This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help needed to determine if PC is infected

56 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Lately, my PC has slowed down dramatically, freezes up on me and at times it appears while I am online that the cursor will suddenly wander by itself. I have run MBAM and SuperAntiSpyware scans and they have not flagged any viruses but I really fear I may be infected with something like a BOT. I was hoping I could get one of you fine folks to take a look at the Attach.zip, DDS.txt, and Gmer.zip logs that I have attached. I would really appreciate any assistance and was very pleased that last time I used this avenue! THANKS! DDS (Ver_10-12-12.01) - NTFSx86 Run by [removed] at 19:42:01.00 on Fri 12/17/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.913 [GMT -6:00] AV: AVG Internet Security 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Firewall *Enabled* FW: AVG Firewall *Enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\System32\svchost.exe -k NetworkService C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVG\AVG10\avgfws.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\WINDOWS\system32\IFXTCS.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Sony\SmartWi Connection Utility\SmartWiService.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Program Files\ThreatFire\TFService.exe C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe c:\program files\verizon wireless\venturi\Client\ventc.exe C:\Program Files\AVG\AVG10\avgam.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files\AVG\AVG10\avgemcx.exe C:\WINDOWS\System32\alg.exe C:\Program Files\AVG\AVG10\avgchsvx.exe C:\Program Files\AVG\AVG10\avgrsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AVG\AVG10\avgtray.exe C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files\ThreatFire\TFTray.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe C:\WINDOWS\system32\lxbucoms.exe C:\Program Files\SuperHideIP\SuperHideIP.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe c:\program files\verizon wireless\venturi\Configurator\ventcfg.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Documents and Settings\User.MARCIA-6X7H850P\Desktop\Virus Stuff\dds.EXE ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyServer = http=174.142.24.206:3128 uURLSearchHooks: H - No File mURLSearchHooks: H - No File mWinlogon: SHELL=c:\windows\Explorer.exe BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - Adobe PDF Reader Link Helper BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File TB: {C70E30C7-140A-4166-A2E8-43557E62B41A} - No File TB: ZoneAlarm Toolbar: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [Controlled StartUp] c:\program files\startup organizer\Ctrl.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [LXBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXBUtime.dll,_RunDLLEntry@16 uPolicies-explorer: MaxRecentDocs = 4 (0x4) mPolicies-explorer: NoRecentDocsNetHood = 1 (0x1) IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm IE: Download with IDM - c:\program files\internet download manager\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: vlsp.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1276897842937 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: {2643ABF9-63C0-479C-B0A1-DBCEAEB940B7} = 69.78.96.14 66.174.92.14 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: IfxWlxEN - IfxWlxEN.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064] R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [2002-3-11 9216] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2010-10-29 51984] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2010-10-29 59664] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 249424] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 299984] R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [2010-8-25 76768] R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2005-11-29 36768] R1 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [2010-6-6 6144] R2 avgfws;AVG Firewall;c:\program files\avg\avg10\avgfws.exe [2010-11-9 3229728] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2010-11-10 6127184] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400] R2 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\microsoft sql server\100\dts\binn\MsDtsSrvr.exe [2008-7-10 218136] R2 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\microsoft sql server\mssql10.mssqlserver\mssql\binn\fdlauncher.exe [2008-7-10 31256] R2 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service –> c:\program files\threatfire\TFService.exe service [?] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2011\TuneUpUtilitiesService32.exe [2010-11-23 1483072] R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-7-12 30432] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192] R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [2010-10-21 44368] R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-8-29 36352] R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [2007-7-19 27392] R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [2007-7-19 41728] R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [2007-7-19 39808] R3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [2007-7-19 5888] R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2010-5-21 71961] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2010-10-29 33552] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2010-5-26 808448] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2011\TuneUpUtilitiesDriver32.sys [2010-10-7 10064] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys –> c:\windows\system32\drivers\avfwim.sys [?] S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-7-12 30432] S3 cpuz132;cpuz132;\??\c:\docume~1\user~2.mar\locals~1\temp\cpuz132\cpuz132_x32.sys –> c:\docume~1\user~2.mar\locals~1\temp\cpuz132\cpuz132_x32.sys [?] S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2010-7-18 23456] S3 icsak;icsak;\??\c:\program files\checkpoint\zaforcefield\ak\icsak.sys –> c:\program files\checkpoint\zaforcefield\ak\icsak.sys [?] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-7-23 20952] S3 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-7-23 304464] S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\drivers\pwi_bus.sys –> c:\windows\system32\drivers\pwi_bus.sys [?] S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\drivers\pwi_mdfl.sys –> c:\windows\system32\drivers\pwi_mdfl.sys [?] S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\drivers\pwi_mdm.sys –> c:\windows\system32\drivers\pwi_mdm.sys [?] S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\drivers\pwi_oflt.sys –> c:\windows\system32\drivers\pwi_oflt.sys [?] S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\drivers\pwi_serd.sys –> c:\windows\system32\drivers\pwi_serd.sys [?] S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-8-19 27064] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2010-5-25 11520] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2003-3-31 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128] S4 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\microsoft sql server\msrs10.mssqlserver\reporting services\reportserver\bin\ReportingServicesService.exe [2009-3-30 1113448] =============== Created Last 30 ================ 2010-12-14 22:53:32 ——– d—–w- c:\program files\Windows Script Control 2010-12-14 22:53:19 ——– d—–w- c:\program files\common files\e.World 2010-12-14 22:53:06 ——– d—–w- c:\windows\ASP.NET Report Maker 2010-12-14 00:00:23 ——– d—–w- c:\docume~1\user~2.mar\applic~1\MetaProducts 2010-12-14 00:00:08 73728 —-a-w- c:\windows\system32\SUO.cpl 2010-12-13 23:59:52 ——– d—–w- c:\program files\StartUp Organizer 2010-12-13 22:34:55 ——– d—–w- c:\docume~1\user~2.mar\applic~1\GetRightToGo 2010-12-13 22:27:35 ——– d—–w- c:\program files\Zards software 2010-12-13 18:58:54 ——– d—–w- c:\windows\system32\wbem\repository\FS 2010-12-13 18:58:54 ——– d—–w- c:\windows\system32\wbem\Repository 2010-12-12 23:07:49 ——– d—–w- C:\$AVG 2010-12-08 05:11:18 ——– d—–w- c:\program files\Business Objects 2010-12-07 00:57:29 ——– d–h–w- c:\documents and settings\user.marcia-6x7h850p\Recent(4) 2010-12-05 23:00:56 ——– d—–w- c:\program files\r2 Studios 2010-12-05 02:41:36 31552 —-a-w- c:\windows\system32\TURegOpt.exe 2010-12-05 02:41:34 29504 —-a-w- c:\windows\system32\uxtuneup.dll 2010-12-05 02:40:49 ——– d—–w- c:\program files\TuneUp Utilities 2011 2010-12-05 01:09:04 266360 —-a-w- c:\windows\system32\TweakUI.exe 2010-11-29 03:59:44 ——– d—–w- c:\docume~1\user~2.mar\applic~1\Smart PC Solutions 2010-11-29 03:59:23 ——– d—–w- c:\program files\Smart PC Solutions 2010-11-28 05:55:17 ——– d—–w- c:\docume~1\user~2.mar\applic~1\iNViSiBLE 2010-11-28 05:49:03 ——– d—–w- c:\documents and settings\user.marcia-6x7h850p\.moneydance 2010-11-28 05:48:06 ——– d—–w- c:\program files\Moneydance 2010-11-28 05:48:06 ——– d—–w- c:\program files\common files\i4j_jres 2010-11-27 22:36:52 ——– d—–w- c:\program files\SUPERAntiSpyware 2010-11-25 15:46:15 ——– d—–w- c:\docume~1\user~2.mar\locals~1\applic~1\Downloaded Installations 2010-11-22 03:07:23 146432 -c–a-w- c:\windows\system32\dllcache\regedit.exe 2010-11-20 01:10:29 ——– d–h–w- c:\windows\PIF ==================== Find3M ==================== 2010-11-18 18:12:44 81920 —-a-w- c:\windows\system32\isign32.dll 2010-11-06 00:26:58 916480 —-a-w- c:\windows\system32\wininet.dll 2010-11-06 00:26:58 43520 —-a-w- c:\windows\system32\licmgr10.dll 2010-11-06 00:26:58 1469440 ——w- c:\windows\system32\inetcpl.cpl 2010-11-03 12:25:54 385024 —-a-w- c:\windows\system32\html.iec 2010-10-28 13:13:22 290048 —-a-w- c:\windows\system32\atmfd.dll 2010-10-27 20:58:22 0 —-atw- c:\windows\system32\spdwnwxp.exe 2010-10-26 13:25:00 1853312 —-a-w- c:\windows\system32\win32k.sys 2010-10-11 02:32:18 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-10-11 02:32:18 423656 —-a-w- c:\windows\system32\deployJava1.dll 2010-09-26 02:12:22 8464 —-a-w- c:\windows\system32\SpOrder.dll 2010-09-26 01:50:29 7921664 —-a-w- c:\windows\system32\IDTSG.cpl 2010-09-22 02:49:23 2756608 —-a-w- c:\windows\system32\NETw5r32.dll 2010-09-22 02:49:22 663552 —-a-w- c:\windows\system32\NETw5c32.dll 2010-09-22 02:48:18 172032 —-a-w- c:\windows\system32\tifmicon.dll ============= FINISH: 19:47:01.10 ===============
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.


Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.

Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove either:
AVG Internet Security 2011
McAfee


AVG > AVG Removal Tool (x86) - AVG Removal Tool (x64)
AVG Identity Protection > AVGIDPUninstaller


After the above:

Internet Explorer (Windows)
1. Click "Tools", then click "Internet Options". This will bring up the Internet Options window.

2. Click the "Connections" tab, then click the "LAN Settings" button.

3. Uncheck the box labeled "Use a proxy server for your LAN". Click "OK", and click "OK" in the previous window. This will remove the proxy server settings in Internet Explorer.



Firefox (Windows)
1. Click "Tools", then click "Options" to bring up the Options window.

