Ok thank you. here is my combofix log. I have run it before though, would it be helpfull to include my other combofix logs?
ComboFix 08-03-07.1 - Christian 2008-03-08 14:35:03.3 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.390 [GMT -5:00]
Running from: C:\Users\Christian\Desktop\Combo-Fix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-02-08 to 2008-03-08 )))))))))))))))))))))))))))))))
.
2008-03-07 16:04 . 2008-03-07 16:13 <DIR> d-------- C:\ComboFix
2008-03-04 19:50 . 2008-03-04 19:50 0 --a------ C:\Windows\System32\AHK
2008-03-04 19:26 . 2008-03-04 19:26 <DIR> d-------- C:\Users\Christian\AppData\Roaming\Uniblue
2008-02-29 18:06 . 2008-03-04 20:53 <DIR> d-------- C:\SDFix
2008-02-27 17:22 . 2008-02-27 17:22 <DIR> d-------- C:\Users\Christian\AppData\Roaming\SUPERAntiSpyware.com
2008-02-27 17:22 . 2008-02-27 17:22 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-02-27 17:22 . 2008-02-27 17:22 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
2008-02-27 17:22 . 2008-02-29 14:54 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-27 17:21 . 2008-02-27 17:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-12 16:01 . 2008-02-12 16:01 <DIR> d-------- C:\_OTMoveIt
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-08 13:00 --------- d-----w C:\Users\Christian\AppData\Roaming\AVG7
2008-03-08 09:00 --------- d-----w C:\Program Files\Steam
2008-03-06 20:04 --------- d-----w C:\ProgramData\Google Updater
2008-02-12 05:11 --------- d-----w C:\ProgramData\Symantec
2008-02-12 05:11 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-10 18:06 --------- d-----w C:\Program Files\Brain Bullet!
2008-02-07 01:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-07 01:15 --------- d-----w C:\Program Files\Full Tilt Poker
2008-02-01 01:42 --------- d-----w C:\Program Files\TrustyFiles
2008-02-01 01:32 --------- d---a-w C:\ProgramData\TEMP
2008-01-30 23:18 9,216 ----a-w C:\Windows\System32\avgwlntf.dll
2008-01-30 23:18 47,104 ----a-w C:\Windows\system32\drivers\avgwfp.sys
2008-01-30 23:18 --------- d-----w C:\ProgramData\Grisoft
2008-01-30 23:18 --------- d-----w C:\Program Files\whadda
2008-01-30 23:16 --------- d-----w C:\ProgramData\avg7
2008-01-30 21:07 --------- d-----w C:\Program Files\ESRI
2008-01-30 21:06 --------- d-----w C:\Users\Christian\AppData\Roaming\ESRI
2008-01-30 20:53 --------- d-----w C:\ProgramData\ESRI
2008-01-30 20:53 --------- d-----w C:\Program Files\Common Files\ESRI
2008-01-30 20:53 --------- d-----w C:\Program Files\ArcGIS
2008-01-30 20:51 --------- d-----w C:\Program Files\Leica Geosystems
2008-01-30 20:46 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-30 19:53 --------- d-----w C:\Program Files\dssd
2008-01-30 01:09 --------- d-----w C:\Program Files\MSN Messenger
2008-01-29 04:57 --------- d-----w C:\Users\Christian\AppData\Roaming\PC Tools
2008-01-29 04:31 --------- d-----w C:\Program Files\Common Files\PC Tools
2008-01-28 23:49 --------- d-----w C:\Users\Christian\AppData\Roaming\ErrorSmart
2008-01-27 19:04 --------- d-----w C:\ProgramData\PurePlay
2008-01-27 19:04 --------- d-----w C:\Program Files\PurePlay
2008-01-27 10:56 --------- d-----w C:\Program Files\Common Files\xing shared
2008-01-27 10:56 --------- d-----w C:\Program Files\Common Files\Real
2008-01-27 10:55 --------- d-----w C:\Program Files\Real
2008-01-27 10:49 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-27 10:45 --------- d-----w C:\Program Files\DivX
2008-01-27 10:44 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-01-27 10:39 --------- d-----w C:\Program Files\Google
2008-01-27 10:19 --------- d-----w C:\Program Files\PS
2008-01-17 21:34 --------- d-----w C:\Program Files\SPSS
2008-01-17 21:23 --------- d-----w C:\Users\Christian\AppData\Roaming\gtk-2.0
2008-01-17 21:19 --------- d-----w C:\ProgramData\Protexis
2008-01-17 21:17 --------- d-----w C:\Program Files\GIMP-2.0
2008-01-15 03:13 --------- d-----w C:\Program Files\ATI
2008-01-09 17:41 --------- d-----w C:\Program Files\Ubisoft
2008-01-09 11:18 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-01-09 11:18 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-01-09 11:18 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-01-09 11:18 129,784 ------w C:\Windows\System32\pxafs.dll
2008-01-09 11:18 120,056 ------w C:\Windows\System32\pxcpyi64.exe
2008-01-09 11:18 118,520 ------w C:\Windows\System32\pxinsi64.exe
2008-01-09 11:18 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-01-09 11:16 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-01-09 11:16 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-01-09 11:16 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-01-09 11:16 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-01-09 11:16 682,496 ----a-w C:\Windows\System32\DivX.dll
2008-01-09 11:16 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-01-09 08:16 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-09 08:16 --------- d-----w C:\Program Files\Windows Mail
2008-01-09 08:08 802,816 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-01-09 08:08 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-01-09 08:08 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-01-09 08:08 216,760 ----a-w C:\Windows\system32\drivers\netio.sys
2008-01-09 08:08 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-01-09 08:06 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-09 08:06 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-09 08:05 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-09 08:05 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-01-09 08:05 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-09 08:05 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-09 08:05 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-01-09 08:05 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-09 08:05 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-01-09 08:05 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-01-09 08:05 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-09 08:05 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-01-09 08:05 1,686,016 ----a-w C:\Windows\System32\gameux.dll
2008-01-09 08:05 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2007-12-21 10:11 704,793 ----a-w C:\Windows\unins000.exe
2007-12-12 02:32 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 02:32 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-12 02:32 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-12 02:31 824,832 ----a-w C:\Windows\System32\wininet.dll
2007-12-12 02:31 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-12 02:31 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 02:31 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-12 02:28 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-12 02:28 3,470,520 ----a-w C:\Windows\System32\ntoskrnl.exe
2007-12-11 19:44 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2007-12-11 19:44 57,344 ----a-w C:\Windows\System32\dpv11.dll
2007-12-11 19:44 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2007-12-11 19:44 344,064 ----a-w C:\Windows\System32\dpus11.dll
2007-12-11 19:44 294,912 ----a-w C:\Windows\System32\dpu11.dll
2007-12-11 19:44 294,912 ----a-w C:\Windows\System32\dpu10.dll
2007-12-11 19:44 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2007-12-11 19:43 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2007-09-01 11:43 24,265,736 ----a-w C:\Users\Christian\dotnetfx.exe
2007-08-31 07:12 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 03:05 1232896]
"TOSCDSPD"="TOSCDSPD.EXE" []
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-07-26 23:34 160832]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 05:27 219520]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:34 201728]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-01-14 22:11 1266936]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
"Uniblue RegistryBooster 2"="c:\program files\regbo\StartRegistryBooster.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-07-16 20:43 1006264]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 20:12 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-07 01:50 3772416 C:\Windows\RtHDVCpl.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-27 00:50 815104]
"NDSTray.exe"="NDSTray.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-08 16:26 155648]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2005-12-16 05:41 188416]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-12 10:39 411768]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2006-12-11 16:45 448632]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2006-12-11 16:27 530552]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-27 05:55 185632]
"AVG7_CC"="C:\PROGRA~1\whadda\avgcc.exe" [2008-01-30 18:18 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\whadda\avgw.exe" [2008-01-30 18:18 219136]
C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ubisoft register.lnk - C:\Program Files\Ubisoft\Register\schedule.exe [2008-01-09 12:41:50 28672]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-01-27 05:39:49 124400]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2008-01-30 18:18 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ErrorSmart]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gamevance]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1430707493-1218470823-3647551161-1000]
"EnableNotificationsRef"=dword:00000004
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{7DA21F9D-439D-440E-8928-68B13C0BD4AF}C:\program files\emule\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule|Desc=eMule
"UDP Query User{2138F8AE-BB66-4B9C-905E-FE9328B0DFF4}C:\program files\emule\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule|Desc=eMule
"{3155DF8C-707C-4E5E-B40D-B71262A174CB}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{C554CA93-1130-4C9E-8151-E457E1FCBD7C}"= UDP:C:\Program Files\Morpheus\Morpheus.exe:Morpheus
"{F42A0312-647C-4BA4-B6DF-F9E85A8807BA}"= TCP:C:\Program Files\Morpheus\Morpheus.exe:Morpheus
"{44567228-F51E-4007-A017-FA75BA579384}"= UDP:C:\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
"{73BD8D77-9C4B-4618-8569-132A03C5A288}"= TCP:C:\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
"{7BC5A10D-3D1E-41FF-AA9A-E7FA193262A0}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{F89F7BD6-F31E-4B86-81EC-C464AFDB3223}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E859015F-CE60-4E72-B3E6-F15714D3A464}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5D0EB16F-FF55-459D-BB38-8E016341ABA4}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{F57B4DF7-CC91-4D5D-B36C-0B2B1EE1FBB3}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{6504310E-042D-4FE5-912D-33CF8186BC47}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{65329195-9B13-490D-86F9-DA6EAE684D0D}"= UDP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{99367266-C791-446A-8818-27EA0C0AF1A8}"= TCP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{6F0A8113-80B1-4254-B201-336699A4BF9E}"= UDP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords.exe:Sid Meier's Civilization 4 Warlords
"{A942B85B-04DA-4721-A96D-749CD335E243}"= TCP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords.exe:Sid Meier's Civilization 4 Warlords
"{8B9A483F-C702-4C25-9628-7F3C56C013AA}"= UDP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords_PitBoss.exe:Sid Meier's Civilization 4 Pitboss
"{1F420B2B-1376-4554-BE0C-3903E9523A75}"= TCP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords_PitBoss.exe:Sid Meier's Civilization 4 Pitboss
"{B8CC146D-DCDA-4120-9C85-80C9F313E49E}"= UDP:C:\Users\Christian\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
"{221A0629-DBB0-4D84-8C26-B25B2FB747B1}"= TCP:C:\Users\Christian\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
"TCP Query User{F04D2388-2F47-42D9-8D66-C5ED89AC69EF}C:\program files\emule\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule|Desc=eMule
"UDP Query User{4489E1C8-755B-46C8-8086-58B72A7135D9}C:\program files\emule\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule|Desc=eMule
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\BitTorrent\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 10:22]
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2006-11-10 16:38]
R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2008-01-30 18:18]
R3 FwLnk;FwLnk Driver;C:\Windows\system32\DRIVERS\FwLnk.sys [2006-11-20 01:11]
R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-24 08:46]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 14:50]
S3 ELIXGKQFW;ELIXGKQFW;C:\Users\CHRIST~1\AppData\Local\Temp\ELIXGKQFW.exe []
S3 GDJPUMJZYVOE;GDJPUMJZYVOE;C:\Users\CHRIST~1\AppData\Local\Temp\GDJPUMJZYVOE.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
"2008-03-08 08:30:00 C:\Windows\Tasks\ErrorSmart Scheduled Scan.job"
- C:\Program Files\ErrorSmart\ErrorSmart.ex
- C:\Program Files\ErrorSmar
"2008-03-08 08:59:35 C:\Windows\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-02-28 08:06:26 C:\Windows\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-03-08 00:13:30 C:\Windows\Tasks\User_Feed_Synchronization-{E103F4D4-3664-4AD6-BCCC-49CC712AD4C0}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-08 14:38:01
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-08 14:38:59
ComboFix-quarantined-files.txt 2008-03-08 19:38:56
ComboFix2.txt 2008-03-07 21:13:07
ComboFix3.txt 2008-03-07 20:42:20
ComboFix4.txt 2008-03-01 23:25:46
ComboFix5.txt 2008-01-31 02:12:59
.
2008-01-09 08:08:57 --- E O F ---
and here is another HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:43:22 PM, on 08/03/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ltmoh\ltmoh.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
G:\HJT\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.ca/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\whadda\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\regbo\StartRegistryBooster.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\whadda\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\whadda\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\whadda\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Ubisoft register.lnk = C:\Program Files\Ubisoft\Register\schedule.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www.yorkphoto...YorkActivia.cabO16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) -
https://media.pineco...loadcontrol.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\whadda\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\whadda\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\whadda\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\whadda\avgemc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: ELIXGKQFW - Unknown owner - C:\Users\CHRIST~1\AppData\Local\Temp\ELIXGKQFW.exe (file missing)
O23 - Service: GDJPUMJZYVOE - Unknown owner - C:\Users\CHRIST~1\AppData\Local\Temp\GDJPUMJZYVOE.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: RYUADZR - Sysinternals - www.sysinternals.com - C:\Windows\system32\config\SYSTEM~1\AppData\Local\Temp\RYUADZR.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: UTBTYGBVRDZ - Unknown owner - C:\Users\CHRIST~1\AppData\Local\Temp\UTBTYGBVRDZ.exe (file missing)
O23 - Service: YAG - Unknown owner - C:\Users\CHRIST~1\AppData\Local\Temp\YAG.exe (file missing)
--
End of file - 11235 bytes