This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] trojan horse AGDS

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Cant remove Trojan horse Generic16.AGDS C:\Windows\system32\drivers\atmarpc.sys

Malwarebytes' Anti-Malware 1.44
Database version: 3595
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/18/2010 6:11:20 PM
mbam-log-2010-01-18 (18-11-20).txt

Scan type: Quick Scan
Objects scanned: 116747
Time elapsed: 9 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a078f691-9c07-4af2-bf43-35e79eecf8b7} (Adware.Softomate) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\spool\prtprocs\w32x86\00002a46.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\00006d85.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\k\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-18 20:15:24
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\k\LOCALS~1\Temp\kwaoifob.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEE5000B0]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \FileSystem\Fastfat \Fat ECBFBD20
Device \FileSystem\Fastfat \Fat ECC028C1

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\mobsync.dll (size mismatch) 32768/207360 bytes executable

—- EOF - GMER 1.0.15 —-

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/24/2008 6:13:34 PM
System Uptime: 1/18/2010 6:12:44 PM (2 hours ago)

Motherboard: IBM | | 2888WQ4
Processor: Intel® Pentium® M processor 1.70GHz | None | 1698/400mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 33 GiB total, 7.796 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP2: 1/12/2010 1:09:36 PM - System Checkpoint
RP3: 1/12/2010 6:10:55 PM - Software Distribution Service 3.0
RP4: 1/12/2010 11:20:36 PM - Installed MSN Toolbar
RP5: 1/13/2010 1:00:06 AM - Software Distribution Service 3.0
RP6: 1/14/2010 5:35:16 AM - System Checkpoint
RP7: 1/15/2010 5:04:18 AM - Installed Java™ 6 Update 17
RP8: 1/15/2010 2:15:28 PM - Removed MSN Toolbar
RP9: 1/16/2010 6:12:47 PM - System Checkpoint
RP10: 1/16/2010 7:06:26 PM - OTS Restore Point
RP11: 1/16/2010 7:09:09 PM - OTS Restore Point
RP12: 1/17/2010 7:23:06 PM - System Checkpoint
RP13: 1/18/2010 5:43:53 PM - Avg8 Update

==== Installed Programs ======================

Access IBM
Access IBM Message Center
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AVG Free 9.0
AVI Media Player 1.0
Bonjour
CCScore
Cisco Network Magic
ERUNT 1.1j
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSSONIC
ESSTOOLS
essvatgt
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
IBM 32-bit Runtime Environment for Java 2, v1.4.1
IBM Active Protection System
IBM DLA
IBM Integrated 56K Modem
IBM RecordNow!
IBM Rescue and Recovery with Rapid Restore
IBM Themes
IBM ThinkPad Battery MaxiMiser and Power Management Features
IBM ThinkPad Configuration
IBM ThinkPad EasyEject Utility
IBM ThinkPad Keyboard Customizer Utility
IBM ThinkPad Power Management Driver
IBM ThinkPad Presentation Director
IBM ThinkPad UltraNav Driver
IBM ThinkPad UltraNav Wizard
IBM ThinkVantage Technologies Welcome Message
IBM TrackPoint Accessibility Features
IBM Update Connector
Intel® Extreme Graphics 2 Driver
Intel® PRO Network Adapters and Drivers
Intel® PROSet/Wireless WiFi Software
Intel® Sebring API
iTunes
Java™ 6 Update 16
kgcbaby
kgcbase
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
KSU
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
netbrdg
Network Magic
Notifier
OfotoXMI
PCDADDIN
PCDHELP
Pure Networks Platform
QuickTime
RealPlayer
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SFR
SHASTA
SKIN0001
SKINXSDK
Sonic Update Manager
Spybot - Search & Destroy
staticcr
SUPERAntiSpyware Free Edition
ThinkPad FullScreen Magnifier
ThinkPad Software Installer
tooltips
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
VLC media player 0.9.2
VPRINTOL
Vuze
Vuze Toolbar
Wallpapers
WebEx Support Manager for Internet Explorer
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 8
Windows XP Service Pack 3
WIRELESS
Yahoo! Software Update
Yahoo! Toolbar

==== Event Viewer Messages From Past Week ========

1/16/2010 7:59:11 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000043' while processing the file 'wmpscfgs.exe' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/16/2010 5:26:40 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\ctfmon.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512.
1/16/2010 5:04:30 PM, error: Service Control Manager [7034] - The IBM KCU Service service terminated unexpectedly. It has done this 1 time(s).
1/16/2010 2:10:40 PM, error: Service Control Manager [7000] - The Intel® PROSet/Wireless Event Log service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/16/2010 2:10:39 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Spooler service.
1/16/2010 2:10:39 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Intel® PROSet/Wireless Event Log service to connect.
1/16/2010 2:10:39 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Apple Mobile Device service to connect.
1/16/2010 2:10:39 PM, error: Service Control Manager [7000] - The Apple Mobile Device service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/16/2010 12:11:34 AM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
1/16/2010 12:02:36 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'is2010.exe' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/15/2010 6:50:53 PM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
1/15/2010 6:50:53 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
1/15/2010 4:54:48 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'wmpscfgs.exe' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/15/2010 10:04:40 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the avg9wd service.
1/14/2010 9:01:51 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Google Software Updater service to connect.
1/14/2010 9:01:46 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service gusvc with arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
1/14/2010 3:18:01 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
1/14/2010 3:18:01 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
1/14/2010 2:02:15 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file aec.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2601.3142.
1/14/2010 2:02:15 AM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file ac97intc.sys. This file was restored to the original version to maintain system stability. The file version of the system file is 5.10.0.3523.
1/14/2010 2:00:02 AM, error: Service Control Manager [7000] - The Microsoft Kernel Acoustic Echo Canceller service failed to start due to the following error: Access is denied.
1/14/2010 1:59:58 AM, error: Service Control Manager [7000] - The Intel® 82801 Audio Driver Install Service (WDM) service failed to start due to the following error: Access is denied.
1/13/2010 1:33:56 AM, error: Service Control Manager [7023] - The Network Security service terminated with the following error: The system cannot find the file specified.
1/13/2010 1:33:56 AM, error: Service Control Manager [7003] - The Spectrum24 Event Monitor service depends on the following nonexistent service: s24trans
1/12/2010 12:53:34 AM, error: Dhcp [1002] - The IP address lease 192.168.1.44 for the Network Card with network address 0012F0E904B4 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
1/11/2010 3:40:49 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
1/11/2010 12:44:11 PM, error: Service Control Manager [7034] - The fastnetsrv Service service terminated unexpectedly. It has done this 1 time(s).

==== End Of File ===========================

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 20:22:28.41 on Mon 01/18/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.590 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Internet Antivirus *On-access scanning enabled* (Outdated) {18B0AD40-E077-4625-850C-DDD3EB0FF925}

============== Running Processes ===============

C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Documents and Settings\k\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://my.yahoo.com/linksys
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {C26CD490-5F01-41E3-B150-EB29F19DA056} - No File
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ibmmessages] c:\program files\ibm\messages by ibm\ibmmessages .exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [S3TRAY2] S3Tray2.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper
mRun: [TpShocks] TpShocks.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [TP4EX] tp4ex.exe
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [UC_Start] c:\program files\ibm\updater\\ucstartup.exe
mRun: [UC_SMB]
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ibmmessages] c:\program files\ibm\messages by ibm\\ibmmessages.exe
mRun: [IBMPRC] c:\ibmtools\utils\ibmprc.exe
mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor
mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE
mRun: [BMMMONWND] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask .exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [nmctxth] "c:\program files\common files\pure networks shared\platform\nmctxth.exe"
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
StartupFolder: c:\docume~1\k\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\Kodak Software Updater.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: E&xport to Microsoft Excel
IE: Google Sidewiki…
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4.1/jinstall-141-win.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

============= SERVICES / DRIVERS ===============

R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [2008-8-20 59520]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-3 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-3 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-3 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-10-12 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-10-12 74480]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2008-8-20 4608]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2008-8-20 16384]
R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2010-1-3 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2010-1-3 234888]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-3 285392]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [2004-9-23 64256]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-3-30 24652]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-10-12 7408]