2. Click the "Advanced" button, then click the "Network" tab.

3. Click the "Settings" button, located next to "Configure how Firefox connects to the Internet".

4. Click the radio button labeled "No proxy". Click "OK" twice. This will remove the proxy server settings in Firefox.



Disable Internet Explorer Proxy Settings and Reset TCP/IP and Winsock

Disable Internet Explorer Proxy Settings and Reset TCP/IP

It is very important that these steps be carried out exactly as shown otherwise the fix will not work.
If you have any questions please ask before moving on.
  • Please start Notepad and using your mouse make sure you select and copy all the information below in the Code box into your new document.
  • Then save the file as "fixme.bat" to your Desktop
  • In the drop down box for Save as type: make sure you select All Files (*.*) and keep the quotes on the name as well. Then close the new file.
    @ECHO OFF
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyServer /f
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyOverride /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyEnable  /t REG_DWORD /d 0 /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v GlobalUserOffline /t REG_DWORD /d 0 /f
    netsh int ip reset resetlog.txt
    netsh winsock reset catalog
  • On Windows XP you can double-click the file to run it.
  • On Vista/Win7 you need to Right click the file and choose Run as administrator to run it. With User Account Control on it should ask permission to run it. Click Yes
  • This will flash a black DOS box very quickly and go away, this is normal.
  • Restart your computer now.
  • Launch Internet Explorer and see if you can connect to the Internet.
  • Launch MBAM and check for Updates
LDTate- Thank you for the reply and direction. It is appreciated! I followed your instructions above and the results are as follows: Internet Explorer(Windows) - Under Internet options -> Connections tab -> LAN Settings button button labeled Use a proxy server for your LAN Settings was not checked. I assembled and ran the "fixme.bat" file as instructed and have attached. Actually I ran it a number of times and the attached file is the last log of the run. Unfortunately when I followed up with a SuperAntiSpyware scan I am still getting the following infection: Malware.Trace -HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON (SHELL - C:\WINDOWS\Explorer.exe) I can quarentine and remove this threat but it ALWALYS re-appears when I re-boot and scan my machine SuperAntiSpyware. I should also add at this point that when I boot-up my laptop I will get a folder that will flash during start-up that says "ASP.NET REPORT" and then disappear. I did download a trial version of ASP.Net Report Maker but shortly thereafter my laptop slowed down so I removed it. I should add that there was a file that I could not delete so I forced uninstalled with REVO Uninstaller. My fear is that it was a protected file. Could this be my problem? Also, when I uninstalled McAffee and ran "fixme.bat" my AVG filewall would not start. I checked thru control panel and noticed that it still showed McAffee was still "active" so I had to regenerate confiquaration AVG and restarted in order to get my AVG filewall working again. Checking Microsoft security center again I noticed that microsoft informed me "At least one of the firewalls you have installed is running" but I don't know how to check which one and if McAffe is still present on my machine. Not sure if it will help but a ran a full command line AVG scan last night in safe mode and have attached as well. Also I got some wierd registries when I did a registry clean and am worried by them. They were empty keys but ended in things like schema\personin and schema\personout (I think that is what they were) and also keyboard layout\toggle. I regularly do a registry clean and have never seen these before. Am I being paronoid here? The machine is still slow and freezes up as well. Any assistance and direction you could provide me at this point would be GREATLY APPRECIATED!~ Say noticed you were from Missouri. I am in Southeastern MO myself. Thanks again and I look forward to your reply!
Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.
  • Please download TDSSKiller.zip
    • Extract it to your desktop
    • Double click TDSSKiller.exe
    • Press Start Scan
      • Only if Malicious objects are found then ensure Cure is selected
      • Then click Continue > Reboot now
    • Copy and paste the log in your next reply
      • A copy of the log will be saved automatically to the root directory, root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
    please post the contents of that log TDSSKiller and GooredFix log.

    Please don't attach the scan results, use Copy/Paste
LDTate-

Thank you once again for the reply. I completed the GooredFix and TDSSKiller scans you instructed and have copied/pasted the results below. I know that I should follow the directions you outline for me to carry out but after I completed the above scans I ran the "fixme.bat" file you instructed me to run in your first reply since running this batch file will cause the ASP.NET FILE to flash on my screen on boot-up and unfortunately after I ran it this time this folder did appear briefly again on start-up. I have attached the log of this latest run as well and I apologize if I went outside of your steps. My computer is still exhibiting the symptoms of the Malware.Trace infection.

Please find the logs below and I do look forward to your reply!

GooredFix log:

GooredFix by jpshortstuff (03.07.10.1)
Log created at 14:02 on 21/12/2010 (User)
Firefox version [Unable to determine]

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
(none)

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [02:10 05/08/2010]
"[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [02:32 11/10/2010]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG10\Firefox\" [21:41 16/11/2010]

-=E.O.F=-

TDSSKiller:

