Here is the CF log:
ComboFix 10-01-04.01 - Waipahe 01/10/2010 16:52:05.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.493 [GMT -10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
((((((((((((((((((((((((( Files Created from 2009-12-11 to 2010-01-11 )))))))))))))))))))))))))))))))
.
2010-01-11 02:51 . 2010-01-11 02:51 12568 —-a-w- c:\windows\system32\drivers\PROCEXP113.SYS
2010-01-09 06:46 . 2010-01-11 02:48 1074 —-a-w- c:\windows\system32\Pen_Tablet.dat
2010-01-09 05:53 . 2010-01-09 05:53 ——– d—–w- c:\program files\ERUNT
2010-01-08 19:50 . 2010-01-08 05:11 875288 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-01-08 19:50 . 2010-01-08 05:11 1656088 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-01-08 19:50 . 2010-01-08 05:11 798488 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-01-08 19:50 . 2010-01-08 05:11 610072 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-01-08 05:12 . 2010-01-08 05:12 ——– d—–w- C:\$AVG
2010-01-08 05:12 . 2010-01-08 19:54 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-08 05:12 . 2010-01-08 05:12 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-08 05:12 . 2010-01-08 19:54 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-08 05:11 . 2010-01-11 00:28 ——– d—–w- c:\windows\system32\drivers\Avg
2010-01-08 05:11 . 2010-01-08 19:54 25608 —-a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-01-08 05:11 . 2010-01-08 19:53 161800 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-01-08 05:11 . 2010-01-08 19:54 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-08 05:10 . 2010-01-08 19:54 50968 —-a-w- c:\windows\system32\avgfwdx.dll
2010-01-08 05:10 . 2010-01-08 19:54 30104 —-a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-01-08 05:10 . 2010-01-08 05:10 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-01-07 08:06 . 2009-12-31 00:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 08:06 . 2009-12-31 00:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 08:06 . 2010-01-07 08:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-07 06:42 . 2010-01-10 01:30 52224 —-a-w- c:\documents and settings\Waipahe\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-07 06:42 . 2010-01-10 01:30 117760 —-a-w- c:\documents and settings\Waipahe\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-07 06:40 . 2010-01-07 06:40 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-07 06:37 . 2010-01-07 06:37 2387816 —-a-w- C:\MGtools.exe
2010-01-07 05:42 . 2010-01-07 05:42 ——– d—–w- c:\documents and settings\Waipahe\Local Settings\Application Data\Threat Expert
2010-01-07 05:15 . 2008-04-14 00:12 50176 -c–a-w- c:\windows\system32\dllcache\proquota.exe
2010-01-07 05:15 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2010-01-06 23:34 . 2010-01-06 23:34 ——– d—–w- c:\program files\Alwil Software
2010-01-06 22:53 . 2010-01-08 04:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-06 19:48 . 2010-01-06 19:48 ——– d—–w- c:\program files\AVG
2009-12-18 19:21 . 2009-12-18 19:21 55816 —-a-w- c:\windows\CompGenCompGen2-uninstall.exe
2009-12-13 18:32 . 2010-01-11 02:44 ——– d—–w- c:\documents and settings\Waipahe\Application Data\WTablet
2009-12-13 18:32 . 2009-12-13 18:32 ——– d—–w- c:\documents and settings\Waipahe\Application Data\WTouch
2009-12-13 18:28 . 2009-12-13 18:28 ——– d—–w- c:\program files\WTouch
2009-12-13 18:28 . 2009-11-24 01:53 245032 —-a-w- c:\windows\system32\Touch_Tablet.dll
2009-12-13 18:28 . 2009-12-13 18:28 ——– d—–w- c:\program files\TabletPlugins
2009-12-13 18:28 . 2007-02-16 20:12 11312 —-a-w- c:\windows\system32\drivers\wacommousefilter.sys
2009-12-13 18:28 . 2009-05-20 21:54 13736 —-a-w- c:\windows\system32\drivers\wacomvhid.sys
2009-12-13 18:28 . 2009-12-13 18:28 ——– d—–w- c:\windows\system32\WTablet
2009-12-13 18:28 . 2009-11-24 01:53 416040 —-a-w- c:\windows\system32\Pen_Tablet.dll
2009-12-13 18:28 . 2009-11-23 22:16 284160 —-a-w- c:\windows\system32\Wintab32.dll