=============== Created Last 30 ================

2010-01-18 20:19 –d—– c:\docume~1\k\applic~1\AVG9
2010-01-18 17:47 4 a——- c:\program files\84409163.dat
2010-01-17 18:46 –d—– c:\program files\Trend Micro
2010-01-16 18:43 a-dshr– C:\autorun.inf
2010-01-16 17:04 4 a——- c:\program files\6466157.dat
2010-01-16 17:04 0 a——- c:\program files\6465346.dat
2010-01-16 17:02 a-dshr– C:\cmdcons
2010-01-16 17:00 261,632 a——- c:\windows\PEV.exe
2010-01-16 17:00 77,312 a——- c:\windows\MBR.exe
2010-01-16 13:58 4 a——- c:\program files\10261194.dat
2010-01-16 11:06 4 a——- c:\program files\11303333.dat
2010-01-16 07:56 4 a——- c:\program files\28497537.dat
2010-01-15 20:47 –d—– c:\docume~1\k\applic~1\AVG8
2010-01-15 18:52 4 a——- c:\program files\3489958.dat
2010-01-15 18:52 4 a——- c:\program files\3489687.dat
2010-01-15 18:52 0 a——- c:\program files\3489527.dat
2010-01-15 10:05 4 a——- c:\program files\18712176.dat
2010-01-15 10:05 4 a——- c:\program files\18711956.dat
2010-01-15 10:05 4 a——- c:\program files\18711585.dat
2010-01-15 10:05 4 a——- c:\program files\18711205.dat
2010-01-15 04:52 4 a——- c:\program files\5971276.dat
2010-01-15 04:52 4 a——- c:\program files\5970344.dat
2010-01-15 04:52 4 a——- c:\program files\5967951.dat
2010-01-15 01:42 4 a——- c:\program files\650445.dat
2010-01-15 01:42 4 a——- c:\program files\649443.dat
2010-01-15 01:29 4 a——- c:\program files\9405304.dat
2010-01-15 01:29 4 a——- c:\program files\9404913.dat
2010-01-14 18:17 4 a——- c:\program files\10799649.dat
2010-01-14 18:16 4 a——- c:\program files\10751399.dat
2010-01-14 12:27 221,184 a——- c:\windows\system32\wmpns.dll
2010-01-14 12:06 4 a——- c:\program files\64140889.dat
2010-01-14 12:06 4 a——- c:\program files\64139768.dat
2010-01-14 12:06 4 a——- c:\program files\64138966.dat
2010-01-14 02:02 142,592 a——- c:\windows\system32\dllcache\aec.sys
2010-01-14 02:02 142,592 ——– c:\windows\system32\drivers\aec.sys
2010-01-13 21:59 4 a——- c:\program files\13301236.dat
2010-01-13 21:59 4 a——- c:\program files\13300505.dat
2010-01-13 19:24 –d—– c:\docume~1\k\applic~1\LimeWire
2010-01-13 19:23 411,368 a——- c:\windows\system32\deploytk.dll
2010-01-13 19:23 73,728 a——- c:\windows\system32\javacpl.cpl
2010-01-13 19:21 –d—– c:\program files\LimeWire
2010-01-13 18:14 4 a——- c:\program files\60104165.dat
2010-01-13 10:47 –d—– c:\program files\AVI Media Player
2010-01-12 23:31 0 a——- c:\program files\19116958.dat
2010-01-12 23:25 –d-h— c:\windows\msdownld.tmp
2010-01-12 14:29 471,552 ——– c:\windows\system32\dllcache\aclayers.dll
2010-01-12 08:28 4 a——- c:\program files\21875695.dat
2010-01-11 11:09 4 a——- c:\program files\5236139.dat
2010-01-11 10:44 40,448 a——- C:\ujsjy.exe
2010-01-07 21:22 –d—– c:\docume~1\alluse~1\applic~1\Norton
2010-01-07 21:22 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-01-07 21:21 –d—– c:\docume~1\k\applic~1\WeatherBug
2010-01-07 21:21 –d—– c:\program files\ffdshow
2010-01-05 09:51 –d—– c:\program files\VideoLAN
2010-01-05 09:44 –d—– c:\docume~1\alluse~1\applic~1\EmailNotifier
2010-01-05 09:44 –d—– c:\docume~1\k\applic~1\myfreezetoolbar
2010-01-05 09:44 –d—– c:\program files\Free Offers from Freeze.com
2010-01-04 15:59 –d—– c:\program files\Linksys
2010-01-04 15:37 –d—– c:\program files\Pure Networks
2010-01-04 15:36 –d—– c:\program files\WebEx
2010-01-04 15:35 23,984 a——- c:\windows\system32\drivers\pnarp.sys
2010-01-04 15:35 25,264 a——- c:\windows\system32\drivers\purendis.sys
2010-01-04 15:35 –d—– c:\program files\common files\Pure Networks Shared
2010-01-04 15:34 –d—– c:\docume~1\alluse~1\applic~1\Pure Networks
2010-01-04 02:26 249 a——- c:\windows\cdplayer.ini
2010-01-04 01:08 –d—– c:\documents and settings\k\C
2010-01-03 21:48 107,368 a——- c:\windows\system32\GEARAspi.dll
2010-01-03 21:48 26,600 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-03 21:47 –d—– c:\program files\iPod
2010-01-03 21:47 –d—– c:\program files\iTunes
2010-01-03 21:47 –d—– c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-03 21:47 –d—– c:\program files\Bonjour
2010-01-03 21:42 2,065,696 a——- c:\windows\system32\usbaaplrc.dll
2010-01-03 21:22 –d—– c:\docume~1\alluse~1\applic~1\Azureus
2010-01-03 21:22 –d—– c:\docume~1\k\applic~1\Hotbar_Icons
2010-01-03 21:22 –d—– c:\docume~1\k\applic~1\Azureus
2010-01-03 21:20 –d—– c:\program files\common files\i4j_jres
2010-01-03 21:20 –d—– c:\program files\AskBarDis
2010-01-03 21:20 –d—– c:\program files\Vuze
2010-01-03 17:49 –d—– C:\$AVG
2010-01-03 17:49 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-01-03 17:49 360,584 a——- c:\windows\system32\drivers\avgtdix.sys
2010-01-03 17:49 333,192 a——- c:\windows\system32\drivers\avgldx86.sys
2010-01-03 17:49 –d—– c:\windows\system32\drivers\Avg
2010-01-03 17:49 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2010-01-03 17:48 –d—– c:\program files\AVG
2010-01-03 17:48 –d—– c:\docume~1\alluse~1\applic~1\avg9
2010-01-03 16:01 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-03 16:00 –d—– c:\program files\SUPERAntiSpyware
2010-01-03 16:00 –d—– c:\docume~1\k\applic~1\SUPERAntiSpyware.com
2010-01-03 16:00 –d—– c:\program files\common files\Wise Installation Wizard
2010-01-03 15:46 –d—– c:\program files\Spybot - Search & Destroy
2010-01-03 15:46 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-01-03 15:43 –d—– c:\docume~1\k\applic~1\Malwarebytes
2010-01-03 15:43 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-03 15:43 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-03 15:43 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-03 15:43 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-31 06:20 –d—– c:\windows\system32\appmgmt

==================== Find3M ====================

2010-01-16 01:00 5,776 a——- c:\windows\system32\drivers\atmarpc.sys
2010-01-15 07:00 96,512 a——- c:\windows\system32\dllcache\atapi.sys
2010-01-15 07:00 96,512 ——– c:\windows\system32\drivers\atapi.sys
2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-10-28 09:40 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-10-21 00:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-21 00:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-21 00:38 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll
2009-10-21 00:38 25,088 ——– c:\windows\system32\dllcache\httpapi.dll

============= FINISH: 20:22:51.76 ===============
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
ComboFix 10-01-21.01 - k 01/24/2010 16:27:02.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.504 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Internet Antivirus *On-access scanning enabled* (Outdated) {18B0AD40-E077-4625-850C-DDD3EB0FF925}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ctfmon .exe

.
((((((((((((((((((((((((( Files Created from 2009-12-24 to 2010-01-24 )))))))))))))))))))))))))))))))
.

