This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] I have vista and as soon as i open a window....it clos

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a new computer and I am having problems out of it. i do alot of downloading and I know this is where my problem has come from. If I try to open any program from the start menu it doesn't open. Opening a folder from the start menu will result in it opening and closing immediately. And then my task bar disappears completely. Any help will be greatly appreciated. Here is my log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:59:51 PM, on 2/25/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\lxbkjswx.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…/www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CDNSCacheObj Object - {376892AE-1825-4E5F-9F85-23F9640051CC} - C:\Windows\xmljacodec.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T\AT&T Internet Security Suite\pkR.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\Avanquest\SystemSuite\LinkScannerIE.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [Setresolution] C:\ACERSW\config\1440x900.cmd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [AT&T Internet Security Suite] "C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [303ebcd9] rundll32.exe "C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [lxbkbmgr.exe] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\mom\AppData\Local\Temp\hgday.dll,#1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: AdwareAlert Scanning Engine (AdwareAlertSrv) - Unknown owner - C:\Program Files\AdwareAlert\AdwareAlert.srv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: AT&T Internet Security Suite Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
O23 - Service: AT&T Internet Security Suite AT&T Firewall (RP_FWS) - AT&T - C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
O23 - Service: SystemSuite Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe

–
End of file - 10912 bytes
Hello and Welcome to the forum.

I suggest you do this:

Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish
Ok I have run the ComboFix and re-run HijackThis Here are the logs.


ComboFix log

ComboFix 08-02-25.3 - mom 2008-02-26 17:41:00.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.211 [GMT -8:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Users\mom\AppData\Roaming\inst.exe
C:\Windows\system32\uninstall.exe

.
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.

