Oh I followed your instructions the letter...not a step missed I assure you. Second MBAM says "clean" but i'll let you decide:
Malwarebytes' Anti-Malware 1.25
Database version: 1076
Windows 5.1.2600 Service Pack 2
1:15:57 AM 8/22/2008
mbam-log-08-22-2008 (01-15-57).txt
Scan type: Quick Scan
Objects scanned: 51924
Time elapsed: 3 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
---------------------
Follows is ComboFix's report:
ComboFix 08-08-21.02 - Maouz 2008-08-22 1:22:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.671 [GMT -4:00]
Running from: C:\Documents and Settings\Maouz.CHRISTOP\Desktop\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Maouz.CHRISTOP\Application Data\macromedia\Flash Player\#SharedObjects\G3YJ2WPZ\interclick.com
C:\Documents and Settings\Maouz.CHRISTOP\Application Data\macromedia\Flash Player\#SharedObjects\G3YJ2WPZ\interclick.com\ud.sol
C:\Documents and Settings\Maouz.CHRISTOP\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Maouz.CHRISTOP\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\system32\Cache
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
((((((((((((((((((((((((( Files Created from 2008-07-22 to 2008-08-22 )))))))))))))))))))))))))))))))
.
2008-08-21 19:30 . 2008-08-21 19:30 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-21 19:30 . 2008-08-21 19:30 <DIR> d-------- C:\Documents and Settings\Maouz.CHRISTOP\Application Data\Malwarebytes
2008-08-21 19:30 . 2008-08-21 19:30 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-08-21 19:30 . 2008-08-17 15:05 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-21 19:30 . 2008-08-17 15:05 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-19 06:29 . 2008-08-19 06:29 <DIR> d-------- C:\Documents and Settings\Maouz.CHRISTOP\Application Data\Webroot
2008-08-15 01:51 . 2008-08-15 01:53 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-11 02:35 . 2008-08-11 02:35 <DIR> d-------- C:\WINDOWS\nview
2008-08-11 02:35 . 2008-08-19 16:59 187,073 --a------ C:\WINDOWS\system32\nvapps.xml
2008-08-11 02:35 . 2008-05-16 14:01 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-07-25 04:36 . 2008-07-25 04:36 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-07-25 04:36 . 2008-07-25 04:36 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-07-23 12:50 . 2008-07-23 12:50 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 12:48 . 2008-07-23 12:48 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-07-23 12:48 . 2008-07-23 12:48 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-07-23 12:47 . 2008-07-23 12:47 634,880 --a------ C:\WINDOWS\system32\divxdec.ax
2008-07-23 12:47 . 2008-07-23 12:47 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
2008-07-23 12:47 . 2008-07-23 12:47 416 --a------ C:\WINDOWS\system32\dtu100.dll.manifest
2008-07-23 12:47 . 2008-07-23 12:47 416 --a------ C:\WINDOWS\system32\dpl100.dll.manifest
2008-07-23 12:46 . 2008-07-23 12:46 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-22 00:03 --------- d-----w C:\Program Files\StarWarsGalaxies
2008-08-20 22:13 --------- d-----w C:\Documents and Settings\Maouz.CHRISTOP\Application Data\uTorrent
2008-08-16 04:37 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-11 06:19 --------- d-----w C:\Program Files\LucasArts
2008-08-08 06:23 --------- d-----w C:\Program Files\DivX
2008-08-06 20:35 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2008-07-30 21:42 23,888 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-07-30 21:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-07-30 21:28 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-07-14 08:25 --------- d-----w C:\Documents and Settings\Maouz.CHRISTOP\Application Data\Ventrilo
2008-07-13 01:56 --------- d-----w C:\Program Files\Oblivion
2008-07-02 18:07 --------- d-----w C:\Program Files\Ventrilo
2008-07-02 18:06 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-30 16:25 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-04-07 01:51 94,080 ----a-w C:\Documents and Settings\Maouz.CHRISTOP\Application Data\ezplay.sys
2007-04-07 01:51 81,920 ----a-w C:\Documents and Settings\Maouz.CHRISTOP\Application Data\ezpinst.exe
2007-04-07 01:51 47,360 ----a-w C:\Documents and Settings\Maouz.CHRISTOP\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 22:22 26248]
"NSWosCheck"="C:\Program Files\Norton SystemWorks Premier\osCheck.exe" [2007-12-03 02:41 25472]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 14:01 86016]
"nwiz"="nwiz.exe" [2008-05-16 14:01 1630208 C:\WINDOWS\system32\nwiz.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogOff"= 1 (0x1)
"NoViewOnDrive"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv32"= ir32.dll
"vidc.X264"= x264vfw.dll
"vidc.hfyu"= huffyuv.dll
"vidc.IV45"= Ir41_qc.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.ZMBV"= zmbv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"54549:TCP"= 54549:TCP:Utorrent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 p17filt;p17filt;C:\WINDOWS\system32\drivers\p17filt.sys [2006-03-20 18:34]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2004-08-04 01:56]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2004-08-04 01:56]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2004-08-04 01:56]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2004-08-04 01:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
- - - - ORPHANS REMOVED - - - -
BHO-{5B839DD9-5A56-4527-B3B4-780A0EB52B97} - (no file)
BHO-{92E68C1D-D265-4692-BC2F-B0160FC7A4C5} - (no file)
BHO-{9ba679c4-be31-4f93-92ce-9ab44b75566e} - (no file)
BHO-{FC48D930-E15E-49A2-ABAB-C691815D7089} - (no file)
Notify-PRISMGNA - PRISMGNA.DLL
Notify-uigempmn - uigempmn.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Maouz.CHRISTOP\Application Data\Mozilla\Firefox\Profiles\aixed0dm.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - about:blank
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-22 01:27:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PRISMSVC]
"ImagePath"=""
.
r Running Proce
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\fxssvc.exe
.
**************************************************************************
.
Completion time: 2008-08-22 1:32:28 - machine was rebooted [Maouz]
ComboFix-quarantined-files.txt 2008-08-22 05:32:26
Pre-Run: 22,618,042,368 bytes free
Post-Run: 22,528,835,584 bytes free
156 --- E O F --- 2008-08-14 10:21:11