2010-01-21 23:33 . 2010-01-21 23:33 ——– d—–w- c:\windows\LastGood
2010-01-19 01:19 . 2010-01-19 01:19 ——– d—–w- c:\documents and settings\k\Application Data\AVG9
2010-01-18 22:47 . 2010-01-18 22:47 4 —-a-w- c:\program files\84409163.dat
2010-01-18 22:44 . 2010-01-03 22:48 1260312 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-17 23:52 . 2010-01-17 23:52 ——– d—–w- c:\program files\ERUNT
2010-01-17 23:46 . 2010-01-17 23:46 ——– d—–w- c:\program files\Trend Micro
2010-01-16 22:04 . 2010-01-16 22:04 4 —-a-w- c:\program files\6466157.dat
2010-01-16 22:04 . 2010-01-16 22:04 0 —-a-w- c:\program files\6465346.dat
2010-01-16 18:58 . 2010-01-16 18:58 4 —-a-w- c:\program files\10261194.dat
2010-01-16 16:06 . 2010-01-16 16:06 4 —-a-w- c:\program files\11303333.dat
2010-01-16 12:56 . 2010-01-16 12:56 4 —-a-w- c:\program files\28497537.dat
2010-01-16 01:47 . 2010-01-16 01:47 ——– d—–w- c:\documents and settings\k\Application Data\AVG8
2010-01-15 23:52 . 2010-01-15 23:52 4 —-a-w- c:\program files\3489958.dat
2010-01-15 23:52 . 2010-01-15 23:52 4 —-a-w- c:\program files\3489687.dat
2010-01-15 23:52 . 2010-01-15 23:52 0 —-a-w- c:\program files\3489527.dat
2010-01-15 22:45 . 2010-01-15 22:45 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18712176.dat
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18711956.dat
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18711585.dat
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18711205.dat
2010-01-15 10:02 . 2010-01-15 10:02 152576 —-a-w- c:\documents and settings\k\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-15 10:01 . 2010-01-15 10:01 79488 —-a-w- c:\documents and settings\k\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-15 09:52 . 2010-01-15 09:52 4 —-a-w- c:\program files\5971276.dat
2010-01-15 09:52 . 2010-01-15 09:52 4 —-a-w- c:\program files\5970344.dat
2010-01-15 09:52 . 2010-01-15 09:52 4 —-a-w- c:\program files\5967951.dat
2010-01-15 06:42 . 2010-01-15 06:42 4 —-a-w- c:\program files\650445.dat
2010-01-15 06:42 . 2010-01-15 06:42 4 —-a-w- c:\program files\649443.dat
2010-01-15 06:29 . 2010-01-15 06:29 4 —-a-w- c:\program files\9405304.dat
2010-01-15 06:29 . 2010-01-15 06:29 4 —-a-w- c:\program files\9404913.dat
2010-01-14 23:17 . 2010-01-14 23:17 4 —-a-w- c:\program files\10799649.dat
2010-01-14 23:16 . 2010-01-14 23:16 4 —-a-w- c:\program files\10751399.dat
2010-01-14 17:27 . 2008-04-14 00:12 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-01-14 17:06 . 2010-01-14 17:06 4 —-a-w- c:\program files\64140889.dat
2010-01-14 17:06 . 2010-01-14 17:06 4 —-a-w- c:\program files\64139768.dat
2010-01-14 17:06 . 2010-01-14 17:06 4 —-a-w- c:\program files\64138966.dat
2010-01-14 07:02 . 2008-04-13 17:39 142592 —-a-w- c:\windows\system32\dllcache\aec.sys
2010-01-14 07:02 . 2008-04-13 17:39 142592 ——w- c:\windows\system32\drivers\aec.sys
2010-01-14 07:00 . 2010-01-14 07:00 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-14 02:59 . 2010-01-14 02:59 4 —-a-w- c:\program files\13301236.dat
2010-01-14 02:59 . 2010-01-14 02:59 4 —-a-w- c:\program files\13300505.dat
2010-01-14 00:23 . 2010-01-14 00:22 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-01-14 00:22 . 2010-01-15 10:03 ——– d—–w- c:\program files\Java
2010-01-14 00:22 . 2010-01-14 00:22 152576 —-a-w- c:\documents and settings\k\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2010-01-14 00:21 . 2010-01-15 08:44 ——– d—–w- c:\program files\LimeWire
2010-01-13 23:14 . 2010-01-13 23:14 4 —-a-w- c:\program files\60104165.dat
2010-01-13 15:47 . 2010-01-13 15:47 ——– d—–w- c:\program files\AVI Media Player
2010-01-13 04:31 . 2010-01-13 04:31 0 —-a-w- c:\program files\19116958.dat
2010-01-13 04:25 . 2010-01-13 04:25 ——– d–h–w- c:\windows\msdownld.tmp
2010-01-13 04:20 . 2010-01-13 04:20 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-12 19:29 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 13:28 . 2010-01-12 13:28 4 —-a-w- c:\program files\21875695.dat
2010-01-11 16:09 . 2010-01-11 16:09 4 —-a-w- c:\program files\5236139.dat
2010-01-11 15:47 . 2010-01-11 17:44 ——– d—–w- c:\documents and settings\k\Local Settings\Application Data\noqtfc
2010-01-08 02:22 . 2010-01-08 02:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-01-08 02:22 . 2010-01-08 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-08 02:21 . 2010-01-08 02:21 ——– d—–w- c:\documents and settings\k\Local Settings\Application Data\WeatherBug
2010-01-08 02:21 . 2010-01-08 02:21 ——– d—–w- c:\documents and settings\k\Application Data\WeatherBug
2010-01-08 02:21 . 2010-01-08 02:28 ——– d—–w- c:\program files\ffdshow
2010-01-06 11:53 . 2010-01-06 11:53 10686001 —-a-w- c:\documents and settings\k\Application Data\Azureus\plugins\azump\mplayer.exe
2010-01-05 14:55 . 2010-01-05 15:04 ——– d—–w- c:\documents and settings\k\Application Data\vlc
2010-01-05 14:54 . 2010-01-06 06:58 ——– d—–w- c:\documents and settings\k\Application Data\dvdcss
2010-01-05 14:51 . 2010-01-05 14:51 ——– d—–w- c:\program files\VideoLAN
2010-01-05 14:44 . 2010-01-05 14:44 ——– d—–w- c:\documents and settings\All Users\Application Data\EmailNotifier
2010-01-05 14:44 . 2010-01-09 05:45 ——– d—–w- c:\documents and settings\k\Application Data\myfreezetoolbar
2010-01-05 14:44 . 2010-01-05 14:44 ——– d—–w- c:\program files\Free Offers from Freeze.com
2010-01-04 21:32 . 2010-01-04 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-04 20:59 . 2010-01-04 21:19 ——– d—–w- c:\program files\Linksys
2010-01-04 20:36 . 2010-01-04 20:36 ——– d—–w- c:\program files\WebEx
2010-01-04 20:35 . 2010-01-04 20:35 ——– d—–w- c:\program files\Common Files\Pure Networks Shared
2010-01-04 16:58 . 2010-01-04 16:58 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-04 16:58 . 2010-01-03 22:48 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-04 16:58 . 2010-01-03 22:48 2033432 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-04 16:58 . 2010-01-04 16:56 3966744 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-04 16:58 . 2010-01-03 22:48 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-04 16:58 . 2010-01-03 22:48 916248 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-04 06:08 . 2010-01-04 06:08 ——– d—–w- c:\documents and settings\k\C
2010-01-04 02:48 . 2009-05-18 19:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-04 02:48 . 2008-04-17 18:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-01-04 02:47 . 2010-01-04 02:47 ——– d—–w- c:\program files\iPod
2010-01-04 02:47 . 2010-01-21 22:38 ——– d—–w- c:\program files\iTunes
2010-01-04 02:47 . 2010-01-04 02:48 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-04 02:47 . 2010-01-04 02:47 ——– d—–w- c:\program files\Bonjour
2010-01-04 02:42 . 2009-08-29 00:42 2065696 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-01-04 02:22 . 2010-01-04 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Azureus
2010-01-04 02:22 . 2010-01-04 02:22 ——– d—–w- c:\documents and settings\k\Application Data\Hotbar_Icons
2010-01-04 02:22 . 2010-01-17 20:43 ——– d—–w- c:\documents and settings\k\Application Data\Azureus
2010-01-04 02:20 . 2010-01-04 02:20 ——– d—–w- c:\program files\Common Files\i4j_jres
2010-01-04 02:20 . 2010-01-04 02:20 ——– d—–w- c:\program files\AskBarDis
2010-01-04 02:20 . 2010-01-04 02:25 ——– d—–w- c:\program files\Vuze
2010-01-03 23:44 . 2009-11-25 18:01 1230080 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-01-03 22:49 . 2010-01-10 01:09 ——– d—–w- C:\$AVG
2010-01-03 22:49 . 2010-01-03 22:49 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-03 22:49 . 2010-01-03 22:49 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-03 22:49 . 2010-01-03 22:49 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-03 22:49 . 2010-01-03 22:49 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-03 22:49 . 2010-01-21 22:35 ——– d—–w- c:\windows\system32\drivers\Avg
2010-01-03 22:49 . 2010-01-07 23:19 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-01-03 22:48 . 2010-01-03 22:48 ——– d—–w- c:\program files\AVG
2010-01-03 22:48 . 2010-01-03 22:48 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-01-03 21:28 . 2010-01-18 22:46 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-03 21:01 . 2010-01-03 21:01 52224 —-a-w- c:\documents and settings\k\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-03 21:01 . 2010-01-03 21:01 117760 —-a-w- c:\documents and settings\k\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-03 21:01 . 2010-01-03 21:01 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-03 21:00 . 2010-01-16 05:11 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-01-03 21:00 . 2010-01-03 21:00 ——– d—–w- c:\documents and settings\k\Application Data\SUPERAntiSpyware.com
2010-01-03 21:00 . 2010-01-03 21:00 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-03 20:46 . 2010-01-21 23:47 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-03 20:46 . 2010-01-03 20:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-03 20:43 . 2010-01-03 20:43 ——– d—–w- c:\documents and settings\k\Application Data\Malwarebytes
2010-01-03 20:43 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-03 20:43 . 2010-01-18 22:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-03 20:43 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 20:43 . 2010-01-03 20:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 23:46 . 2009-01-14 22:12 ——– d—–w- c:\program files\QuickTime
2010-01-21 23:38 . 2008-08-20 23:04 64368 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-16 06:00 . 1980-01-01 07:00 5776 —-a-w- c:\windows\system32\drivers\atmarpc.sys
2010-01-15 12:00 . 2003-02-20 17:38 96512 ——w- c:\windows\system32\drivers\atapi.sys
2010-01-15 08:44 . 2010-01-14 00:24 ——– d—–w- c:\documents and settings\k\Application Data\LimeWire
2010-01-08 02:22 . 2008-08-20 23:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-07 15:52 . 2009-01-14 22:14 ——– d—–w- c:\documents and settings\k\Application Data\Apple Computer
2010-01-07 15:31 . 2009-01-14 22:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-01-05 13:40 . 2009-02-12 22:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-01-05 06:36 . 2008-08-20 23:08 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-05 06:35 . 2008-12-24 23:26 ——– d—–w- c:\program files\CyberLink
2010-01-04 21:32 . 2009-02-12 21:52 ——– d—–w- c:\program files\Yahoo!
2010-01-04 20:36 . 2010-01-04 20:36 8892928 —-a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2010-01-04 02:47 . 2009-01-14 22:11 ——– d—–w- c:\program files\Common Files\Apple
2010-01-04 02:45 . 2009-01-14 22:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-01-03 22:17 . 2008-08-20 23:20 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-03 21:52 . 2008-08-20 23:20 ——– d—–w- c:\program files\Norton AntiVirus
2009-12-31 11:19 . 2009-03-30 19:39 ——– d—–w- c:\program files\Common Files\AOL
2009-11-21 15:51 . 1980-01-01 07:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-12 22:07 . 2009-11-12 22:07 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-29 07:45 . 1980-01-01 07:00 916480 ——w- c:\windows\system32\wininet.dll
.
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Common Files\Sonic\Update Manager\sgtray .exe
c:\program files\IBM\Messages By IBM\ibmmessages		   .exe
c:\program files\IBM\Updater\ucstartup .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
c:\program files\QuickTime\qttask						  .exe
c:\program files\SUPERAntiSpyware\superantispyware .exe
c:\program files\Synaptics\SynTP\syntplpr .exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\tphkmgr .exe
c:\program files\ThinkPad\Utilities\bmmlref .exe
c:\program files\ThinkPad\Utilities\ezejmnap .exe
c:\windows\system32\dla\tfswctrl .exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-16 2002160]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-09 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3Tray2.exe" [2001-10-12 69632]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-06-16 512000]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [N/A]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-05 897024]
"TpShocks"="TpShocks.exe" [2004-03-27 102400]
"TP4EX"="tp4ex.exe" [2002-09-04 53248]
"UC_SMB"="" [N/A]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [N/A]
"ibmmessages"="c:\program files\IBM\Messages By IBM\\ibmmessages.exe" [N/A]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2004-07-29 110592]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2004-07-29 395776]