2010/12/21 14:04:26.0296 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46
2010/12/21 14:04:26.0296 ================================================================================
2010/12/21 14:04:26.0296 SystemInfo:
2010/12/21 14:04:26.0296
2010/12/21 14:04:26.0296 OS Version: 5.1.2600 ServicePack: 3.0
2010/12/21 14:04:26.0296 Product type: Workstation
2010/12/21 14:04:26.0296 ComputerName: MARCIA-6X7H850P
2010/12/21 14:04:26.0296 UserName: User
2010/12/21 14:04:26.0296 Windows directory: C:\WINDOWS
2010/12/21 14:04:26.0296 System windows directory: C:\WINDOWS
2010/12/21 14:04:26.0296 Processor architecture: Intel x86
2010/12/21 14:04:26.0296 Number of processors: 1
2010/12/21 14:04:26.0296 Page size: 0x1000
2010/12/21 14:04:26.0296 Boot type: Normal boot
2010/12/21 14:04:26.0296 ================================================================================
2010/12/21 14:04:26.0843 Initialize success
2010/12/21 14:05:03.0921 ================================================================================
2010/12/21 14:05:03.0921 Scan started
2010/12/21 14:05:03.0921 Mode: Manual;
2010/12/21 14:05:03.0921 ================================================================================
2010/12/21 14:05:04.0875 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/12/21 14:05:05.0078 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2010/12/21 14:05:05.0203 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2010/12/21 14:05:05.0296 AegisP (91f3df93f40a74d222cd166fe95db633) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2010/12/21 14:05:05.0375 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2010/12/21 14:05:05.0625 ApfiltrService (b21fcbc58cb13bac70f74b5ac5da7409) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
2010/12/21 14:05:05.0703 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2010/12/21 14:05:05.0921 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/12/21 14:05:05.0984 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/12/21 14:05:06.0078 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/12/21 14:05:06.0156 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/12/21 14:05:06.0265 Avgfwdx (0c5941af0b6bf2fdf378937392865217) C:\WINDOWS\system32\DRIVERS\avgfwdx.sys
2010/12/21 14:05:06.0281 Avgfwfd (0c5941af0b6bf2fdf378937392865217) C:\WINDOWS\system32\DRIVERS\avgfwdx.sys
2010/12/21 14:05:06.0359 AVGIDSDriver (0c61f066f4d94bd67063dc6691935143) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
2010/12/21 14:05:06.0406 AVGIDSEH (84853f800cd69252c3c764fe50d0346f) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
2010/12/21 14:05:06.0437 AVGIDSFilter (28d6adcd03e10f3838488b9b5d407dd4) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
2010/12/21 14:05:06.0484 AVGIDSShim (0eb16f4dbbb946360af30d2b13a52d1d) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
2010/12/21 14:05:06.0546 Avgldx86 (1119e5bec6e749e0d292f0f84d48edba) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
2010/12/21 14:05:06.0578 Avgmfx86 (54f1a9b4c9b540c2d8ac4baa171696b1) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
2010/12/21 14:05:06.0656 Avgrkx86 (8da3b77993c5f354cc2977b7ea06d03a) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
2010/12/21 14:05:06.0750 Avgtdix (354e0fec3bfdfa9c369e0f67ac362f9f) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
2010/12/21 14:05:06.0890 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/12/21 14:05:07.0000 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/12/21 14:05:07.0078 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2010/12/21 14:05:07.0203 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/12/21 14:05:07.0296 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/12/21 14:05:07.0375 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/12/21 14:05:07.0531 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2010/12/21 14:05:07.0625 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2010/12/21 14:05:07.0921 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/12/21 14:05:07.0984 DKRtWrt (42823617433f6f9463e627644e716358) C:\WINDOWS\system32\DRIVERS\DKRtWrt.sys
2010/12/21 14:05:08.0046 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2010/12/21 14:05:08.0203 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2010/12/21 14:05:08.0281 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/12/21 14:05:08.0406 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2010/12/21 14:05:08.0546 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/12/21 14:05:08.0640 DrvAgent32 (651554e483712b708ede864d0ca1aa73) C:\WINDOWS\system32\Drivers\DrvAgent32.sys
2010/12/21 14:05:08.0828 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/12/21 14:05:08.0937 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2010/12/21 14:05:09.0015 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2010/12/21 14:05:09.0093 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2010/12/21 14:05:09.0156 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2010/12/21 14:05:09.0265 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/12/21 14:05:09.0312 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/12/21 14:05:09.0375 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/12/21 14:05:09.0437 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2010/12/21 14:05:09.0515 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2010/12/21 14:05:09.0609 HSFHWAZL (acc46dda7fece95a253ae88cea172e12) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys
2010/12/21 14:05:09.0703 HSF_DPV (c9f4e7da78a02623abf78a4a34ce79b1) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
2010/12/21 14:05:09.0890 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/12/21 14:05:10.0015 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/12/21 14:05:10.0125 IDMTDI (63634d0b790aee804988e9fe0f5eea9f) C:\WINDOWS\system32\DRIVERS\idmtdi.sys
2010/12/21 14:05:10.0218 IFXTPM (0a359837e021bc04a04a6fd189492c65) C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS
2010/12/21 14:05:10.0281 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/12/21 14:05:10.0390 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2010/12/21 14:05:10.0437 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2010/12/21 14:05:10.0515 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/12/21 14:05:10.0578 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/12/21 14:05:10.0609 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/12/21 14:05:10.0687 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/12/21 14:05:10.0718 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/12/21 14:05:10.0781 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/12/21 14:05:10.0859 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/12/21 14:05:10.0937 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2010/12/21 14:05:11.0000 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/12/21 14:05:11.0125 MBAMProtector (67b48a903430c6d4fb58cbaca1866601) C:\WINDOWS\system32\drivers\mbam.sys
2010/12/21 14:05:11.0203 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
2010/12/21 14:05:11.0265 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/12/21 14:05:11.0343 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2010/12/21 14:05:11.0390 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/12/21 14:05:11.0453 moufiltr (a4a897ec59ce8c52d2537da00128ef40) C:\WINDOWS\system32\drivers\moufiltr.sys
2010/12/21 14:05:11.0515 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2010/12/21 14:05:11.0593 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/12/21 14:05:11.0671 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/12/21 14:05:11.0750 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/12/21 14:05:11.0859 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2010/12/21 14:05:11.0921 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/12/21 14:05:11.0984 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/12/21 14:05:12.0046 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/12/21 14:05:12.0125 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/12/21 14:05:12.0218 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2010/12/21 14:05:12.0296 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2010/12/21 14:05:12.0343 Mvc25U870_VID_1262&PID_25FD (e88e7e9aa0ab34b6c664a4a43cea6316) C:\WINDOWS\system32\Drivers\Mvc25U870.sys
2010/12/21 14:05:12.0390 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2010/12/21 14:05:12.0468 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2010/12/21 14:05:12.0500 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2010/12/21 14:05:12.0562 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2010/12/21 14:05:12.0609 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/12/21 14:05:12.0656 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/12/21 14:05:12.0718 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/12/21 14:05:12.0781 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/12/21 14:05:12.0828 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/12/21 14:05:13.0078 NETw5x32 (91f027c242d3ff6e5c09f92a0518297f) C:\WINDOWS\system32\DRIVERS\NETw5x32.sys
2010/12/21 14:05:13.0281 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2010/12/21 14:05:13.0328 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2010/12/21 14:05:13.0390 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/12/21 14:05:13.0484 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/12/21 14:05:13.0671 nv (6866504ee1570ef783309abfb56f87e5) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2010/12/21 14:05:13.0921 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/12/21 14:05:14.0000 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/12/21 14:05:14.0078 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2010/12/21 14:05:14.0140 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
2010/12/21 14:05:14.0187 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/12/21 14:05:14.0250 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/12/21 14:05:14.0312 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/12/21 14:05:14.0421 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2010/12/21 14:05:14.0484 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2010/12/21 14:05:14.0718 PersonalSecureDrive (e07d23de6e595a24b3f0b8bab0080149) C:\WINDOWS\System32\drivers\psd.sys
2010/12/21 14:05:14.0781 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/12/21 14:05:14.0828 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
2010/12/21 14:05:14.0906 PTDWBus (fbd9a22ec513457bc4b9227a239bce2c) C:\WINDOWS\system32\DRIVERS\PTDWBus.sys
2010/12/21 14:05:14.0953 PTDWMdm (33477b60160223e71c2850532cbba647) C:\WINDOWS\system32\DRIVERS\PTDWMdm.sys
2010/12/21 14:05:15.0015 PTDWVsp (80811c30bc5ec69078bd45cae6dec82e) C:\WINDOWS\system32\DRIVERS\PTDWVsp.sys
2010/12/21 14:05:15.0078 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/12/21 14:05:15.0109 PWCTLDRV (f82f63e56c9d0c769a2bb385a972120b) C:\WINDOWS\system32\drivers\PWCTLDRV.sys
2010/12/21 14:05:15.0484 PxHelp20 (1962166e0ceb740704f30fa55ad3d509) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2010/12/21 14:05:15.0703 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/12/21 14:05:15.0796 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/12/21 14:05:15.0875 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/12/21 14:05:15.0953 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/12/21 14:05:16.0078 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/12/21 14:05:16.0156 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/12/21 14:05:16.0265 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2010/12/21 14:05:16.0343 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/12/21 14:05:16.0421 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/12/21 14:05:16.0546 Revoflt (8b5b8a11306190c6963d3473f052d3c8) C:\WINDOWS\system32\DRIVERS\revoflt.sys
2010/12/21 14:05:16.0671 RsFx0103 (fd692c6ffade58f7c4c3c3c9a0ec35bd) C:\WINDOWS\system32\DRIVERS\RsFx0103.sys
2010/12/21 14:05:16.0796 s24trans (078eba5670fdaa041552cd86b984f2de) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2010/12/21 14:05:16.0968 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2010/12/21 14:05:17.0000 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2010/12/21 14:05:17.0156 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/12/21 14:05:17.0218 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
2010/12/21 14:05:17.0296 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/12/21 14:05:17.0406 shpf (b8e1ac2cdad522572bfc73781d0e37e2) C:\WINDOWS\system32\DRIVERS\shpf.sys
2010/12/21 14:05:17.0546 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2010/12/21 14:05:17.0703 SMNDIS5 (4ef5ea44583c37383c289d4b8c354698) C:\PROGRA~1\VERIZO~1\VZAccess Manager\SMNDIS5.SYS
2010/12/21 14:05:17.0843 SNC (be6038e0a7d2e2fe69107e41a0265831) C:\WINDOWS\system32\DRIVERS\SonyNC.sys
2010/12/21 14:05:17.0968 SPI (ad9436c46c10222b8f03405628a8cd86) C:\WINDOWS\system32\DRIVERS\SonyPI.sys
2010/12/21 14:05:18.0046 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2010/12/21 14:05:18.0156 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/12/21 14:05:18.0234 SRS_SSCFilter (25ecea986742275ecb23a1cb6bc87a61) C:\WINDOWS\system32\drivers\srs_sscfilter_i386.sys
2010/12/21 14:05:18.0328 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/12/21 14:05:18.0468 STHDA (bbbc5bf9a5f1fb5d57e91b944d2e51a5) C:\WINDOWS\system32\drivers\sthda.sys
2010/12/21 14:05:18.0546 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2010/12/21 14:05:18.0625 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/12/21 14:05:18.0687 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2010/12/21 14:05:18.0875 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/12/21 14:05:18.0968 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/12/21 14:05:19.0046 TcUsb (fc6fe02f400308606a911640e72326b5) C:\WINDOWS\system32\Drivers\tcusb.sys
2010/12/21 14:05:19.0125 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/12/21 14:05:19.0171 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/12/21 14:05:19.0218 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/12/21 14:05:19.0296 TfFsMon (95746e5b1473432f3d9458940dba6e3a) C:\WINDOWS\system32\drivers\TfFsMon.sys
2010/12/21 14:05:19.0343 TfNetMon (02ffdd873e31c5c2d57ca87d11ec36af) C:\WINDOWS\system32\drivers\TfNetMon.sys
2010/12/21 14:05:19.0375 TfSysMon (f8bd92251ab439383c051ce907d78cce) C:\WINDOWS\system32\drivers\TfSysMon.sys
2010/12/21 14:05:19.0468 ti21sony (3106074a87bd5a16e2a3af6902bb6d91) C:\WINDOWS\system32\drivers\ti21sony.sys
2010/12/21 14:05:19.0546 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
2010/12/21 14:05:19.0640 tosporte (2c15b4856f929ac7dd144044d8334b54) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2010/12/21 14:05:19.0687 Tosrfbd (926ca0b7fd2fa62d82c33b3117936070) C:\WINDOWS\system32\Drivers\tosrfbd.sys
2010/12/21 14:05:19.0750 Tosrfbnp (1ae2ba74b2a4f5a358b13fcd35258c30) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2010/12/21 14:05:19.0796 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2010/12/21 14:05:19.0843 Tosrfhid (5dbf390aab62dd0d4d43a9278614e001) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2010/12/21 14:05:19.0906 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2010/12/21 14:05:19.0953 TosRfSnd (ab6fd13d7efa2634fa6bdf84c7ef0696) C:\WINDOWS\system32\drivers\TosRfSnd.sys
2010/12/21 14:05:20.0000 Tosrfusb (d870fd6ce9060b73289f47e88630ee0e) C:\WINDOWS\system32\Drivers\tosrfusb.sys
2010/12/21 14:05:20.0156 TuneUpUtilitiesDrv (f2107c9d85ec0df116939ccce06ae697) C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys
2010/12/21 14:05:20.0218 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2010/12/21 14:05:20.0312 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2010/12/21 14:05:20.0406 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2010/12/21 14:05:20.0468 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/12/21 14:05:20.0531 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/12/21 14:05:20.0593 UsbFltr (c1bd31ac0c1397fa7cd0a23012c87a10) C:\WINDOWS\system32\drivers\UsbFltr.sys
2010/12/21 14:05:20.0656 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/12/21 14:05:20.0734 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2010/12/21 14:05:20.0796 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2010/12/21 14:05:20.0859 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2010/12/21 14:05:20.0921 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/12/21 14:05:21.0000 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2010/12/21 14:05:21.0062 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2010/12/21 14:05:21.0125 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/12/21 14:05:21.0265 w39n51 (4e7b07653f4f9937cf62ad2869fba520) C:\WINDOWS\system32\DRIVERS\w39n51.sys
2010/12/21 14:05:21.0375 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/12/21 14:05:21.0437 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\WINDOWS\system32\DRIVERS\wdcsam.sys
2010/12/21 14:05:21.0531 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/12/21 14:05:21.0609 winachsf (c1d5cbd8aa0d674da1ba1bb189696396) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
2010/12/21 14:05:21.0812 WpdUsb (c60dc16d4e406810fad54b98dc92d5ec) C:\WINDOWS\system32\Drivers\wpdusb.sys
2010/12/21 14:05:21.0875 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2010/12/21 14:05:21.0953 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2010/12/21 14:05:22.0031 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/12/21 14:05:22.0109 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2010/12/21 14:05:22.0218 yukonwxp (d590231272d61b470c3c24a08ace03b0) C:\WINDOWS\system32\DRIVERS\yk51x86.sys
2010/12/21 14:05:22.0468 ================================================================================
2010/12/21 14:05:22.0468 Scan finished
2010/12/21 14:05:22.0468 ================================================================================
2010/12/21 14:05:56.0656 Deinitialize success

Latest fixme.bat run:

reset Linkage\UpperBind for SW\{48926476-2CAE-4DED-A86E-73DDEBED6779}\NDISIP. bad value was:
REG_MULTI_SZ =
Avgfwfd

reset Linkage\UpperBind for PCI\VEN_11AB&DEV_4351&SUBSYS_81E6104D&REV_15\4&2803E7C1&0&00E2. bad value was:
REG_MULTI_SZ =
Avgfwfd

reset Linkage\UpperBind for BLUETOOTH\0004&0007\0000. bad value was:
REG_MULTI_SZ =
Avgfwfd

reset Linkage\UpperBind for PCI\VEN_8086&DEV_4222&SUBSYS_10508086&REV_02\4&20975680&0&00E1. bad value was:
REG_MULTI_SZ =
Avgfwfd

reset Linkage\UpperBind for ROOT\MS_NDISWANIP\0000. bad value was:
REG_MULTI_SZ =
Avgfwfd



reset SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{2643ABF9-63C0-479C-B0A1-DBCEAEB940B7}\NameServerList
old REG_MULTI_SZ =


added SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{2643ABF9-63C0-479C-B0A1-DBCEAEB940B7}\NetbiosOptions
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2643ABF9-63C0-479C-B0A1-DBCEAEB940B7}\NameServer
reset Linkage\UpperBind for SW\{48926476-2CAE-4DED-A86E-73DDEBED6779}\NDISIP. bad value was:
REG_MULTI_SZ =
Avgfwfd

reset Linkage\UpperBind for PCI\VEN_11AB&DEV_4351&SUBSYS_81E6104D&REV_15\4&2803E7C1&0&00E2. bad value was:
REG_MULTI_SZ =
Avgfwfd

reset Linkage\UpperBind for BLUETOOTH\0004&0007\0000. bad value was:
REG_MULTI_SZ =
Avgfwfd

reset Linkage\UpperBind for PCI\VEN_8086&DEV_4222&SUBSYS_10508086&REV_02\4&20975680&0&00E1. bad value was:
REG_MULTI_SZ =
Avgfwfd

reset Linkage\UpperBind for ROOT\MS_NDISWANIP\0000. bad value was:
REG_MULTI_SZ =
Avgfwfd

Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
LDTate-

Thank you for the reply and instructions. It is appreciated. I followed your instructions below and there is still a number of troubling signs my laptop exhibits:

Upon opening a word document it suddenly started to install something like windows enterprise(?) and now when I close out a document it indicates at the bottom of the page "connecting to server".

