here are the results from the combofix program ( it took a while to run ):
ComboFix 10-08-29.04 - The Smith Family 08/30/2010 13:59:09.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1978.1105 [GMT -7:00]
Running from: c:\users\The Smith Family\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\The Smith Family\AppData\Local\{93BDE5E5-B043-4EED-84E1-1760A4F19813}
c:\users\The Smith Family\AppData\Local\{93BDE5E5-B043-4EED-84E1-1760A4F19813}\chrome.manifest
c:\users\The Smith Family\AppData\Local\{93BDE5E5-B043-4EED-84E1-1760A4F19813}\chrome\content\_cfg.js
c:\users\The Smith Family\AppData\Local\{93BDE5E5-B043-4EED-84E1-1760A4F19813}\chrome\content\overlay.xul
c:\users\The Smith Family\AppData\Local\{93BDE5E5-B043-4EED-84E1-1760A4F19813}\install.rdf
.
((((((((((((((((((((((((( Files Created from 2010-07-28 to 2010-08-30 )))))))))))))))))))))))))))))))
.
2010-08-24 16:51 . 2010-08-29 19:00 -------- d-----w- c:\users\The Smith Family\AppData\Local\Adobe
2010-08-20 04:52 . 2010-08-20 04:52 170584 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\prloader.dll
2010-08-20 04:52 . 2010-08-20 04:52 340520 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\avp.exe
2010-08-15 19:52 . 2010-08-15 19:52 -------- d-----w- c:\program files\Trend Micro
2010-08-15 16:12 . 2010-06-26 06:05 916480 ----a-w- c:\windows\system32\wininet.dll
2010-08-15 16:12 . 2010-06-26 06:02 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-08-15 16:11 . 2010-06-26 06:02 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-08-15 16:11 . 2010-06-26 04:25 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-08-15 04:34 . 2009-11-08 17:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-08-15 04:34 . 2009-11-08 17:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-08-15 04:34 . 2009-11-08 17:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-08-15 04:34 . 2009-11-08 17:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-08-15 04:34 . 2009-11-08 17:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-08-15 04:26 . 2010-04-23 13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-08-15 04:26 . 2010-04-16 16:10 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-08-15 04:23 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2010-08-15 04:22 . 2010-06-11 15:31 274432 ----a-w- c:\windows\system32\schannel.dll
2010-08-15 04:22 . 2010-05-27 19:16 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-08-15 04:22 . 2010-04-05 16:07 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-08-15 04:22 . 2009-12-23 12:43 171520 ----a-w- c:\windows\system32\wintrust.dll
2010-08-15 04:22 . 2010-06-18 16:43 36352 ----a-w- c:\windows\system32\rtutils.dll
2010-08-15 04:22 . 2010-06-11 15:30 1257472 ----a-w- c:\windows\system32\msxml3.dll
2010-08-15 04:22 . 2010-06-21 13:18 2036736 ----a-w- c:\windows\system32\win32k.sys
2010-08-15 04:09 . 2009-09-10 15:21 310784 ----a-w- c:\windows\system32\unregmp2.exe
2010-08-15 04:09 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2010-08-15 04:09 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2010-08-15 04:09 . 2009-09-10 15:21 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2010-08-15 04:06 . 2009-04-02 12:37 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-30 20:06 . 2010-07-29 20:03 -------- d-----w- c:\programdata\Kaspersky Lab
2010-08-22 19:33 . 2008-12-26 06:34 75440 ----a-w- c:\users\The Smith Family\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-17 19:40 . 2008-07-26 06:12 -------- d-----w- c:\programdata\Microsoft Help
2010-08-17 17:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-15 04:48 . 2008-07-26 05:49 -------- d-----w- c:\program files\Microsoft Works
2010-07-29 20:17 . 2010-07-29 20:04 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-07-29 20:17 . 2010-07-29 20:04 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-07-29 20:17 . 2010-07-29 20:17 80400 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2010-07-29 20:17 . 2010-07-29 20:17 133720 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-07-29 20:17 . 2010-07-29 20:17 109072 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mzvkbd3.dll
2010-07-29 20:17 . 2010-07-29 20:17 311312 ----a-w- c:\programdata\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\sys\i386\6.0\klif.sys
2010-07-29 20:03 . 2010-07-29 20:03 -------- d-----w- c:\program files\Kaspersky Lab
2010-07-29 20:01 . 2010-06-24 08:07 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-07-19 05:43 . 2010-07-19 05:43 -------- d-----w- c:\program files\HazMat Operations Training
2010-07-18 23:10 . 2010-07-18 23:10 -------- d-----w- c:\program files\Common Files\Macromedia
2010-07-02 22:03 . 2010-07-02 22:01 -------- d-----w- c:\program files\Driver-Operator - Pumper Training
2010-07-02 21:58 . 2010-07-02 21:56 -------- d-----w- c:\program files\Driver-Operator - Mobile Water Supply Training
2010-07-02 21:54 . 2010-07-02 21:51 -------- d-----w- c:\program files\Driver-Operator - ARFF Training
2010-07-02 21:49 . 2010-06-19 05:24 -------- d-----w- c:\program files\HazMat Awareness Training
2010-06-24 07:30 . 2010-06-24 07:30 2523 ----a-w- c:\users\The Smith Family\AppData\Local\izafaneyaf.dll
2010-06-24 07:30 . 2010-06-24 03:13 120 ----a-w- c:\users\The Smith Family\AppData\Local\Rbipobakamodet.dat
2010-06-24 07:30 . 2010-06-24 03:13 0 ----a-w- c:\users\The Smith Family\AppData\Local\Ntipetapediwih.bin
2010-06-24 02:36 . 2010-06-24 02:36 106496 --sha-r- c:\users\The Smith Family\AppData\Roaming\vbscriptu.dll
2010-06-24 02:36 . 2010-06-24 02:36 106496 --sha-r- c:\users\The Smith Family\AppData\Roaming\vbscriptu.dll
2010-06-18 14:43 . 2010-08-15 04:23 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 14:43 . 2010-08-15 04:23 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-16 15:59 . 2010-08-15 04:21 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-08 17:00 . 2010-08-15 04:23 3598216 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-08 17:00 . 2010-08-15 04:23 3545992 ----a-w- c:\windows\system32\ntoskrnl.exe
2008-07-26 03:45 . 2008-07-26 03:45 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fdsrablhud"="c:\users\The Smith Family\AppData\Roaming\vbscriptu.dll" [2010-06-24 106496]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-05-12 202032]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2009-07-31 1626112]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2010-08-20 340520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^The Smith Family^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\The Smith Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 08:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-06-17 13:39 170520 ----a-w- c:\windows\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-04-15 20:42 70912 ----a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 23:24 54840 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2008-06-02 07:55 80896 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-06-17 13:39 150040 ----a-w- c:\windows\System32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-06-17 13:39 145944 ----a-w- c:\windows\System32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2008-06-12 05:17 468264 ----a-w- c:\program files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2008-01-21 02:32 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:33 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:35 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R3 rcmirror;rcmirror;c:\windows\system32\DRIVERS\rcmirror.sys [2008-10-08 3328]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-15 36880]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2009-09-14 21520]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-04-26 361808]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-04 113664]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-10-03 19472]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - KLMD24
*Deregistered* - klmd24
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
2010-08-30 c:\windows\Tasks\User_Feed_Synchronization-{A2D68242-02FA-4FF3-A122-F318E5E0ED52}.job
- c:\windows\system32\msfeedssync.exe [2010-08-15 04:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cnnb
uInternet Settings,ProxyServer = http=127.0.0.1:5577
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-klmdb.sys
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-30 14:08
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-08-30 14:12:26
ComboFix-quarantined-files.txt 2010-08-30 21:12
Pre-Run: 98,135,896,064 bytes free
Post-Run: 98,065,018,880 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 1036178E0070D96568BB6673993E5B29