c:\documents and settings\k\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-20 24576]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-2-20 282624]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-03 22:49 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AVPath"="\\\\.\\root\\SecurityCenter:AntiVirusProduct.instanceGuid=\"{18B0AD40-E077-4625-850C-DDD3EB0FF925}\""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"%ProgramFiles%\\IBM\\Updater\\jre\\bin\\java.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/3/2010 5:49 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/3/2010 5:49 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/12/2009 9:24 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/12/2009 9:24 PM 74480]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [8/20/2008 6:33 PM 16384]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [1/3/2010 9:20 PM 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [1/3/2010 9:21 PM 234888]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/3/2010 5:48 PM 285392]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/30/2009 2:40 PM 24652]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [10/12/2009 9:24 PM 7408]

— Other Services/Drivers In Memory —

*Deregistered* - pnarp
*Deregistered* - purendis
.
Contents of the 'Scheduled Tasks' folder

2010-01-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]

2008-08-20 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2008-08-20 08:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://my.yahoo.com/linksys
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel
IE: Google Sidewiki…
.
- - - - ORPHANS REMOVED - - - -

BHO-{C26CD490-5F01-41E3-B150-EB29F19DA056} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-24 16:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7f,9b,82,a6,c9,ab,de,47,9c,61,e6,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7f,9b,82,a6,c9,ab,de,47,9c,61,e6,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(604)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
Completion time: 2010-01-24 16:36:57
ComboFix-quarantined-files.txt 2010-01-24 21:36

Pre-Run: 8,239,091,712 bytes free
Post-Run: 8,235,970,560 bytes free

- - End Of File - - 768D600F11B1CB40EBB529AE336FCFDB

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:48:25 PM, on 1/17/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\IBM\Updater\ucstartup.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\program files\ibm\messages by ibm\ibmmessages.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
c:\windows\system32\dla\tfswctrl .exe
c:\program files\itunes\ituneshelper .exe
c:\ibmtools\utils\ibmprc .exe
c:\progra~1\avg\avg9\avgtray .exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
c:\program files\internet explorer\wmpscfgs.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\internet explorer\wmpscfgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {C26CD490-5F01-41E3-B150-EB29F19DA056} - (no file)
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "c:\program files\quicktime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKCU\..\Run: [ibmmessages] c:\program files\ibm\messages by ibm\ibmmessages .exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 10639 bytes
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\program files\84409163.dat
c:\program files\6466157.dat
c:\program files\6465346.dat
c:\program files\10261194.dat
c:\program files\11303333.dat
c:\program files\28497537.dat
c:\program files\3489958.dat
c:\program files\3489687.dat
c:\program files\3489527.dat
c:\program files\18712176.dat
c:\program files\18711956.dat
c:\program files\18711585.dat
c:\program files\18711205.dat
c:\program files\5971276.dat
c:\program files\5970344.dat
c:\program files\5967951.dat
c:\program files\650445.dat
c:\program files\649443.dat
c:\program files\9405304.dat
c:\program files\9404913.dat
c:\program files\10799649.dat
c:\program files\10751399.dat
c:\program files\64140889.dat
c:\program files\64139768.dat
c:\program files\64138966.dat
c:\program files\13301236.dat
c:\program files\13300505.dat
c:\program files\60104165.dat
c:\program files\19116958.dat
c:\program files\21875695.dat
c:\program files\5236139.dat

Folder::
c:\program files\AskBarDis
C:\Program Files\Viewpoint

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
still has the same problem.
ComboFix 10-01-21.01 - k 01/24/2010 16:27:02.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.504 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Internet Antivirus *On-access scanning enabled* (Outdated) {18B0AD40-E077-4625-850C-DDD3EB0FF925}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ctfmon .exe

.
((((((((((((((((((((((((( Files Created from 2009-12-24 to 2010-01-24 )))))))))))))))))))))))))))))))
.