My Malware bytes application suddenly stopped initializing with an error 404.

I thought putting in a new firewall and went with a trial version of Kaspersky Internet Security and I noticed under users it has Administrator, Guest and most troubling Todd\ASP (which is the file I think infected my machine).

Also when I am browsing the web my page will page back suddenly at times and I have noticed that when I type at times when I type and for each letter I type my hour glass will show and typing will become slow.

Finally as I used my laptop during the day it became slower and slower and froze a couple of times.

Thanks again for all your help and please find my log below:

ComboFix 10-12-21.01 - User 12/21/2010 21:59:59.1.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\Virus Stuff\ComboFix.exe
AV: AVG Internet Security 2011 *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
PEV Error: ProgramsFile

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users.WINDOWS\Application Data\1doc2pdf.dll
c:\windows\system32\images
c:\windows\system32\images\toolbar\calendar.gif
c:\windows\system32\images\toolbar\crlogo.gif
c:\windows\system32\images\toolbar\export.gif
c:\windows\system32\images\toolbar\export_over.gif
c:\windows\system32\images\toolbar\exportd.gif
c:\windows\system32\images\toolbar\First.gif
c:\windows\system32\images\toolbar\first_over.gif
c:\windows\system32\images\toolbar\Firstd.gif
c:\windows\system32\images\toolbar\gotopage.gif
c:\windows\system32\images\toolbar\gotopage_over.gif
c:\windows\system32\images\toolbar\gotopaged.gif
c:\windows\system32\images\toolbar\grouptree.gif
c:\windows\system32\images\toolbar\grouptree_over.gif
c:\windows\system32\images\toolbar\grouptreed.gif
c:\windows\system32\images\toolbar\grouptreepressed.gif
c:\windows\system32\images\toolbar\Last.gif
c:\windows\system32\images\toolbar\last_over.gif
c:\windows\system32\images\toolbar\Lastd.gif
c:\windows\system32\images\toolbar\Next.gif
c:\windows\system32\images\toolbar\next_over.gif
c:\windows\system32\images\toolbar\Nextd.gif
c:\windows\system32\images\toolbar\Prev.gif
c:\windows\system32\images\toolbar\prev_over.gif
c:\windows\system32\images\toolbar\Prevd.gif
c:\windows\system32\images\toolbar\print.gif
c:\windows\system32\images\toolbar\print_over.gif
c:\windows\system32\images\toolbar\printd.gif
c:\windows\system32\images\toolbar\Refresh.gif
c:\windows\system32\images\toolbar\refresh_over.gif
c:\windows\system32\images\toolbar\refreshd.gif
c:\windows\system32\images\toolbar\Search.gif
c:\windows\system32\images\toolbar\search_over.gif
c:\windows\system32\images\toolbar\searchd.gif
c:\windows\system32\images\toolbar\up.gif
c:\windows\system32\images\toolbar\up_over.gif
c:\windows\system32\images\toolbar\upd.gif
c:\windows\system32\images\tree\begindots.gif
c:\windows\system32\images\tree\beginminus.gif
c:\windows\system32\images\tree\beginplus.gif
c:\windows\system32\images\tree\blank.gif
c:\windows\system32\images\tree\blankdots.gif
c:\windows\system32\images\tree\dots.gif
c:\windows\system32\images\tree\lastdots.gif
c:\windows\system32\images\tree\lastminus.gif
c:\windows\system32\images\tree\lastplus.gif
c:\windows\system32\images\tree\Magnify.gif
c:\windows\system32\images\tree\minus.gif
c:\windows\system32\images\tree\minusbox.gif
c:\windows\system32\images\tree\plus.gif
c:\windows\system32\images\tree\plusbox.gif
c:\windows\system32\images\tree\singleminus.gif
c:\windows\system32\images\tree\singleplus.gif
c:\windows\system32\spdwnwxp.exe

Infected copy of c:\windows\regedit.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\REGEDIT.EXE

.
((((((((((((((((((((((((( Files Created from 2010-11-22 to 2010-12-22 )))))))))))))))))))))))))))))))
.

2010-12-22 03:43 . 2010-12-22 03:45 ——– d—–r- C:\32788R22FWJFW
2010-12-22 03:40 . 2008-04-14 10:42 146432 ——w- c:\windows\regedit.exe
2010-12-19 03:00 . 2010-12-19 03:00 ——– d—–w- c:\program files\Free ISO Creator
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Windows Script Control
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Common Files\e.World
2010-12-14 00:00 . 2010-12-14 00:00 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\MetaProducts
2010-12-14 00:00 . 2009-03-02 19:55 73728 —-a-w- c:\windows\system32\SUO.cpl
2010-12-13 23:59 . 2010-12-14 00:00 ——– d—–w- c:\program files\StartUp Organizer
2010-12-13 22:34 . 2010-12-13 22:35 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\GetRightToGo
2010-12-13 18:58 . 2010-12-13 18:58 ——– d—–w- c:\windows\system32\wbem\Repository
2010-12-12 23:07 . 2010-12-12 23:07 ——– d—–w- C:\$AVG
2010-12-08 05:11 . 2010-12-08 05:16 ——– d—–w- c:\program files\Business Objects
2010-12-05 02:41 . 2010-11-23 23:16 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2010-12-05 02:41 . 2010-11-23 23:11 29504 —-a-w- c:\windows\system32\uxtuneup.dll
2010-12-05 02:40 . 2010-12-05 02:41 ——– d—–w- c:\program files\TuneUp Utilities 2011
2010-12-05 01:09 . 2003-06-25 22:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2010-11-29 03:59 . 2010-12-18 23:53 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\Smart PC Solutions
2010-11-28 05:55 . 2010-11-28 05:55 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\iNViSiBLE
2010-11-28 05:49 . 2010-11-28 05:52 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\.moneydance
2010-11-28 05:48 . 2010-11-28 05:48 ——– d—–w- c:\program files\Moneydance
2010-11-28 05:48 . 2010-11-28 05:48 ——– d—–w- c:\program files\Common Files\i4j_jres
2010-11-27 22:36 . 2010-11-28 03:50 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-11-25 15:46 . 2010-11-25 15:47 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Local Settings\Application Data\Downloaded Installations

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-08 05:19 . 2010-06-16 02:19 1748416 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2010-11-18 18:12 . 2010-05-21 23:35 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-12 02:14 . 2010-06-06 22:07 18368 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-11-06 00:26 . 2003-03-31 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2003-03-31 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2003-03-31 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2010-05-25 16:35 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2003-03-31 12:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2003-03-31 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2003-03-31 12:00 1853312 —-a-w- c:\windows\system32\win32k.sys
2010-10-11 02:32 . 2010-10-11 02:32 73728 —-a-w- c:\windows\system32\javacpl.cpl
2010-10-11 02:32 . 2010-10-11 02:32 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-09-26 02:12 . 2010-09-26 02:12 8464 —-a-w- c:\windows\system32\SpOrder.dll
2010-09-26 01:50 . 2010-09-24 03:28 7921664 —-a-w- c:\windows\system32\IDTSG.cpl
2010-09-26 01:45 . 2010-05-26 16:02 41472 —-a-w- c:\windows\system32\drivers\tosporte.sys
2010-09-24 03:30 . 2010-09-24 03:30 55680 —-a-w- c:\windows\system32\drivers\Mvc25U870.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2010-08-25 14:36 70264 —-a-w- c:\program files\Internet Download Manager\IDMShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Controlled StartUp"="c:\program files\StartUp Organizer\Ctrl.exe" [2009-03-02 193576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2004-09-10 69632]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

c:\documents and settings\user\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [N/A]

c:\documents and settings\User.MARCIA-6X7H850P\Start Menu\Programs\Startup\
Startup Defender.lnk - c:\program files\Zards software\Startup Defender\Startup Defender.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 4 (0x4)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2006-03-10 20:20 434176 —-a-w- c:\windows\system32\IfxWlxEN.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0autocheck c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [3/11/2002 1:55 AM 9216]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [10/29/2010 9:40 PM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [10/29/2010 9:40 PM 59664]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [8/25/2010 8:40 AM 76768]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [11/29/2005 5:50 PM 36768]
R1 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [3/30/2009 2:09 AM 239336]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [6/6/2010 7:57 PM 6144]
R2 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [7/10/2008 12:22 AM 218136]
R2 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [7/10/2008 12:15 AM 31256]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [11/23/2010 5:13 PM 1483072]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [7/12/2010 4:33 AM 30432]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [10/21/2010 1:08 PM 44368]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [8/29/2006 7:31 PM 36352]
R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [7/19/2007 10:38 AM 27392]
R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [7/19/2007 10:38 AM 41728]
R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [7/19/2007 10:38 AM 39808]
R3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [7/19/2007 10:38 AM 5888]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [5/21/2010 12:29 PM 71961]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [10/29/2010 9:40 PM 33552]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [5/26/2010 11:26 AM 808448]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10/7/2010 12:34 PM 10064]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys –> c:\windows\system32\DRIVERS\AVGIDSEH.Sys [?]
S2 avgfws;AVG Firewall;"c:\program files\AVG\AVG10\avgfws.exe" –> c:\program files\AVG\AVG10\avgfws.exe [?]
S2 avgwd;AVG WatchDog;"c:\program files\AVG\AVG10\avgwdsvc.exe" –> c:\program files\AVG\AVG10\avgwdsvc.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys –> c:\windows\system32\DRIVERS\avfwim.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [7/12/2010 4:33 AM 30432]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [7/18/2010 9:58 PM 23456]
S3 icsak;icsak;\??\c:\program files\CheckPoint\ZAForceField\AK\icsak.sys –> c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [?]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/23/2010 2:50 PM 20952]
S3 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/23/2010 2:50 PM 304464]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\DRIVERS\pwi_bus.sys –> c:\windows\system32\DRIVERS\pwi_bus.sys [?]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\DRIVERS\pwi_mdfl.sys –> c:\windows\system32\DRIVERS\pwi_mdfl.sys [?]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\DRIVERS\pwi_mdm.sys –> c:\windows\system32\DRIVERS\pwi_mdm.sys [?]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\DRIVERS\pwi_oflt.sys –> c:\windows\system32\DRIVERS\pwi_oflt.sys [?]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\pwi_serd.sys –> c:\windows\system32\DRIVERS\pwi_serd.sys [?]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [8/19/2010 9:08 PM 27064]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [5/25/2010 7:33 PM 11520]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [3/31/2003 6:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 1:49 AM 47128]
S4 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [3/30/2009 1:16 AM 1113448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-12-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-12-22 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-10-27 18:38]

