Can you please post the log from it so we can finish cleaning up your computer? The log will be located at c:\combofix.txt. As also said please provide me with an uninstall list from hijackthis.
ComboFix 09-12-29.02 - User 12/29/2009 13:36:27.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1315 [GMT -6:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
ADS - system32: deleted 142 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\User\My Documents\ZbThumbnail.info
c:\program files\Helper
c:\windows\Downloaded Program Files\webinst.dll
c:\windows\javcorain.dll
c:\windows\javcorbin.dll
c:\windows\kb913800.exe
c:\windows\sntlevel.dll
c:\windows\system32\_000022_.tmp.dll
c:\windows\system32\_000023_.tmp.dll
c:\windows\system32\_000024_.tmp.dll
c:\windows\system32\_000025_.tmp.dll
c:\windows\system32\_000026_.tmp.dll
c:\windows\system32\_000027_.tmp.dll
c:\windows\system32\_000028_.tmp.dll
c:\windows\system32\_000029_.tmp.dll
c:\windows\system32\_000030_.tmp.dll
c:\windows\system32\_000031_.tmp.dll
c:\windows\system32\_000032_.tmp.dll
c:\windows\system32\_000033_.tmp.dll
c:\windows\system32\_000034_.tmp.dll
c:\windows\system32\_000035_.tmp.dll
c:\windows\system32\_000036_.tmp.dll
c:\windows\system32\_000037_.tmp.dll
c:\windows\system32\_000038_.tmp.dll
c:\windows\system32\_000039_.tmp.dll
c:\windows\system32\_000040_.tmp.dll
c:\windows\system32\_000041_.tmp.dll
c:\windows\system32\_000042_.tmp.dll
c:\windows\system32\_000043_.tmp.dll
c:\windows\system32\_000044_.tmp.dll
c:\windows\system32\_000045_.tmp.dll
c:\windows\system32\_000046_.tmp.dll
c:\windows\system32\_000047_.tmp.dll
c:\windows\system32\_000048_.tmp.dll
c:\windows\system32\_000049_.tmp.dll
c:\windows\system32\_000050_.tmp.dll
c:\windows\system32\_000051_.tmp.dll
c:\windows\system32\_000052_.tmp.dll
c:\windows\system32\_000053_.tmp.dll
c:\windows\system32\_000054_.tmp.dll
c:\windows\system32\Cache
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.
2009-12-29 19:41 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-12-29 19:41 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-12-29 09:56 . 2009-12-29 09:56 -------- d-----w- c:\program files\Trend Micro
2009-12-29 07:15 . 2009-12-29 07:15 -------- dc-h--w- c:\windows\ie8
2009-12-29 00:17 . 2009-12-29 05:24 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\eqtchu
2009-12-06 14:31 . 2009-12-06 14:31 -------- d-----w- c:\program files\Guitar Pro 5
2009-12-06 14:10 . 2009-12-06 14:10 -------- d-----w- c:\documents and settings\User\Application Data\comcasttb
2009-12-05 03:48 . 2009-12-05 03:48 262144 ----a-w- C:\ntuser.dat
2009-11-29 23:40 . 2009-09-10 20:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-29 23:40 . 2009-11-29 23:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-29 23:40 . 2009-09-10 20:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 15:23 . 2007-01-03 09:11 -------- d-----w- c:\program files\Starcraft
2009-12-29 09:23 . 2009-02-12 21:50 -------- d-----w- c:\program files\Steam
2009-12-28 09:23 . 2006-12-11 14:34 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-12-28 09:23 . 2006-12-11 14:34 -------- d-----w- c:\documents and settings\User\Application Data\Corel
2009-12-28 02:55 . 2009-05-15 00:59 -------- d-----w- c:\documents and settings\User\Application Data\FrostWire
2009-12-26 23:54 . 2008-12-17 01:54 -------- d-----w- c:\program files\Absolute Poker
2009-12-24 09:14 . 2007-01-08 00:10 -------- d-----w- c:\program files\Lx_cats
2009-12-12 10:12 . 2009-04-23 04:35 -------- d-----w- c:\program files\PokerStars
2009-12-06 14:31 . 2006-12-02 22:05 88688 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-05 03:50 . 2007-01-20 11:20 -------- d-----w- c:\documents and settings\User\Application Data\Yahoo!
2009-12-05 03:48 . 2007-01-20 05:56 -------- d-----w- c:\program files\Yahoo!
2009-12-05 03:48 . 2007-08-07 06:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-12-05 03:48 . 2007-01-20 11:11 -------- d-----w- c:\documents and settings\All Users\Application Data\yahoo!
2009-11-26 15:38 . 2009-11-26 15:38 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-11-26 02:26 . 2009-11-26 02:26 -------- d-----w- c:\program files\FrostWire
2009-11-24 00:05 . 2009-09-27 14:29 -------- d-----w- c:\documents and settings\User\Application Data\Move Networks
2009-11-23 22:11 . 2009-11-23 00:41 -------- d-----w- c:\documents and settings\User\Application Data\CallingID
2009-11-23 11:30 . 2006-11-29 18:12 -------- d-----w- c:\program files\Microsoft Plus! Digital Media Edition
2009-11-23 11:14 . 2009-11-23 03:00 -------- d-----w- c:\program files\McAfee
2009-11-23 09:36 . 2009-11-23 00:40 -------- d-----w- c:\program files\Common Files\scanner
2009-11-23 03:02 . 2006-11-29 18:16 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-04 22:54 . 2009-11-04 22:54 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-11-04 22:53 . 2009-11-23 02:55 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-11-03 02:42 . 2009-10-02 16:23 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-31 17:14 . 2009-04-14 21:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-31 17:00 . 2009-10-31 17:00 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes
2009-10-31 17:00 . 2009-10-31 17:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-31 02:34 . 2008-01-23 06:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-29 07:45 . 2005-08-16 10:18 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-27 15:44 . 2009-08-10 03:18 1750 ----a-w- c:\documents and settings\User\Application Data\wklnhst.dat
2009-10-21 05:38 . 2005-08-16 10:18 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2005-08-16 10:18 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 05:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2005-08-16 10:18 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2005-08-16 10:18 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2005-08-16 10:18 79872 ----a-w- c:\windows\system32\raschap.dll
2008-10-02 03:09 . 2008-10-02 03:09 251 ----a-w- c:\program files\wt3d.ini
2009-12-01 03:12 . 2007-05-19 17:33 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-12-01 03:12 . 2007-05-19 17:33 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-12-01 03:12 . 2007-05-19 17:33 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-12-01 03:12 . 2007-05-19 17:33 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-12-01 03:12 . 2007-05-19 17:33 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"CoreADManager"="c:\windows\diskperfm.exe" [2009-07-14 749568]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-07-20 73728]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ddoctorv2]
2008-04-24 19:25 202560 ----a-w- c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\SteamApps\\legend1983\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [10/5/2006 10:11 PM 13592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 10:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2009-12-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2009-12-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-23 18:22]
2009-12-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-23 18:22]
c:\windows\Tasks\MP Scheduled Scan.job
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search - ?p=ZJman000
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: returnval()
Trusted Zone: villagephotos.com\www
Trusted Zone: musicmatch.com\online
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {8B67B37E-1AE2-4B99-B8CF-55AF4D58DF0D} - file://d:\win\setup\iamce.dll
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\vi0fj36o.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL -
FF - component: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\vi0fj36o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-NavLogon - (no file)
AddRemove-Absolute Poker - c:\program files\_uninstallation_info\Absolute Poker\CasinoUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-29 13:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2924)
c:\windows\system32\WININET.dll
c:\windows\mdiwindb.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\stivendor.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2009-12-29 13:57:00 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-29 19:56
Pre-Run: 122,699,862,016 bytes free
Post-Run: 122,535,858,176 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - FD1A558C82F7E0DCDAFFAA9DA3FC01D8
the combofix