2010-01-21 23:33 . 2010-01-21 23:33 ——– d—–w- c:\windows\LastGood
2010-01-19 01:19 . 2010-01-19 01:19 ——– d—–w- c:\documents and settings\k\Application Data\AVG9
2010-01-18 22:47 . 2010-01-18 22:47 4 —-a-w- c:\program files\84409163.dat
2010-01-18 22:44 . 2010-01-03 22:48 1260312 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-17 23:52 . 2010-01-17 23:52 ——– d—–w- c:\program files\ERUNT
2010-01-17 23:46 . 2010-01-17 23:46 ——– d—–w- c:\program files\Trend Micro
2010-01-16 22:04 . 2010-01-16 22:04 4 —-a-w- c:\program files\6466157.dat
2010-01-16 22:04 . 2010-01-16 22:04 0 —-a-w- c:\program files\6465346.dat
2010-01-16 18:58 . 2010-01-16 18:58 4 —-a-w- c:\program files\10261194.dat
2010-01-16 16:06 . 2010-01-16 16:06 4 —-a-w- c:\program files\11303333.dat
2010-01-16 12:56 . 2010-01-16 12:56 4 —-a-w- c:\program files\28497537.dat
2010-01-16 01:47 . 2010-01-16 01:47 ——– d—–w- c:\documents and settings\k\Application Data\AVG8
2010-01-15 23:52 . 2010-01-15 23:52 4 —-a-w- c:\program files\3489958.dat
2010-01-15 23:52 . 2010-01-15 23:52 4 —-a-w- c:\program files\3489687.dat
2010-01-15 23:52 . 2010-01-15 23:52 0 —-a-w- c:\program files\3489527.dat
2010-01-15 22:45 . 2010-01-15 22:45 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18712176.dat
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18711956.dat
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18711585.dat
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18711205.dat
2010-01-15 10:02 . 2010-01-15 10:02 152576 —-a-w- c:\documents and settings\k\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-15 10:01 . 2010-01-15 10:01 79488 —-a-w- c:\documents and settings\k\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-15 09:52 . 2010-01-15 09:52 4 —-a-w- c:\program files\5971276.dat
2010-01-15 09:52 . 2010-01-15 09:52 4 —-a-w- c:\program files\5970344.dat
2010-01-15 09:52 . 2010-01-15 09:52 4 —-a-w- c:\program files\5967951.dat
2010-01-15 06:42 . 2010-01-15 06:42 4 —-a-w- c:\program files\650445.dat
2010-01-15 06:42 . 2010-01-15 06:42 4 —-a-w- c:\program files\649443.dat
2010-01-15 06:29 . 2010-01-15 06:29 4 —-a-w- c:\program files\9405304.dat
2010-01-15 06:29 . 2010-01-15 06:29 4 —-a-w- c:\program files\9404913.dat
2010-01-14 23:17 . 2010-01-14 23:17 4 —-a-w- c:\program files\10799649.dat
2010-01-14 23:16 . 2010-01-14 23:16 4 —-a-w- c:\program files\10751399.dat
2010-01-14 17:27 . 2008-04-14 00:12 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-01-14 17:06 . 2010-01-14 17:06 4 —-a-w- c:\program files\64140889.dat
2010-01-14 17:06 . 2010-01-14 17:06 4 —-a-w- c:\program files\64139768.dat
2010-01-14 17:06 . 2010-01-14 17:06 4 —-a-w- c:\program files\64138966.dat
2010-01-14 07:02 . 2008-04-13 17:39 142592 —-a-w- c:\windows\system32\dllcache\aec.sys
2010-01-14 07:02 . 2008-04-13 17:39 142592 ——w- c:\windows\system32\drivers\aec.sys
2010-01-14 07:00 . 2010-01-14 07:00 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-14 02:59 . 2010-01-14 02:59 4 —-a-w- c:\program files\13301236.dat
2010-01-14 02:59 . 2010-01-14 02:59 4 —-a-w- c:\program files\13300505.dat
2010-01-14 00:23 . 2010-01-14 00:22 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-01-14 00:22 . 2010-01-15 10:03 ——– d—–w- c:\program files\Java
2010-01-14 00:22 . 2010-01-14 00:22 152576 —-a-w- c:\documents and settings\k\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2010-01-14 00:21 . 2010-01-15 08:44 ——– d—–w- c:\program files\LimeWire
2010-01-13 23:14 . 2010-01-13 23:14 4 —-a-w- c:\program files\60104165.dat
2010-01-13 15:47 . 2010-01-13 15:47 ——– d—–w- c:\program files\AVI Media Player
2010-01-13 04:31 . 2010-01-13 04:31 0 —-a-w- c:\program files\19116958.dat
2010-01-13 04:25 . 2010-01-13 04:25 ——– d–h–w- c:\windows\msdownld.tmp
2010-01-13 04:20 . 2010-01-13 04:20 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-12 19:29 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 13:28 . 2010-01-12 13:28 4 —-a-w- c:\program files\21875695.dat
2010-01-11 16:09 . 2010-01-11 16:09 4 —-a-w- c:\program files\5236139.dat
2010-01-11 15:47 . 2010-01-11 17:44 ——– d—–w- c:\documents and settings\k\Local Settings\Application Data\noqtfc
2010-01-08 02:22 . 2010-01-08 02:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-01-08 02:22 . 2010-01-08 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-08 02:21 . 2010-01-08 02:21 ——– d—–w- c:\documents and settings\k\Local Settings\Application Data\WeatherBug
2010-01-08 02:21 . 2010-01-08 02:21 ——– d—–w- c:\documents and settings\k\Application Data\WeatherBug
2010-01-08 02:21 . 2010-01-08 02:28 ——– d—–w- c:\program files\ffdshow
2010-01-06 11:53 . 2010-01-06 11:53 10686001 —-a-w- c:\documents and settings\k\Application Data\Azureus\plugins\azump\mplayer.exe
2010-01-05 14:55 . 2010-01-05 15:04 ——– d—–w- c:\documents and settings\k\Application Data\vlc
2010-01-05 14:54 . 2010-01-06 06:58 ——– d—–w- c:\documents and settings\k\Application Data\dvdcss
2010-01-05 14:51 . 2010-01-05 14:51 ——– d—–w- c:\program files\VideoLAN
2010-01-05 14:44 . 2010-01-05 14:44 ——– d—–w- c:\documents and settings\All Users\Application Data\EmailNotifier
2010-01-05 14:44 . 2010-01-09 05:45 ——– d—–w- c:\documents and settings\k\Application Data\myfreezetoolbar
2010-01-05 14:44 . 2010-01-05 14:44 ——– d—–w- c:\program files\Free Offers from Freeze.com
2010-01-04 21:32 . 2010-01-04 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-04 20:59 . 2010-01-04 21:19 ——– d—–w- c:\program files\Linksys
2010-01-04 20:36 . 2010-01-04 20:36 ——– d—–w- c:\program files\WebEx
2010-01-04 20:35 . 2010-01-04 20:35 ——– d—–w- c:\program files\Common Files\Pure Networks Shared
2010-01-04 16:58 . 2010-01-04 16:58 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-04 16:58 . 2010-01-03 22:48 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-04 16:58 . 2010-01-03 22:48 2033432 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-04 16:58 . 2010-01-04 16:56 3966744 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-04 16:58 . 2010-01-03 22:48 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-04 16:58 . 2010-01-03 22:48 916248 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-04 06:08 . 2010-01-04 06:08 ——– d—–w- c:\documents and settings\k\C
2010-01-04 02:48 . 2009-05-18 19:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-04 02:48 . 2008-04-17 18:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-01-04 02:47 . 2010-01-04 02:47 ——– d—–w- c:\program files\iPod
2010-01-04 02:47 . 2010-01-21 22:38 ——– d—–w- c:\program files\iTunes
2010-01-04 02:47 . 2010-01-04 02:48 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-04 02:47 . 2010-01-04 02:47 ——– d—–w- c:\program files\Bonjour
2010-01-04 02:42 . 2009-08-29 00:42 2065696 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-01-04 02:22 . 2010-01-04 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Azureus
2010-01-04 02:22 . 2010-01-04 02:22 ——– d—–w- c:\documents and settings\k\Application Data\Hotbar_Icons
2010-01-04 02:22 . 2010-01-17 20:43 ——– d—–w- c:\documents and settings\k\Application Data\Azureus
2010-01-04 02:20 . 2010-01-04 02:20 ——– d—–w- c:\program files\Common Files\i4j_jres
2010-01-04 02:20 . 2010-01-04 02:20 ——– d—–w- c:\program files\AskBarDis
2010-01-04 02:20 . 2010-01-04 02:25 ——– d—–w- c:\program files\Vuze
2010-01-03 23:44 . 2009-11-25 18:01 1230080 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-01-03 22:49 . 2010-01-10 01:09 ——– d—–w- C:\$AVG
2010-01-03 22:49 . 2010-01-03 22:49 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-03 22:49 . 2010-01-03 22:49 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-03 22:49 . 2010-01-03 22:49 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-03 22:49 . 2010-01-03 22:49 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-03 22:49 . 2010-01-21 22:35 ——– d—–w- c:\windows\system32\drivers\Avg
2010-01-03 22:49 . 2010-01-07 23:19 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-01-03 22:48 . 2010-01-03 22:48 ——– d—–w- c:\program files\AVG
2010-01-03 22:48 . 2010-01-03 22:48 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-01-03 21:28 . 2010-01-18 22:46 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-03 21:01 . 2010-01-03 21:01 52224 —-a-w- c:\documents and settings\k\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-03 21:01 . 2010-01-03 21:01 117760 —-a-w- c:\documents and settings\k\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-03 21:01 . 2010-01-03 21:01 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-03 21:00 . 2010-01-16 05:11 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-01-03 21:00 . 2010-01-03 21:00 ——– d—–w- c:\documents and settings\k\Application Data\SUPERAntiSpyware.com
2010-01-03 21:00 . 2010-01-03 21:00 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-03 20:46 . 2010-01-21 23:47 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-03 20:46 . 2010-01-03 20:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-03 20:43 . 2010-01-03 20:43 ——– d—–w- c:\documents and settings\k\Application Data\Malwarebytes
2010-01-03 20:43 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-03 20:43 . 2010-01-18 22:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-03 20:43 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 20:43 . 2010-01-03 20:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-21 23:46 . 2009-01-14 22:12 ——– d—–w- c:\program files\QuickTime
2010-01-21 23:38 . 2008-08-20 23:04 64368 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-16 06:00 . 1980-01-01 07:00 5776 —-a-w- c:\windows\system32\drivers\atmarpc.sys
2010-01-15 12:00 . 2003-02-20 17:38 96512 ——w- c:\windows\system32\drivers\atapi.sys
2010-01-15 08:44 . 2010-01-14 00:24 ——– d—–w- c:\documents and settings\k\Application Data\LimeWire
2010-01-08 02:22 . 2008-08-20 23:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-07 15:52 . 2009-01-14 22:14 ——– d—–w- c:\documents and settings\k\Application Data\Apple Computer
2010-01-07 15:31 . 2009-01-14 22:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-01-05 13:40 . 2009-02-12 22:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-01-05 06:36 . 2008-08-20 23:08 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-05 06:35 . 2008-12-24 23:26 ——– d—–w- c:\program files\CyberLink
2010-01-04 21:32 . 2009-02-12 21:52 ——– d—–w- c:\program files\Yahoo!
2010-01-04 20:36 . 2010-01-04 20:36 8892928 —-a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2010-01-04 02:47 . 2009-01-14 22:11 ——– d—–w- c:\program files\Common Files\Apple
2010-01-04 02:45 . 2009-01-14 22:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-01-03 22:17 . 2008-08-20 23:20 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-03 21:52 . 2008-08-20 23:20 ——– d—–w- c:\program files\Norton AntiVirus
2009-12-31 11:19 . 2009-03-30 19:39 ——– d—–w- c:\program files\Common Files\AOL
2009-11-21 15:51 . 1980-01-01 07:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-12 22:07 . 2009-11-12 22:07 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-29 07:45 . 1980-01-01 07:00 916480 ——w- c:\windows\system32\wininet.dll
.
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Common Files\Sonic\Update Manager\sgtray .exe
c:\program files\IBM\Messages By IBM\ibmmessages		   .exe
c:\program files\IBM\Updater\ucstartup .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
c:\program files\QuickTime\qttask						  .exe
c:\program files\SUPERAntiSpyware\superantispyware .exe
c:\program files\Synaptics\SynTP\syntplpr .exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\tphkmgr .exe
c:\program files\ThinkPad\Utilities\bmmlref .exe
c:\program files\ThinkPad\Utilities\ezejmnap .exe
c:\windows\system32\dla\tfswctrl .exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-16 2002160]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-09 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3Tray2.exe" [2001-10-12 69632]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-06-16 512000]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [N/A]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-05 897024]
"TpShocks"="TpShocks.exe" [2004-03-27 102400]
"TP4EX"="tp4ex.exe" [2002-09-04 53248]
"UC_SMB"="" [N/A]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [N/A]
"ibmmessages"="c:\program files\IBM\Messages By IBM\\ibmmessages.exe" [N/A]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2004-07-29 110592]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2004-07-29 395776]

c:\documents and settings\k\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-20 24576]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-2-20 282624]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-03 22:49 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AVPath"="\\\\.\\root\\SecurityCenter:AntiVirusProduct.instanceGuid=\"{18B0AD40-E077-4625-850C-DDD3EB0FF925}\""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"%ProgramFiles%\\IBM\\Updater\\jre\\bin\\java.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/3/2010 5:49 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/3/2010 5:49 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/12/2009 9:24 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/12/2009 9:24 PM 74480]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [8/20/2008 6:33 PM 16384]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [1/3/2010 9:20 PM 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [1/3/2010 9:21 PM 234888]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/3/2010 5:48 PM 285392]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/30/2009 2:40 PM 24652]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [10/12/2009 9:24 PM 7408]

— Other Services/Drivers In Memory —

*Deregistered* - pnarp
*Deregistered* - purendis
.
Contents of the 'Scheduled Tasks' folder

2010-01-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]

2008-08-20 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2008-08-20 08:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://my.yahoo.com/linksys
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel
IE: Google Sidewiki…
.
- - - - ORPHANS REMOVED - - - -

BHO-{C26CD490-5F01-41E3-B150-EB29F19DA056} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-24 16:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7f,9b,82,a6,c9,ab,de,47,9c,61,e6,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7f,9b,82,a6,c9,ab,de,47,9c,61,e6,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(604)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
Completion time: 2010-01-24 16:36:57
ComboFix-quarantined-files.txt 2010-01-24 21:36

Pre-Run: 8,239,091,712 bytes free
Post-Run: 8,235,970,560 bytes free

- - End Of File - - 768D600F11B1CB40EBB529AE336FCFDB
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:38:43 AM, on 1/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 7447 bytes
still has the same problem.
ComboFix 10-01-21.01 - k 01/24/2010 16:27:02.2.1 - x86
ComboFix 10-01-21.01 - k 01/24/2010 16:27:02.2.1 - x86


Did you run my last fix?
The last combofix scan you posted is the same one from before
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\drivers\atmarpc.sys
c:\program files\84409163.dat
c:\program files\6466157.dat
c:\program files\6465346.dat
c:\program files\10261194.dat
c:\program files\11303333.dat
c:\program files\28497537.dat
c:\program files\3489958.dat
c:\program files\3489687.dat
c:\program files\3489527.dat
c:\program files\18712176.dat
c:\program files\18711956.dat
c:\program files\18711585.dat
c:\program files\18711205.dat
c:\program files\5971276.dat
c:\program files\5970344.dat
c:\program files\5967951.dat
c:\program files\650445.dat
c:\program files\649443.dat
c:\program files\9405304.dat
c:\program files\9404913.dat
c:\program files\10799649.dat
c:\program files\10751399.dat
c:\program files\64140889.dat
c:\program files\64139768.dat
c:\program files\64138966.dat
c:\program files\13301236.dat
c:\program files\13300505.dat
c:\program files\60104165.dat
c:\program files\19116958.dat
c:\program files\21875695.dat
c:\program files\5236139.dat

Driver::
atmarpc

RenV::
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Common Files\Sonic\Update Manager\sgtray .exe
c:\program files\IBM\Messages By IBM\ibmmessages		   .exe
c:\program files\IBM\Updater\ucstartup .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
c:\program files\QuickTime\qttask						  .exe
c:\program files\SUPERAntiSpyware\superantispyware .exe
c:\program files\Synaptics\SynTP\syntplpr .exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\tphkmgr .exe
c:\program files\ThinkPad\Utilities\bmmlref .exe
c:\program files\ThinkPad\Utilities\ezejmnap .exe
c:\windows\system32\dla\tfswctrl .exe


Folder::
c:\program files\AskBarDis
C:\Program Files\Viewpoint

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
ComboFix 10-01-26.02 - k 01/27/2010 1:50.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.511 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\k\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Internet Antivirus *On-access scanning enabled* (Outdated) {18B0AD40-E077-4625-850C-DDD3EB0FF925}
.

((((((((((((((((((((((((( Files Created from 2009-12-27 to 2010-01-27 )))))))))))))))))))))))))))))))
.

2010-01-19 01:19 . 2010-01-19 01:19 ——– d—–w- c:\documents and settings\k\Application Data\AVG9
2010-01-18 22:47 . 2010-01-18 22:47 4 —-a-w- c:\program files\84409163.dat
2010-01-17 23:52 . 2010-01-17 23:52 ——– d—–w- c:\program files\ERUNT
2010-01-17 23:46 . 2010-01-17 23:46 ——– d—–w- c:\program files\Trend Micro
2010-01-16 22:04 . 2010-01-16 22:04 4 —-a-w- c:\program files\6466157.dat
2010-01-16 22:04 . 2010-01-16 22:04 0 —-a-w- c:\program files\6465346.dat
2010-01-16 18:58 . 2010-01-16 18:58 4 —-a-w- c:\program files\10261194.dat
2010-01-16 16:06 . 2010-01-16 16:06 4 —-a-w- c:\program files\11303333.dat
2010-01-16 12:56 . 2010-01-16 12:56 4 —-a-w- c:\program files\28497537.dat
2010-01-16 01:47 . 2010-01-16 01:47 ——– d—–w- c:\documents and settings\k\Application Data\AVG8
2010-01-15 23:52 . 2010-01-15 23:52 4 —-a-w- c:\program files\3489958.dat
2010-01-15 23:52 . 2010-01-15 23:52 4 —-a-w- c:\program files\3489687.dat
2010-01-15 23:52 . 2010-01-15 23:52 0 —-a-w- c:\program files\3489527.dat
2010-01-15 22:45 . 2010-01-15 22:45 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18712176.dat
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18711956.dat
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18711585.dat
2010-01-15 15:05 . 2010-01-15 15:05 4 —-a-w- c:\program files\18711205.dat
2010-01-15 09:52 . 2010-01-15 09:52 4 —-a-w- c:\program files\5971276.dat
2010-01-15 09:52 . 2010-01-15 09:52 4 —-a-w- c:\program files\5970344.dat
2010-01-15 09:52 . 2010-01-15 09:52 4 —-a-w- c:\program files\5967951.dat
2010-01-15 06:42 . 2010-01-15 06:42 4 —-a-w- c:\program files\650445.dat
2010-01-15 06:42 . 2010-01-15 06:42 4 —-a-w- c:\program files\649443.dat
2010-01-15 06:29 . 2010-01-15 06:29 4 —-a-w- c:\program files\9405304.dat
2010-01-15 06:29 . 2010-01-15 06:29 4 —-a-w- c:\program files\9404913.dat
2010-01-14 23:17 . 2010-01-14 23:17 4 —-a-w- c:\program files\10799649.dat
2010-01-14 23:16 . 2010-01-14 23:16 4 —-a-w- c:\program files\10751399.dat
2010-01-14 17:27 . 2008-04-14 00:12 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-01-14 17:06 . 2010-01-14 17:06 4 —-a-w- c:\program files\64140889.dat
2010-01-14 17:06 . 2010-01-14 17:06 4 —-a-w- c:\program files\64139768.dat
2010-01-14 17:06 . 2010-01-14 17:06 4 —-a-w- c:\program files\64138966.dat
2010-01-14 07:02 . 2008-04-13 17:39 142592 —-a-w- c:\windows\system32\dllcache\aec.sys
2010-01-14 07:02 . 2008-04-13 17:39 142592 ——w- c:\windows\system32\drivers\aec.sys
2010-01-14 07:00 . 2010-01-14 07:00 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-14 02:59 . 2010-01-14 02:59 4 —-a-w- c:\program files\13301236.dat
2010-01-14 02:59 . 2010-01-14 02:59 4 —-a-w- c:\program files\13300505.dat
2010-01-14 00:24 . 2010-01-15 08:44 ——– d—–w- c:\documents and settings\k\Application Data\LimeWire
2010-01-14 00:23 . 2010-01-14 00:22 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-01-14 00:22 . 2010-01-15 10:03 ——– d—–w- c:\program files\Java
2010-01-14 00:21 . 2010-01-15 08:44 ——– d—–w- c:\program files\LimeWire
2010-01-13 23:14 . 2010-01-13 23:14 4 —-a-w- c:\program files\60104165.dat
2010-01-13 15:47 . 2010-01-13 15:47 ——– d—–w- c:\program files\AVI Media Player
2010-01-13 04:31 . 2010-01-13 04:31 0 —-a-w- c:\program files\19116958.dat
2010-01-13 04:25 . 2010-01-13 04:25 ——– d–h–w- c:\windows\msdownld.tmp
2010-01-13 04:20 . 2010-01-13 04:20 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-12 19:29 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 13:28 . 2010-01-12 13:28 4 —-a-w- c:\program files\21875695.dat
2010-01-11 16:09 . 2010-01-11 16:09 4 —-a-w- c:\program files\5236139.dat
2010-01-11 15:47 . 2010-01-11 17:44 ——– d—–w- c:\documents and settings\k\Local Settings\Application Data\noqtfc
2010-01-08 02:22 . 2010-01-08 02:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-01-08 02:22 . 2010-01-08 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-08 02:21 . 2010-01-08 02:21 ——– d—–w- c:\documents and settings\k\Local Settings\Application Data\WeatherBug
2010-01-08 02:21 . 2010-01-08 02:21 ——– d—–w- c:\documents and settings\k\Application Data\WeatherBug
2010-01-08 02:21 . 2010-01-08 02:28 ——– d—–w- c:\program files\ffdshow
2010-01-05 14:55 . 2010-01-05 15:04 ——– d—–w- c:\documents and settings\k\Application Data\vlc
2010-01-05 14:54 . 2010-01-06 06:58 ——– d—–w- c:\documents and settings\k\Application Data\dvdcss
2010-01-05 14:51 . 2010-01-05 14:51 ——– d—–w- c:\program files\VideoLAN
2010-01-05 14:44 . 2010-01-05 14:44 ——– d—–w- c:\documents and settings\All Users\Application Data\EmailNotifier
2010-01-05 14:44 . 2010-01-09 05:45 ——– d—–w- c:\documents and settings\k\Application Data\myfreezetoolbar
2010-01-05 14:44 . 2010-01-05 14:44 ——– d—–w- c:\program files\Free Offers from Freeze.com
2010-01-04 21:32 . 2010-01-04 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-04 20:59 . 2010-01-04 21:19 ——– d—–w- c:\program files\Linksys
2010-01-04 20:36 . 2010-01-04 20:36 ——– d—–w- c:\program files\WebEx
2010-01-04 20:35 . 2010-01-04 20:35 ——– d—–w- c:\program files\Common Files\Pure Networks Shared
2010-01-04 06:08 . 2010-01-04 06:08 ——– d—–w- c:\documents and settings\k\C
2010-01-04 02:48 . 2009-05-18 19:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-04 02:48 . 2008-04-17 18:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-01-04 02:47 . 2010-01-04 02:47 ——– d—–w- c:\program files\iPod
2010-01-04 02:47 . 2010-01-27 06:02 ——– d—–w- c:\program files\iTunes
2010-01-04 02:47 . 2010-01-04 02:48 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-04 02:47 . 2010-01-04 02:47 ——– d—–w- c:\program files\Bonjour
2010-01-04 02:42 . 2009-08-29 00:42 2065696 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-01-04 02:22 . 2010-01-04 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Azureus
2010-01-04 02:22 . 2010-01-04 02:22 ——– d—–w- c:\documents and settings\k\Application Data\Hotbar_Icons
2010-01-04 02:22 . 2010-01-17 20:43 ——– d—–w- c:\documents and settings\k\Application Data\Azureus
2010-01-04 02:20 . 2010-01-04 02:20 ——– d—–w- c:\program files\Common Files\i4j_jres
2010-01-04 02:20 . 2010-01-04 02:25 ——– d—–w- c:\program files\Vuze
2010-01-03 22:49 . 2010-01-10 01:09 ——– d—–w- C:\$AVG
2010-01-03 22:49 . 2010-01-03 22:49 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-03 22:49 . 2010-01-03 22:49 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-03 22:49 . 2010-01-03 22:49 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-03 22:49 . 2010-01-03 22:49 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-03 22:49 . 2010-01-27 05:56 ——– d—–w- c:\windows\system32\drivers\Avg
2010-01-03 22:49 . 2010-01-07 23:19 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-01-03 22:48 . 2010-01-03 22:48 ——– d—–w- c:\program files\AVG
2010-01-03 22:48 . 2010-01-03 22:48 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-01-03 21:01 . 2010-01-03 21:01 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-03 21:00 . 2010-01-16 05:11 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-01-03 21:00 . 2010-01-03 21:00 ——– d—–w- c:\documents and settings\k\Application Data\SUPERAntiSpyware.com
2010-01-03 21:00 . 2010-01-03 21:00 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-03 20:46 . 2010-01-21 23:47 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-03 20:46 . 2010-01-03 20:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-03 20:43 . 2010-01-03 20:43 ——– d—–w- c:\documents and settings\k\Application Data\Malwarebytes
2010-01-03 20:43 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-03 20:43 . 2010-01-27 06:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-03 20:43 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-03 20:43 . 2010-01-03 20:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-27 06:02 . 2009-01-14 22:12 ——– d—–w- c:\program files\QuickTime
2010-01-27 05:58 . 2010-01-27 05:58 1261336 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\prepare\avgfrw.exe
2010-01-21 23:38 . 2008-08-20 23:04 64368 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-18 22:46 . 2010-01-03 21:28 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-18 22:43 . 2010-01-18 22:44 1260800 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-18 22:43 . 2010-01-04 16:58 3777280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-16 06:00 . 1980-01-01 07:00 5776 —-a-w- c:\windows\system32\drivers\atmarpc.sys
2010-01-15 12:00 . 2003-02-20 17:38 96512 ——w- c:\windows\system32\drivers\atapi.sys
2010-01-15 10:02 . 2010-01-15 10:02 152576 —-a-w- c:\documents and settings\k\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-15 10:01 . 2010-01-15 10:01 79488 —-a-w- c:\documents and settings\k\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-14 00:22 . 2010-01-14 00:22 152576 —-a-w- c:\documents and settings\k\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2010-01-08 02:22 . 2008-08-20 23:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-07 15:52 . 2009-01-14 22:14 ——– d—–w- c:\documents and settings\k\Application Data\Apple Computer
2010-01-07 15:31 . 2009-01-14 22:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-01-06 11:53 . 2010-01-06 11:53 10686001 —-a-w- c:\documents and settings\k\Application Data\Azureus\plugins\azump\mplayer.exe
2010-01-05 13:40 . 2009-02-12 22:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-01-05 06:36 . 2008-08-20 23:08 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-05 06:35 . 2008-12-24 23:26 ——– d—–w- c:\program files\CyberLink
2010-01-04 21:32 . 2009-02-12 21:52 ——– d—–w- c:\program files\Yahoo!
2010-01-04 20:36 . 2010-01-04 20:36 8892928 —-a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2010-01-04 16:56 . 2010-01-04 16:58 3966744 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-04 02:47 . 2009-01-14 22:11 ——– d—–w- c:\program files\Common Files\Apple
2010-01-04 02:45 . 2009-01-14 22:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-01-03 22:48 . 2010-01-04 16:58 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-03 22:48 . 2010-01-04 16:58 2033432 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-03 22:48 . 2010-01-04 16:58 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-03 22:48 . 2010-01-04 16:58 916248 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-03 22:17 . 2008-08-20 23:20 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-03 21:52 . 2008-08-20 23:20 ——– d—–w- c:\program files\Norton AntiVirus
2010-01-03 21:01 . 2010-01-03 21:01 52224 —-a-w- c:\documents and settings\k\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-03 21:01 . 2010-01-03 21:01 117760 —-a-w- c:\documents and settings\k\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-31 11:19 . 2009-03-30 19:39 ——– d—–w- c:\program files\Common Files\AOL
2009-12-21 19:14 . 1980-01-01 07:00 916480 ——w- c:\windows\system32\wininet.dll
2009-11-25 18:01 . 2010-01-03 23:44 1230080 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-11-12 22:07 . 2009-11-12 22:07 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.
c:\program files\SUPERAntiSpyware\superantispyware .exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-16 2002160]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-09 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3Tray2.exe" [2001-10-12 69632]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-06-16 512000]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-05 897024]
"TpShocks"="TpShocks.exe" [2004-03-27 102400]
"TP4EX"="tp4ex.exe" [2002-09-04 53248]
"UC_SMB"="" [N/A]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2004-07-29 110592]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2004-07-29 395776]