2010-12-05 c:\windows\Tasks\Security Platform Backup Schedule.job
- c:\program files\Infineon\Security Platform Software\SpBackupWz.exe [2006-03-10 20:33]

2010-12-21 c:\windows\Tasks\User_Feed_Synchronization-{06B1BC02-2B9F-4237-AF0C-834FD0BDA026}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {2643ABF9-63C0-479C-B0A1-DBCEAEB940B7} = 69.78.96.14 66.174.92.14
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-21 22:38
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ThreatFire]
"AlternateImagePath"=""
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6175B6E8-3D5E-8729-2540-D055604E5C59}*]
"kaggmdejllmffnhbnbhiod"=hex:61,61,00,00
"faggmdejamki"=hex:66,61,6a,68,68,67,6e,63,68,6a,65,6d,00,00

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9C6CF11F-216C-07F5-E86A-095ECC1154CA}*]
"oakejaihmocgedmecojhjmchapjlnm"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54
"naielbhcbbjkfininppakggoecap"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e0,a1,23,af,68,fc,2d,6a,cb,34,5f,bf,47,3b,62,7f,b7,d2,33,0e,96,
27,2e,b5,dc,b8,92,b1,c9,d5,77,69,f1,05,b4,49,db,0c,65,0e,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{64409a28-305a-4819-afa1-bd8419a6a32c}]
@Denied: (Full) (Everyone)
"Model"=dword:000000e6
"Therad"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{75d7991b-88b7-4692-b431-987876646407}]
@Denied: (Full) (Everyone)
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8f,d2,4d,a1,8f,eb,94,ad,30,43,d0,63,83,f2,01,57,f0,c1,28,fd,a3,
b1,76,9e,ce,65,77,04,5b,b1,78,29,37,3d,3d,76,92,d0,05,90,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(832)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\documents and settings\User.MARCIA-6X7H850P\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\documents and settings\User.MARCIA-6X7H850P\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
c:\documents and settings\User.MARCIA-6X7H850P\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
c:\program files\ThreatFire\TFWAH.dll
c:\program files\ThreatFire\TFNI.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\IfxWlxEN.dll

- - - - - - - > 'lsass.exe'(888)
c:\program files\ThreatFire\TFWAH.dll

- - - - - - - > 'explorer.exe'(784)
c:\windows\system32\WININET.dll
c:\program files\ThreatFire\TfWah.dll
c:\program files\Internet Download Manager\IDMShellExt.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\program files\ThreatFire\TFNI.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sony\SmartWi Connection Utility\SmartWiService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\ThreatFire\TFService.exe
c:\program files\verizon wireless\venturi\Client\ventc.exe
c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\program files\ThreatFire\TFTray.exe
c:\program files\Intel\Wireless\bin\ZCfgSvc.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Intel\Wireless\Bin\ifrmewrk.exe
c:\program files\Apoint\Apoint.exe
c:\program files\Apoint\Apntex.exe
c:\program files\IObit\Advanced SystemCare 3\AWC.exe
.
**************************************************************************
.
Completion time: 2010-12-21 22:55:42 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-22 04:55

Pre-Run: 64,231,858,176 bytes free
Post-Run: 64,206,376,960 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 13E74D5ACC6ECB86CA5D96B529988EC2
While I'm looking at your log, please try uninstall AVG again
If AVG will not uninstall, it is first recommended to uninstall it with AppRemover by Opswat. The AVG uninstaller can be downloaded from here > http://www.appremove.../AppRemover.exe Go to their homepage and you will see they have support for removal of other AV's as well http://www.appremover.com/
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

RegLock:: 
[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6175B6E8-3D5E-8729-2540-D055604E5C59}*]
[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9C6CF11F-216C-07F5-E86A-095ECC1154CA}*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{64409a28-305a-4819-afa1-bd8419a6a32c}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{75d7991b-88b7-4692-b431-987876646407}]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
LDTate-
This did it! :woot: You folks at WhatTheTech are AWESOME! Thank you so much for your assistance with this as it is GREATLY APPRECIATED! I do have one issue remaining and a couple of questions.

For some reason I am still not able to completely uninstall AVG. I ran the Appremover tool above and the AVG uninstall tools again with no luck. Appremover does not list it. I have also repeatedly scanned my hard drive for “AVG” with no luck. Would you by chance have any suggestions on where to go from here as I know the problem involved with running 2 AV’s?

Also I have a key which will not remove when I do a registry scan even though it comes up as an empty key it is:
HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Keyboard Layout\Toggle\
Is this okay?

Finally, I want to purchase a GOOD and SOLID Internet Security Suite for myself and my parent’s laptops and I was hoping to get you opinion on one. I need to get one with 2 licenses.

THANKS again for the WONDERFUL assistance! You guys are lifesavers! :clap:

ComboFix 10-12-21.01 - User 12/23/2010 16:30:25.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1455 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Virus Stuff\ComboFix.exe
Command switches used :: c:\documents and settings\User.MARCIA-6X7H850P\Desktop\CFScript.txt
AV: AVG Anti-Virus 2011 *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *Enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.

((((((((((((((((((((((((( Files Created from 2010-11-23 to 2010-12-23 )))))))))))))))))))))))))))))))
.

2010-12-23 16:06 . 2010-12-23 16:06 ——– d—–w- c:\windows\system32\wbem\Repository
2010-12-23 07:25 . 2010-12-23 07:25 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-12-23 07:25 . 2010-12-23 07:25 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-12-23 07:20 . 2010-12-23 21:57 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2010-12-23 07:16 . 2010-12-23 07:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2010-12-23 04:33 . 2010-12-21 00:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 04:33 . 2010-12-23 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-12-23 04:33 . 2010-12-21 00:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 00:12 . 2010-12-23 00:19 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2010-12-23 00:12 . 2010-12-23 00:14 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\BitDefender
2010-12-23 00:12 . 2010-12-23 00:12 ——– d—–w- c:\program files\BitDefender
2010-12-23 00:00 . 2010-12-23 00:13 ——– d—–w- c:\program files\Common Files\BitDefender
2010-12-22 23:56 . 2010-12-22 23:59 37099 —-a-w- C:\BdUninstallTool2010.12.22-05.56.18.reg
2010-12-22 21:23 . 2010-12-22 21:23 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\QuickScan
2010-12-22 21:21 . 2010-12-22 22:42 520994 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\bdinstall.bin
2010-12-22 03:40 . 2008-04-14 10:42 146432 ——w- c:\windows\regedit.exe
2010-12-19 03:00 . 2010-12-19 03:00 ——– d—–w- c:\program files\Free ISO Creator
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Windows Script Control
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Common Files\e.World
2010-12-14 00:00 . 2010-12-14 00:00 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\MetaProducts
2010-12-14 00:00 . 2009-03-02 19:55 73728 —-a-w- c:\windows\system32\SUO.cpl
2010-12-13 23:59 . 2010-12-14 00:00 ——– d—–w- c:\program files\StartUp Organizer
2010-12-13 22:34 . 2010-12-13 22:35 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\GetRightToGo
2010-12-12 23:07 . 2010-12-12 23:07 ——– d—–w- C:\$AVG
2010-12-08 05:11 . 2010-12-08 05:16 ——– d—–w- c:\program files\Business Objects
2010-12-05 02:41 . 2010-11-23 23:16 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2010-12-05 02:41 . 2010-11-23 23:11 29504 —-a-w- c:\windows\system32\uxtuneup.dll
2010-12-05 02:40 . 2010-12-05 02:41 ——– d—–w- c:\program files\TuneUp Utilities 2011
2010-12-05 01:09 . 2003-06-25 22:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2010-11-29 03:59 . 2010-12-18 23:53 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\Smart PC Solutions
2010-11-28 05:55 . 2010-11-28 05:55 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\iNViSiBLE
2010-11-28 05:49 . 2010-11-28 05:52 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\.moneydance
2010-11-28 05:48 . 2010-11-28 05:48 ——– d—–w- c:\program files\Moneydance
2010-11-28 05:48 . 2010-11-28 05:48 ——– d—–w- c:\program files\Common Files\i4j_jres
2010-11-27 22:36 . 2010-11-28 03:50 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-11-25 15:46 . 2010-11-25 15:47 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Local Settings\Application Data\Downloaded Installations