2009-12-13 18:28 . 2009-11-24 01:53 4497704 —-a-w- c:\windows\system32\Pen_Tablet.exe
2009-12-13 18:27 . 2009-12-13 18:28 ——– d—–w- c:\program files\Tablet
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-08 19:54 . 2009-04-30 06:00 ——– d—–w- c:\documents and settings\Waipahe\Application Data\Corel
2010-01-08 05:26 . 2009-04-30 19:03 ——– d—–w- c:\documents and settings\Waipahe\Application Data\uTorrent
2010-01-08 05:12 . 2010-01-08 19:55 12464 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgrsstx.dll
2010-01-08 05:12 . 2010-01-08 19:55 28424 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-01-08 05:11 . 2010-01-08 19:55 502040 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgrsx.exe
2010-01-08 05:11 . 2010-01-08 19:55 25608 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSxx.sys
2010-01-08 05:11 . 2010-01-08 19:55 161672 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgrkx86.sys
2010-01-08 05:11 . 2010-01-08 19:55 356616 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-01-08 05:11 . 2010-01-08 19:55 74760 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\UniversalDD.sys
2010-01-08 05:11 . 2010-01-08 19:55 122376 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSDriver.sys
2010-01-08 05:11 . 2010-01-08 19:55 30216 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSFilter.sys
2010-01-08 05:11 . 2010-01-08 19:55 25736 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSShim.sys
2010-01-08 05:10 . 2010-01-08 19:55 29208 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfwdx.sys
2010-01-08 05:10 . 2010-01-08 19:55 50968 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfwdx.dll
2010-01-08 05:10 . 2010-01-08 19:55 55576 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfwda.dll
2010-01-08 05:10 . 2010-01-08 19:55 35096 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfwda.sys
2010-01-07 08:31 . 2009-05-21 17:06 147264 —-a-w- c:\windows\hpoins17.dat
2010-01-07 06:41 . 2009-05-11 20:00 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-01-07 06:40 . 2009-05-11 20:00 ——– d—–w- c:\documents and settings\Waipahe\Application Data\SUPERAntiSpyware.com
2010-01-06 19:12 . 2009-11-27 18:04 0 —-a-w- c:\windows\Ybacehoco.bin
2010-01-06 19:12 . 2009-11-27 18:04 120 —-a-w- c:\windows\Nwixiduhaka.dat
2010-01-03 18:46 . 2009-04-30 19:47 ——– d—–w- c:\documents and settings\Waipahe\Application Data\Vso
2010-01-03 05:40 . 2009-11-23 23:32 ——– d—–w- c:\program files\Xvid
2009-12-16 02:52 . 2009-06-21 22:22 60423 —-a-w- c:\windows\TCompGenTCompGen-uninstall.exe
2009-12-13 18:28 . 2009-04-30 02:19 134808 —-a-w- c:\documents and settings\Waipahe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-12 02:03 . 2004-04-01 02:21 134808 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-12 00:56 . 2009-05-21 17:12 ——– d—–w- c:\documents and settings\Waipahe\Application Data\HPAppData
2009-12-08 01:39 . 2009-11-27 19:55 ——– d—–w- c:\program files\RealFlightG3
2009-12-08 01:38 . 2009-11-27 20:00 ——– d—–w- c:\program files\Common Files\KnifeEdge
2009-11-27 20:46 . 2009-11-27 20:46 ——– d—–w- c:\program files\directx
2009-11-20 19:57 . 2009-11-20 19:57 ——– d—–w- c:\program files\Rainbow Technologies
2009-11-20 19:56 . 2009-11-20 19:56 ——– d—–w- c:\program files\Freehand Graphics
2009-11-20 19:17 . 2009-11-20 19:16 ——– d—–w- c:\program files\QuickTime
2009-11-20 04:09 . 2009-04-30 02:25 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-20 00:57 . 2009-11-20 00:57 82712 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-20 00:56 . 2009-04-30 06:13 ——– d—–w- c:\documents and settings\Waipahe\Application Data\Apple Computer
2009-11-16 18:10 . 2009-11-16 18:09 ——– d—–w- c:\program files\iTunes
2009-11-16 18:10 . 2009-11-16 18:09 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-16 18:09 . 2009-11-16 18:09 ——– d—–w- c:\program files\iPod
2009-11-16 18:09 . 2009-11-16 18:01 ——– d—–w- c:\program files\Common Files\Apple
2009-11-16 18:08 . 2009-11-16 18:08 ——– d—–w- c:\program files\Bonjour
2009-11-16 18:04 . 2009-11-16 18:04 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-16 18:00 . 2009-11-16 18:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-16 17:35 . 2009-11-16 17:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Fawkes
2009-11-16 17:35 . 2009-11-16 17:35 ——– d—–w- c:\program files\Fawkes Engineering
2009-10-30 07:09 . 2009-10-30 07:10 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-10-30 07:08 . 2009-10-30 07:08 152576 —-a-w- c:\documents and settings\Waipahe\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-29 07:46 . 2004-01-22 00:16 832512 ——w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2009-04-30 04:21 78336 ——w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2004-04-01 01:05 17408 ——w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2009-04-30 04:21 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-21 05:38 . 2009-04-30 04:21 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-20 16:20 . 2009-04-30 04:21 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-04-01 01:06 270336 —-a-w- c:\windows\system32\oakley.dll
2006-06-21 08:58 . 2009-04-30 05:39 17426 —-a-w- c:\program files\CutStudioPlugIn.gms
2006-03-23 10:02 . 2009-04-30 05:39 66053 —-a-w- c:\program files\CSAIPin_e.chm
2006-03-03 09:33 . 2009-04-30 05:39 118784 —-a-w- c:\program files\CutStudioPlugin.aip
2004-12-22 20:39 . 2009-04-30 05:39 384 —-a-w- c:\program files\CutStudioPlugIn.bmp
2009-04-30 06:00 . 2009-04-30 06:00 848 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-01-07_05.16.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-11 02:48 . 2010-01-11 02:48 16384 c:\windows\Temp\Perflib_Perfdata_634.dat
- 2004-04-01 02:17 . 2010-01-04 06:52 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-04-01 02:17 . 2010-01-07 17:59 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-04-01 02:17 . 2010-01-07 17:59 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-04-01 02:17 . 2010-01-04 06:52 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-01-07 17:59 . 2010-01-07 17:59 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2004-04-01 02:17 . 2010-01-04 06:52 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-01-07 06:41 . 2010-01-07 06:41 65024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2010-01-07 06:41 . 2010-01-07 06:41 18944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2010-01-07 06:41 . 2010-01-07 06:41 5120 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
+ 2010-01-09 05:54 . 2010-01-09 05:54 262144 c:\windows\ERDNT\1-8-2010\Users\00000002\UsrClass.dat
+ 2010-01-09 05:54 . 2005-10-20 22:02 163328 c:\windows\ERDNT\1-8-2010\ERDNT.EXE
+ 2010-01-07 06:18 . 2010-01-07 06:18 262144 c:\windows\ERDNT\1-6-2010\Users\00000002\UsrClass.dat
- 2010-01-06 21:38 . 2010-01-06 21:38 262144 c:\windows\ERDNT\1-6-2010\Users\00000002\UsrClass.dat
+ 2010-01-07 16:11 . 2010-01-07 18:27 2292660 c:\windows\system32\Restore\rstrlog.dat
+ 2010-01-07 06:41 . 2010-01-07 06:41 1583616 c:\windows\Installer\90357e.msi
+ 2010-01-09 05:54 . 2010-01-09 05:54 4739072 c:\windows\ERDNT\1-8-2010\Users\00000001\NTUSER.DAT
+ 2010-01-07 06:18 . 2010-01-07 06:18 4714496 c:\windows\ERDNT\1-6-2010\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-04 00:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-08 19:54 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 22:08 935288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 14:08 35696 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 17:58 611712 —-a-w- c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2003-05-23 18:43 88363 —-a-w- c:\windows\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-01-08 19:54 2033432 —-a-w- c:\progra~1\AVG\AVG9\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2008-04-14 00:12 50176 —-a-w- c:\windows\eHome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ezShieldProtector for Px]
2002-08-20 18:29 40960 —-a-w- c:\windows\system32\ezSP_Px.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-12 07:34 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-08-12 02:30 249856 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-08-12 02:30 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-29 06:21 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2004-05-25 03:21 4841472 —-a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-07-07 07:34 167936 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 09:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sHotKey]
2003-08-22 17:22 45056 —-a-w- c:\program files\Sony\sHotKey\SHOTKEY.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-30 07:09 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-01-05 17:56 2002160 —-a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-12-12 00:52 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Recovery]
2003-04-20 05:08 28672 —-a-w- c:\windows\SONYSYS\VAIO Recovery\PartSeal.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
2004-01-17 11:36 135168 —-a-w- c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Corel\\CorelDRAW Graphics Suite 13\\Programs\\CorelDRW.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [1/7/2010 7:11 PM 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [1/7/2010 7:11 PM 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/7/2010 7:12 PM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/7/2010 7:11 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/8/2010 9:54 AM 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [1/8/2010 9:53 AM 2303680]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [1/8/2010 9:54 AM 5832712]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [12/13/2009 8:28 AM 4497704]
R2 VAIO Entertainment File Import Service;VAIO Entertainment File Import Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe [4/29/2009 4:23 PM 86098]
R2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [12/13/2009 8:28 AM 113448]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [1/7/2010 7:10 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [1/7/2010 7:11 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [1/7/2010 7:11 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [1/7/2010 7:11 PM 25736]
R3 epppdt;EPSON 1394.3 Class;c:\windows\system32\drivers\epppdt.sys [5/6/2009 2:50 PM 31275]
R3 epppdtpr;EPSON 1394.3 Printer Class;c:\windows\system32\drivers\epppdtpr.sys [5/6/2009 2:51 PM 14463]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe –> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe –> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S2 RipCore;RipCore;c:\program files\Fawkes Engineering\AccuRIP\RipCore.exe [1/23/2008 3:37 PM 1835008]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [1/7/2010 7:10 PM 30104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
S3 VAIO Entertainment UPnP Client Adapter;VAIO Entertainment UPnP Client Adapter;c:\program files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe -RunBySCM –> c:\program files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe -RunBySCM [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Waipahe\Application Data\Mozilla\Firefox\Profiles\h3aokjba.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\TabletPlugins\npwacom.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-ISTray - c:\program files\Spyware Doctor\pctsTray.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-10 16:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1048)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(2476)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2010-01-10 17:01:52
ComboFix-quarantined-files.txt 2010-01-11 03:01
ComboFix2.txt 2010-01-07 15:49
ComboFix3.txt 2010-01-07 09:54
ComboFix4.txt 2010-01-07 08:45
ComboFix5.txt 2010-01-11 02:31
Pre-Run: 220,199,235,584 bytes free
Post-Run: 220,165,390,336 bytes free
- - End Of File - - 586A6775506D834422A21EF8288EC815