2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Users\mom\AppData\Roaming\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Program Files\SUPERAntiSpyware
2008-02-26 03:11 . 2008-02-26 03:11 d——– C:\Users\mom\AppData\Roaming\PC Tools
2008-02-26 03:11 . 2008-02-26 03:34 d——– C:\Program Files\Spyware Doctor
2008-02-26 03:11 . 2007-12-10 14:53 81,288 –a—— C:\Windows\System32\drivers\iksyssec.sys
2008-02-26 03:11 . 2007-12-10 14:53 66,952 –a—— C:\Windows\System32\drivers\iksysflt.sys
2008-02-26 03:11 . 2008-02-01 12:55 42,376 –a—— C:\Windows\System32\drivers\ikfilesec.sys
2008-02-26 03:11 . 2007-12-10 14:53 29,576 –a—— C:\Windows\System32\drivers\kcom.sys
2008-02-25 17:22 . 2008-02-25 17:26 d——– C:\Program Files\SpywareBlaster
2008-02-25 17:18 . 2008-02-25 17:18 d——– C:\ie-spyad
2008-02-25 16:27 . 2008-02-26 13:03 d——– C:\temp
2008-02-25 16:16 . 2008-02-25 16:16 d——– C:\Users\mom\AppData\Roaming\Grisoft
2008-02-25 16:16 . 2007-05-30 04:10 10,872 –a—— C:\Windows\System32\drivers\AvgAsCln.sys
2008-02-25 16:15 . 2008-02-26 17:16 246 –a—— C:\Windows\Lexstat.ini
2008-02-25 16:13 . 2008-02-25 16:18 d——– C:\Program Files\Lexmark X1100 Series
2008-02-25 16:12 . 2008-02-25 16:12 d——– C:\drivers
2008-02-25 16:11 . 2008-02-25 16:12 36,487,088 –a—— C:\Users\mom\cjrX1100EN.exe
2008-02-25 12:08 . 2008-02-25 12:08 d——– C:\f24a1aca0b9794bd2211db
2008-02-25 12:08 . 2008-02-25 12:08 0 –ah—t- C:\Windows\wusa.lock
2008-02-25 11:50 . 2007-07-26 17:07 621,056 –a—— C:\Windows\System32\drivers\dxgkrnl.sys
2008-02-25 11:50 . 2007-07-26 18:17 36,864 –a—— C:\Windows\System32\cdd.dll
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Users\All Users\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\ProgramData\HP
2008-02-25 05:42 . 2008-02-25 05:43 d——– C:\Program Files\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Program Files\Common Files\HP
2008-02-25 05:42 . 2008-02-25 05:43 102,364 –a—— C:\Windows\hpqins13.dat
2008-02-25 05:06 . 2008-02-25 05:08 125 –a—— C:\ioSpecial.ini
2008-02-24 15:11 . 2008-02-25 04:54 d——– C:\Program Files\BuildALot_at
2008-02-24 08:52 . 2008-02-24 08:52 d——– C:\Program Files\ReflexiveArcade
2008-02-24 08:09 . 2008-02-24 08:09 d——– C:\Program Files\Agatha Christie - Peril at End House
2008-02-24 05:07 . 2008-02-24 05:07 d——– C:\Program Files\Mystery Case Files - Prime Suspects
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\mom\AppData\Roaming\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\All Users\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\ProgramData\Oberon Games
2008-02-22 22:09 . 2008-02-22 22:09 d——– C:\Users\mom\AppData\Roaming\Magic Seeds
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\Users\All Users\HipSoft
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\ProgramData\HipSoft
2008-02-22 10:07 . 2008-02-22 10:07 d——– C:\Program Files\bfgclient
2008-02-22 10:07 . 2008-02-22 10:21 d——– C:\BigFishGamesCache
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\Users\All Users\BVRP Software
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\ProgramData\BVRP Software
2008-02-20 22:04 . 2008-02-20 22:04 dr-hs—- C:\_Backup.RC
2008-02-20 22:04 . 2008-02-20 23:43 d–h—– C:\_Backup
2008-02-20 22:00 . 2008-02-24 15:23 d——– C:\Users\mom\AppData\Roaming\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\Users\All Users\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\ProgramData\Avanquest
2008-02-20 21:59 . 2008-02-20 21:59 d——– C:\Program Files\Avanquest
2008-02-20 21:55 . 2008-02-26 17:27 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:18 . 2007-03-06 18:51 543,232 –a—— C:\Windows\System32\FWPUCLNT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 416,768 –a—— C:\Windows\System32\IKEEXT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 317,440 –a—— C:\Windows\System32\BFE.DLL
2008-02-19 21:18 . 2007-03-06 18:08 84,992 –a—— C:\Windows\System32\drivers\FWPKCLNT.SYS
2008-02-19 21:17 . 2008-02-19 21:17 d——– C:\Users\mom\AppData\Roaming\Sammsoft
2008-02-19 21:16 . 2008-02-19 22:25 d——– C:\Program Files\Advanced Registry Optimizer
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\Users\All Users\Grisoft
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\ProgramData\Grisoft
2008-02-19 21:06 . 2008-02-19 21:06 1,420 –a—— C:\Windows\wininit.ini
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\ProgramData\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 21:12 d——– C:\Program Files\Trend Micro
2008-02-19 20:25 . 2008-02-19 22:35 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-19 20:12 . 2008-02-19 20:12 d——– C:\kav
2008-02-19 19:37 . 2008-02-19 19:37 3,764 –a—— C:\Windows\System32\tmp.reg
2008-02-19 19:36 . 2008-02-19 19:41 d——– C:\Windows\System32\SmitfraudFix
2008-02-19 05:33 . 2008-02-19 05:37 d——– C:\Users\mom\.housecall6.6
2008-02-18 23:00 . 2008-02-25 04:53 d——– C:\Program Files\AdwareAlert
2008-02-18 22:51 . 2008-02-18 22:51 d——– C:\Program Files\Enigma Software Group
2008-02-17 11:52 . 2008-02-17 11:52 d——– C:\Users\mom\AppData\Roaming\PCF-VLC
2008-02-16 21:34 . 2008-02-26 17:18 dr——- C:\Windows\System32\config\systemprofile\Documents
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Users\All Users\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\ProgramData\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Common Files\Authentium
2008-02-16 21:23 . 2007-04-04 17:15 839,880 –a—— C:\Windows\System32\drivers\css-dvp.sys
2008-02-16 21:23 . 2007-03-06 13:24 55,296 –a—— C:\Windows\System32\drivers\rp_skt32.sys
2008-02-16 21:23 . 2007-04-05 14:52 48,384 –a—— C:\Windows\System32\drivers\rp_pkt32.sys
2008-02-16 21:22 . 2008-02-19 23:02 d——– C:\Program Files\Common Files\Scanner
2008-02-16 21:22 . 2008-02-16 21:22 d——– C:\Program Files\CA
2008-02-16 21:20 . 2008-02-16 21:20 d——– C:\Users\mom\AppData\Roaming\InstallShield
2008-02-15 21:09 . 2008-01-09 21:50 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-02-15 18:38 . 2008-02-15 18:38 d——– C:\Users\mom\AppData\Roaming\Template
2008-02-15 18:37 . 2008-02-22 21:53 90 –a—— C:\Users\mom\AppData\Roaming\wklnhst.dat
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\Users\All Users\Macrovision
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\ProgramData\Macrovision
2008-02-15 16:58 . 2008-02-15 16:58 d——– C:\Program Files\Common Files\Macromedia Shared
2008-02-15 16:55 . 2008-02-15 16:55 d——– C:\Program Files\Common Files\Macromedia
2008-02-15 16:53 . 2008-02-15 16:53 d——– C:\Program Files\Macromedia
2008-02-14 06:02 . 2008-02-14 06:02 d——– C:\Users\mom\AppData\Roaming\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\Users\All Users\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\ProgramData\Participatory Culture Foundation
2008-02-14 06:00 . 2008-02-14 06:00 d——– C:\My Documents
2008-02-13 18:05 . 2008-02-13 18:05 194,560 –a—— C:\Windows\System32\WebClnt.dll
2008-02-13 18:05 . 2008-02-13 18:05 110,080 –a—— C:\Windows\System32\drivers\mrxdav.sys
2008-02-13 18:01 . 2008-02-13 18:01 3,505,720 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-02-13 18:01 . 2008-02-13 18:01 3,471,928 –a—— C:\Windows\System32\ntoskrnl.exe
2008-02-13 18:01 . 2008-02-13 18:01 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-02-13 18:01 . 2008-02-13 18:01 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-02-13 18:01 . 2008-02-13 18:01 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 13:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-13 20:00 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 20:00 449,536 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 20:00 2,144,256 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 20:00 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 19:57 824,832 —-a-w C:\Windows\System32\wininet.dll
2008-02-13 19:57 56,320 —-a-w C:\Windows\System32\iesetup.dll
2008-02-13 19:57 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-13 19:57 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2008-02-02 17:15 ——— d—–w C:\Users\mom\AppData\Roaming\.wyzo
2008-02-02 16:04 ——— d—–w C:\Users\mom\AppData\Roaming\.BitTornado
2008-02-02 15:44 ——— d—–w C:\Program Files\eSobi
2008-02-01 23:04 ——— d—–w C:\Program Files\Microsoft Games
2008-02-01 11:31 174 –sha-w C:\Program Files\desktop.ini
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Mail
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Calendar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Sidebar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Defender
2008-02-01 11:17 704,000 —-a-w C:\Windows\System32\PhotoScreensaver.scr
2008-02-01 11:17 67,584 —-a-w C:\Windows\System32\wlanhlp.dll
2008-02-01 11:17 542,720 —-a-w C:\Windows\System32\sysmain.dll
2008-02-01 11:17 502,784 —-a-w C:\Windows\System32\wlansvc.dll
2008-02-01 11:17 47,104 —-a-w C:\Windows\System32\wlanapi.dll
2008-02-01 11:17 297,984 —-a-w C:\Windows\System32\wlansec.dll
2008-02-01 11:17 290,816 —-a-w C:\Windows\System32\wlanmsm.dll
2008-02-01 11:17 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2008-02-01 11:17 24,064 —-a-w C:\Windows\System32\wtsapi32.dll
2008-02-01 11:17 2,923,520 —-a-w C:\Windows\explorer.exe
2008-02-01 11:17 2,027,008 —-a-w C:\Windows\System32\win32k.sys
2008-02-01 11:07 9,728 —-a-w C:\Windows\System32\LAPRXY.DLL
2008-02-01 11:07 57,856 —-a-w C:\Windows\System32\SLUINotify.dll
2008-02-01 11:07 566,784 —-a-w C:\Windows\System32\SLCommDlg.dll
2008-02-01 11:07 39,936 —-a-w C:\Windows\System32\slcinst.dll
2008-02-01 11:07 351,232 —-a-w C:\Windows\System32\SLUI.exe
2008-02-01 11:07 33,280 —-a-w C:\Windows\System32\slwmi.dll
2008-02-01 11:07 268,288 —-a-w C:\Windows\System32\mcbuilder.exe
2008-02-01 11:07 223,232 —-a-w C:\Windows\System32\WMASF.DLL
2008-02-01 11:07 223,232 —-a-w C:\Windows\System32\SLC.dll
2008-02-01 11:07 2,605,568 —-a-w C:\Windows\System32\SLsvc.exe
2008-02-01 11:07 186,368 —-a-w C:\Windows\System32\SLLUA.exe
2008-02-01 08:25 ——— d—–w C:\ProgramData\eSobi
2008-02-01 07:40 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-01 07:39 ——— d—–w C:\ProgramData\Symantec
2008-01-16 13:09 24,626 —-a-w C:\Windows\System32\ScrrnES.dll
2008-01-04 21:59 524,288 —-a-w C:\Windows\System32\DivXsm.exe
2008-01-04 21:58 200,704 —-a-w C:\Windows\System32\ssldivx.dll
2008-01-04 21:58 1,044,480 —-a-w C:\Windows\System32\libdivx.dll
2008-01-04 21:57 823,296 —-a-w C:\Windows\System32\divx_xx0c.dll
2008-01-04 21:57 823,296 —-a-w C:\Windows\System32\divx_xx07.dll
2008-01-04 21:57 802,816 —-a-w C:\Windows\System32\divx_xx11.dll
2008-01-04 21:57 593,920 —-a-w C:\Windows\System32\dpuGUI11.dll
2008-01-04 21:57 57,344 —-a-w C:\Windows\System32\dpv11.dll
2008-01-04 21:57 53,248 —-a-w C:\Windows\System32\dpuGUI10.dll
2008-01-04 21:57 344,064 —-a-w C:\Windows\System32\dpus11.dll
2008-01-04 21:57 294,912 —-a-w C:\Windows\System32\dpu11.dll
2008-01-04 21:57 294,912 —-a-w C:\Windows\System32\dpu10.dll
2008-01-04 21:57 196,608 —-a-w C:\Windows\System32\dtu100.dll
2008-01-04 21:56 156,992 —-a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-01-04 21:56 12,288 —-a-w C:\Windows\System32\DivXWMPExtType.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{376892AE-1825-4E5F-9F85-23F9640051CC}]
2007-11-08 08:36 130048 –a—— C:\Windows\xmljacodec.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-01 03:04 1232896]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-31 23:32 68856]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 04:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 04:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 03:04 4423680 C:\Windows\RtHDVCpl.exe]
"Acer Empowering Technology Monitor"="C:\Acer\Empowering Technology\SysMonitor.exe" [2007-01-24 09:27 319488]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 23:04 464168]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-02-02 00:37 630784]
"Acer Product Registration"="C:\Program Files\Acer Registration\ACE1.exe" [2007-02-02 11:24 3383296]
"Acer Assist Launcher"="C:\Program Files\Acer Assist\launcher.exe" [2007-02-02 10:05 1261568]
"Setresolution"="C:\ACERSW\config\1440x900.cmd" [2007-10-11 11:15 198]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 01:45 222208]
"ISW.exe"="C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"AT&T; Internet Security Suite"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\Rps.exe" [2007-06-28 16:09 310000]
"-FreedomNeedsReboot"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 16:09 13552]
"VirusScannerPro"="C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe" [2007-09-11 02:32 173312]
"hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 16:31 80896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]
"lxbkbmgr.exe"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2007-04-26 12:02 74672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-04-16 17:09:28 528384]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PCM Media Sharing.lnk]
backup=C:\Windows\pss\PCM Media Sharing.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-10-02 14:45 67488 C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LimeShop]
javaw -cp C:\Program Files\LimeShop\System\Code Main lp: C:\Program Files\LimeShop