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-23 03:04 . 2009-11-10 23:03 106464 —-a-w- c:\windows\system32\drivers\bdhv.sys
2010-12-23 03:04 . 2009-11-10 23:04 153448 —-a-w- c:\windows\system32\drivers\bdfm.sys
2010-12-23 03:04 . 2009-07-24 17:26 291352 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2010-12-23 02:59 . 2009-10-19 22:04 111312 —-a-w- c:\windows\system32\drivers\bdfndisf.sys
2010-12-08 05:19 . 2010-06-16 02:19 1748416 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2010-11-18 18:12 . 2010-05-21 23:35 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-12 02:14 . 2010-06-06 22:07 18368 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-11-06 00:26 . 2003-03-31 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2003-03-31 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2003-03-31 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2010-05-25 16:35 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2003-03-31 12:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2003-03-31 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2003-03-31 12:00 1853312 —-a-w- c:\windows\system32\win32k.sys
2010-10-11 02:32 . 2010-10-11 02:32 73728 —-a-w- c:\windows\system32\javacpl.cpl
2010-10-11 02:32 . 2010-10-11 02:32 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-09-26 02:12 . 2010-09-26 02:12 8464 —-a-w- c:\windows\system32\SpOrder.dll
2010-09-26 01:50 . 2010-09-24 03:28 7921664 —-a-w- c:\windows\system32\IDTSG.cpl
2010-09-26 01:45 . 2010-05-26 16:02 41472 —-a-w- c:\windows\system32\drivers\tosporte.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2010-08-25 14:36 70264 —-a-w- c:\program files\Internet Download Manager\IDMShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Controlled StartUp"="c:\program files\StartUp Organizer\Ctrl.exe" [2009-03-02 193576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-12-21 443728]
"LXBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2004-09-10 69632]

c:\documents and settings\user\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 4 (0x4)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2006-03-10 20:20 434176 —-a-w- c:\windows\system32\IfxWlxEN.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0autocheck c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [3/11/2002 1:55 AM 9216]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [8/25/2010 8:40 AM 76768]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [11/29/2005 5:50 PM 36768]
R1 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [3/30/2009 2:09 AM 239336]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [6/6/2010 7:57 PM 6144]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [9/22/2009 8:22 AM 85128]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/22/2010 10:33 PM 363344]
R2 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [7/10/2008 12:22 AM 218136]
R2 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [7/10/2008 12:15 AM 31256]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [11/23/2010 5:13 PM 1483072]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [11/10/2009 5:04 PM 153448]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [10/19/2009 4:04 PM 111312]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [10/21/2010 1:08 PM 44368]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [8/29/2006 7:31 PM 36352]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/22/2010 10:33 PM 20952]
R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [7/19/2007 10:38 AM 27392]
R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [7/19/2007 10:38 AM 41728]
R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [7/19/2007 10:38 AM 39808]
R3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [7/19/2007 10:38 AM 5888]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [5/21/2010 12:29 PM 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [5/26/2010 11:26 AM 808448]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10/7/2010 12:34 PM 10064]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys –> c:\windows\system32\DRIVERS\AVGIDSEH.Sys [?]
S2 avgfws;AVG Firewall;"c:\program files\AVG\AVG10\avgfws.exe" –> c:\program files\AVG\AVG10\avgfws.exe [?]
S2 avgwd;AVG WatchDog;"c:\program files\AVG\AVG10\avgwdsvc.exe" –> c:\program files\AVG\AVG10\avgwdsvc.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [10/19/2009 4:06 PM 183880]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys –> c:\windows\system32\DRIVERS\avfwim.sys [?]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\DRIVERS\avgfwdx.sys –> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwdx.sys –> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [7/18/2010 9:58 PM 23456]
S3 icsak;icsak;\??\c:\program files\CheckPoint\ZAForceField\AK\icsak.sys –> c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [?]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\DRIVERS\pwi_bus.sys –> c:\windows\system32\DRIVERS\pwi_bus.sys [?]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\DRIVERS\pwi_mdfl.sys –> c:\windows\system32\DRIVERS\pwi_mdfl.sys [?]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\DRIVERS\pwi_mdm.sys –> c:\windows\system32\DRIVERS\pwi_mdm.sys [?]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\DRIVERS\pwi_oflt.sys –> c:\windows\system32\DRIVERS\pwi_oflt.sys [?]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\pwi_serd.sys –> c:\windows\system32\DRIVERS\pwi_serd.sys [?]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [8/19/2010 9:08 PM 27064]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [5/25/2010 7:33 PM 11520]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [3/31/2003 6:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 1:49 AM 47128]
S4 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [3/30/2009 1:16 AM 1113448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
bdx REG_MULTI_SZ scan

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-12-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-12-23 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-10-27 18:38]

2010-12-05 c:\windows\Tasks\Security Platform Backup Schedule.job
- c:\program files\Infineon\Security Platform Software\SpBackupWz.exe [2006-03-10 20:33]

2010-12-23 c:\windows\Tasks\User_Feed_Synchronization-{06B1BC02-2B9F-4237-AF0C-834FD0BDA026}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = about:blank
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {2643ABF9-63C0-479C-B0A1-DBCEAEB940B7} = 69.78.96.14 66.174.92.14
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-23 16:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBUCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6175B6E8-3D5E-8729-2540-D055604E5C59}*]
"kaggmdejllmffnhbnbhiod"=hex:61,61,00,00
"faggmdejamki"=hex:66,61,6a,68,68,67,6e,63,68,6a,65,6d,00,00

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9C6CF11F-216C-07F5-E86A-095ECC1154CA}*]
"oakejaihmocgedmecojhjmchapjlnm"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54
"naielbhcbbjkfininppakggoecap"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e0,a1,23,af,68,fc,2d,6a,cb,34,5f,bf,47,3b,62,7f,b7,d2,33,0e,96,
27,2e,b5,dc,b8,92,b1,c9,d5,77,69,f1,05,b4,49,db,0c,65,0e,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8f,d2,4d,a1,8f,eb,94,ad,30,43,d0,63,83,f2,01,57,f0,c1,28,fd,a3,
b1,76,9e,ce,65,77,04,5b,b1,78,29,37,3d,3d,76,92,d0,05,90,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(928)
c:\windows\system32\IfxWlxEN.dll

- - - - - - - > 'explorer.exe'(3012)
c:\windows\system32\WININET.dll
c:\program files\Internet Download Manager\IDMShellExt.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sony\SmartWi Connection Utility\SmartWiService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\verizon wireless\venturi\Client\ventc.exe
c:\windows\system32\wscntfy.exe
c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\program files\Intel\Wireless\bin\ZCfgSvc.exe
c:\program files\Intel\Wireless\Bin\ifrmewrk.exe
c:\program files\Apoint\Apoint.exe
c:\program files\IObit\Advanced SystemCare 3\AWC.exe
c:\program files\Apoint\Apntex.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2010-12-23 16:49:04 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-23 22:49
ComboFix2.txt 2010-12-22 04:55

Pre-Run: 59,601,330,176 bytes free
Post-Run: 59,639,472,128 bytes free

- - End Of File - - 3E995FC343FC3BBDC8E86C7ADF96F305

HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Keyboard Layout\Toggle\
Is this okay?

I'd leave that alone. It's not hurting anything that I know of.


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

File::
c:\program files\AVG\AVG10\avgfws.exe
c:\program files\AVG\AVG10\avgwdsvc.exe
c:\windows\system32\DRIVERS\avfwim.sys
c:\windows\system32\DRIVERS\avgfwdx.sys
c:\windows\system32\DRIVERS\avgfwdx.sys

Folder::
c:\program files\AVG

Driver::
avfwim
Avgfwdx
Avgfwfd

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste

Also please describe how your computer behaves at the moment.


Finally, I want to purchase a GOOD and SOLID Internet Security Suite

I think if you just purchase MalwareBytes (MBAM) anti-malware
along with a updated anti-virus, that would be good.
LDTate-

Thank you for the reply and direction. As always it is appreciated! Followed your instructions above to remove the AVG Antivirus 2011 but unfortunately I do not think it did the trick. When I boot up my laptop and after the “Windows is starting up” but before it gets to the windows logon screen the following Windows XP screen will flash  avgchsvx.exe and avgrsx.exe not found  Autocheck is skipping. Windows will then boot to the logon screen. It gives me somewhat of a path for the above 2 execs but the screen flashes so quickly I cannot record.

Not sure where to go from here and any further direction would be GREATLY appreciated.

With the IS suite that I am looking to purchase I am in need of something that my parents can use with minimal user interface. Something that the antivirus will update itself and I can set to scan automatically etc . I was thinking of something like Bitdefender, Kaspersky, or Webroot. Is it possible to get your opinion on your thoughts on the best one of these?

Please find my log below and Thanks AGAIN!

ComboFix 10-12-21.01 - User 12/26/2010 10:21:02.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1460 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Virus Stuff\ComboFix.exe
Command switches used :: c:\documents and settings\User.MARCIA-6X7H850P\Desktop\CFScript.txt
AV: AVG Anti-Virus 2011 *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *Enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

FILE ::
"c:\program files\AVG\AVG10\avgfws.exe"
"c:\program files\AVG\AVG10\avgwdsvc.exe"
"c:\windows\system32\DRIVERS\avfwim.sys"
"c:\windows\system32\DRIVERS\avgfwdx.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_avfwim


((((((((((((((((((((((((( Files Created from 2010-11-26 to 2010-12-26 )))))))))))))))))))))))))))))))
.

2010-12-25 21:24 . 2010-12-25 21:24 ——– d—–w- c:\windows\system32\FxsTmp
2010-12-25 21:22 . 2010-12-25 21:22 ——– d—–w- c:\windows\addins
2010-12-25 21:22 . 2003-03-31 12:00 31744 -c–a-w- c:\windows\system32\dllcache\fxsroute.dll
2010-12-25 21:22 . 2003-03-31 12:00 31744 —-a-w- c:\windows\system32\fxsroute.dll
2010-12-25 21:22 . 2003-03-31 12:00 132608 -c–a-w- c:\windows\system32\dllcache\fxsclntr.dll
2010-12-25 21:22 . 2003-03-31 12:00 132608 —-a-w- c:\windows\system32\fxsclntR.dll
2010-12-25 21:22 . 2003-03-31 12:00 11264 -c–a-w- c:\windows\system32\dllcache\fxssend.exe
2010-12-25 21:22 . 2003-03-31 12:00 11264 —-a-w- c:\windows\system32\fxssend.exe
2010-12-25 21:22 . 2003-03-31 12:00 111104 -c–a-w- c:\windows\system32\dllcache\fxscfgwz.dll
2010-12-25 21:22 . 2003-03-31 12:00 111104 —-a-w- c:\windows\system32\fxscfgwz.dll
2010-12-23 16:06 . 2010-12-23 16:06 ——– d—–w- c:\windows\system32\wbem\Repository
2010-12-23 07:25 . 2010-12-23 07:25 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-12-23 07:25 . 2010-12-23 07:25 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-12-23 07:20 . 2010-12-23 21:57 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2010-12-23 07:16 . 2010-12-23 07:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2010-12-23 04:33 . 2010-12-21 00:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 04:33 . 2010-12-23 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-12-23 04:33 . 2010-12-21 00:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 00:12 . 2010-12-23 00:19 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2010-12-23 00:12 . 2010-12-23 00:14 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\BitDefender
2010-12-23 00:12 . 2010-12-23 00:12 ——– d—–w- c:\program files\BitDefender
2010-12-23 00:00 . 2010-12-23 00:13 ——– d—–w- c:\program files\Common Files\BitDefender
2010-12-22 23:56 . 2010-12-22 23:59 37099 —-a-w- C:\BdUninstallTool2010.12.22-05.56.18.reg
2010-12-22 21:23 . 2010-12-22 21:23 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\QuickScan
2010-12-22 21:21 . 2010-12-22 22:42 520994 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\bdinstall.bin
2010-12-22 03:40 . 2008-04-14 10:42 146432 -c–a-w- c:\windows\system32\dllcache\regedit.exe
2010-12-22 03:40 . 2008-04-14 10:42 146432 ——w- c:\windows\regedit.exe
2010-12-19 03:00 . 2010-12-19 03:00 ——– d—–w- c:\program files\Free ISO Creator
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Windows Script Control
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Common Files\e.World
2010-12-14 00:00 . 2010-12-14 00:00 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\MetaProducts
2010-12-14 00:00 . 2009-03-02 19:55 73728 —-a-w- c:\windows\system32\SUO.cpl
2010-12-13 23:59 . 2010-12-14 00:00 ——– d—–w- c:\program files\StartUp Organizer
2010-12-13 22:34 . 2010-12-13 22:35 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\GetRightToGo
2010-12-08 05:11 . 2010-12-25 21:25 ——– d—–w- c:\program files\Business Objects
2010-12-05 02:41 . 2010-11-23 23:16 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2010-12-05 02:41 . 2010-11-23 23:11 29504 —-a-w- c:\windows\system32\uxtuneup.dll
2010-12-05 02:40 . 2010-12-05 02:41 ——– d—–w- c:\program files\TuneUp Utilities 2011
2010-12-05 01:09 . 2003-06-25 22:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2010-11-29 03:59 . 2010-12-18 23:53 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\Smart PC Solutions
2010-11-28 05:55 . 2010-11-28 05:55 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\iNViSiBLE
2010-11-28 05:49 . 2010-11-28 05:52 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\.moneydance
2010-11-28 05:48 . 2010-11-28 05:48 ——– d—–w- c:\program files\Moneydance
2010-11-28 05:48 . 2010-11-28 05:48 ——– d—–w- c:\program files\Common Files\i4j_jres
2010-11-27 22:36 . 2010-11-28 03:50 ——– d—–w- c:\program files\SUPERAntiSpyware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-23 03:04 . 2009-11-10 23:03 106464 —-a-w- c:\windows\system32\drivers\bdhv.sys
2010-12-23 03:04 . 2009-11-10 23:04 153448 —-a-w- c:\windows\system32\drivers\bdfm.sys
2010-12-23 03:04 . 2009-07-24 17:26 291352 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2010-12-23 02:59 . 2009-10-19 22:04 111312 —-a-w- c:\windows\system32\drivers\bdfndisf.sys
2010-12-08 05:19 . 2010-06-16 02:19 1748416 -c–a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2010-11-18 18:12 . 2010-05-21 23:35 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-12 02:14 . 2010-06-06 22:07 18368 -c–a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-11-06 00:26 . 2003-03-31 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2003-03-31 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2003-03-31 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2010-05-25 16:35 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2003-03-31 12:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2003-03-31 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2003-03-31 12:00 1853312 —-a-w- c:\windows\system32\win32k.sys
2010-10-11 02:32 . 2010-10-11 02:32 73728 -c–a-w- c:\windows\system32\javacpl.cpl
2010-10-11 02:32 . 2010-10-11 02:32 423656 -c–a-w- c:\windows\system32\deployJava1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2010-08-25 14:36 70264 —-a-w- c:\program files\Internet Download Manager\IDMShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Controlled StartUp"="c:\program files\StartUp Organizer\Ctrl.exe" [2009-03-02 193576]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
"LXBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2004-09-10 69632]

c:\documents and settings\user\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 4 (0x4)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2006-03-10 20:20 434176 —-a-w- c:\windows\system32\IfxWlxEN.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0autocheck c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [3/11/2002 1:55 AM 9216]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [8/25/2010 8:40 AM 76768]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [11/29/2005 5:50 PM 36768]
R1 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [3/30/2009 2:09 AM 239336]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [6/6/2010 7:57 PM 6144]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [9/22/2009 8:22 AM 85128]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/22/2010 10:33 PM 363344]
R2 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [7/10/2008 12:22 AM 218136]
R2 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [7/10/2008 12:15 AM 31256]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [11/23/2010 5:13 PM 1483072]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [11/10/2009 5:04 PM 153448]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [10/19/2009 4:04 PM 111312]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [10/21/2010 1:08 PM 44368]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [8/29/2006 7:31 PM 36352]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/22/2010 10:33 PM 20952]
R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [7/19/2007 10:38 AM 27392]
R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [7/19/2007 10:38 AM 41728]
R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [7/19/2007 10:38 AM 39808]
R3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [7/19/2007 10:38 AM 5888]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [5/21/2010 12:29 PM 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [5/26/2010 11:26 AM 808448]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10/7/2010 12:34 PM 10064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [10/19/2009 4:06 PM 183880]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [7/18/2010 9:58 PM 23456]
S3 icsak;icsak;\??\c:\program files\CheckPoint\ZAForceField\AK\icsak.sys –> c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [?]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\DRIVERS\pwi_bus.sys –> c:\windows\system32\DRIVERS\pwi_bus.sys [?]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\DRIVERS\pwi_mdfl.sys –> c:\windows\system32\DRIVERS\pwi_mdfl.sys [?]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\DRIVERS\pwi_mdm.sys –> c:\windows\system32\DRIVERS\pwi_mdm.sys [?]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\DRIVERS\pwi_oflt.sys –> c:\windows\system32\DRIVERS\pwi_oflt.sys [?]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\pwi_serd.sys –> c:\windows\system32\DRIVERS\pwi_serd.sys [?]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [8/19/2010 9:08 PM 27064]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [5/25/2010 7:33 PM 11520]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [3/31/2003 6:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 1:49 AM 47128]
S4 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [3/30/2009 1:16 AM 1113448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
bdx REG_MULTI_SZ scan

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-12-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-12-05 c:\windows\Tasks\Security Platform Backup Schedule.job
- c:\program files\Infineon\Security Platform Software\SpBackupWz.exe [2006-03-10 20:33]

2010-12-26 c:\windows\Tasks\User_Feed_Synchronization-{06B1BC02-2B9F-4237-AF0C-834FD0BDA026}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = about:blank
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {2643ABF9-63C0-479C-B0A1-DBCEAEB940B7} = 69.78.96.14 66.174.92.14
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-26 10:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBUCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6175B6E8-3D5E-8729-2540-D055604E5C59}*]
"kaggmdejllmffnhbnbhiod"=hex:61,61,00,00
"faggmdejamki"=hex:66,61,6a,68,68,67,6e,63,68,6a,65,6d,00,00

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9C6CF11F-216C-07F5-E86A-095ECC1154CA}*]
"oakejaihmocgedmecojhjmchapjlnm"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54
"naielbhcbbjkfininppakggoecap"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e0,a1,23,af,68,fc,2d,6a,cb,34,5f,bf,47,3b,62,7f,b7,d2,33,0e,96,
27,2e,b5,dc,b8,92,b1,c9,d5,77,69,f1,05,b4,49,db,0c,65,0e,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8f,d2,4d,a1,8f,eb,94,ad,30,43,d0,63,83,f2,01,57,f0,c1,28,fd,a3,
b1,76,9e,ce,65,77,04,5b,b1,78,29,37,3d,3d,76,92,d0,05,90,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(624)
c:\windows\system32\IfxWlxEN.dll

- - - - - - - > 'explorer.exe'(3436)
c:\windows\system32\WININET.dll
c:\program files\Internet Download Manager\IDMShellExt.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sony\SmartWi Connection Utility\SmartWiService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\verizon wireless\venturi\Client\ventc.exe
c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Intel\Wireless\bin\ZCfgSvc.exe
c:\program files\Intel\Wireless\Bin\ifrmewrk.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Apoint\Apoint.exe
c:\program files\IObit\Advanced SystemCare 3\AWC.exe
c:\program files\Apoint\Apntex.exe
.
**************************************************************************
.
Completion time: 2010-12-26 10:38:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-26 16:38
ComboFix2.txt 2010-12-23 22:49
ComboFix3.txt 2010-12-22 04:55

Pre-Run: 71,521,603,584 bytes free
Post-Run: 71,340,187,648 bytes free

- - End Of File - - 3B936FFF38A766600A07FB4045E57933
LDTate- A quick update on the AVG AV 2011 problem that I am still having after a number of restart I was able to get the path for the following exe files: avgchsvx.exe avgrsx.exe. That path is : C:\Progra~1\AVG\AVG10\(filename) Not sure if it helps but thought I would advise. THANK YOU!
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::


Folder::
c:\program files\AVG\AVG10

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
LDTate-

Thanks once again for the reply. I carried out the instructions above but it still looks like AVG AV 2011 is still there :pullhair: as I still get the Autocheck skip on startup! I really appreciate your work on this and I would be grateful for any further assistance you could provide me at this point.

My log is below:

ComboFix 10-12-26.01 - User 12/27/2010 11:32:53.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1450 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\User.MARCIA-6X7H850P\Desktop\CFScript.txt
AV: AVG Anti-Virus 2011 *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *Disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.

((((((((((((((((((((((((( Files Created from 2010-11-27 to 2010-12-27 )))))))))))))))))))))))))))))))
.

2010-12-26 21:12 . 2010-12-26 21:12 ——– d—–w- c:\documents and settings\Administrator.MARCIA-6X7H850P\Application Data\BitDefender
2010-12-26 21:00 . 2010-12-26 21:00 ——– d—–w- c:\documents and settings\Guest\Application Data\TuneUp Software
2010-12-26 20:57 . 2010-12-26 20:57 ——– d—–w- c:\documents and settings\Guest\Application Data\BitDefender
2010-12-26 20:50 . 2010-12-26 20:50 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\VS Revo Group
2010-12-25 21:24 . 2010-12-25 21:24 ——– d—–w- c:\windows\system32\FxsTmp
2010-12-25 21:22 . 2010-12-25 21:22 ——– d—–w- c:\windows\addins
2010-12-25 21:22 . 2003-03-31 12:00 31744 -c–a-w- c:\windows\system32\dllcache\fxsroute.dll
2010-12-25 21:22 . 2003-03-31 12:00 31744 —-a-w- c:\windows\system32\fxsroute.dll
2010-12-25 21:22 . 2003-03-31 12:00 132608 -c–a-w- c:\windows\system32\dllcache\fxsclntr.dll
2010-12-25 21:22 . 2003-03-31 12:00 132608 —-a-w- c:\windows\system32\fxsclntR.dll
2010-12-25 21:22 . 2003-03-31 12:00 11264 -c–a-w- c:\windows\system32\dllcache\fxssend.exe
2010-12-25 21:22 . 2003-03-31 12:00 11264 —-a-w- c:\windows\system32\fxssend.exe
2010-12-25 21:22 . 2003-03-31 12:00 111104 -c–a-w- c:\windows\system32\dllcache\fxscfgwz.dll
2010-12-25 21:22 . 2003-03-31 12:00 111104 —-a-w- c:\windows\system32\fxscfgwz.dll
2010-12-23 16:06 . 2010-12-23 16:06 ——– d—–w- c:\windows\system32\wbem\Repository
2010-12-23 07:25 . 2010-12-23 07:25 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-12-23 07:25 . 2010-12-23 07:25 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-12-23 07:20 . 2010-12-23 21:57 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2010-12-23 07:16 . 2010-12-23 07:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2010-12-23 04:33 . 2010-12-21 00:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 04:33 . 2010-12-23 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-12-23 04:33 . 2010-12-21 00:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 00:12 . 2010-12-23 00:19 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2010-12-23 00:12 . 2010-12-23 00:14 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\BitDefender
2010-12-23 00:12 . 2010-12-23 00:12 ——– d—–w- c:\program files\BitDefender
2010-12-23 00:00 . 2010-12-23 00:13 ——– d—–w- c:\program files\Common Files\BitDefender
2010-12-22 23:56 . 2010-12-22 23:59 37099 —-a-w- C:\BdUninstallTool2010.12.22-05.56.18.reg
2010-12-22 21:23 . 2010-12-22 21:23 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\QuickScan
2010-12-22 21:21 . 2010-12-22 22:42 520994 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\bdinstall.bin
2010-12-22 03:40 . 2008-04-14 10:42 146432 -c–a-w- c:\windows\system32\dllcache\regedit.exe
2010-12-22 03:40 . 2008-04-14 10:42 146432 ——w- c:\windows\regedit.exe
2010-12-19 03:00 . 2010-12-19 03:00 ——– d—–w- c:\program files\Free ISO Creator
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Windows Script Control
2010-12-14 22:53 . 2010-12-14 22:53 ——– d—–w- c:\program files\Common Files\e.World
2010-12-14 00:00 . 2010-12-14 00:00 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\MetaProducts
2010-12-14 00:00 . 2009-03-02 19:55 73728 —-a-w- c:\windows\system32\SUO.cpl
2010-12-13 23:59 . 2010-12-14 00:00 ——– d—–w- c:\program files\StartUp Organizer
2010-12-13 22:34 . 2010-12-13 22:35 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\GetRightToGo
2010-12-08 05:11 . 2010-12-25 21:25 ——– d—–w- c:\program files\Business Objects
2010-12-05 02:41 . 2010-11-23 23:16 31552 —-a-w- c:\windows\system32\TURegOpt.exe
2010-12-05 02:41 . 2010-11-23 23:11 29504 —-a-w- c:\windows\system32\uxtuneup.dll
2010-12-05 02:40 . 2010-12-05 02:41 ——– d—–w- c:\program files\TuneUp Utilities 2011
2010-12-05 01:09 . 2003-06-25 22:05 266360 —-a-w- c:\windows\system32\TweakUI.exe
2010-11-29 03:59 . 2010-12-18 23:53 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\Smart PC Solutions
2010-11-28 05:55 . 2010-11-28 05:55 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\Application Data\iNViSiBLE
2010-11-28 05:49 . 2010-11-28 05:52 ——– d—–w- c:\documents and settings\User.MARCIA-6X7H850P\.moneydance
2010-11-28 05:48 . 2010-11-28 05:48 ——– d—–w- c:\program files\Moneydance
2010-11-28 05:48 . 2010-11-28 05:48 ——– d—–w- c:\program files\Common Files\i4j_jres
2010-11-27 22:36 . 2010-11-28 03:50 ——– d—–w- c:\program files\SUPERAntiSpyware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-23 03:04 . 2009-11-10 23:03 106464 —-a-w- c:\windows\system32\drivers\bdhv.sys
2010-12-23 03:04 . 2009-11-10 23:04 153448 —-a-w- c:\windows\system32\drivers\bdfm.sys
2010-12-23 03:04 . 2009-07-24 17:26 291352 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2010-12-23 02:59 . 2009-10-19 22:04 111312 —-a-w- c:\windows\system32\drivers\bdfndisf.sys
2010-12-08 05:19 . 2010-06-16 02:19 1748416 -c–a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2010-11-18 18:12 . 2010-05-21 23:35 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-12 02:14 . 2010-06-06 22:07 18368 -c–a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2010-11-06 00:26 . 2003-03-31 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2003-03-31 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2003-03-31 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2010-05-25 16:35 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2003-03-31 12:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2003-03-31 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2003-03-31 12:00 1853312 —-a-w- c:\windows\system32\win32k.sys
2010-10-11 02:32 . 2010-10-11 02:32 73728 -c–a-w- c:\windows\system32\javacpl.cpl
2010-10-11 02:32 . 2010-10-11 02:32 423656 -c–a-w- c:\windows\system32\deployJava1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2010-08-25 14:36 70264 —-a-w- c:\program files\Internet Download Manager\IDMShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Controlled StartUp"="c:\program files\StartUp Organizer\Ctrl.exe" [2009-03-02 193576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]

c:\documents and settings\user\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 4 (0x4)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2006-03-10 20:20 434176 —-a-w- c:\windows\system32\IfxWlxEN.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0autocheck c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [3/11/2002 1:55 AM 9216]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [8/25/2010 8:40 AM 76768]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [11/29/2005 5:50 PM 36768]
R1 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [3/30/2009 2:09 AM 239336]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R1 UsbFltr;WayTechUSBFilterDriver;c:\windows\system32\drivers\UsbFltr.sys [6/6/2010 7:57 PM 6144]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [9/22/2009 8:22 AM 85128]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/22/2010 10:33 PM 363344]
R2 MsDtsServer100;SQL Server Integration Services 10.0;c:\program files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe [7/10/2008 12:22 AM 218136]
R2 MSSQLFDLauncher;SQL Full-text Filter Daemon Launcher (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [7/10/2008 12:15 AM 31256]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [11/23/2010 5:13 PM 1483072]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [11/10/2009 5:04 PM 153448]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [10/19/2009 4:04 PM 111312]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [10/21/2010 1:08 PM 44368]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [8/29/2006 7:31 PM 36352]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/22/2010 10:33 PM 20952]
R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\drivers\PTDWBus.sys [7/19/2007 10:38 AM 27392]
R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\drivers\PTDWMdm.sys [7/19/2007 10:38 AM 41728]
R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\drivers\PTDWVsp.sys [7/19/2007 10:38 AM 39808]
R3 PWCTLDRV;The NECHostController Filter Driver;c:\windows\system32\drivers\PWCTLDRV.sys [7/19/2007 10:38 AM 5888]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [5/21/2010 12:29 PM 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [5/26/2010 11:26 AM 808448]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [10/7/2010 12:34 PM 10064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [10/19/2009 4:06 PM 183880]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [7/18/2010 9:58 PM 23456]
S3 icsak;icsak;\??\c:\program files\CheckPoint\ZAForceField\AK\icsak.sys –> c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [?]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\DRIVERS\pwi_bus.sys –> c:\windows\system32\DRIVERS\pwi_bus.sys [?]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\DRIVERS\pwi_mdfl.sys –> c:\windows\system32\DRIVERS\pwi_mdfl.sys [?]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\DRIVERS\pwi_mdm.sys –> c:\windows\system32\DRIVERS\pwi_mdm.sys [?]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\DRIVERS\pwi_oflt.sys –> c:\windows\system32\DRIVERS\pwi_oflt.sys [?]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\pwi_serd.sys –> c:\windows\system32\DRIVERS\pwi_serd.sys [?]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [8/19/2010 9:08 PM 27064]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [5/25/2010 7:33 PM 11520]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [3/31/2003 6:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 1:49 AM 47128]
S4 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSRS10.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [3/30/2009 1:16 AM 1113448]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
bdx REG_MULTI_SZ scan

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-12-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-12-05 c:\windows\Tasks\Security Platform Backup Schedule.job
- c:\program files\Infineon\Security Platform Software\SpBackupWz.exe [2006-03-10 20:33]

2010-12-27 c:\windows\Tasks\User_Feed_Synchronization-{06B1BC02-2B9F-4237-AF0C-834FD0BDA026}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = about:blank
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {2643ABF9-63C0-479C-B0A1-DBCEAEB940B7} = 69.78.96.14 66.174.92.14
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-27 11:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6175B6E8-3D5E-8729-2540-D055604E5C59}*]
"kaggmdejllmffnhbnbhiod"=hex:61,61,00,00
"faggmdejamki"=hex:66,61,6a,68,68,67,6e,63,68,6a,65,6d,00,00

[HKEY_USERS\S-1-5-21-1060284298-839522115-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9C6CF11F-216C-07F5-E86A-095ECC1154CA}*]
"oakejaihmocgedmecojhjmchapjlnm"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54
"naielbhcbbjkfininppakggoecap"=hex:6a,61,6f,68,62,68,67,6d,64,6f,6a,64,6f,6f,
65,68,6b,67,69,6b,00,54

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e0,a1,23,af,68,fc,2d,6a,cb,34,5f,bf,47,3b,62,7f,b7,d2,33,0e,96,
27,2e,b5,dc,b8,92,b1,c9,d5,77,69,f1,05,b4,49,db,0c,65,0e,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):8f,d2,4d,a1,8f,eb,94,ad,30,43,d0,63,83,f2,01,57,f0,c1,28,fd,a3,
b1,76,9e,ce,65,77,04,5b,b1,78,29,37,3d,3d,76,92,d0,05,90,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1932)
c:\windows\system32\IfxWlxEN.dll

- - - - - - - > 'explorer.exe'(1356)
c:\windows\system32\WININET.dll
c:\program files\Internet Download Manager\IDMShellExt.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sony\SmartWi Connection Utility\SmartWiService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\verizon wireless\venturi\Client\ventc.exe
c:\program files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Intel\Wireless\bin\ZCfgSvc.exe
c:\program files\Intel\Wireless\Bin\ifrmewrk.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Apoint\Apoint.exe
c:\program files\IObit\Advanced SystemCare 3\AWC.exe
c:\program files\Apoint\Apntex.exe
.
**************************************************************************
.
Completion time: 2010-12-27 11:49:18 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-27 17:49
ComboFix2.txt 2010-12-27 17:03
ComboFix3.txt 2010-12-26 16:38
ComboFix4.txt 2010-12-23 22:49
ComboFix5.txt 2010-12-27 17:31

Pre-Run: 71,219,298,304 bytes free
Post-Run: 71,228,796,928 bytes free

- - End Of File - - 4A95193BC11E231FD52E5120E7386630

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI