Hi here are those two logs.....
Logfile of HijackThis v1.99.1
Scan saved at 7:48:24 PM, on 10/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\tcpip.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Thinkpad\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKLM\..\Run: [StorageGuard] "c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [loaddr] C:\DOCUME~1\Thinkpad\LOCALS~1\Temp\fred.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: Update ThinkPad Software - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\ThinkPad\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?LinkID=39204O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://download.ewid...oOnlineScan.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1160698891503O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1160698870963O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) -
http://www-307.ibm.c...rt/IbmEgath.cabO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
Thinkpad - 06-10-29 19:48:53.32 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Thinkpad\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-09-29 to 2006-10-29 ))))))))))))))))))))))))))))))))))
2006-10-29 07:59 7,105 --a------ C:\WINDOWS\system32\dlh9jkdq7.exe
2006-10-29 07:59 6,593 --a------ C:\WINDOWS\system32\dlh9jkdq6.exe
2006-10-29 07:59 18,369 --a------ C:\WINDOWS\system32\dlh9jkdq2.exe
2006-10-29 07:50 15 --a------ C:\WINDOWS\system32\dlh9jkdq8.exe
2006-10-28 10:24 160,768 --a------ C:\WINDOWS\system32\mkhrq.dll
2006-10-27 23:10 217,346 --a------ C:\WINDOWS\srvfdbgoww.exe
2006-10-25 19:51 816,288 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-10-25 19:51 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2006-10-25 19:51 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-10-25 19:51 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-10-25 19:51 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2006-10-25 19:51 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-10-25 19:51 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-10-25 10:12 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-24 13:37 17,920 --a------ C:\WINDOWS\system32\tcpip.exe
2006-10-24 13:37 1,259 --a------ C:\WINDOWS\system32\iog4dbc8.sys
2006-10-17 09:52 38,229 --------- C:\WINDOWS\system32\drivers\StMp3Rec.sys
2006-10-14 17:39 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2006-10-13 19:24 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2006-10-12 19:51 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2006-10-12 19:51 39,936 --a------ C:\WINDOWS\system32\mf3216.dll
2006-10-12 19:51 331,264 --a------ C:\WINDOWS\system32\ipnathlp.dll
2006-10-12 19:49 947,472 --a------ C:\WINDOWS\system32\msjava.dll
2006-10-12 19:49 63,248 --a------ C:\WINDOWS\system32\javaprxy.dll
2006-10-12 19:49 49,424 --a------ C:\WINDOWS\system32\clspack.exe
2006-10-12 19:49 46,352 --a------ C:\WINDOWS\setdebug.exe
2006-10-12 19:49 404,752 --a------ C:\WINDOWS\system32\javart.dll
2006-10-12 19:49 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2006-10-12 19:49 286,992 --a------ C:\WINDOWS\system32\vmhelper.dll
2006-10-12 19:49 21,264 --a------ C:\WINDOWS\system32\msjdbc10.dll
2006-10-12 19:49 187,152 --a------ C:\WINDOWS\system32\javacypt.dll
2006-10-12 19:49 172,304 --a------ C:\WINDOWS\system32\jview.exe
2006-10-12 19:49 171,792 --a------ C:\WINDOWS\system32\wjview.exe
2006-10-12 19:49 171,280 --a------ C:\WINDOWS\system32\jit.dll
2006-10-12 19:49 154,384 --a------ C:\WINDOWS\system32\msawt.dll
2006-10-12 19:49 15,120 --a------ C:\WINDOWS\system32\jdbgmgr.exe
2006-10-12 19:49 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2006-10-12 19:49 113 --a------ C:\WINDOWS\system32\zonedon.reg
2006-10-12 19:49 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2006-10-12 19:44 1,082,368 --a------ C:\WINDOWS\system32\esent.dll
2006-10-12 19:27 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-10-12 19:24 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2006-10-12 19:24 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2006-10-12 19:24 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2006-10-12 19:24 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2006-10-12 19:21 465,176 --a------ C:\WINDOWS\system32\wuapi.dll
2006-10-12 19:21 41,240 --a------ C:\WINDOWS\system32\wups.dll
2006-10-12 19:21 194,328 --a------ C:\WINDOWS\system32\wuaueng1.dll
2006-10-12 19:21 18,200 --a------ C:\WINDOWS\system32\wups2.dll
2006-10-12 19:21 172,312 --a------ C:\WINDOWS\system32\wuauclt1.exe
2006-10-12 19:21 127,256 --a------ C:\WINDOWS\system32\wucltui.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-10-29 19:43 7371 --ahs---- C:\Documents and Settings\Thinkpad\Application Data\F873E073A50F40A2B71BA6964213C7D4.sta
2006-10-29 19:43 17414 --ahs---- C:\Documents and Settings\Thinkpad\Application Data\F873E073A50F40A2B71BA6964213C7D4.rul
2006-10-29 19:41 -------- d-------- C:\Program Files\Common Files
2006-10-29 19:37 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-29 08:00 -------- d-------- C:\Documents and Settings\Thinkpad\Application Data\AVG7
2006-10-28 19:34 -------- d-------- C:\Program Files\Spider Wizard
2006-10-27 22:41 -------- d--h----- C:\Program Files\BHO Plugin
2006-10-27 11:59 -------- d-------- C:\Program Files\Common Files\Real
2006-10-27 11:57 -------- d-------- C:\Program Files\GameFiesta
2006-10-27 01:19 -------- d-------- C:\Program Files\Real
2006-10-26 22:58 774144 --a------ C:\Program Files\RngInterstitial.dll
2006-10-26 21:50 -------- d-------- C:\Program Files\BFG
2006-10-26 16:52 -------- d-------- C:\Program Files\Outlook Express
2006-10-26 16:52 -------- d-------- C:\Program Files\Common Files\System
2006-10-26 06:27 -------- d-------- C:\Program Files\TryMedia
2006-10-26 05:24 -------- d-------- C:\Program Files\Windows Defender
2006-10-26 05:24 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-10-26 05:22 -------- d---s---- C:\Documents and Settings\Thinkpad\Application Data\Microsoft
2006-10-25 19:51 -------- d-------- C:\Program Files\Grisoft
2006-10-25 19:38 -------- d-------- C:\Program Files\Messenger
2006-10-25 19:38 -------- d-------- C:\Program Files\Internet Explorer
2006-10-25 16:26 -------- d-------- C:\Program Files\Windows Media Player
2006-10-25 16:23 -------- d-------- C:\Program Files\Movie Maker
2006-10-25 16:20 -------- d-------- C:\Program Files\NetMeeting
2006-10-25 16:19 -------- d-------- C:\Program Files\Windows NT
2006-10-25 13:13 -------- d-------- C:\Program Files\MSN Gaming Zone
2006-10-25 11:12 -------- d-------- C:\Program Files\PCFriendly
2006-10-25 11:09 -------- d-------- C:\Program Files\Ares
2006-10-25 10:13 -------- d-------- C:\Documents and Settings\Thinkpad\Application Data\MSN6
2006-10-24 19:28 -------- d-------- C:\Documents and Settings\Thinkpad\Application Data\Mozilla
2006-10-24 19:07 -------- d-------- C:\Program Files\XoftSpySE
2006-10-24 13:46 -------- d--h----- C:\Program Files\WindowsUpdate
2006-10-24 13:37 -------- d-------- C:\Program Files\em
2006-10-22 08:16 -------- d-------- C:\Program Files\ReflexiveArcade
2006-10-18 16:21 -------- d-------- C:\Program Files\Common Files\Adobe
2006-10-18 16:20 -------- d-------- C:\Program Files\Adobe
2006-10-18 16:20 -------- d-------- C:\Documents and Settings\Thinkpad\Application Data\InterTrust
2006-10-18 16:20 -------- d-------- C:\Documents and Settings\Thinkpad\Application Data\Adobe
2006-10-18 16:14 -------- d-------- C:\Documents and Settings\Thinkpad\Application Data\Sun
2006-10-17 10:05 -------- d-------- C:\Program Files\iTunes
2006-10-17 10:05 -------- d-------- C:\Program Files\iPod
2006-10-17 10:03 -------- d-------- C:\Program Files\QuickTime
2006-10-17 10:02 -------- d-------- C:\Program Files\Apple Software Update
2006-10-17 09:54 -------- d-------- C:\Documents and Settings\Thinkpad\Application Data\Apple Computer
2006-10-14 16:56 -------- d-------- C:\Documents and Settings\Thinkpad\Application Data\Goodsol
2006-10-13 19:04 -------- d-------- C:\Program Files\LimeWire
2006-10-13 18:57 -------- d-------- C:\Program Files\Java
2006-10-13 18:55 -------- d-------- C:\Program Files\Common Files\Java
2006-10-11 17:04 -------- d-------- C:\Documents and Settings\Thinkpad\Application Data\Lavasoft
2006-10-11 17:03 -------- d-------- C:\Program Files\Lavasoft
2006-09-15 16:16 53248 --a------ C:\WINDOWS\uni_e6h.exe
2006-09-13 00:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-08-25 10:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-16 06:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"tgcmd"=""
"ibmmessages"="C:\\Program Files\\IBM\\Messages By IBM\\ibmmessages.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ares"="\"C:\\Program Files\\Ares\\Ares.exe\" -h"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"S3TRAY2"="S3Tray2.exe"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"BluetoothAuthenticationAgent"="rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent"
"TPHOTKEY"="C:\\PROGRA~1\\ThinkPad\\PkgMgr\\HOTKEY\\TPHKMGR.exe"
"BMMGAG"="RunDll32 C:\\PROGRA~1\\ThinkPad\\UTILIT~1\\pwrmonit.dll,StartPwrMonitor"
"BMMLREF"="C:\\Program Files\\ThinkPad\\Utilities\\BMMLREF.EXE"
"TPKMAPMN"="C:\\Program Files\\ThinkPad\\Utilities\\TpKmapMn.exe"
"TP4EX"="tp4ex.exe"
"EZEJMNAP"="C:\\PROGRA~1\\ThinkPad\\UTILIT~1\\EzEjMnAp.Exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"UC_SMB"=""
"tgcmd"=""
"ibmmessages"="C:\\Program Files\\IBM\\Messages By IBM\\ibmmessages.exe"
"StorageGuard"="\"c:\\Program Files\\VERITAS Software\\Update Manager\\sgtray.exe\" /r"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"QCTRAY"="C:\\Program Files\\ThinkPad\\ConnectUtilities\\QCTRAY.EXE"
"QCWLICON"="C:\\Program Files\\ThinkPad\\ConnectUtilities\\QCWLICON.EXE"
"AGRSMMSG"="AGRSMMSG.exe"
"TPKMAPHELPER"="C:\\Program Files\\ThinkPad\\Utilities\\TpKmapAp.exe -helper"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMax4PNP.exe"
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
"PRONoMgrWired"="C:\\Program Files\\Intel\\PROSetWired\\NCS\\PROSet\\PRONoMgr.exe"
"McAfee.InstantUpdate.Monitor"="\"C:\\Program Files\\McAfee\\McAfee Shared Components\\Instant Updater\\RuLaunch.exe\" /startmonitor"
"McAfee Guardian"="\"C:\\Program Files\\McAfee\\McAfee Shared Components\\Guardian\\CMGrdian.exe\" /SU"
"WorksFUD"="C:\\Program Files\\Microsoft Works\\wkfud.exe"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"Microsoft Works Update Detection"="C:\\Program Files\\Microsoft Works\\WkDetect.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"loaddr"="C:\\DOCUME~1\\Thinkpad\\LOCALS~1\\Temp\\fred.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="C:\\Program Files\\MSN Gaming Zone\\pokof.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\Program Files\\Windows NT\\mehecyw.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,ec,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,52,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{2C1CD3D7-86AC-4068-93BC-A02304BB2236}"="DCOM Server 2236"
"{2C1CD3D7-86AC-4068-93BC-A02304BB2234}"="DCOM Server 2234"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\instcat
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rpcc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wavecr
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winsys2freg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\BMMTask.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\XoftSpySE.job
Completion time: 06-10-29 19:50:20.66
C:\ComboFix.txt ... 06-10-29 19:50
C:\ComboFix2.txt ... 06-10-29 19:36
C:\ComboFix3.txt ... 06-10-27 23:07