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-01-31 23:32 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{ED1E9675-5C5C-4552-8979-8FFBD704C996}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C5A6A6A0-D297-4AA6-9383-21A16C3F9929}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C0B04953-9D63-4886-9FEE-B20972592777}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live|Desc=Acer Arcade Live
"{64C52DD3-2977-4C34-BDA1-8FD96179DF00}"= C:\Program Files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess|Desc=SlideShow DVD workprocess
"{F42A10AE-D383-4A78-9E05-64BBC84376C5}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess|Desc=DV Magician ARA workprocess
"{A0E22BD1-9D17-41A4-BF50-419B503C50D0}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess|Desc=DV Magician AVAX workprocess
"{E59634F8-1C07-40AC-84E1-E301FBC238EE}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine|Desc=DVDivine
"{DFFF3429-DA90-43DB-898C-FAEEFE3F39E2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia|Desc=HomeMedia
"{5F06C73B-3B46-4ED5-983C-2880071833B2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect|Desc=HomeMedia Connect
"{1955E669-BE1F-4C13-B854-FB32F2900974}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service|Desc=HomeMedia Connect Service
"{A8757501-B402-4C19-AD10-EA4697A9512B}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician|Desc=VideoMagician
"{9234C2B8-F04E-4204-A09F-3FCCBFA126AE}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B2B007CA-B0EE-4273-9F70-DC3EA7ABA9ED}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B456AA34-D9D2-4AA1-B344-8B09EAECC6B8}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0C714E48-AC34-4FD8-9B2A-59D42C53B5D7}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{46815E3A-9CC6-45F8-A148-A9473F8E7769}C:\program files\windows sidebar\sidebar.exe"= UDP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"UDP Query User{0866C7EE-A71E-4654-8CA1-0E1F5CE3E61B}C:\program files\windows sidebar\sidebar.exe"= TCP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"TCP Query User{5465F7B4-AB26-4F4D-933A-FF89AF66E9CB}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{977F1337-B2E4-45C8-BD56-64A89A48894E}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"{94AA03C4-97DD-4A17-AC0E-944B0071DAD9}"= UDP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{B1C11E30-1213-4486-BBA4-EC18397A5EC4}"= TCP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{FFCAA06D-B93F-4761-95C2-ED89CD2E1795}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{F44736BC-EC14-4700-B298-7914E0856207}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{D7709ABE-C477-4DC0-B614-9683BC741823}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"{1E358188-B5AE-4DC6-8C6E-319E3BB034B0}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"TCP Query User{B2D87FF7-832C-49FE-BD9E-89ACD040F655}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{F6A71D3E-5BA8-4449-8DDB-23D0DF2A9708}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"TCP Query User{EC8CE942-D080-4BA8-AE3B-0F834E4969CC}C:\windows\system32\javaw.exe"= UDP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"UDP Query User{F3285B82-9AA8-438E-8AD8-14ECE6877D4D}C:\windows\system32\javaw.exe"= TCP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"{5780BA34-CFE2-423E-B53C-D00E62E549CF}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{0A80E1F4-015B-4A63-BDCA-AA0349472A0F}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{53213690-2F90-48B7-88C0-0EC426C28D83}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{26BDE5B8-667C-4659-BD7E-1B40D4A2FC4B}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{FA80AA46-E4BC-4AF2-AE1F-48DE47BA08DF}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CA99614-5EA4-4858-A86D-078ED9E34859}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CDEA102-A4A2-46C9-9926-BB6C7A327CF1}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{A51AE3A2-2ED8-40AB-90EE-17AF90D79C16}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{2A015A47-5926-4EC6-B4F2-7A271F2EB118}C:\program files\ares ultra\ares ultra.exe"= Disabled:UDP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"UDP Query User{2ADF9AAE-7C9D-4D54-8F66-BFDD44542910}C:\program files\ares ultra\ares ultra.exe"= Disabled:TCP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"TCP Query User{D51C1380-4F13-455B-BAEC-A8957567347F}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{915AC283-DB84-4A06-AACC-531197D15028}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{05AF3670-5012-41C7-BE3B-90E8B91D6618}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{519F3CCD-78C9-4D71-8241-8545D5E28844}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"TCP Query User{06B02AE2-9D81-4A20-9FB9-E497EA8FD740}C:\program files\wyzo\wyzo.exe"= UDP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"UDP Query User{1B57D6E7-155E-4450-8365-27D8D5548C34}C:\program files\wyzo\wyzo.exe"= TCP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"TCP Query User{4C971860-1839-4552-B334-9CC70301ABCB}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{6C063307-082D-4B83-B397-D4950890871E}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{B733EB0A-5624-4DA0-94FE-BE4CBEDA5950}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{63641DF6-E896-4EB4-BD1B-5693B1BBB4AC}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"TCP Query User{979A8622-97BB-4327-893C-1E933B2DD82F}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{9984BA5E-7108-492F-A1CE-E82DEA8DA5BD}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"TCP Query User{3CCD6E95-EB20-413A-A1D8-4B11C7DE15CC}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{FDC9E13B-2EDC-4F19-9A6C-F7019E1EE034}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"{1EA8CC77-0C78-4A5F-9358-00995778259E}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{0515436C-451C-4970-B3FA-617E20EE7E95}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{47A29E79-4ED1-48A0-941D-F8C203508FE4}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{05A0B5DF-7D19-41C8-A704-EDB7FF9561E3}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"{35656831-0F96-4AE7-84B7-80ABD02C2A59}"= UDP:52555:utor1
"{E7FC6750-7D3B-4B3A-900B-E7EBE5BD0494}"= UDP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{B11A941D-BACA-4B0E-AEF7-8CAB19B0B5F7}"= TCP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{0E690F73-7BE2-42B3-8E93-9149D1DA9C14}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
"{0F122DF0-5137-4336-9DD4-FC51C50AC9A0}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-29 19:22]
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-02-06 23:04]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-02-06 23:04]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-02-06 23:04]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-04-04 17:54]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 14:46]
R2 AdwareAlertSrv;AdwareAlert Scanning Engine;"C:\Program Files\AdwareAlert\AdwareAlert.srv.exe" [2008-02-14 13:27]
R2 eDataSecurity Service;eDataSecurity Service;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-02-06 23:04]
R2 lxbk_device;lxbk_device;C:\Windows\system32\lxbkcoms.exe [2007-04-26 12:01]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-03-14 06:04]
R3 KFilter;KFilter;C:\PROGRA~1\AVANQU~1\SYSTEM~1\KFilter.sys [2007-09-11 02:32]
R3 MailScan;MailScan;C:\PROGRA~1\AVANQU~1\SYSTEM~1\MailScan.sys [2007-09-11 02:32]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-03-22 18:12]
S3 Radialpoint Security Services;AT&T; Internet Security Suite;C:\Windows\system32\dllhost.exe [2006-11-02 01:45]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6818ae31-d20c-11dc-8e7b-001c2552ea58}]
\shell\AutoRun\command - LinksysConnectPC.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5783dde-d202-11dc-8197-001c2552ea58}]
\shell\AutoRun\command - K:\RCAMemoryMgr.exe
\shell\Manage your videos\command - K:\RCAMemoryMgr.exe

*Newly Created Service* - SASDIFSV
*Newly Created Service* - SASENUM
*Newly Created Service* - SASKUTIL
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 17:43:56
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-26 17:45:21
ComboFix-quarantined-files.txt 2008-02-27 01:45:18
.
2008-02-17 01:05:47 — E O F —















Hijack This log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:59:51 PM, on 2/25/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\lxbkjswx.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…/www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CDNSCacheObj Object - {376892AE-1825-4E5F-9F85-23F9640051CC} - C:\Windows\xmljacodec.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T;\AT&T; Internet Security Suite\pkR.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\Avanquest\SystemSuite\LinkScannerIE.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [Setresolution] C:\ACERSW\config\1440x900.cmd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [AT&T; Internet Security Suite] "C:\Program Files\AT&T;\AT&T; Internet Security Suite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\AT&T;\AT&T; Internet Security Suite\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [303ebcd9] rundll32.exe "C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [lxbkbmgr.exe] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\mom\AppData\Local\Temp\hgday.dll,#1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: AdwareAlert Scanning Engine (AdwareAlertSrv) - Unknown owner - C:\Program Files\AdwareAlert\AdwareAlert.srv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: AT&T; Internet Security Suite Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\AT&T;\AT&T; Internet Security Suite\rpsupdaterR.exe
O23 - Service: AT&T; Internet Security Suite AT&T; Firewall (RP_FWS) - AT&T; - C:\Program Files\AT&T;\AT&T; Internet Security Suite\Fws.exe
O23 - Service: SystemSuite Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe

–
End of file - 10912 bytes
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Windows\wusa.lock
C:\Windows\xmljacodec.dll
C:\Windows\system32\msconfig.exe
C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll
C:\Users\mom\AppData\Local\Temp\hgday.dll

Folder::
C:\f24a1aca0b9794bd2211db

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{376892AE-1825-4E5F-9F85-23F9640051CC}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"=-

Save this as Save this as "CFScript"


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
ok here are the two logs you requested….


combofix

ComboFix 08-02-25.3 - mom 2008-02-26 18:14:10.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.159 [GMT -8:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\mom\Desktop\CFScript.txt

FILE ::
C:\Users\mom\AppData\Local\Temp\hgday.dll
C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll
C:\Windows\system32\msconfig.exe
C:\Windows\wusa.lock
C:\Windows\xmljacodec.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\f24a1aca0b9794bd2211db
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86-pkgProperties.txt
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86.cab
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86.xml
C:\f24a1aca0b9794bd2211db\WSUSSCAN.cab
C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll
C:\Windows\wusa.lock
C:\Windows\xmljacodec.dll
C:\Windows\system32\msconfig.exe . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.

2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Users\mom\AppData\Roaming\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Program Files\SUPERAntiSpyware
2008-02-26 03:11 . 2008-02-26 03:11 d——– C:\Users\mom\AppData\Roaming\PC Tools
2008-02-26 03:11 . 2008-02-26 03:34 d——– C:\Program Files\Spyware Doctor
2008-02-26 03:11 . 2007-12-10 14:53 81,288 –a—— C:\Windows\System32\drivers\iksyssec.sys
2008-02-26 03:11 . 2007-12-10 14:53 66,952 –a—— C:\Windows\System32\drivers\iksysflt.sys
2008-02-26 03:11 . 2008-02-01 12:55 42,376 –a—— C:\Windows\System32\drivers\ikfilesec.sys
2008-02-26 03:11 . 2007-12-10 14:53 29,576 –a—— C:\Windows\System32\drivers\kcom.sys
2008-02-25 17:22 . 2008-02-25 17:26 d——– C:\Program Files\SpywareBlaster
2008-02-25 17:18 . 2008-02-25 17:18 d——– C:\ie-spyad
2008-02-25 16:27 . 2008-02-26 13:03 d——– C:\temp
2008-02-25 16:16 . 2008-02-25 16:16 d——– C:\Users\mom\AppData\Roaming\Grisoft
2008-02-25 16:16 . 2007-05-30 04:10 10,872 –a—— C:\Windows\System32\drivers\AvgAsCln.sys
2008-02-25 16:15 . 2008-02-26 17:16 246 –a—— C:\Windows\Lexstat.ini
2008-02-25 16:13 . 2008-02-25 16:18 d——– C:\Program Files\Lexmark X1100 Series
2008-02-25 16:12 . 2008-02-25 16:12 d——– C:\drivers
2008-02-25 16:11 . 2008-02-25 16:12 36,487,088 –a—— C:\Users\mom\cjrX1100EN.exe
2008-02-25 11:50 . 2007-07-26 17:07 621,056 –a—— C:\Windows\System32\drivers\dxgkrnl.sys
2008-02-25 11:50 . 2007-07-26 18:17 36,864 –a—— C:\Windows\System32\cdd.dll
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Users\All Users\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\ProgramData\HP
2008-02-25 05:42 . 2008-02-25 05:43 d——– C:\Program Files\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Program Files\Common Files\HP
2008-02-25 05:42 . 2008-02-25 05:43 102,364 –a—— C:\Windows\hpqins13.dat
2008-02-25 05:06 . 2008-02-25 05:08 125 –a—— C:\ioSpecial.ini
2008-02-24 15:11 . 2008-02-25 04:54 d——– C:\Program Files\BuildALot_at
2008-02-24 08:52 . 2008-02-24 08:52 d——– C:\Program Files\ReflexiveArcade
2008-02-24 08:09 . 2008-02-24 08:09 d——– C:\Program Files\Agatha Christie - Peril at End House
2008-02-24 05:07 . 2008-02-24 05:07 d——– C:\Program Files\Mystery Case Files - Prime Suspects
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\mom\AppData\Roaming\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\All Users\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\ProgramData\Oberon Games
2008-02-22 22:09 . 2008-02-22 22:09 d——– C:\Users\mom\AppData\Roaming\Magic Seeds
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\Users\All Users\HipSoft
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\ProgramData\HipSoft
2008-02-22 10:07 . 2008-02-22 10:07 d——– C:\Program Files\bfgclient
2008-02-22 10:07 . 2008-02-22 10:21 d——– C:\BigFishGamesCache
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\Users\All Users\BVRP Software
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\ProgramData\BVRP Software
2008-02-20 22:04 . 2008-02-20 22:04 dr-hs—- C:\_Backup.RC
2008-02-20 22:04 . 2008-02-20 23:43 d–h—– C:\_Backup
2008-02-20 22:00 . 2008-02-24 15:23 d——– C:\Users\mom\AppData\Roaming\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\Users\All Users\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\ProgramData\Avanquest
2008-02-20 21:59 . 2008-02-20 21:59 d——– C:\Program Files\Avanquest
2008-02-20 21:55 . 2008-02-26 17:27 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:18 . 2007-03-06 18:51 543,232 –a—— C:\Windows\System32\FWPUCLNT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 416,768 –a—— C:\Windows\System32\IKEEXT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 317,440 –a—— C:\Windows\System32\BFE.DLL
2008-02-19 21:18 . 2007-03-06 18:08 84,992 –a—— C:\Windows\System32\drivers\FWPKCLNT.SYS
2008-02-19 21:17 . 2008-02-19 21:17 d——– C:\Users\mom\AppData\Roaming\Sammsoft
2008-02-19 21:16 . 2008-02-19 22:25 d——– C:\Program Files\Advanced Registry Optimizer
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\Users\All Users\Grisoft
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\ProgramData\Grisoft
2008-02-19 21:06 . 2008-02-19 21:06 1,420 –a—— C:\Windows\wininit.ini
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\ProgramData\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 21:12 d——– C:\Program Files\Trend Micro
2008-02-19 20:25 . 2008-02-19 22:35 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-19 20:12 . 2008-02-19 20:12 d——– C:\kav
2008-02-19 19:37 . 2008-02-19 19:37 3,764 –a—— C:\Windows\System32\tmp.reg
2008-02-19 19:36 . 2008-02-19 19:41 d——– C:\Windows\System32\SmitfraudFix
2008-02-19 05:33 . 2008-02-19 05:37 d——– C:\Users\mom\.housecall6.6
2008-02-18 23:00 . 2008-02-25 04:53 d——– C:\Program Files\AdwareAlert
2008-02-18 22:51 . 2008-02-18 22:51 d——– C:\Program Files\Enigma Software Group
2008-02-17 11:52 . 2008-02-17 11:52 d——– C:\Users\mom\AppData\Roaming\PCF-VLC
2008-02-16 21:34 . 2008-02-26 17:52 dr——- C:\Windows\System32\config\systemprofile\Documents
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Users\All Users\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\ProgramData\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Common Files\Authentium
2008-02-16 21:23 . 2007-04-04 17:15 839,880 –a—— C:\Windows\System32\drivers\css-dvp.sys
2008-02-16 21:23 . 2007-03-06 13:24 55,296 –a—— C:\Windows\System32\drivers\rp_skt32.sys
2008-02-16 21:23 . 2007-04-05 14:52 48,384 –a—— C:\Windows\System32\drivers\rp_pkt32.sys
2008-02-16 21:22 . 2008-02-19 23:02 d——– C:\Program Files\Common Files\Scanner
2008-02-16 21:22 . 2008-02-16 21:22 d——– C:\Program Files\CA
2008-02-16 21:20 . 2008-02-16 21:20 d——– C:\Users\mom\AppData\Roaming\InstallShield
2008-02-15 21:09 . 2008-01-09 21:50 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-02-15 18:38 . 2008-02-15 18:38 d——– C:\Users\mom\AppData\Roaming\Template
2008-02-15 18:37 . 2008-02-22 21:53 90 –a—— C:\Users\mom\AppData\Roaming\wklnhst.dat
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\Users\All Users\Macrovision
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\ProgramData\Macrovision
2008-02-15 16:58 . 2008-02-15 16:58 d——– C:\Program Files\Common Files\Macromedia Shared
2008-02-15 16:55 . 2008-02-15 16:55 d——– C:\Program Files\Common Files\Macromedia
2008-02-15 16:53 . 2008-02-15 16:53 d——– C:\Program Files\Macromedia
2008-02-14 06:02 . 2008-02-14 06:02 d——– C:\Users\mom\AppData\Roaming\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\Users\All Users\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\ProgramData\Participatory Culture Foundation
2008-02-14 06:00 . 2008-02-14 06:00 d——– C:\My Documents
2008-02-13 18:05 . 2008-02-13 18:05 194,560 –a—— C:\Windows\System32\WebClnt.dll
2008-02-13 18:05 . 2008-02-13 18:05 110,080 –a—— C:\Windows\System32\drivers\mrxdav.sys
2008-02-13 18:01 . 2008-02-13 18:01 3,505,720 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-02-13 18:01 . 2008-02-13 18:01 3,471,928 –a—— C:\Windows\System32\ntoskrnl.exe
2008-02-13 18:01 . 2008-02-13 18:01 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-02-13 18:01 . 2008-02-13 18:01 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-02-13 18:01 . 2008-02-13 18:01 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-02-13 18:01 . 2008-02-13 18:01 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-02-13 18:01 . 2008-02-13 18:01 15,928 –a—— C:\Windows\System32\drivers\pciide.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 13:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-14 02:04 54,784 —-a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-14 02:04 495,160 —-a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-14 02:04 35,384 —-a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-14 02:04 35,384 —-a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-14 02:04 34,360 —-a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-14 02:04 19,968 —-a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-14 02:04 15,872 —-a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-13 20:00 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 20:00 449,536 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 20:00 2,144,256 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 20:00 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 19:57 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-02 17:15 ——— d—–w C:\Users\mom\AppData\Roaming\.wyzo
2008-02-02 16:04 ——— d—–w C:\Users\mom\AppData\Roaming\.BitTornado
2008-02-02 15:44 ——— d—–w C:\Program Files\eSobi
2008-02-01 23:04 ——— d—–w C:\Program Files\Microsoft Games
2008-02-01 11:31 174 –sha-w C:\Program Files\desktop.ini
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Mail
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Calendar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Sidebar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Defender
2008-02-01 11:19 70,144 —-a-w C:\Windows\system32\drivers\pacer.sys
2008-02-01 11:19 61,952 —-a-w C:\Windows\system32\drivers\wanarp.sys
2008-02-01 11:19 48,640 —-a-w C:\Windows\system32\drivers\ndproxy.sys
2008-02-01 11:19 20,480 —-a-w C:\Windows\system32\drivers\ndistapi.sys
2008-02-01 11:17 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2008-02-01 11:17 2,923,520 —-a-w C:\Windows\explorer.exe
2008-02-01 11:12 63,488 —-a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-02-01 11:12 23,040 —-a-w C:\Windows\system32\drivers\tunnel.sys
2008-02-01 11:12 15,360 —-a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-02-01 08:25 ——— d—–w C:\ProgramData\eSobi
2008-02-01 07:40 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-01 07:39 ——— d—–w C:\ProgramData\Symantec
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-01 03:04 1232896]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-31 23:32 68856]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 04:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 04:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 03:04 4423680 C:\Windows\RtHDVCpl.exe]
"Acer Empowering Technology Monitor"="C:\Acer\Empowering Technology\SysMonitor.exe" [2007-01-24 09:27 319488]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 23:04 464168]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-02-02 00:37 630784]
"Acer Product Registration"="C:\Program Files\Acer Registration\ACE1.exe" [2007-02-02 11:24 3383296]
"Acer Assist Launcher"="C:\Program Files\Acer Assist\launcher.exe" [2007-02-02 10:05 1261568]
"Setresolution"="C:\ACERSW\config\1440x900.cmd" [2007-10-11 11:15 198]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ISW.exe"="C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"AT&T; Internet Security Suite"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\Rps.exe" [2007-06-28 16:09 310000]
"-FreedomNeedsReboot"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 16:09 13552]
"VirusScannerPro"="C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe" [2007-09-11 02:32 173312]
"hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 16:31 80896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]
"lxbkbmgr.exe"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2007-04-26 12:02 74672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-04-16 17:09:28 528384]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PCM Media Sharing.lnk]
backup=C:\Windows\pss\PCM Media Sharing.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-10-02 14:45 67488 C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LimeShop]
javaw -cp C:\Program Files\LimeShop\System\Code Main lp: C:\Program Files\LimeShop

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-01-31 23:32 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{ED1E9675-5C5C-4552-8979-8FFBD704C996}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C5A6A6A0-D297-4AA6-9383-21A16C3F9929}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C0B04953-9D63-4886-9FEE-B20972592777}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live|Desc=Acer Arcade Live
"{64C52DD3-2977-4C34-BDA1-8FD96179DF00}"= C:\Program Files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess|Desc=SlideShow DVD workprocess
"{F42A10AE-D383-4A78-9E05-64BBC84376C5}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess|Desc=DV Magician ARA workprocess
"{A0E22BD1-9D17-41A4-BF50-419B503C50D0}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess|Desc=DV Magician AVAX workprocess
"{E59634F8-1C07-40AC-84E1-E301FBC238EE}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine|Desc=DVDivine
"{DFFF3429-DA90-43DB-898C-FAEEFE3F39E2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia|Desc=HomeMedia
"{5F06C73B-3B46-4ED5-983C-2880071833B2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect|Desc=HomeMedia Connect
"{1955E669-BE1F-4C13-B854-FB32F2900974}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service|Desc=HomeMedia Connect Service
"{A8757501-B402-4C19-AD10-EA4697A9512B}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician|Desc=VideoMagician
"{9234C2B8-F04E-4204-A09F-3FCCBFA126AE}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B2B007CA-B0EE-4273-9F70-DC3EA7ABA9ED}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B456AA34-D9D2-4AA1-B344-8B09EAECC6B8}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0C714E48-AC34-4FD8-9B2A-59D42C53B5D7}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{46815E3A-9CC6-45F8-A148-A9473F8E7769}C:\program files\windows sidebar\sidebar.exe"= UDP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"UDP Query User{0866C7EE-A71E-4654-8CA1-0E1F5CE3E61B}C:\program files\windows sidebar\sidebar.exe"= TCP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"TCP Query User{5465F7B4-AB26-4F4D-933A-FF89AF66E9CB}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{977F1337-B2E4-45C8-BD56-64A89A48894E}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"{94AA03C4-97DD-4A17-AC0E-944B0071DAD9}"= UDP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{B1C11E30-1213-4486-BBA4-EC18397A5EC4}"= TCP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{FFCAA06D-B93F-4761-95C2-ED89CD2E1795}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{F44736BC-EC14-4700-B298-7914E0856207}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{D7709ABE-C477-4DC0-B614-9683BC741823}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"{1E358188-B5AE-4DC6-8C6E-319E3BB034B0}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"TCP Query User{B2D87FF7-832C-49FE-BD9E-89ACD040F655}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{F6A71D3E-5BA8-4449-8DDB-23D0DF2A9708}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"TCP Query User{EC8CE942-D080-4BA8-AE3B-0F834E4969CC}C:\windows\system32\javaw.exe"= UDP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"UDP Query User{F3285B82-9AA8-438E-8AD8-14ECE6877D4D}C:\windows\system32\javaw.exe"= TCP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"{5780BA34-CFE2-423E-B53C-D00E62E549CF}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{0A80E1F4-015B-4A63-BDCA-AA0349472A0F}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{53213690-2F90-48B7-88C0-0EC426C28D83}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{26BDE5B8-667C-4659-BD7E-1B40D4A2FC4B}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{FA80AA46-E4BC-4AF2-AE1F-48DE47BA08DF}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CA99614-5EA4-4858-A86D-078ED9E34859}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CDEA102-A4A2-46C9-9926-BB6C7A327CF1}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{A51AE3A2-2ED8-40AB-90EE-17AF90D79C16}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{2A015A47-5926-4EC6-B4F2-7A271F2EB118}C:\program files\ares ultra\ares ultra.exe"= Disabled:UDP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"UDP Query User{2ADF9AAE-7C9D-4D54-8F66-BFDD44542910}C:\program files\ares ultra\ares ultra.exe"= Disabled:TCP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"TCP Query User{D51C1380-4F13-455B-BAEC-A8957567347F}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{915AC283-DB84-4A06-AACC-531197D15028}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{05AF3670-5012-41C7-BE3B-90E8B91D6618}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{519F3CCD-78C9-4D71-8241-8545D5E28844}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"TCP Query User{06B02AE2-9D81-4A20-9FB9-E497EA8FD740}C:\program files\wyzo\wyzo.exe"= UDP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"UDP Query User{1B57D6E7-155E-4450-8365-27D8D5548C34}C:\program files\wyzo\wyzo.exe"= TCP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"TCP Query User{4C971860-1839-4552-B334-9CC70301ABCB}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{6C063307-082D-4B83-B397-D4950890871E}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{B733EB0A-5624-4DA0-94FE-BE4CBEDA5950}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{63641DF6-E896-4EB4-BD1B-5693B1BBB4AC}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"TCP Query User{979A8622-97BB-4327-893C-1E933B2DD82F}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{9984BA5E-7108-492F-A1CE-E82DEA8DA5BD}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"TCP Query User{3CCD6E95-EB20-413A-A1D8-4B11C7DE15CC}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{FDC9E13B-2EDC-4F19-9A6C-F7019E1EE034}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"{1EA8CC77-0C78-4A5F-9358-00995778259E}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{0515436C-451C-4970-B3FA-617E20EE7E95}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{47A29E79-4ED1-48A0-941D-F8C203508FE4}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{05A0B5DF-7D19-41C8-A704-EDB7FF9561E3}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"{35656831-0F96-4AE7-84B7-80ABD02C2A59}"= UDP:52555:utor1
"{E7FC6750-7D3B-4B3A-900B-E7EBE5BD0494}"= UDP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{B11A941D-BACA-4B0E-AEF7-8CAB19B0B5F7}"= TCP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{0E690F73-7BE2-42B3-8E93-9149D1DA9C14}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
"{0F122DF0-5137-4336-9DD4-FC51C50AC9A0}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-29 19:22]
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-02-06 23:04]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-02-06 23:04]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-02-06 23:04]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-04-04 17:54]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 14:46]
R2 AdwareAlertSrv;AdwareAlert Scanning Engine;"C:\Program Files\AdwareAlert\AdwareAlert.srv.exe" [2008-02-14 13:27]
R2 eDataSecurity Service;eDataSecurity Service;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-02-06 23:04]
R2 lxbk_device;lxbk_device;C:\Windows\system32\lxbkcoms.exe [2007-04-26 12:01]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-03-14 06:04]
R3 KFilter;KFilter;C:\PROGRA~1\AVANQU~1\SYSTEM~1\KFilter.sys [2007-09-11 02:32]
R3 MailScan;MailScan;C:\PROGRA~1\AVANQU~1\SYSTEM~1\MailScan.sys [2007-09-11 02:32]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-03-22 18:12]
S3 Radialpoint Security Services;AT&T; Internet Security Suite;C:\Windows\system32\dllhost.exe [2006-11-02 01:45]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6818ae31-d20c-11dc-8e7b-001c2552ea58}]
\shell\AutoRun\command - LinksysConnectPC.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5783dde-d202-11dc-8197-001c2552ea58}]
\shell\AutoRun\command - K:\RCAMemoryMgr.exe
\shell\Manage your videos\command - K:\RCAMemoryMgr.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 18:19:27
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\AT&T;\AT&T; Internet Security Suite\Fws.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\mxtask.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Program Files\Avanquest\SystemSuite\MemCheck.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2008-02-26 18:22:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-27 02:22:38
ComboFix2.txt 2008-02-27 01:45:22
.
2008-02-17 01:05:47 — E O F —



and hijack

ComboFix 08-02-25.3 - mom 2008-02-26 18:14:10.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.159 [GMT -8:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\mom\Desktop\CFScript.txt

FILE ::
C:\Users\mom\AppData\Local\Temp\hgday.dll
C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll
C:\Windows\system32\msconfig.exe
C:\Windows\wusa.lock
C:\Windows\xmljacodec.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\f24a1aca0b9794bd2211db
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86-pkgProperties.txt
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86.cab
C:\f24a1aca0b9794bd2211db\Windows6.0-KB943899-v2-x86.xml
C:\f24a1aca0b9794bd2211db\WSUSSCAN.cab
C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll
C:\Windows\wusa.lock
C:\Windows\xmljacodec.dll
C:\Windows\system32\msconfig.exe . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.

2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-02-26 17:29 . 2008-02-26 17:29 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Users\mom\AppData\Roaming\SUPERAntiSpyware.com
2008-02-26 17:28 . 2008-02-26 17:28 d——– C:\Program Files\SUPERAntiSpyware
2008-02-26 03:11 . 2008-02-26 03:11 d——– C:\Users\mom\AppData\Roaming\PC Tools
2008-02-26 03:11 . 2008-02-26 03:34 d——– C:\Program Files\Spyware Doctor
2008-02-26 03:11 . 2007-12-10 14:53 81,288 –a—— C:\Windows\System32\drivers\iksyssec.sys
2008-02-26 03:11 . 2007-12-10 14:53 66,952 –a—— C:\Windows\System32\drivers\iksysflt.sys
2008-02-26 03:11 . 2008-02-01 12:55 42,376 –a—— C:\Windows\System32\drivers\ikfilesec.sys
2008-02-26 03:11 . 2007-12-10 14:53 29,576 –a—— C:\Windows\System32\drivers\kcom.sys
2008-02-25 17:22 . 2008-02-25 17:26 d——– C:\Program Files\SpywareBlaster
2008-02-25 17:18 . 2008-02-25 17:18 d——– C:\ie-spyad
2008-02-25 16:27 . 2008-02-26 13:03 d——– C:\temp
2008-02-25 16:16 . 2008-02-25 16:16 d——– C:\Users\mom\AppData\Roaming\Grisoft
2008-02-25 16:16 . 2007-05-30 04:10 10,872 –a—— C:\Windows\System32\drivers\AvgAsCln.sys
2008-02-25 16:15 . 2008-02-26 17:16 246 –a—— C:\Windows\Lexstat.ini
2008-02-25 16:13 . 2008-02-25 16:18 d——– C:\Program Files\Lexmark X1100 Series
2008-02-25 16:12 . 2008-02-25 16:12 d——– C:\drivers
2008-02-25 16:11 . 2008-02-25 16:12 36,487,088 –a—— C:\Users\mom\cjrX1100EN.exe
2008-02-25 11:50 . 2007-07-26 17:07 621,056 –a—— C:\Windows\System32\drivers\dxgkrnl.sys
2008-02-25 11:50 . 2007-07-26 18:17 36,864 –a—— C:\Windows\System32\cdd.dll
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Users\All Users\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\ProgramData\HP
2008-02-25 05:42 . 2008-02-25 05:43 d——– C:\Program Files\HP
2008-02-25 05:42 . 2008-02-25 05:42 d——– C:\Program Files\Common Files\HP
2008-02-25 05:42 . 2008-02-25 05:43 102,364 –a—— C:\Windows\hpqins13.dat
2008-02-25 05:06 . 2008-02-25 05:08 125 –a—— C:\ioSpecial.ini
2008-02-24 15:11 . 2008-02-25 04:54 d——– C:\Program Files\BuildALot_at
2008-02-24 08:52 . 2008-02-24 08:52 d——– C:\Program Files\ReflexiveArcade
2008-02-24 08:09 . 2008-02-24 08:09 d——– C:\Program Files\Agatha Christie - Peril at End House
2008-02-24 05:07 . 2008-02-24 05:07 d——– C:\Program Files\Mystery Case Files - Prime Suspects
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\mom\AppData\Roaming\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\Users\All Users\Oberon Games
2008-02-22 23:12 . 2008-02-22 23:12 d——– C:\ProgramData\Oberon Games
2008-02-22 22:09 . 2008-02-22 22:09 d——– C:\Users\mom\AppData\Roaming\Magic Seeds
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\Users\All Users\HipSoft
2008-02-22 12:13 . 2008-02-22 12:13 d——– C:\ProgramData\HipSoft
2008-02-22 10:07 . 2008-02-22 10:07 d——– C:\Program Files\bfgclient
2008-02-22 10:07 . 2008-02-22 10:21 d——– C:\BigFishGamesCache
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\Users\All Users\BVRP Software
2008-02-20 22:09 . 2008-02-20 22:09 d——– C:\ProgramData\BVRP Software
2008-02-20 22:04 . 2008-02-20 22:04 dr-hs—- C:\_Backup.RC
2008-02-20 22:04 . 2008-02-20 23:43 d–h—– C:\_Backup
2008-02-20 22:00 . 2008-02-24 15:23 d——– C:\Users\mom\AppData\Roaming\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\Users\All Users\Avanquest
2008-02-20 22:00 . 2008-02-20 22:00 d——– C:\ProgramData\Avanquest
2008-02-20 21:59 . 2008-02-20 21:59 d——– C:\Program Files\Avanquest
2008-02-20 21:55 . 2008-02-26 17:27 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:18 . 2007-03-06 18:51 543,232 –a—— C:\Windows\System32\FWPUCLNT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 416,768 –a—— C:\Windows\System32\IKEEXT.DLL
2008-02-19 21:18 . 2007-03-06 18:51 317,440 –a—— C:\Windows\System32\BFE.DLL
2008-02-19 21:18 . 2007-03-06 18:08 84,992 –a—— C:\Windows\System32\drivers\FWPKCLNT.SYS
2008-02-19 21:17 . 2008-02-19 21:17 d——– C:\Users\mom\AppData\Roaming\Sammsoft
2008-02-19 21:16 . 2008-02-19 22:25 d——– C:\Program Files\Advanced Registry Optimizer
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\Users\All Users\Grisoft
2008-02-19 21:09 . 2008-02-19 21:09 d——– C:\ProgramData\Grisoft
2008-02-19 21:06 . 2008-02-19 21:06 1,420 –a—— C:\Windows\wininit.ini
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 22:34 d——– C:\ProgramData\Spybot - Search & Destroy
2008-02-19 20:25 . 2008-02-19 21:12 d——– C:\Program Files\Trend Micro
2008-02-19 20:25 . 2008-02-19 22:35 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-19 20:12 . 2008-02-19 20:12 d——– C:\kav
2008-02-19 19:37 . 2008-02-19 19:37 3,764 –a—— C:\Windows\System32\tmp.reg
2008-02-19 19:36 . 2008-02-19 19:41 d——– C:\Windows\System32\SmitfraudFix
2008-02-19 05:33 . 2008-02-19 05:37 d——– C:\Users\mom\.housecall6.6
2008-02-18 23:00 . 2008-02-25 04:53 d——– C:\Program Files\AdwareAlert
2008-02-18 22:51 . 2008-02-18 22:51 d——– C:\Program Files\Enigma Software Group
2008-02-17 11:52 . 2008-02-17 11:52 d——– C:\Users\mom\AppData\Roaming\PCF-VLC
2008-02-16 21:34 . 2008-02-26 17:52 dr——- C:\Windows\System32\config\systemprofile\Documents
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Users\All Users\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\ProgramData\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Raxco
2008-02-16 21:23 . 2008-02-16 21:23 d——– C:\Program Files\Common Files\Authentium
2008-02-16 21:23 . 2007-04-04 17:15 839,880 –a—— C:\Windows\System32\drivers\css-dvp.sys
2008-02-16 21:23 . 2007-03-06 13:24 55,296 –a—— C:\Windows\System32\drivers\rp_skt32.sys
2008-02-16 21:23 . 2007-04-05 14:52 48,384 –a—— C:\Windows\System32\drivers\rp_pkt32.sys
2008-02-16 21:22 . 2008-02-19 23:02 d——– C:\Program Files\Common Files\Scanner
2008-02-16 21:22 . 2008-02-16 21:22 d——– C:\Program Files\CA
2008-02-16 21:20 . 2008-02-16 21:20 d——– C:\Users\mom\AppData\Roaming\InstallShield
2008-02-15 21:09 . 2008-01-09 21:50 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-02-15 18:38 . 2008-02-15 18:38 d——– C:\Users\mom\AppData\Roaming\Template
2008-02-15 18:37 . 2008-02-22 21:53 90 –a—— C:\Users\mom\AppData\Roaming\wklnhst.dat
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\Users\All Users\Macrovision
2008-02-15 17:00 . 2008-02-15 17:00 d——– C:\ProgramData\Macrovision
2008-02-15 16:58 . 2008-02-15 16:58 d——– C:\Program Files\Common Files\Macromedia Shared
2008-02-15 16:55 . 2008-02-15 16:55 d——– C:\Program Files\Common Files\Macromedia
2008-02-15 16:53 . 2008-02-15 16:53 d——– C:\Program Files\Macromedia
2008-02-14 06:02 . 2008-02-14 06:02 d——– C:\Users\mom\AppData\Roaming\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\Users\All Users\Participatory Culture Foundation
2008-02-14 06:01 . 2008-02-14 06:01 d——– C:\ProgramData\Participatory Culture Foundation
2008-02-14 06:00 . 2008-02-14 06:00 d——– C:\My Documents
2008-02-13 18:05 . 2008-02-13 18:05 194,560 –a—— C:\Windows\System32\WebClnt.dll
2008-02-13 18:05 . 2008-02-13 18:05 110,080 –a—— C:\Windows\System32\drivers\mrxdav.sys
2008-02-13 18:01 . 2008-02-13 18:01 3,505,720 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-02-13 18:01 . 2008-02-13 18:01 3,471,928 –a—— C:\Windows\System32\ntoskrnl.exe
2008-02-13 18:01 . 2008-02-13 18:01 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-02-13 18:01 . 2008-02-13 18:01 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-02-13 18:01 . 2008-02-13 18:01 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-02-13 18:01 . 2008-02-13 18:01 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-02-13 18:01 . 2008-02-13 18:01 15,928 –a—— C:\Windows\System32\drivers\pciide.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 13:05 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-14 02:04 54,784 —-a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-14 02:04 495,160 —-a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-14 02:04 35,384 —-a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-14 02:04 35,384 —-a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-14 02:04 34,360 —-a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-14 02:04 19,968 —-a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-14 02:04 15,872 —-a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-13 20:00 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 20:00 449,536 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 20:00 2,144,256 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 20:00 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 19:57 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-02 17:15 ——— d—–w C:\Users\mom\AppData\Roaming\.wyzo
2008-02-02 16:04 ——— d—–w C:\Users\mom\AppData\Roaming\.BitTornado
2008-02-02 15:44 ——— d—–w C:\Program Files\eSobi
2008-02-01 23:04 ——— d—–w C:\Program Files\Microsoft Games
2008-02-01 11:31 174 –sha-w C:\Program Files\desktop.ini
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Mail
2008-02-01 11:28 ——— d—–w C:\Program Files\Windows Calendar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Sidebar
2008-02-01 11:27 ——— d—–w C:\Program Files\Windows Defender
2008-02-01 11:19 70,144 —-a-w C:\Windows\system32\drivers\pacer.sys
2008-02-01 11:19 61,952 —-a-w C:\Windows\system32\drivers\wanarp.sys
2008-02-01 11:19 48,640 —-a-w C:\Windows\system32\drivers\ndproxy.sys
2008-02-01 11:19 20,480 —-a-w C:\Windows\system32\drivers\ndistapi.sys
2008-02-01 11:17 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2008-02-01 11:17 2,923,520 —-a-w C:\Windows\explorer.exe
2008-02-01 11:12 63,488 —-a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-02-01 11:12 23,040 —-a-w C:\Windows\system32\drivers\tunnel.sys
2008-02-01 11:12 15,360 —-a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-02-01 08:25 ——— d—–w C:\ProgramData\eSobi
2008-02-01 07:40 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-01 07:39 ——— d—–w C:\ProgramData\Symantec
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-01 03:04 1232896]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16 454784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-31 23:32 68856]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 04:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 04:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 03:04 4423680 C:\Windows\RtHDVCpl.exe]
"Acer Empowering Technology Monitor"="C:\Acer\Empowering Technology\SysMonitor.exe" [2007-01-24 09:27 319488]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 23:04 464168]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-02-02 00:37 630784]
"Acer Product Registration"="C:\Program Files\Acer Registration\ACE1.exe" [2007-02-02 11:24 3383296]
"Acer Assist Launcher"="C:\Program Files\Acer Assist\launcher.exe" [2007-02-02 10:05 1261568]
"Setresolution"="C:\ACERSW\config\1440x900.cmd" [2007-10-11 11:15 198]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ISW.exe"="C:\Program Files\AT&T;\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"AT&T; Internet Security Suite"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\Rps.exe" [2007-06-28 16:09 310000]
"-FreedomNeedsReboot"="C:\Program Files\AT&T;\AT&T; Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 16:09 13552]
"VirusScannerPro"="C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe" [2007-09-11 02:32 173312]
"hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 16:31 80896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]
"lxbkbmgr.exe"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2007-04-26 12:02 74672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-04-16 17:09:28 528384]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PCM Media Sharing.lnk]
backup=C:\Windows\pss\PCM Media Sharing.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-10-02 14:45 67488 C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LimeShop]
javaw -cp C:\Program Files\LimeShop\System\Code Main lp: C:\Program Files\LimeShop

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-01-31 23:32 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{ED1E9675-5C5C-4552-8979-8FFBD704C996}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C5A6A6A0-D297-4AA6-9383-21A16C3F9929}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C0B04953-9D63-4886-9FEE-B20972592777}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live|Desc=Acer Arcade Live
"{64C52DD3-2977-4C34-BDA1-8FD96179DF00}"= C:\Program Files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess|Desc=SlideShow DVD workprocess
"{F42A10AE-D383-4A78-9E05-64BBC84376C5}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess|Desc=DV Magician ARA workprocess
"{A0E22BD1-9D17-41A4-BF50-419B503C50D0}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess|Desc=DV Magician AVAX workprocess
"{E59634F8-1C07-40AC-84E1-E301FBC238EE}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine|Desc=DVDivine
"{DFFF3429-DA90-43DB-898C-FAEEFE3F39E2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia|Desc=HomeMedia
"{5F06C73B-3B46-4ED5-983C-2880071833B2}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect|Desc=HomeMedia Connect
"{1955E669-BE1F-4C13-B854-FB32F2900974}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service|Desc=HomeMedia Connect Service
"{A8757501-B402-4C19-AD10-EA4697A9512B}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician|Desc=VideoMagician
"{9234C2B8-F04E-4204-A09F-3FCCBFA126AE}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B2B007CA-B0EE-4273-9F70-DC3EA7ABA9ED}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{B456AA34-D9D2-4AA1-B344-8B09EAECC6B8}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{0C714E48-AC34-4FD8-9B2A-59D42C53B5D7}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{46815E3A-9CC6-45F8-A148-A9473F8E7769}C:\program files\windows sidebar\sidebar.exe"= UDP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"UDP Query User{0866C7EE-A71E-4654-8CA1-0E1F5CE3E61B}C:\program files\windows sidebar\sidebar.exe"= TCP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar|Desc=Windows Sidebar
"TCP Query User{5465F7B4-AB26-4F4D-933A-FF89AF66E9CB}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{977F1337-B2E4-45C8-BD56-64A89A48894E}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"{94AA03C4-97DD-4A17-AC0E-944B0071DAD9}"= UDP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{B1C11E30-1213-4486-BBA4-EC18397A5EC4}"= TCP:C:\Program Files\Blubster\Blubster.exe:Blubster
"{FFCAA06D-B93F-4761-95C2-ED89CD2E1795}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{F44736BC-EC14-4700-B298-7914E0856207}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{D7709ABE-C477-4DC0-B614-9683BC741823}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"{1E358188-B5AE-4DC6-8C6E-319E3BB034B0}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:Age of Empires III - The WarChiefs
"TCP Query User{B2D87FF7-832C-49FE-BD9E-89ACD040F655}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{F6A71D3E-5BA8-4449-8DDB-23D0DF2A9708}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"TCP Query User{EC8CE942-D080-4BA8-AE3B-0F834E4969CC}C:\windows\system32\javaw.exe"= UDP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"UDP Query User{F3285B82-9AA8-438E-8AD8-14ECE6877D4D}C:\windows\system32\javaw.exe"= TCP:C:\windows\system32\javaw.exe:Java™ Platform SE binary|Desc=Java™ Platform SE binary
"{5780BA34-CFE2-423E-B53C-D00E62E549CF}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{0A80E1F4-015B-4A63-BDCA-AA0349472A0F}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{53213690-2F90-48B7-88C0-0EC426C28D83}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{26BDE5B8-667C-4659-BD7E-1B40D4A2FC4B}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{FA80AA46-E4BC-4AF2-AE1F-48DE47BA08DF}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CA99614-5EA4-4858-A86D-078ED9E34859}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8CDEA102-A4A2-46C9-9926-BB6C7A327CF1}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{A51AE3A2-2ED8-40AB-90EE-17AF90D79C16}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{2A015A47-5926-4EC6-B4F2-7A271F2EB118}C:\program files\ares ultra\ares ultra.exe"= Disabled:UDP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"UDP Query User{2ADF9AAE-7C9D-4D54-8F66-BFDD44542910}C:\program files\ares ultra\ares ultra.exe"= Disabled:TCP:C:\program files\ares ultra\ares ultra.exe:Ares Ultra p2p for windows|Desc=Ares Ultra p2p for windows
"TCP Query User{D51C1380-4F13-455B-BAEC-A8957567347F}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{915AC283-DB84-4A06-AACC-531197D15028}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{05AF3670-5012-41C7-BE3B-90E8B91D6618}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{519F3CCD-78C9-4D71-8241-8545D5E28844}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"TCP Query User{06B02AE2-9D81-4A20-9FB9-E497EA8FD740}C:\program files\wyzo\wyzo.exe"= UDP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"UDP Query User{1B57D6E7-155E-4450-8365-27D8D5548C34}C:\program files\wyzo\wyzo.exe"= TCP:C:\program files\wyzo\wyzo.exe:Wyzo|Desc=Wyzo
"TCP Query User{4C971860-1839-4552-B334-9CC70301ABCB}C:\program files\bittornado\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"UDP Query User{6C063307-082D-4B83-B397-D4950890871E}C:\program files\bittornado\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui|Desc=btdownloadgui
"TCP Query User{B733EB0A-5624-4DA0-94FE-BE4CBEDA5950}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{63641DF6-E896-4EB4-BD1B-5693B1BBB4AC}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"TCP Query User{979A8622-97BB-4327-893C-1E933B2DD82F}C:\program files\ares destiny powered by advantage\ares.exe"= UDP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"UDP Query User{9984BA5E-7108-492F-A1CE-E82DEA8DA5BD}C:\program files\ares destiny powered by advantage\ares.exe"= TCP:C:\program files\ares destiny powered by advantage\ares.exe:Ares p2p for windows|Desc=Ares p2p for windows
"TCP Query User{3CCD6E95-EB20-413A-A1D8-4B11C7DE15CC}C:\program files\streamcast\morpheus\morpheus.exe"= UDP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"UDP Query User{FDC9E13B-2EDC-4F19-9A6C-F7019E1EE034}C:\program files\streamcast\morpheus\morpheus.exe"= TCP:C:\program files\streamcast\morpheus\morpheus.exe:Morpheus|Desc=Morpheus
"{1EA8CC77-0C78-4A5F-9358-00995778259E}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{0515436C-451C-4970-B3FA-617E20EE7E95}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{47A29E79-4ED1-48A0-941D-F8C203508FE4}C:\program files\utorrent\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"UDP Query User{05A0B5DF-7D19-41C8-A704-EDB7FF9561E3}C:\program files\utorrent\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent|Desc=uTorrent
"{35656831-0F96-4AE7-84B7-80ABD02C2A59}"= UDP:52555:utor1
"{E7FC6750-7D3B-4B3A-900B-E7EBE5BD0494}"= UDP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{B11A941D-BACA-4B0E-AEF7-8CAB19B0B5F7}"= TCP:C:\Windows\System32\lxbkcoms.exe:Lexmark Communications System
"{0E690F73-7BE2-42B3-8E93-9149D1DA9C14}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window
"{0F122DF0-5137-4336-9DD4-FC51C50AC9A0}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbkpswx.exe:Printer Status Window

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-29 19:22]
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-02-06 23:04]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-02-06 23:04]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-02-06 23:04]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-04-04 17:54]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 14:46]
R2 AdwareAlertSrv;AdwareAlert Scanning Engine;"C:\Program Files\AdwareAlert\AdwareAlert.srv.exe" [2008-02-14 13:27]
R2 eDataSecurity Service;eDataSecurity Service;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-02-06 23:04]
R2 lxbk_device;lxbk_device;C:\Windows\system32\lxbkcoms.exe [2007-04-26 12:01]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-03-14 06:04]
R3 KFilter;KFilter;C:\PROGRA~1\AVANQU~1\SYSTEM~1\KFilter.sys [2007-09-11 02:32]
R3 MailScan;MailScan;C:\PROGRA~1\AVANQU~1\SYSTEM~1\MailScan.sys [2007-09-11 02:32]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-03-22 18:12]
S3 Radialpoint Security Services;AT&T; Internet Security Suite;C:\Windows\system32\dllhost.exe [2006-11-02 01:45]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6818ae31-d20c-11dc-8e7b-001c2552ea58}]
\shell\AutoRun\command - LinksysConnectPC.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5783dde-d202-11dc-8197-001c2552ea58}]
\shell\AutoRun\command - K:\RCAMemoryMgr.exe
\shell\Manage your videos\command - K:\RCAMemoryMgr.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 18:19:27
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\AT&T;\AT&T; Internet Security Suite\Fws.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~1\AVANQU~1\SYSTEM~1\mxtask.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Program Files\Avanquest\SystemSuite\MemCheck.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2008-02-26 18:22:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-27 02:22:38
ComboFix2.txt 2008-02-27 01:45:22
.
2008-02-17 01:05:47 — E O F —
At the moment my computer is acting more like normal than it has in days. Before now, if I clicked on anything in the start menu it would pop up and close immediately. Then my task bar would disappear. I just opened a folder from the start menu and it didn't close down like before and my taskbar is still showing.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:59:51 PM, on 2/25/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\lxbkjswx.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…/www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CDNSCacheObj Object - {376892AE-1825-4E5F-9F85-23F9640051CC} - C:\Windows\xmljacodec.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T\AT&T Internet Security Suite\pkR.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\Avanquest\SystemSuite\LinkScannerIE.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [Setresolution] C:\ACERSW\config\1440x900.cmd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [AT&T Internet Security Suite] "C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [303ebcd9] rundll32.exe "C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [lxbkbmgr.exe] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\mom\AppData\Local\Temp\hgday.dll,#1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: AdwareAlert Scanning Engine (AdwareAlertSrv) - Unknown owner - C:\Program Files\AdwareAlert\AdwareAlert.srv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: AT&T Internet Security Suite Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
O23 - Service: AT&T Internet Security Suite AT&T Firewall (RP_FWS) - AT&T - C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
O23 - Service: SystemSuite Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe

–
End of file - 10912 bytes
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O2 - BHO: CDNSCacheObj Object - {376892AE-1825-4E5F-9F85-23F9640051CC} - C:\Windows\xmljacodec.dll
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [303ebcd9] rundll32.exe "C:\Users\mom\AppData\Local\Temp\rfgumhtc.dll",b
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\mom\AppData\Local\Temp\hgday.dll,#1
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm

Close ALL windows and browsers except HijackThis and click "Fix checked"


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
There was only one of those in my list so I checked it and fixed it.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:47:33 PM, on 2/26/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Lexmark X1100 Series\LXBKbmgr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\Explorer.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…/www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T\AT&T Internet Security Suite\pkR.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\Avanquest\SystemSuite\LinkScannerIE.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [Setresolution] C:\ACERSW\config\1440x900.cmd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [AT&T Internet Security Suite] "C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [VirusScannerPro] C:\PROGRA~1\AVANQU~1\SYSTEM~1\MemCheck.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [lxbkbmgr.exe] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (User 'Default user')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: AdwareAlert Scanning Engine (AdwareAlertSrv) - Unknown owner - C:\Program Files\AdwareAlert\AdwareAlert.srv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbk_device - - C:\Windows\system32\lxbkcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: AT&T Internet Security Suite Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
O23 - Service: AT&T Internet Security Suite AT&T Firewall (RP_FWS) - AT&T - C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SystemSuite Task Manager - Avanquest Software USA, Inc. - C:\PROGRA~1\AVANQU~1\SYSTEM~1\MXTask.exe

–
End of file - 10183 bytes
Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]




    Log looks good :D


    You need to create a new Clean restore point.

    Note: This will remove all previous Restore Points

    Click Start Menu > Run > copy and paste

    %SystemRoot%\System32\restore\rstrui.exe

    Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.
Thank you so much for you help. Big cyber hugs to you. Also wanted to ask, where does this virus or spyware come from so I can try to NOT get it again?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI