-06-26 16:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-26 15:58 . 2008-07-17 13:11 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\OpenOffice.org2
2008-06-26 15:56 . 2008-06-26 15:56 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-06-26 15:40 . 2008-06-26 15:40 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-06-26 13:20 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-26 13:20 . 2008-06-13 09:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-26 13:20 . 2008-05-08 08:28 202,752 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-25 23:01 . 2008-06-25 23:01 25 --a------ C:\WINDOWS\cdplayer.ini
2008-06-25 22:58 . 2008-06-25 22:58 <DIR> d-------- C:\Program Files\Real
2008-06-25 22:58 . 2008-06-25 22:58 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-06-25 22:58 . 2008-06-25 22:58 <DIR> d-------- C:\Program Files\Common Files\Real
2008-06-25 22:54 . 2008-06-25 22:54 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-25 22:54 . 2008-07-17 15:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-25 22:49 . 2008-06-25 22:49 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-25 22:49 . 2008-06-25 22:49 <DIR> d-------- C:\Documents and Settings\mdg\Application Data\Malwarebytes
2008-06-25 22:49 . 2008-06-25 22:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-25 22:49 . 2008-06-19 17:48 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-25 22:49 . 2008-06-19 17:47 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-25 22:30 . 2008-06-25 22:30 <DIR> d-------- C:\WINDOWS\Google Earth Pro 4.2
2008-06-25 22:30 . 2008-06-25 22:30 <DIR> d-------- C:\Program Files\Google Earth Pro 4.2
2008-06-25 21:48 . 2004-06-10 10:31 135,168 -ra------ C:\WINDOWS\UNDPX2A.exe
2008-06-25 21:48 . 2004-06-10 10:34 53,693 -ra------ C:\WINDOWS\UNDPX2A.sys
2008-06-25 21:48 . 2004-06-09 19:42 15,429 -ra------ C:\WINDOWS\system32\drivers\Sacm2A.sys
2008-06-24 13:10 . 2008-06-24 13:10 <DIR> d-------- C:\Program Files\Infogrames Interactive
2008-06-23 17:10 . 2008-06-23 17:10 754 --a------ C:\WINDOWS\WORDPAD.INI
2008-06-20 13:41 . 2008-06-20 13:41 245,248 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 06:44 . 2008-06-20 06:44 138,368 -----c--- C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 05:52 . 2008-06-20 05:52 225,920 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-18 14:28 . 2008-06-18 14:28 <DIR> d-------- C:\Documents and Settings\Kuzniak\Application Data\McAfee
2008-06-17 22:47 . 2008-06-17 22:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-17 17:27 . 2008-06-17 17:27 5,120 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-06-17 13:19 . 2008-06-17 13:26 <DIR> d-------- C:\Program Files\HammerHead
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 21:45 --------- d-----w C:\Program Files\PeerGuardian2
2008-07-17 19:00 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-17 18:44 --------- d-----w C:\Program Files\SiteAdvisor
2008-07-17 18:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-07-17 14:22 --------- d-----w C:\Documents and Settings\mdg\Application Data\Hamachi
2008-07-14 16:36 --------- d-----w C:\Documents and Settings\mdg\Application Data\Skype
2008-07-14 16:01 --------- d-----w C:\Program Files\Java
2008-07-14 03:58 --------- d-----w C:\Documents and Settings\mdg\Application Data\uTorrent
2008-07-07 03:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-07 03:33 --------- d-----w C:\Documents and Settings\mdg\Application Data\McAfee
2008-07-04 20:40 26,056 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-07-03 20:57 --------- d-----w C:\Program Files\Steam
2008-07-03 17:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-02 13:17 --------- d-----w C:\Documents and Settings\Kuzniak\Application Data\Skype
2008-07-01 00:53 --------- d-----w C:\Program Files\OCCT
2008-07-01 00:53 --------- d-----w C:\Program Files\Guild Wars
2008-07-01 00:53 --------- d-----w C:\Program Files\Cheat Engine
2008-06-30 03:13 --------- d-----w C:\Program Files\DAEMON Tools
2008-06-29 23:25 --------- d-----w C:\Program Files\Yahoo!
2008-06-27 02:39 --------- d-----w C:\Program Files\LimeWire
2008-06-26 20:09 --------- d-----w C:\Program Files\CyberLink
2008-06-26 02:58 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-26 02:58 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-26 02:01 --------- d-----w C:\Program Files\McAfee
2008-06-23 17:38 --------- d-----w C:\Program Files\SpeedFan
2008-06-23 17:38 --------- d-----w C:\Program Files\ShortKeys2
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-18 19:16 2,842 -c--a-w C:\Documents and Settings\Kuzniak\Application Data\wklnhst.dat
2008-06-18 02:48 --------- d-----w C:\Program Files\Lavasoft
2008-06-18 02:48 --------- d-----w C:\Documents and Settings\mdg\Application Data\Lavasoft
2008-06-18 02:47 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-17 00:06 10,942 -c--a-w C:\Documents and Settings\mdg\Application Data\wklnhst.dat
2008-06-01 00:44 --------- d-----w C:\Documents and Settings\mdg\Application Data\Nero
2008-06-01 00:41 --------- d-----w C:\Program Files\Common Files\Nero
2008-06-01 00:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-06-01 00:38 --------- d-----w C:\Program Files\Nero
2008-05-31 21:14 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-28 23:18 --------- d-----w C:\Program Files\Common Files\McAfee
2008-05-28 23:16 --------- d-----w C:\Program Files\McAfee.com
2008-05-28 23:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-05-26 02:52 --------- d-----w C:\Program Files\Paint.NET
2008-05-26 02:51 --------- d-----w C:\Program Files\QuickTime
2008-05-26 02:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-24 04:11 --------- d-----w C:\Documents and Settings\mdg\Application Data\HPAppData
2008-05-24 00:54 --------- d-----w C:\Program Files\7-Zip
2008-05-22 17:33 --------- d-----w C:\Program Files\Trymedia
2008-05-20 23:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-05-20 21:11 --------- d-----w C:\Documents and Settings\mdg\Application Data\HP
2008-05-18 22:17 --------- d-----w C:\Program Files\nLite
2008-05-18 21:16 --------- d-----w C:\Documents and Settings\LocalService\Application Data\HP
2008-05-18 21:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-05-18 21:14 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\HPAppData
2008-05-18 21:14 --------- d-----w C:\Program Files\HP
2008-05-18 21:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-05-18 21:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-05-18 21:11 --------- d-----w C:\Program Files\Common Files\HP
2008-05-18 21:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-05-18 21:10 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-05-18 21:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-05-18 18:35 --------- d-----w C:\Program Files\Copysafe
2008-05-18 18:35 --------- d-----w C:\Program Files\ATITool
2008-05-18 17:58 --------- d-----w C:\Program Files\Incomplete
2008-05-18 02:19 --------- d-----w C:\Program Files\Lavalys
2008-05-18 01:48 --------- d-----w C:\Program Files\Electronic Arts
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-26 20:14 42,672 ----a-w C:\WINDOWS\system32\wbsys.dll
2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2007-04-29 21:26 374 -c--a-w C:\Documents and Settings\mdg\Application Data\internaldb6334.dat
2007-04-29 21:25 18,432 ----a-w C:\Documents and Settings\mdg\Application Data\internaldb41.dat
2007-04-29 21:24 538 -c--a-w C:\Documents and Settings\mdg\Application Data\internaldb8467.dat
2006-12-06 03:57 59,952 -c--a-w C:\Documents and Settings\Kuzniak\Application Data\GDIPFONTCACHEV1.DAT
2007-10-17 00:35 56 --sh--r C:\WINDOWS\system32\CF7EBFD16D.sys
2007-10-17 00:38 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
------- Sigcheck -------
2007-06-13 06:23 1617920 5411554c84b28fc522ca788aaf3d2e44 C:\WINDOWS\explorer.exe
2007-06-13 07:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 08:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 06:23 1617920 5411554c84b28fc522ca788aaf3d2e44 C:\WINDOWS\icon_TMP\explorer.exe
2007-06-13 06:23 4918784 a4d32bd82c68d8f1407064ad8d2b9ccb C:\WINDOWS\system_backup\explorer.exe
2007-06-13 06:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_SAVE\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-17 14:59 266497]
"BootSkin Startup Jobs"="C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" [2004-04-26 16:21 270336]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-05-02 00:15 15872]
C:\Documents and Settings\Kuzniak\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 16:41:28 393216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-04-29 21:58 210168 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^mdg^Start Menu^Programs^Startup^Xfire.lnk]
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
--a------ 2005-08-12 14:43 45056 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]
--a------ 2008-07-04 11:55 1655552 C:\Program Files\COMODO\Firewall\cfp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO SafeSurf]
--a------ 2008-07-04 10:54 278264 C:\Program Files\COMODO\SafeSurf\cssurf.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-09-18 10:16 171464 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DelayShred]
--a------ 2007-12-04 13:32 111904 c:\PROGRA~1\McAfee\MSHR\ShrCL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2004-08-10 05:04 59392 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fraps]
--a------ 2007-03-15 23:58 781992 C:\Fraps\fraps.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-03-11 21:34 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MBkLogOnHook]
--a------ 2007-01-08 11:22 20480 C:\Program Files\McAfee\MBK\LogonHook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee Backup]
--a------ 2007-01-16 13:59 4838952 C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
--a------ 2007-11-01 19:12 582992 C:\Program Files\McAfee.com\Agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McENUI]
--a------ 2007-11-30 05:42 1164576 C:\PROGRA~1\McAfee\MHN\McENUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-12-03 14:21 2213160 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 14:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-01-20 03:05 217088 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2007-08-31 17:40 22879528 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-06-30 23:33 1271032 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2008-02-29 16:03 1481968 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-06-25 22:58 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
--a------ 2006-06-29 19:55 707376 C:\WINDOWS\vVX3000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2007-02-26 15:03 16125440 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
--a------ 2006-05-16 18:04 2879488 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrB"=3 (0x3)
"PnkBstrA"=2 (0x2)
"NBService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Dcfssvc"=2 (0x2)
"BITS"=2 (0x2)
"ATI Smart"=2 (0x2)
"aspnet_state"=3 (0x3)
"AppMgmt"=3 (0x3)
"ALG"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Steam\\steamapps\\kuzniak2\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Steam\\steamapps\\kuzniak2\\half-life 2 deathmatch\\hl2.exe"=
"C:\\Program Files\\KODAK\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"C:\\Program Files\\Steam\\steamapps\\kuzniak2\\day of defeat source\\hl2.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*

isabled

xpsp2res.dll,-22009
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-07-04 11:55]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-07-04 11:55]
R3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-06-19 17:48]
S2 0233271214445745mcinstcleanup;McAfee Application Installer Cleanup (0233271214445745);C:\WINDOWS\TEMP\
023327~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 cheetah1;cheetah1;C:\DOCUME~1\mdg\LOCALS~1\Temp\Rar$EX01.375\ce13\cheetah.sys []
S3 cpuz126;cpuz126;C:\DOCUME~1\mdg\LOCALS~1\Temp\cpuz.sys []
S3 cpuz128;cpuz128;C:\DOCUME~1\mdg\LOCALS~1\Temp\cpuz_x32.sys []
S3 CrystalCpuInfo;CrystalCpuInfo;C:\Program Files\OCCT\CpuInfo.sys []
S3 iCheat1;iCheat1;C:\DOCUME~1\mdg\LOCALS~1\Temp\Rar$EX04.953\Engine\
WWW.TSFOROS.COM\bin\iDriver.sys []
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\DOCUME~1\mdg\LOCALS~1\Temp\Rar$EX00.609\MoonLight_Engine_1083.3\IlvMoney1083.sys []
S3 kaspersky1;Kaspersky1;C:\DOCUME~1\mdg\LOCALS~1\Temp\Rar$EX19.406\Kaspersky.sys []
S3 sejt1;sejt1;C:\DOCUME~1\mdg\LOCALS~1\Temp\Rar$EX01.469\akuma\akuma\sejt.sys []
S3 SoRa01;SoRa01;C:\Documents and Settings\mdg\Desktop\SoRa Remake Engine 2.6\SoRa Remak Engine 2.6\SoRa.sys []
S3 spuce1;spuce1;C:\DOCUME~1\mdg\LOCALS~1\Temp\Rar$EX00.078\Spuc3ngine!\spuce.sys []
S3 SQTECH930B;USB 2.0 PC CAMERA;C:\WINDOWS\system32\Drivers\Capt930b.sys []
S3 sys_com001;sys_com001;C:\DOCUME~1\mdg\LOCALS~1\Temp\Rar$EX00.219\SysComEngine_1059\syscom.sys []
S3 TSHAK3T1;TSHAK3T1;C:\DOCUME~1\mdg\LOCALS~1\Temp\Rar$EX02.891\RE 3.2\spuce.sys []
S3 xp1;xp1;C:\Documents and Settings\mdg\Desktop\XPEngine\xp.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - MBAMCATCHME
*Newly Created Service* - PGFILTER
.
Contents of the 'Scheduled Tasks' folder
"2008-05-28 23:16:37 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-05-28 23:16:36 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-07-11 02:44:27 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-07-01 00:50:17 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-17 17:47:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-17 17:49:20
ComboFix-quarantined-files.txt 2008-07-17 21:49:11
Pre-Run: 123,790,409,728 bytes free
Post-Run: 123,780,014,080 bytes free
375 --- E O F --- 2008-07-10 17:34:29
Thanks in advance.

P.S: Please PLEASE PLEASE tell me it was a false positive....

Nest is the HJT log.