All done, it is now after 2300 hrs here and I depart foe a flight at 0500 so I will not be able to progress this further until my return next Wednesday - but we seem to be making progress. Thank you here is the Combofix log
ComboFix 10-07-27.05 - Ewing Consultants 28/07/2010 22:52:22.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.476 [GMT 1:00]
Running from: c:\documents and settings\Ewing Consultants\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ewing Consultants\Desktop\CFScript.txt
AV: ESET Smart Security 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-28 )))))))))))))))))))))))))))))))
.
2010-07-25 10:57 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-25 10:57 . 2010-07-25 10:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-25 10:57 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-14 06:57 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-14 18:47 . 2006-03-08 09:19 -------- d-----w- c:\program files\QuickTime
2010-06-30 16:28 . 2009-05-16 14:17 -------- d-----w- c:\documents and settings\Ewing Consultants\Application Data\Oksyta
2010-06-30 16:14 . 2007-12-08 15:32 -------- d-----w- c:\documents and settings\Ewing Consultants\Application Data\Ubve
2010-06-28 14:33 . 2005-03-21 21:48 702464 ----a-w- c:\program files\ms money Nov 09.mny
2010-06-14 14:31 . 2004-08-10 13:02 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-11 19:47 . 2010-03-31 21:58 -------- d-----w- c:\documents and settings\Ewing Consultants\Application Data\Xoree
2010-06-11 19:45 . 2007-07-16 17:53 -------- d-----w- c:\documents and settings\Ewing Consultants\Application Data\Mycuor
2010-06-04 15:46 . 2009-09-29 09:23 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-02 14:43 . 2009-12-02 11:33 -------- d-----w- c:\documents and settings\Ewing Consultants\Application Data\HpUpdate
2010-05-10 13:35 . 2010-05-10 13:35 161632 ----a-w- c:\documents and settings\Ewing Consultants\Application Data\Juniper Networks\Setup Client\x86_Microsoft.VC80.CRTP_8.0.50727.762.exe
2010-05-10 13:34 . 2010-05-10 13:34 823928 ----a-w- c:\documents and settings\Ewing Consultants\Application Data\Juniper Networks\Host Checker\AVManagerUnified.dll
2010-05-10 13:34 . 2010-05-10 13:34 291696 ----a-w- c:\documents and settings\Ewing Consultants\Application Data\Juniper Networks\Setup Client\x86_Microsoft.VC80.CRTR_8.0.50727.762.exe
2010-05-10 13:33 . 2010-05-10 13:33 36948 ----a-w- c:\documents and settings\Ewing Consultants\Application Data\Juniper Networks\setup\uninstall.exe
2010-05-02 05:22 . 2004-08-10 12:51 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-02-28 12:30 . 2010-02-28 12:30 2169915 ----a-w- c:\program files\ImgBurn_2.5.0.0.exe
2009-09-07 16:21 . 2009-09-07 16:21 1648478 ----a-w- c:\program files\FileManager.exe
2007-10-04 07:10 . 2007-10-04 07:10 12531691 -c--a-w- c:\program files\Kd50e.exe
2006-06-20 17:16 . 2006-06-20 17:16 774144 -c--a-w- c:\program files\RngInterstitial.dll
2005-07-04 14:00 . 2000-10-16 12:30 217088 -c--a-w- c:\program files\SpaceMonger.exe
2005-04-08 11:11 . 2005-04-08 10:53 121558528 -c--a-w- c:\program files\AcTR7EFG.exe
2005-03-21 19:52 . 2005-03-21 19:52 272384 -c--a-w- c:\program files\SAMPLE.MNY
2005-03-21 19:52 . 2005-03-21 19:52 4320768 ----a-w- c:\program files\MSMONEY.EXE
2005-03-21 19:52 . 2005-03-21 19:52 14253 -c--a-w- c:\program files\README.TXT
2004-08-04 05:00 . 2004-08-10 12:51 94784 -csh--w- c:\windows\twain.dll
2008-04-14 00:12 . 2004-08-10 12:51 50688 --sh--w- c:\windows\twain_32.dll
2007-05-29 14:11 . 1602-07-12 21:55 1031 -csh--w- c:\windows\system\ws32ntfl.dat
2002-04-16 10:27 . 2002-04-16 10:27 5 -csha-w- c:\windows\system32\CdI5T.drv
1998-03-20 00:00 . 1998-03-20 00:00 1048 -csha-w- c:\windows\system32\flfnlf.sys
2008-04-14 00:11 . 2004-08-10 12:51 1028096 --sha-w- c:\windows\system32\mfc42.dll
2008-04-14 00:12 . 2004-08-10 12:51 57344 --sh--w- c:\windows\system32\msvcirt.dll
2008-04-14 00:12 . 2004-08-10 12:51 11776 --sh--w- c:\windows\system32\regsvr32.exe
2010-02-09 15:46 . 2010-02-09 15:46 88576 --sha-r- c:\windows\system32\shdocvwp.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\Ewing Consultants\Application Data\Mycuor ----
---- Directory of c:\documents and settings\Ewing Consultants\Application Data\Oksyta ----
2010-06-30 16:28 . 2010-06-30 16:28 3024 ----a-w- c:\documents and settings\Ewing Consultants\Application Data\Oksyta\ufzuf.aru
---- Directory of c:\documents and settings\Ewing Consultants\Application Data\Ubve ----
---- Directory of c:\documents and settings\Ewing Consultants\Application Data\Xoree ----
2010-06-11 19:48 . 2010-06-11 19:55 1720 ----a-w- c:\documents and settings\Ewing Consultants\Application Data\Xoree\dicu.iqy
((((((((((((((((((((((((((((( SnapShot@2010-07-27_18.05.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-28 21:40 . 2010-07-28 21:40 16384 c:\windows\temp\Perflib_Perfdata_d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-19 196608]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-03-24 2145000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-07-14 417792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [09/04/2009 15:18 114984]
R1 eusk2par;EUTRON SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [02/10/2007 17:00 24786]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [24/03/2010 20:31 810120]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [14/01/2010 10:04 135664]
S3 ADM8511;%ADM8511.Service.DispName%;c:\windows\system32\drivers\ADM8511.SYS [17/08/2001 12:11 20160]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [18/12/2009 11:58 11336]
S3 eusk3usb;SmartKey 3 USB;c:\windows\system32\drivers\eusk3usb.sys [02/10/2007 17:00 45534]
--- Other Services/Drivers In Memory ---
*Deregistered* - uphcleanhlp
.
Contents of the 'Scheduled Tasks' folder
2010-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-14 09:04]
2010-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-14 09:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
IE: Search Using Copernic Agent - c:\program files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: motive.com\pbttbc.bt
Handler: copernicagent - {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - c:\progra~1\COPERN~1\COPERN~1.DLL
Handler: copernicagentcache - {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - c:\progra~1\COPERN~1\COPERN~1.DLL
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://ras-uk.ihs.com/dana-cached/sc/JuniperSetupClient.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-28 22:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3000975372-3708929796-4007856590-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2900)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-07-28 23:01:43
ComboFix-quarantined-files.txt 2010-07-28 22:01
ComboFix2.txt 2010-07-27 18:08
Pre-Run: 7,436,615,680 bytes free
Post-Run: 7,420,194,816 bytes free
- - End Of File - - 6137A28B1506A2371E68DC04746BB343