c:\documents and settings\k\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-20 24576]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-2-20 282624]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-03 22:49 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AVPath"="\\\\.\\root\\SecurityCenter:AntiVirusProduct.instanceGuid=\"{18B0AD40-E077-4625-850C-DDD3EB0FF925}\""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"%ProgramFiles%\\IBM\\Updater\\jre\\bin\\java.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/3/2010 5:49 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/3/2010 5:49 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/12/2009 9:24 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/12/2009 9:24 PM 74480]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [8/20/2008 6:33 PM 16384]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/3/2010 5:48 PM 285392]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [10/12/2009 9:24 PM 7408]
.
Contents of the 'Scheduled Tasks' folder

2010-01-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]

2008-08-20 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2008-08-20 08:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://my.yahoo.com/linksys
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel
IE: Google Sidewiki…
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-27 02:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7f,9b,82,a6,c9,ab,de,47,9c,61,e6,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7f,9b,82,a6,c9,ab,de,47,9c,61,e6,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(600)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3324)
c:\windows\system32\WININET.dll
c:\docume~1\k\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\ibmpmsvc.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\TpShocks.exe
c:\windows\system32\RunDll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\TpKmpSVC.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-01-27 02:09:56 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-27 07:09
ComboFix2.txt 2010-01-27 06:22
ComboFix3.txt 2010-01-25 01:27
ComboFix4.txt 2010-01-24 21:36

Pre-Run: 7,921,102,848 bytes free
Post-Run: 7,873,568,768 bytes free

- - End Of File - - F9C451CF4B0DC16FAB597AD7FC800E73
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:33:32 PM, on 1/27/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 7480 bytes
still says i got it.did i do it right?think i just saved the log in a different spot when i reposted it.
Try that again. It didn't delete them.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\drivers\atmarpc.sys
c:\program files\84409163.dat
c:\program files\6466157.dat
c:\program files\6465346.dat
c:\program files\10261194.dat
c:\program files\11303333.dat
c:\program files\28497537.dat
c:\program files\3489958.dat
c:\program files\3489687.dat
c:\program files\3489527.dat
c:\program files\18712176.dat
c:\program files\18711956.dat
c:\program files\18711585.dat
c:\program files\18711205.dat
c:\program files\5971276.dat
c:\program files\5970344.dat
c:\program files\5967951.dat
c:\program files\650445.dat
c:\program files\649443.dat
c:\program files\9405304.dat
c:\program files\9404913.dat
c:\program files\10799649.dat
c:\program files\10751399.dat
c:\program files\64140889.dat
c:\program files\64139768.dat
c:\program files\64138966.dat
c:\program files\13301236.dat
c:\program files\13300505.dat
c:\program files\60104165.dat
c:\program files\19116958.dat
c:\program files\21875695.dat
c:\program files\5236139.dat

Driver::
atmarpc

RenV::
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Common Files\Sonic\Update Manager\sgtray .exe
c:\program files\IBM\Messages By IBM\ibmmessages		   .exe
c:\program files\IBM\Updater\ucstartup .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
c:\program files\QuickTime\qttask						  .exe
c:\program files\SUPERAntiSpyware\superantispyware .exe
c:\program files\Synaptics\SynTP\syntplpr .exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\tphkmgr .exe
c:\program files\ThinkPad\Utilities\bmmlref .exe
c:\program files\ThinkPad\Utilities\ezejmnap .exe
c:\windows\system32\dla\tfswctrl .exe
c:\program files\SUPERAntiSpyware\superantispyware .exe

Folder::
c:\program files\AskBarDis
C:\Program Files\Viewpoint

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI