I have followed the prior instructions and here are the combofix log and dds log:
ComboFix 09-05-13.04 - Abed Keis 05/14/2009 11:25.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1526.895 [GMT -4:00]
Running from: c:\documents and settings\Abed Keis\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\jestertb.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-14 to 2009-05-14 )))))))))))))))))))))))))))))))
.
2009-05-14 13:56 . 2009-05-14 13:56 -------- d-----w c:\windows\PeachInst
2009-05-13 18:53 . 2009-05-13 18:53 -------- d--h--w c:\windows\PIF
2009-05-13 14:48 . 2009-03-24 20:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-13 14:48 . 2009-05-13 14:48 -------- d-----w c:\program files\Avira
2009-05-13 14:48 . 2009-05-13 14:48 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-05-13 14:31 . 2009-05-13 14:31 -------- d-----w c:\documents and settings\Abed Keis\Application Data\GlarySoft
2009-05-13 14:29 . 2009-05-13 14:29 -------- d-----w c:\program files\Glary Registry Repair
2009-05-13 14:18 . 2009-05-13 14:42 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-13 14:08 . 2009-05-13 14:08 -------- d-----w c:\documents and settings\Abed Keis\Application Data\Uniblue
2009-05-13 14:07 . 2009-05-14 15:10 -------- dc-h--w c:\documents and settings\All Users\Application Data\~0
2009-05-13 14:00 . 2009-05-13 14:00 -------- d-----w C:\Hi Jack This
2009-05-13 12:21 . 2009-05-13 12:21 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-05-13 12:21 . 2009-05-13 12:57 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-12 20:59 . 2009-05-13 14:43 -------- d-----w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-05-12 20:56 . 2009-05-12 20:56 -------- d-----w c:\program files\Trend Micro
2009-05-12 20:23 . 2009-05-12 20:23 -------- d-----w C:\TrendMicro_TISPro_17.10_en-US_32-bit
2009-05-12 20:00 . 2009-05-12 20:00 -------- d-----w c:\program files\Windows Installer Clean Up
2009-05-12 15:01 . 2007-11-30 22:29 102664 ----a-w c:\windows\system32\drivers\tmcomm.sys
2009-04-16 21:43 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-16 21:43 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-16 21:43 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 21:43 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-16 21:43 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 21:43 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 21:43 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 21:43 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 21:43 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 21:43 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 21:42 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 21:42 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-14 14:53 . 2008-12-16 19:36 -------- d-----w c:\program files\MSECACHE
2009-05-14 13:54 . 2007-07-02 17:58 -------- d-----w c:\program files\Mozilla Thunderbird
2009-05-13 14:44 . 2008-08-13 20:37 -------- d-----w c:\program files\PopCap Games
2009-05-12 14:36 . 2008-12-05 20:33 -------- d-----w c:\program files\LogMeIn
2009-05-12 13:26 . 2007-01-24 14:46 56 --sh--r c:\windows\system32\ECA81E101C.sys
2009-05-12 13:26 . 2006-08-26 17:16 8040 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-05-06 15:44 . 2009-02-04 15:07 967376 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-27 15:27 . 2006-08-30 14:45 -------- d-----w c:\program files\Best Software
2009-04-12 14:41 . 2008-05-07 18:26 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-30 12:32 . 2007-07-05 19:50 -------- d-----w c:\program files\Mozilla Sunbird
2009-03-23 14:35 . 2009-03-23 14:34 -------- d-----w c:\program files\iTunes
2009-03-23 14:34 . 2009-03-23 14:34 -------- d-----w c:\program files\iPod
2009-03-23 14:34 . 2007-11-12 14:40 -------- d-----w c:\program files\Common Files\Apple
2009-03-23 14:33 . 2009-03-23 14:33 -------- d-----w c:\program files\Bonjour
2009-03-23 14:32 . 2009-03-23 14:31 -------- d-----w c:\program files\QuickTime
2009-03-20 13:59 . 2009-03-20 13:58 -------- d-----w c:\program files\EFTPS Batch Provider Client
2009-03-20 13:59 . 2009-03-20 13:58 -------- d--h--w c:\program files\Zero G Registry
2009-03-06 14:22 . 2004-08-10 16:51 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-02 23:24 . 2009-03-20 13:59 32768 ----a-w c:\windows\system32\JAWTAccessBridge.dll
2009-03-02 23:24 . 2009-03-20 13:59 90112 ----a-w c:\windows\system32\WindowsAccessBridge.dll
2009-03-02 23:24 . 2009-03-20 13:59 167936 ----a-w c:\windows\system32\JavaAccessBridge.dll
2009-02-20 08:10 . 2004-08-10 16:51 666112 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-10 16:51 81920 ----a-w c:\windows\system32\ieencode.dll
2008-09-19 02:22 . 2008-09-30 18:51 827144 ----a-w c:\program files\tpnd103.r04
2007-06-18 12:56 . 2006-08-26 17:16 88 --sh--r c:\windows\system32\1C101EA8EC.sys
2008-02-05 16:15 . 2007-11-27 15:33 168 --sh--r c:\windows\system32\679057F535.sys
2009-01-17 16:17 . 2009-01-17 16:07 608 --sha-w c:\windows\system32\winzvprt5.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"ToolBoxFX"="c:\program files\HP\ToolBoxFX\bin\HPTLBXFX.exe" [2008-01-10 53248]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"LELA"="c:\program files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" [2008-05-01 131072]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-04-09 648504]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-17 01:35 87352 ----a-w c:\windows\system32\LMIinit.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Abed Keis^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SmartUI.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless-B Notebook Adapter Utility.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cleanup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X83 Button Manager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X83 Button Monitor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msci
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Brother\\BRAdmin Professional\\BRAdmPro.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\hp laserjet m2727\\Fax Config utility0.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\EFTPS Batch Provider Client\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Sage Software\\Peachtree\\peachw.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP

HCP Discovery Service
"1583:TCP"= 1583:TCP

ervasive DBEngine
"3351:TCP"= 3351:TCP

ervasive DBEngine
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/13/2009 10:48 AM 108289]
R2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [4/18/2008 5:30 AM 204800]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 7:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [12/5/2008 4:33 PM 47640]
R2 Peachtree SmartPosting 2009;Peachtree SmartPosting 2009;c:\program files\Sage Software\Peachtree\SmartPostingService2009.exe [5/3/2008 6:10 PM 49152]
S3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [1/17/2009 12:14 PM 20504]
S3 IPN2120;Wireless-B PCI Adapter Driver;c:\windows\system32\drivers\LSIPNDS.sys [8/23/2006 2:27 PM 96256]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-05-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.irs.gov/
mStart Page = hxxp://www.irs.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Abed Keis\Application Data\Mozilla\Firefox\Profiles\zte3d68e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.keiscpa.com/links.html
FF - plugin: c:\documents and settings\Abed Keis\Application Data\Mozilla\Firefox\Profiles\zte3d68e.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\Abed Keis\Application Data\Mozilla\Firefox\Profiles\zte3d68e.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07074039.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPFxViewer.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvirtools.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-14 11:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1465395269-1342718679-777237088-1006\Software\Local AppWizard-Generated Applications\MMDiag]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\BVRP Software, Inc\Digital Line Detect]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\BVRP Software, Inc\NetWaiting]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Creative Tech\Installation]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Intel\PROSetWired\NCS\PROSet\SupportTabKey]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Intel\PROSetWired\NCS\SyncLayer\8023Adapters]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Intel\PROSetWired\NCS\WMI]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\10.0]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Objects\Effects\Alchemy]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\services]
@DACL=(02 0000)
"NoServices"=dword:00000000
"ServiceExtra"="Partner=Dell&MachineID=J6Q5NB1\
00\
00????i\
00Ÿ'?\
06\
00'??\1d\
00?'\
00'\
00\
00?\
06???\
06???\
00?\
06??\
00'??\
00'?'\
00\
00\
00\
00\
00\
00?? \
00????Ÿ'\
00'\
00\
00\
00'?\
06???\
06?\
01\
04\
00?\
06???\
06??????????\
00'\
00\
00???????\
06\
00'??\
03\
00?'\
00'???\
06???\
06??????????????\
0e\
00???\
06?\
06\
00\
00???????'\
00'???\
06?\
06?\
06??\
08\
00??????Ÿ'????????????Ÿ'???????\
06\
00'Ÿ'?\
06\
01\
00???'?\
06???'?????'?????"
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Settings]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\KnownDeviceClasses]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\KnownDevices]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\Plugins\SCP\SCPTRANS]
@DACL=(02 0000)
"ProgID"="MsScp.SCPTRANS.1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\Plugins\SP\WMDMCESP]
@DACL=(02 0000)
"ProgID"="WMDMCESP.WMDMCESP"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\Plugins\SP\WPDSp]
@DACL=(02 0000)
"PnPAware"=dword:00000001
"ProgID"="WPDSp.WPDServiceProvider"
[HKEY_LOCAL_MACHINE\software\MozillaPlugins\@viewpoint.com/VMP\MimeTypes]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\MozillaPlugins\@viewpoint.com/VMP\Suffixes]
@DACL=(02 0000)
"mtx"=""
"mtz"=""
"mts"=""
[HKEY_LOCAL_MACHINE\software\Pervasive Software\PSQL]
@Denied: ) (Everyone)
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(936)
c:\windows\system32\LMIinit.dll
c:\program files\Funk Software\Odyssey Client\odLogin.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-05-14 11:30
ComboFix-quarantined-files.txt 2009-05-14 15:29
Pre-Run: 20,045,099,008 bytes free
Post-Run: 21,134,557,184 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
240 --- E O F --- 2009-05-13 07:01
ComboFix 09-05-13.04 - Abed Keis 05/14/2009 11:25.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1526.895 [GMT -4:00]
Running from: c:\documents and settings\Abed Keis\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\jestertb.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-14 to 2009-05-14 )))))))))))))))))))))))))))))))
.
2009-05-14 13:56 . 2009-05-14 13:56 -------- d-----w c:\windows\PeachInst
2009-05-13 18:53 . 2009-05-13 18:53 -------- d--h--w c:\windows\PIF
2009-05-13 14:48 . 2009-03-24 20:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-13 14:48 . 2009-05-13 14:48 -------- d-----w c:\program files\Avira
2009-05-13 14:48 . 2009-05-13 14:48 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-05-13 14:31 . 2009-05-13 14:31 -------- d-----w c:\documents and settings\Abed Keis\Application Data\GlarySoft
2009-05-13 14:29 . 2009-05-13 14:29 -------- d-----w c:\program files\Glary Registry Repair
2009-05-13 14:18 . 2009-05-13 14:42 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-13 14:08 . 2009-05-13 14:08 -------- d-----w c:\documents and settings\Abed Keis\Application Data\Uniblue
2009-05-13 14:07 . 2009-05-14 15:10 -------- dc-h--w c:\documents and settings\All Users\Application Data\~0
2009-05-13 14:00 . 2009-05-13 14:00 -------- d-----w C:\Hi Jack This
2009-05-13 12:21 . 2009-05-13 12:21 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-05-13 12:21 . 2009-05-13 12:57 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-12 20:59 . 2009-05-13 14:43 -------- d-----w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-05-12 20:56 . 2009-05-12 20:56 -------- d-----w c:\program files\Trend Micro
2009-05-12 20:23 . 2009-05-12 20:23 -------- d-----w C:\TrendMicro_TISPro_17.10_en-US_32-bit
2009-05-12 20:00 . 2009-05-12 20:00 -------- d-----w c:\program files\Windows Installer Clean Up
2009-05-12 15:01 . 2007-11-30 22:29 102664 ----a-w c:\windows\system32\drivers\tmcomm.sys
2009-04-16 21:43 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-16 21:43 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-16 21:43 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 21:43 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-16 21:43 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 21:43 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 21:43 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 21:43 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 21:43 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 21:43 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 21:42 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 21:42 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-14 14:53 . 2008-12-16 19:36 -------- d-----w c:\program files\MSECACHE
2009-05-14 13:54 . 2007-07-02 17:58 -------- d-----w c:\program files\Mozilla Thunderbird
2009-05-13 14:44 . 2008-08-13 20:37 -------- d-----w c:\program files\PopCap Games
2009-05-12 14:36 . 2008-12-05 20:33 -------- d-----w c:\program files\LogMeIn
2009-05-12 13:26 . 2007-01-24 14:46 56 --sh--r c:\windows\system32\ECA81E101C.sys
2009-05-12 13:26 . 2006-08-26 17:16 8040 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-05-06 15:44 . 2009-02-04 15:07 967376 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-27 15:27 . 2006-08-30 14:45 -------- d-----w c:\program files\Best Software
2009-04-12 14:41 . 2008-05-07 18:26 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-30 12:32 . 2007-07-05 19:50 -------- d-----w c:\program files\Mozilla Sunbird
2009-03-23 14:35 . 2009-03-23 14:34 -------- d-----w c:\program files\iTunes
2009-03-23 14:34 . 2009-03-23 14:34 -------- d-----w c:\program files\iPod
2009-03-23 14:34 . 2007-11-12 14:40 -------- d-----w c:\program files\Common Files\Apple
2009-03-23 14:33 . 2009-03-23 14:33 -------- d-----w c:\program files\Bonjour
2009-03-23 14:32 . 2009-03-23 14:31 -------- d-----w c:\program files\QuickTime
2009-03-20 13:59 . 2009-03-20 13:58 -------- d-----w c:\program files\EFTPS Batch Provider Client
2009-03-20 13:59 . 2009-03-20 13:58 -------- d--h--w c:\program files\Zero G Registry
2009-03-06 14:22 . 2004-08-10 16:51 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-02 23:24 . 2009-03-20 13:59 32768 ----a-w c:\windows\system32\JAWTAccessBridge.dll
2009-03-02 23:24 . 2009-03-20 13:59 90112 ----a-w c:\windows\system32\WindowsAccessBridge.dll
2009-03-02 23:24 . 2009-03-20 13:59 167936 ----a-w c:\windows\system32\JavaAccessBridge.dll
2009-02-20 08:10 . 2004-08-10 16:51 666112 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-10 16:51 81920 ----a-w c:\windows\system32\ieencode.dll
2008-09-19 02:22 . 2008-09-30 18:51 827144 ----a-w c:\program files\tpnd103.r04
2007-06-18 12:56 . 2006-08-26 17:16 88 --sh--r c:\windows\system32\1C101EA8EC.sys
2008-02-05 16:15 . 2007-11-27 15:33 168 --sh--r c:\windows\system32\679057F535.sys
2009-01-17 16:17 . 2009-01-17 16:07 608 --sha-w c:\windows\system32\winzvprt5.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"ToolBoxFX"="c:\program files\HP\ToolBoxFX\bin\HPTLBXFX.exe" [2008-01-10 53248]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"LELA"="c:\program files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" [2008-05-01 131072]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-04-09 648504]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-17 01:35 87352 ----a-w c:\windows\system32\LMIinit.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Abed Keis^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SmartUI.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless-B Notebook Adapter Utility.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cleanup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X83 Button Manager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X83 Button Monitor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msci
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Brother\\BRAdmin Professional\\BRAdmPro.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\hp laserjet m2727\\Fax Config utility0.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\EFTPS Batch Provider Client\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Sage Software\\Peachtree\\peachw.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP

HCP Discovery Service
"1583:TCP"= 1583:TCP

ervasive DBEngine
"3351:TCP"= 3351:TCP

ervasive DBEngine
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/13/2009 10:48 AM 108289]
R2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [4/18/2008 5:30 AM 204800]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 7:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [12/5/2008 4:33 PM 47640]
R2 Peachtree SmartPosting 2009;Peachtree SmartPosting 2009;c:\program files\Sage Software\Peachtree\SmartPostingService2009.exe [5/3/2008 6:10 PM 49152]
S3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [1/17/2009 12:14 PM 20504]
S3 IPN2120;Wireless-B PCI Adapter Driver;c:\windows\system32\drivers\LSIPNDS.sys [8/23/2006 2:27 PM 96256]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-05-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.irs.gov/
mStart Page = hxxp://www.irs.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Abed Keis\Application Data\Mozilla\Firefox\Profiles\zte3d68e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.keiscpa.com/links.html
FF - plugin: c:\documents and settings\Abed Keis\Application Data\Mozilla\Firefox\Profiles\zte3d68e.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\Abed Keis\Application Data\Mozilla\Firefox\Profiles\zte3d68e.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07074039.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPFxViewer.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvirtools.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-14 11:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1465395269-1342718679-777237088-1006\Software\Local AppWizard-Generated Applications\MMDiag]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\BVRP Software, Inc\Digital Line Detect]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\BVRP Software, Inc\NetWaiting]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Creative Tech\Installation]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Intel\PROSetWired\NCS\PROSet\SupportTabKey]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Intel\PROSetWired\NCS\SyncLayer\8023Adapters]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Intel\PROSetWired\NCS\WMI]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\10.0]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Objects\Effects\Alchemy]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\services]
@DACL=(02 0000)
"NoServices"=dword:00000000
"ServiceExtra"="Partner=Dell&MachineID=J6Q5NB1\
00\
00????i\
00Ÿ'?\
06\
00'??\1d\
00?'\
00'\
00\
00?\
06???\
06???\
00?\
06??\
00'??\
00'?'\
00\
00\
00\
00\
00\
00?? \
00????Ÿ'\
00'\
00\
00\
00'?\
06???\
06?\
01\
04\
00?\
06???\
06??????????\
00'\
00\
00???????\
06\
00'??\
03\
00?'\
00'???\
06???\
06??????????????\
0e\
00???\
06?\
06\
00\
00???????'\
00'???\
06?\
06?\
06??\
08\
00??????Ÿ'????????????Ÿ'???????\
06\
00'Ÿ'?\
06\
01\
00???'?\
06???'?????'?????"
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Settings]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\KnownDeviceClasses]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\KnownDevices]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\Plugins\SCP\SCPTRANS]
@DACL=(02 0000)
"ProgID"="MsScp.SCPTRANS.1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\Plugins\SP\WMDMCESP]
@DACL=(02 0000)
"ProgID"="WMDMCESP.WMDMCESP"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\Plugins\SP\WPDSp]
@DACL=(02 0000)
"PnPAware"=dword:00000001
"ProgID"="WPDSp.WPDServiceProvider"
[HKEY_LOCAL_MACHINE\software\MozillaPlugins\@viewpoint.com/VMP\MimeTypes]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\MozillaPlugins\@viewpoint.com/VMP\Suffixes]
@DACL=(02 0000)
"mtx"=""
"mtz"=""
"mts"=""
[HKEY_LOCAL_MACHINE\software\Pervasive Software\PSQL]
@Denied: ) (Everyone)
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(936)
c:\windows\system32\LMIinit.dll
c:\program files\Funk Software\Odyssey Client\odLogin.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-05-14 11:30
ComboFix-quarantined-files.txt 2009-05-14 15:29
Pre-Run: 20,045,099,008 bytes free
Post-Run: 21,134,557,184 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
240 --- E O F --- 2009-05-13 07:01