Here is the ComboFix Log
ComboFix 10-02-23.03 - Jeff 02/23/2010 19:14:35.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1388 [GMT -6:00]
Running from: c:\documents and settings\Jeff\Bluetooth Software\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-346308534-839334332-2326838845-1003
c:\windows\Downloaded Program Files\Install.inf
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.
2010-02-23 23:20 . 2010-02-23 23:20 -------- d-----w- c:\documents and settings\Jeff\Application Data\Malwarebytes
2010-02-23 23:20 . 2010-01-07 22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 23:20 . 2010-02-23 23:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-23 23:20 . 2010-02-23 23:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 23:20 . 2010-01-07 22:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 21:47 . 2010-02-23 21:47 -------- d-----w- c:\program files\CCleaner
2010-02-23 04:50 . 2010-02-23 17:33 -------- d-----w- c:\documents and settings\Jeff\Application Data\eMusic
2010-02-23 04:50 . 2010-02-23 04:50 -------- d-----w- c:\documents and settings\Jeff\Local Settings\Application Data\eMusic
2010-02-23 04:50 . 2010-02-23 17:34 -------- d-----w- c:\program files\eMusic Download Manager
2010-02-22 23:53 . 2010-02-22 23:53 -------- d-----w- c:\program files\Trend Micro
2010-02-22 10:00 . 2010-02-22 10:03 -------- d-----w- c:\documents and settings\Jeff\Application Data\Download Manager
2010-02-21 21:16 . 2010-02-21 23:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-21 21:16 . 2010-02-21 21:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-21 04:42 . 2010-02-21 04:42 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2010-02-21 04:42 . 2010-02-21 04:48 -------- d-----w- c:\program files\RegCure
2010-02-21 03:27 . 2010-02-21 03:27 -------- d--h--w- c:\windows\PIF
2010-02-21 00:16 . 2010-01-14 17:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-02-21 00:06 . 2010-02-21 00:06 -------- d-----w- c:\documents and settings\Jeff\Application Data\ConsumerSoft
2010-02-21 00:06 . 2010-02-21 01:00 -------- d-----w- c:\program files\ConsumerSoft
2010-02-20 16:50 . 2010-02-20 16:50 -------- d-----w- c:\documents and settings\Jeff\Local Settings\Application Data\PCHealth
2010-02-20 16:50 . 2010-02-20 16:50 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2010-02-20 14:27 . 2010-02-20 14:27 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-02-09 00:01 . 2010-02-09 00:01 -------- d-----w- c:\documents and settings\Jeff\Local Settings\Application Data\Yahoo
2010-02-08 23:42 . 2010-02-09 00:01 -------- d-----w- c:\program files\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 17:11 . 2009-08-09 23:51 -------- d-----w- c:\documents and settings\Jeff\Application Data\U3
2010-01-23 22:51 . 2010-01-23 22:51 503808 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6349b862-n\msvcp71.dll
2010-01-23 22:51 . 2010-01-23 22:51 499712 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6349b862-n\jmc.dll
2010-01-23 22:51 . 2010-01-23 22:51 348160 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6349b862-n\msvcr71.dll
2010-01-23 22:51 . 2010-01-23 22:51 61440 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6365fdb7-n\decora-sse.dll
2010-01-23 22:51 . 2010-01-23 22:51 12800 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6365fdb7-n\decora-d3d.dll
2010-01-20 17:12 . 2010-01-20 17:12 -------- d-----w- c:\program files\Common Files\Java
2010-01-20 17:10 . 2010-01-20 17:10 503808 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-4ac07d12-n\msvcp71.dll
2010-01-20 17:10 . 2010-01-20 17:10 348160 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-4ac07d12-n\msvcr71.dll
2010-01-20 17:10 . 2010-01-20 17:10 499712 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-4ac07d12-n\jmc.dll
2010-01-20 17:10 . 2010-01-20 17:10 61440 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-4ac07d12-n\decora-sse.dll
2010-01-20 17:10 . 2010-01-20 17:10 315392 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-4b73100c-n\jogl.dll
2010-01-20 17:10 . 2010-01-20 17:10 20480 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-4b73100c-n\jogl_awt.dll
2010-01-20 17:10 . 2010-01-20 17:10 20480 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\45\4f710eed-3925db03-n\gluegen-rt.dll
2010-01-20 17:10 . 2010-01-20 17:10 12800 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\759e98ee-4ac07d12-n\decora-d3d.dll
2010-01-20 17:10 . 2010-01-20 17:10 114688 ----a-w- c:\documents and settings\Jeff\Application Data\Sun\Java\Deployment\SystemCache\6.0\62\6baea4fe-4b73100c-n\jogl_cg.dll
2010-01-20 17:10 . 2009-10-01 16:59 -------- d-----w- c:\program files\Java
2010-01-16 14:36 . 2009-06-23 03:51 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-05 10:00 . 2009-05-20 19:07 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2009-05-20 19:07 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2009-05-20 19:07 17408 ----a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2009-05-20 19:07 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-17 23:14 . 2009-10-01 16:59 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-16 18:43 . 2009-05-20 19:16 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2009-05-20 19:07 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2008-04-14 00:54 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2008-04-14 00:01 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2009-05-20 19:07 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-02 21:23 . 2009-12-02 21:23 149040 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2009-11-27 17:11 . 2009-05-20 19:07 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2008-04-14 05:42 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2009-05-20 19:07 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2009-05-20 19:07 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2009-05-20 19:06 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2008-04-14 05:41 48128 ----a-w- c:\windows\system32\iyuv_32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-17 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-17 118784]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-06 1434920]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-03-06 79144]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2009-07-08 3054136]
"LiveUpdate"="c:\program files\Asus\LiveUpdate\LiveUpdate.exe" [2009-08-27 735208]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-27 17567744]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-01-29 1095872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\Jeff\Start Menu\Programs\Startup\
Shortcut to SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-8-10 813584]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-6-22 376832]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 16:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-18 14:58 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-07 01:51 3885408 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [6/22/2009 10:03 PM 55152]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [8/10/2009 8:58 PM 10384]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [6/1/2009 1:26 AM 38912]
R3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [6/1/2009 1:26 AM 39040]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [6/22/2009 9:49 PM 1684736]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 7:08 PM 533360]
.
Contents of the 'Scheduled Tasks' folder
2010-02-23 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-02-12 20:17]
2010-02-23 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2010-02-12 20:17]
2010-02-21 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-02-12 20:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} - hxxp://173.9.66.81:8082/SysCamInst.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-23 19:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys >>UNKNOWN [0x8A3A78C8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0fcf28
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\iaStor -> iaStor.sys @ 0xb9ea0716
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Atheros AR8132 PCI-E Fast Ethernet Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9d69bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9d76a21
SendHandler -> NDIS.sys @ 0xb9d5487b
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2010-02-23 19:25:55
ComboFix-quarantined-files.txt 2010-02-24 01:25
Pre-Run: 62,325,989,376 bytes free
Post-Run: 62,369,415,168 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - C0FED35051E6A77E24BB707A6BE6443B