Goodmorning Derek!!!
i did as written above step by step, but again no zip file at my desktop .
ComboFix 08-03-22.3 - User 2008-03-23 11:08:44.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1253.1.1032.18.1455 [GMT 2:00]
Running from: C:\Documents and Settings\User\Επιφάνεια εργασίας\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Επιφάνεια εργασίας\CFScript.txt
* Created a new restore point
FILE ::
C:\Program Files\tmp10362437.exe
C:\Program Files\tmp114421.exe
C:\Program Files\tmp13941125.exe
C:\Program Files\tmp183437.exe
C:\Program Files\tmp183484.exe
C:\Program Files\tmp185578.exe
C:\Program Files\tmp186078.exe
C:\Program Files\tmp1917234.exe
C:\Program Files\tmp1926593.exe
C:\Program Files\tmp21163343.exe
C:\Program Files\tmp222250.exe
C:\Program Files\tmp228687.exe
C:\Program Files\tmp2985296.exe
C:\Program Files\tmp2986984.exe
C:\Program Files\tmp512453.exe
C:\Program Files\tmp514468.exe
C:\Program Files\udefender_setup.exe
C:\Program Files\xloader30029.exe
C:\WINDOWS\Irremote.ini
C:\WINDOWS\system32\cuylpddo.ini
C:\WINDOWS\system32\jcseynhq.ini
C:\WINDOWS\system32\mwvbmddr.ini
C:\WINDOWS\system32\qsqpqepg.ini
C:\WINDOWS\system32\tieqjeey.ini
C:\WINDOWS\system32\winbjt32.dll
C:\WINDOWS\system32\ysveahrh.ini
C:\WINDOWS\ujf635.bin
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\IE Extensions
C:\Program Files\IE Extensions\cj.v2.dll
C:\Program Files\tmp183437.exe
C:\Program Files\tmp183484.exe
C:\Program Files\tmp185578.exe
C:\Program Files\tmp21163343.exe
C:\Program Files\udefender_setup.exe
C:\WINDOWS\Irremote.ini
C:\WINDOWS\ujf635.bin
.
((((((((((((((((((((((((( Files Created from 2008-02-23 to 2008-03-23 )))))))))))))))))))))))))))))))
.
2008-03-23 11:08 . 2008-03-23 11:08 58,833 --a------ C:\Documents and Settings\User\catchme.zip
2008-03-22 23:27 . 2008-03-22 23:27 16,620 --a------ C:\Program Files\tmp22648875.exe
2008-03-22 23:27 . 2008-03-22 23:27 16,504 --a------ C:\Program Files\tmp22654156.exe
2008-03-22 20:33 . 2008-03-22 20:33 0 --a------ C:\WINDOWS\system32\SBRC.dat
2008-03-22 20:33 . 2008-03-22 20:33 0 --a------ C:\WINDOWS\system32\SBFC.dat
2008-03-22 19:40 . 2008-03-22 19:40 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys
2008-03-22 19:39 . 2008-03-22 19:39 <DIR> d-------- C:\Documents and Settings\User\Application Data\Sunbelt Software
2008-03-22 19:39 . 2008-03-22 19:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software
2008-03-22 19:38 . 2008-03-22 19:38 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-03-19 21:12 . 2008-03-19 21:12 <DIR> d-------- C:\WINDOWS\Sun
2008-03-19 12:01 . 2008-03-19 12:01 <DIR> d-------- C:\Documents and Settings\User\Application Data\Malwarebytes
2008-03-19 12:00 . 2008-03-19 12:45 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-19 12:00 . 2008-03-19 12:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-18 08:58 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-18 08:57 . 2008-03-18 08:58 <DIR> d-------- C:\Program Files\Java
2008-03-18 08:51 . 2008-03-18 08:51 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-16 10:52 . 2008-03-16 10:52 <DIR> d-------- C:\Documents and Settings\User\Application Data\Talkback
2008-03-11 18:53 . 2006-04-10 14:03 38,400 --a------ C:\WINDOWS\system32\hpz3l054.dll
2008-03-11 18:39 . 2008-03-11 18:47 128,670 --a------ C:\WINDOWS\hpoins11.dat
2008-03-06 15:14 . 2008-03-06 15:14 <DIR> d-------- C:\Documents and Settings\User\Application Data\Nero
2008-03-06 15:00 . 2008-03-06 15:00 <DIR> d-------- C:\Program Files\Nero
2008-03-06 15:00 . 2008-03-20 23:44 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-03-06 15:00 . 2008-03-20 23:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-04 12:29 . 2008-03-04 14:50 13,030 --a------ C:\PDOXUSRS.NET
2008-03-04 12:27 . 2008-03-04 12:27 <DIR> d-------- C:\Program Files\Common Files\Borland Shared
2008-03-04 12:27 . 2008-03-04 12:28 <DIR> d-------- C:\MapGuide
2008-03-04 12:27 . 2008-03-04 12:27 <DIR> d-------- C:\Documents and Settings\User\WINDOWS
2008-03-04 12:27 . 1999-03-23 09:12 299,520 --a------ C:\WINDOWS\uninst.exe
2008-03-01 13:23 . 2008-03-01 13:27 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2008-03-01 13:22 . 2008-03-01 13:22 <DIR> d-------- C:\Program Files\Betfair
2008-03-01 13:22 . 2008-03-01 13:22 <DIR> d-------- C:\Documents and Settings\User\Application Data\Betfair
2008-02-29 18:48 . 2008-02-29 18:48 19,552 --a------ C:\Documents and Settings\User\Application Data\GDIPFONTCACHEV1.DAT
2008-02-27 11:05 . 2008-02-27 11:05 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-02-27 11:02 . 2008-02-27 11:02 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-02-27 11:02 . 2008-02-27 11:03 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-02-26 16:56 . 2008-02-26 17:21 <DIR> d-------- C:\Documents and Settings\User\Application Data\HP
2008-02-26 16:30 . 2005-10-12 04:20 77,824 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-02-26 16:30 . 2006-07-03 11:54 38,400 --a------ C:\WINDOWS\system32\hpz3l4sa.dll
2008-02-26 16:25 . 2008-02-26 16:57 139,975 --a------ C:\WINDOWS\hpwins10.dat
2008-02-26 16:25 . 2006-12-11 08:28 771 --------- C:\WINDOWS\hpwmdl10.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-22 12:49 --------- d-----w C:\Program Files\ScanPro
2008-03-20 19:11 --------- d-----w C:\Program Files\PKR
2008-03-07 06:02 --------- d-----w C:\Program Files\Panda Security
2008-02-26 14:48 --------- d-----w C:\Program Files\HP
2008-02-15 14:44 --------- d-----w C:\Program Files\GeoValues
2008-02-14 15:05 --------- d-----w C:\Documents and Settings\User\Application Data\Saxo Bank
2008-02-14 14:58 --------- d-----w C:\Program Files\Saxo Bank
2008-02-14 06:22 --------- d-----w C:\Program Files\MSXML 4.0
2008-02-13 22:00 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-13 21:39 --------- d-----w C:\Documents and Settings\User\Application Data\InterTrust
2008-02-13 19:49 249,856 ------w C:\WINDOWS\Setup1.exe
2008-02-13 19:48 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-02-13 12:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-02-13 12:11 --------- d-----w C:\Program Files\Common Files\HP
2008-02-13 12:08 --------- d-----w C:\Program Files\Hewlett-Packard
2008-02-13 12:06 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-02-13 08:40 --------- d-----w C:\Program Files\Google
2008-02-12 19:02 --------- d-----w C:\Program Files\Common Files\Panda Software
2008-02-12 18:57 38,968 ----a-w C:\WINDOWS\system32\drivers\ShlDrv51.sys
2008-02-12 18:57 178,872 ----a-w C:\WINDOWS\system32\drivers\PavProc.sys
2008-02-12 16:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\sentinel
2008-02-12 16:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-12 16:17 --------- d-----w C:\Program Files\CONEXANT
2008-02-12 16:14 --------- d-----w C:\Program Files\Realtek
2008-02-12 16:14 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-12 16:04 --------- d-----w C:\Program Files\Intel
2008-02-12 15:55 --------- d-----w C:\Program Files\microsoft frontpage
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Program Files\PKR ----
2008-03-22 08:29 782030243 --a------ C:\Program Files\PKR\cache\data.arc
2008-03-22 08:29 35 --a------ C:\Program Files\PKR\cache\data.arc.dat
2008-03-22 08:29 1822 --a------ C:\Program Files\PKR\preferences.xml
2008-03-22 08:29 126675 --a------ C:\Program Files\PKR\client_gamelog.txt
2008-03-22 08:29 1171456 --ahs---- C:\Program Files\PKR\cache\radial.cdb
2008-03-22 08:28 7552 --a------ C:\Program Files\PKR\pkr_log.log
2008-03-22 08:28 745 --a------ C:\Program Files\PKR\client_logfile.txt
2008-03-22 08:28 189 --a------ C:\Program Files\PKR\pkrpal_startup.xml
2008-03-22 08:28 1386 --a------ C:\Program Files\PKR\d3dcaps.txt
2008-03-22 08:28 0 --a------ C:\Program Files\PKR\webservercomms_logfile.txt
2008-03-22 08:28 0 --a------ C:\Program Files\PKR\profile_logfile.txt
2008-03-20 22:23 25309 --a------ C:\Program Files\PKR\handhistory\boubal\20080320\Tournament #4793458 Table #2.txt
2008-03-20 22:03 19960 --a------ C:\Program Files\PKR\handhistory\boubal\20080320\Tournament #4793458 Table #1.txt
2008-03-20 21:11 4944488 --a------ C:\Program Files\PKR\pokerapp.exe
2008-03-20 21:11 262144 --a------ C:\Program Files\PKR\crashreport.exe
2008-03-20 21:10 464 --a------ C:\Program Files\PKR\system-hashes.cache
2008-03-20 21:06 610 --a------ C:\Program Files\PKR\cache\deltacache\deltas.info
2008-03-20 21:06 2273896 --a------ C:\Program Files\PKR\pkrpal.exe
2008-03-20 21:05 2478696 --a------ C:\Program Files\PKR\pkr.exe
2008-03-15 20:51 37140 --a------ C:\Program Files\PKR\handhistory\boubal\20080315\Tournament #4710117 Table #9.txt
2008-03-15 20:04 22647 --a------ C:\Program Files\PKR\handhistory\boubal\20080315\STT #4734459.txt
2008-03-04 00:18 14449 --a------ C:\Program Files\PKR\handhistory\boubal\20080304\Kangaroo Island.txt
2008-03-04 00:00 92754 --a------ C:\Program Files\PKR\handhistory\boubal\20080303\Kangaroo Island.txt
2008-03-03 19:46 90271 --a------ C:\Program Files\PKR\handhistory\boubal\20080303\Tournament #4578141 Table #4.txt
2008-03-03 17:14 60729 --a------ C:\Program Files\PKR\handhistory\boubal\20080303\Cloud of Love 1.txt
2008-03-02 23:24 4028 --a------ C:\Program Files\PKR\handhistory\boubal\20080302\Crouching Tiger 2.txt
2008-03-02 23:16 37829 --a------ C:\Program Files\PKR\handhistory\boubal\20080302\Heroes & Villians 2.txt
2008-03-02 22:30 9620 --a------ C:\Program Files\PKR\handhistory\boubal\20080302\Tournament #4569521 Table #7.txt
2008-03-02 22:21 39900 --a------ C:\Program Files\PKR\handhistory\boubal\20080302\Tournament #4569521 Table #12.txt
2008-03-02 20:00 15874 --a------ C:\Program Files\PKR\handhistory\boubal\20080302\Rochelle.txt
2008-03-02 14:32 61412 --a------ C:\Program Files\PKR\pokerapp.zip.0001
2008-03-02 14:32 61412 --a------ C:\Program Files\PKR\pokerapp.zip
2008-03-02 14:32 299155 --a------ C:\Program Files\PKR\dxdiag.txt
2008-03-02 14:31 62432 --a------ C:\Program Files\PKR\CRASH.DMP
2008-03-02 14:31 43852 --a------ C:\Program Files\PKR\ERRORLOG.TXT
2008-03-02 14:31 27464 --a------ C:\Program Files\PKR\handhistory\boubal\20080302\Tournament #4575548 Table #2.txt
2008-03-02 14:31 177 --a------ C:\Program Files\PKR\REGISTRY.TXT
2008-03-01 11:20 43646 --a------ C:\Program Files\PKR\handhistory\boubal\20080301\Tournament #4560242 Table #2.txt
2008-03-01 10:45 15085 --a------ C:\Program Files\PKR\handhistory\boubal\20080301\Tournament #4560242 Table #4.txt
2008-02-28 23:04 8871 --a------ C:\Program Files\PKR\handhistory\boubal\20080228\STT #4547729.txt
2008-02-27 22:26 70166 --a------ C:\Program Files\PKR\handhistory\boubal\20080227\Tournament #4535806 Table #2.txt
2008-02-27 21:46 3638 --a------ C:\Program Files\PKR\handhistory\boubal\20080227\Tournament #4535806 Table #1.txt
2008-02-27 16:39 27884 --a------ C:\Program Files\PKR\handhistory\boubal\20080227\STT #4532695.txt
2008-02-25 23:15 26319 --a------ C:\Program Files\PKR\handhistory\boubal\20080225\Tournament #4515934 Table #2.txt
2008-02-25 12:38 38857 --a------ C:\Program Files\PKR\handhistory\boubal\20080225\St. Eustatius.txt
2008-02-25 12:03 31131 --a------ C:\Program Files\PKR\handhistory\boubal\20080225\STT #4509646.txt
2008-02-25 00:37 2851 --a------ C:\Program Files\PKR\handhistory\boubal\20080225\Tournament #4494392 Table #14.txt
2008-02-25 00:34 25252 --a------ C:\Program Files\PKR\handhistory\boubal\20080225\Tournament #4494392 Table #11.txt
2008-02-23 23:08 18570 --a------ C:\Program Files\PKR\handhistory\boubal\20080223\STT #4493318.txt
2008-02-23 01:12 11362 --a------ C:\Program Files\PKR\handhistory\boubal\20080223\Airlie Beach 1.txt
2008-02-23 00:48 13248 --a------ C:\Program Files\PKR\handhistory\boubal\20080223\Tournament #4482667 Table #2.txt
2008-02-23 00:00 3656 --a------ C:\Program Files\PKR\handhistory\boubal\20080222\Tournament #4482667 Table #2.txt
2008-02-22 23:38 16135 --a------ C:\Program Files\PKR\handhistory\boubal\20080222\Airlie Beach 1.txt
2008-02-22 23:19 54383 --a------ C:\Program Files\PKR\handhistory\boubal\20080222\STT #4481671.txt
2008-02-18 22:34 12864 --a------ C:\Program Files\PKR\handhistory\boubal\20080218\STT #4437756.txt
2008-02-18 21:43 15545 --a------ C:\Program Files\PKR\handhistory\boubal\20080218\STT #4437277.txt
2008-02-18 21:26 72614 --a------ C:\Program Files\PKR\handhistory\boubal\20080218\STT #4436386.txt
2008-02-18 14:55 29691 --a------ C:\Program Files\PKR\handhistory\boubal\20080218\Airlie Beach 2.txt
2008-02-18 12:45 28012 --a------ C:\Program Files\PKR\handhistory\boubal\20080218\STT #4432264.txt
2008-02-18 12:13 33591 --a------ C:\Program Files\PKR\handhistory\boubal\20080218\STT #4431885.txt
2008-02-18 11:28 9656 --a------ C:\Program Files\PKR\handhistory\boubal\20080218\Dokos.txt
2008-02-18 00:13 21751 --a------ C:\Program Files\PKR\handhistory\boubal\20080218\Tournament #4427443 Table #2.txt
2008-02-18 00:00 26746 --a------ C:\Program Files\PKR\handhistory\boubal\20080217\Tournament #4427443 Table #2.txt
2008-02-17 23:34 50691 --a------ C:\Program Files\PKR\handhistory\boubal\20080217\Tournament #4427443 Table #1.txt
2008-02-17 21:47 49985 --a------ C:\Program Files\PKR\handhistory\boubal\20080217\STT #4426103.txt
2008-02-17 20:31 8837 --a------ C:\Program Files\PKR\handhistory\boubal\20080217\Hapuna Beach.txt
2008-02-17 10:10 21994 --a------ C:\Program Files\PKR\handhistory\boubal\20080217\STT #4419933.txt
2008-02-16 23:03 6350 --a------ C:\Program Files\PKR\handhistory\boubal\20080216\Tournament #4415203 Table #4.txt
2008-02-16 22:57 17932 --a------ C:\Program Files\PKR\handhistory\boubal\20080216\Tournament #4415203 Table #1.txt
2008-02-16 22:07 39506 --a------ C:\Program Files\PKR\handhistory\boubal\20080216\Arctic Barrel.txt
2008-02-16 22:00 7609 --a------ C:\Program Files\PKR\handhistory\boubal\20080216\Tournament #4406354 Table #1.txt
2008-02-16 01:39 35271 --a------ C:\Program Files\PKR\handhistory\boubal\20080216\Tournament #4404910 Table #6.txt
2008-02-15 23:44 40300 --a------ C:\Program Files\PKR\handhistory\boubal\20080215\Tournament #4403251 Table #2.txt
2008-02-15 23:05 6021 --a------ C:\Program Files\PKR\handhistory\boubal\20080215\Tournament #4403083 Table #5.txt
2008-02-15 22:58 1617 --a------ C:\Program Files\PKR\handhistory\boubal\20080215\STT #4403487.txt
2008-02-14 20:12 25155 --a------ C:\Program Files\PKR\handhistory\boubal\20080214\STT #4390429.txt
2008-02-14 10:31 21226 --a------ C:\Program Files\PKR\handhistory\boubal\20080214\STT #4386395.txt
2008-02-13 03:44 79360 --a------ C:\Program Files\PKR\miles\msssoft.m3d
2008-02-13 03:44 72704 --a------ C:\Program Files\PKR\miles\mssa3d.m3d
2008-02-13 03:44 65536 --a------ C:\Program Files\PKR\miles\mssdx7.m3d
2008-02-13 03:44 596480 --a------ C:\Program Files\PKR\granny2.dll
2008-02-13 03:44 56320 --a------ C:\Program Files\PKR\miles\mssds3d.m3d
2008-02-13 03:44 388096 --a------ C:\Program Files\PKR\mss32.dll
2008-02-13 03:44 372224 --a------ C:\Program Files\PKR\miles\mssrsx.m3d
2008-02-13 03:44 2297552 --a------ C:\Program Files\PKR\d3dx9_26.dll
2008-02-13 03:44 215040 --a------ C:\Program Files\PKR\miles\mssvoice.asi
2008-02-13 03:44 200704 --a------ C:\Program Files\PKR\ssleay32.dll
2008-02-13 03:44 150016 --a------ C:\Program Files\PKR\miles\mssmp3.asi
2008-02-13 03:44 143872 --a------ C:\Program Files\PKR\miles\msseax.m3d
2008-02-13 03:44 108544 --a------ C:\Program Files\PKR\miles\mssdsp.flt
2008-02-13 03:44 1069056 --a------ C:\Program Files\PKR\libeay32.dll
2008-02-13 03:05 205 --a------ C:\Program Files\PKR\pkrpal.xml
2008-02-13 02:35 81606 --a------ C:\Program Files\PKR\uninstall-pkr.exe
2007-12-20 13:21 22486 --a------ C:\Program Files\PKR\PKR.ico
---- Directory of C:\Program Files\ScanPro ----
2008-03-21 09:59 62492672 --a------ C:\Program Files\ScanPro\Archive_tn.mdb
2008-03-21 09:59 432447488 --a------ C:\Program Files\ScanPro\Archive_xe.mdb
2008-03-17 19:03 184664064 --a------ C:\Program Files\ScanPro\Archive_ka.mdb
2008-02-13 21:49 6853 --a------ C:\Program Files\ScanPro\ST6UNST.LOG
2007-05-22 10:25 860160 --a------ C:\Program Files\ScanPro\ScanPro.exe
((((((((((((((((((((((((((((( snapshot@2008-03-19_22.02.18.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-22 17:39:11 19,230 ----a-r C:\WINDOWS\Installer\{7136FE70-D1A9-42A5-9BBD-87C440701D9F}\ARPPRODUCTICON.exe
+ 2006-12-28 14:13:52 516,832 ----a-w C:\WINDOWS\system32\capicom.dll
+ 2006-10-30 08:30:30 10,032 ----a-w C:\WINDOWS\system32\drivers\SBTEDrv.sys
+ 2005-11-02 08:39:14 131,072 ----a-w C:\WINDOWS\system32\MD5.dll
+ 2005-11-02 08:39:16 24,924 ----a-w C:\WINDOWS\system32\openports.dll
+ 2003-02-21 05:16:08 49,152 ----a-w C:\WINDOWS\system32\REGTLIB.EXE
+ 2007-08-27 08:26:10 27,120 ----a-w C:\WINDOWS\system32\SBBD.exe
+ 2005-11-02 08:39:16 40,960 ----a-w C:\WINDOWS\system32\SDelete.dll
+ 2006-06-22 12:40:28 493,400 ----a-w C:\WINDOWS\system32\XceedZip.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-02-13 10:40 171448]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-03-02 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"RTHDCPL"="RTHDCPL.EXE" [2006-02-10 12:25 15969280 C:\WINDOWS\RTHDCPL.exe]
"CIR"="C:\WINDOWS\system32\drivers\CIR.exe" [2006-03-08 10:53 36864]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-12-21 15:30 698864]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
C:\Documents and Settings\All Users\Start Menu\α\„΅΅ε\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 12:01:04 83360]
‚γ ΅΅ε HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\WINDOWS\system32\avldr.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 O2MDRDR;O2MDRDR;C:\WINDOWS\system32\DRIVERS\o2media.sys [2005-08-05 04:51]
R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys [2008-03-22 19:40]
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\DRIVERS\ShlDrv51.sys [2008-02-12 20:57]
R2 MTC0301_CIR;CIR Device;C:\WINDOWS\system32\drivers\CIR.sys [2004-11-26 08:41]
R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\system32\DRIVERS\PavProc.sys [2008-02-12 20:57]
R3 SBAPIFS;SBAPIFS;C:\WINDOWS\system32\drivers\sbapifs.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
*Newly Created Service* - CATCHME
*Newly Created Service* - SBAPIFS
.
Contents of the 'Scheduled Tasks' folder
"2008-12-23 05:50:32 C:\WINDOWS\Tasks\User_Feed_Synchronization-{1DE4FEF4-9E98-4668-A106-B689A4205B2D}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-23 11:10:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-23 11:10:38
ComboFix-quarantined-files.txt 2008-03-23 09:10:30
ComboFix2.txt 2008-03-23 00:03:29
ComboFix3.txt 2008-03-21 21:47:47
ComboFix4.txt 2008-03-21 21:28:38
ComboFix5.txt 2008-03-20 17:35:42
.
2008-03-12 01:02:09 --- E O F ---