Ok, here is my combofix log:
ComboFix 08-03-30.2 - Samara 2008-03-30 14:06:16.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.650 [GMT -5:00]
Running from: C:\Documents and Settings\Samara\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\{B8E7A79E-CAA4-4C59-A212-780FC2D1B0A8}.exe
C:\WINDOWS\system32\{EF7F68B2-0A49-4C46-BBB6-0A085C9B764F}.exe
.
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-30 )))))))))))))))))))))))))))))))
.
2008-03-30 11:23 . 2008-03-30 11:23 <DIR> d-------- C:\Documents and Settings\Samara\Application Data\Grisoft
2008-03-30 11:23 . 2008-03-30 11:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-30 11:23 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-30 10:51 . 2008-03-30 10:51 <DIR> d-------- C:\WINDOWS\system32\bits
2008-03-30 10:51 . 2008-03-30 14:04 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-03-30 10:51 . 2005-02-24 22:35 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-30 10:51 . 2008-03-30 10:51 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-03-30 10:48 . 2004-07-01 17:08 331,776 --a------ C:\WINDOWS\system32\winhttp.dll
2008-03-30 10:48 . 2004-06-30 18:59 158,720 --------- C:\WINDOWS\system32\xpob2res.dll
2008-03-30 10:48 . 2004-07-01 17:08 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-03-30 10:48 . 2004-07-01 17:08 7,680 -----c--- C:\WINDOWS\system32\dllcache\bitsprx2.dll
2008-03-30 10:48 . 2004-07-01 17:08 7,680 --------- C:\WINDOWS\system32\bitsprx2.dll
2008-03-30 10:48 . 2004-07-01 17:08 7,168 -----c--- C:\WINDOWS\system32\dllcache\bitsprx3.dll
2008-03-30 10:48 . 2004-07-01 17:08 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2008-03-30 10:44 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2008-03-30 10:44 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2008-03-30 10:44 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-03-30 10:44 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-03-30 10:44 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-03-30 10:44 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2008-03-30 10:44 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-03-30 10:44 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-03-30 10:44 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-03-30 10:40 . 2008-03-30 10:40 <DIR> d-------- C:\Program Files\Lavasoft
2008-03-30 10:40 . 2008-03-30 10:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-30 10:02 . 2008-03-29 13:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-03-29 10:52 . 2008-03-29 10:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-29 10:52 . 2008-03-29 10:52 <DIR> d-------- C:\Documents and Settings\Samara\Application Data\Malwarebytes
2008-03-29 10:52 . 2008-03-29 10:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-29 09:33 . 2008-03-29 09:33 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-29 09:33 . 2008-03-29 09:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-29 09:22 . 2002-08-29 03:41 286,720 --a------ C:\WINDOWS\system32\msh263.drv
2008-03-29 09:22 . 2002-08-29 03:41 49,664 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-03-29 09:22 . 2002-08-29 03:41 49,664 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-03-29 09:22 . 2001-08-17 22:36 45,568 --a------ C:\WINDOWS\system32\iyuv_32.dll
2008-03-29 09:22 . 2001-08-17 22:36 45,568 --a--c--- C:\WINDOWS\system32\dllcache\iyuv_32.dll
2008-03-29 09:22 . 2002-08-29 01:48 14,208 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-03-29 09:22 . 2002-08-29 01:48 14,208 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-03-29 09:22 . 2001-08-17 22:36 8,192 --a------ C:\WINDOWS\system32\tsbyuv.dll
2008-03-29 09:22 . 2001-08-17 22:36 8,192 --a--c--- C:\WINDOWS\system32\dllcache\tsbyuv.dll
2008-03-29 09:21 . 2003-04-07 13:22 424,143 --a------ C:\WINDOWS\system32\drivers\SonyVcc.sys
2008-03-29 09:21 . 2003-04-07 13:22 43,984 --a------ C:\WINDOWS\system32\drivers\snyluvcc.sys
2008-03-29 09:06 . 2003-08-25 18:06 182,880 --a------ C:\WINDOWS\system32\iuengine.dll
2008-03-29 09:06 . 2003-08-25 18:06 182,880 --a--c--- C:\WINDOWS\system32\dllcache\iuengine.dll
2008-03-29 00:48 . 2008-03-29 00:48 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-28 21:36 . 2008-03-28 22:12 <DIR> d-------- C:\VundoFix Backups
2008-03-28 06:41 . 2008-03-28 06:42 1,488,236 --ahs---- C:\WINDOWS\system32\jksfught.ini
2008-03-27 23:08 . 2008-03-30 11:36 <DIR> d-------- C:\found.001
2008-03-26 07:27 . 2008-03-26 07:27 <DIR> d-------- C:\Program Files\CCleaner
2008-03-26 07:24 . 2008-03-26 07:24 <DIR> d-------- C:\Program Files\Bazooka Scanner
2008-03-24 07:26 . 2008-03-28 05:42 1,488,176 --ahs---- C:\WINDOWS\system32\mhlsvrfh.ini
2008-03-24 00:02 . 2008-03-24 07:18 1,541,923 --ahs---- C:\WINDOWS\system32\vuqplewf.ini
2008-03-23 19:44 . 2008-03-28 21:06 54,584 --a------ C:\WINDOWS\system32\drivers\sbapifs.sys
2008-03-23 19:42 . 2008-03-23 19:42 <DIR> d-------- C:\Documents and Settings\Samara\Application Data\Sunbelt Software
2008-03-17 20:21 . 2008-03-17 20:21 <DIR> d-------- C:\found.000
2008-03-17 16:38 . 2008-03-23 23:53 1,775,968 --ahs---- C:\WINDOWS\system32\lhnlmtmq.ini
2008-03-14 08:54 . 2008-03-14 08:54 1,304,536 --ahs---- C:\WINDOWS\system32\gbqmpknk.ini
2008-03-12 23:39 . 2008-03-13 23:41 1,383,775 --ahs---- C:\WINDOWS\system32\ohmmgigi.ini
2008-03-10 16:53 . 2008-03-11 14:45 1,318,223 --ahs---- C:\WINDOWS\system32\dydbwaqo.ini
2008-03-09 13:44 . 2008-03-10 16:45 1,318,043 --ahs---- C:\WINDOWS\system32\gpsavdqk.ini
2008-03-08 13:41 . 2008-03-09 13:42 1,307,801 --ahs---- C:\WINDOWS\system32\hgkcxill.ini
2008-03-07 12:31 . 2008-03-08 13:36 1,307,681 --ahs---- C:\WINDOWS\system32\mortikbi.ini
2008-03-06 10:36 . 2008-03-06 10:36 1,306,943 --ahs---- C:\WINDOWS\system32\useedfoc.ini
2008-03-05 10:27 . 2008-03-05 10:27 1,306,943 --ahs---- C:\WINDOWS\system32\pxtbaoaq.tmp
2008-03-05 10:27 . 2008-03-05 10:27 1,306,883 --ahs---- C:\WINDOWS\system32\pxtbaoaq.ini
2008-03-03 15:45 . 2008-03-05 10:24 1,306,883 --ahs---- C:\WINDOWS\system32\cnhofvvd.ini
2008-03-02 21:06 . 2008-03-30 13:53 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-02 21:06 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-02 21:06 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-02 21:06 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-02 21:06 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-03-02 21:05 . 2008-03-02 21:05 <DIR> d-------- C:\Documents and Settings\Samara\Application Data\PC Tools
2008-03-01 09:00 . 2008-03-01 09:00 1,286,141 --ahs---- C:\WINDOWS\system32\rqfqltxm.tmp
2008-02-24 13:54 . 2008-02-29 23:38 <DIR> d-------- C:\WINDOWS\system32\ez2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-30 15:36 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-29 18:45 1,146,232 ----a-w C:\WINDOWS\system32\aswBoot.exe
2008-03-29 18:35 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-29 18:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-29 18:27 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-29 18:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-29 18:23 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2008-03-29 07:51 --------- d-----w C:\Program Files\Spyware Doctor
2008-03-25 06:40 --------- d-----w C:\Program Files\adsoft
2008-03-17 09:27 65,536 ----a-w C:\WINDOWS\DUMPad0f.tmp
2008-03-17 09:25 65,536 ----a-w C:\WINDOWS\DUMPa76d.tmp
2008-03-17 09:23 65,536 ----a-w C:\WINDOWS\DUMPab43.tmp
2008-03-17 09:21 65,536 ----a-w C:\WINDOWS\DUMPa1f3.tmp
2008-03-17 09:19 65,536 ----a-w C:\WINDOWS\DUMPa96c.tmp
2008-03-17 09:17 65,536 ----a-w C:\WINDOWS\DUMPb0ef.tmp
2008-03-17 09:14 65,536 ----a-w C:\WINDOWS\DUMPafb8.tmp
2008-03-17 09:12 65,536 ----a-w C:\WINDOWS\DUMPab7f.tmp
2008-03-17 09:10 65,536 ----a-w C:\WINDOWS\DUMPadd7.tmp
2008-03-17 09:08 65,536 ----a-w C:\WINDOWS\DUMPb1d5.tmp
2008-03-17 09:06 65,536 ----a-w C:\WINDOWS\DUMPaff4.tmp
2008-03-17 09:04 65,536 ----a-w C:\WINDOWS\DUMPb912.tmp
2008-03-17 09:02 65,536 ----a-w C:\WINDOWS\DUMPb438.tmp
2008-03-17 08:59 65,536 ----a-w C:\WINDOWS\DUMPb899.tmp
2008-03-17 08:57 65,536 ----a-w C:\WINDOWS\DUMPa99e.tmp
2008-03-17 08:55 65,536 ----a-w C:\WINDOWS\DUMPae28.tmp
2008-03-17 08:53 65,536 ----a-w C:\WINDOWS\DUMPb6eb.tmp
2008-03-17 08:51 65,536 ----a-w C:\WINDOWS\DUMPa958.tmp
2008-03-17 08:48 65,536 ----a-w C:\WINDOWS\DUMPb167.tmp
2008-03-17 08:46 65,536 ----a-w C:\WINDOWS\DUMPa673.tmp
2008-03-17 08:44 65,536 ----a-w C:\WINDOWS\DUMPad2d.tmp
2008-03-17 08:41 65,536 ----a-w C:\WINDOWS\DUMPa9e4.tmp
2008-03-17 08:39 65,536 ----a-w C:\WINDOWS\DUMPa9bc.tmp
2008-03-17 08:37 65,536 ----a-w C:\WINDOWS\DUMPacdd.tmp
2008-03-17 08:35 65,536 ----a-w C:\WINDOWS\DUMPb930.tmp
2008-03-17 08:33 65,536 ----a-w C:\WINDOWS\DUMPa4ba.tmp
2008-03-17 08:31 65,536 ----a-w C:\WINDOWS\DUMPa3e8.tmp
2008-03-17 08:29 65,536 ----a-w C:\WINDOWS\DUMPae0a.tmp
2008-03-17 08:27 65,536 ----a-w C:\WINDOWS\DUMPb135.tmp
2008-03-17 08:25 65,536 ----a-w C:\WINDOWS\DUMPb6d7.tmp
2008-03-17 08:22 65,536 ----a-w C:\WINDOWS\DUMPae14.tmp
2008-03-17 08:20 65,536 ----a-w C:\WINDOWS\DUMPa410.tmp
2008-03-17 08:18 65,536 ----a-w C:\WINDOWS\DUMPb582.tmp
2008-03-17 08:16 65,536 ----a-w C:\WINDOWS\DUMPc008.tmp
2008-03-17 08:13 65,536 ----a-w C:\WINDOWS\DUMPaffe.tmp
2008-03-17 08:11 65,536 ----a-w C:\WINDOWS\DUMPad73.tmp
2008-03-17 08:09 65,536 ----a-w C:\WINDOWS\DUMPa803.tmp
2008-03-17 08:07 65,536 ----a-w C:\WINDOWS\DUMPb99e.tmp
2008-03-17 08:04 65,536 ----a-w C:\WINDOWS\DUMPa5aa.tmp
2008-03-17 08:02 65,536 ----a-w C:\WINDOWS\DUMPb550.tmp
2008-03-17 08:00 65,536 ----a-w C:\WINDOWS\DUMPb384.tmp
2008-03-17 07:57 65,536 ----a-w C:\WINDOWS\DUMPb980.tmp
2008-03-17 07:55 65,536 ----a-w C:\WINDOWS\DUMPabed.tmp
2008-03-17 07:53 65,536 ----a-w C:\WINDOWS\DUMPbb42.tmp
2008-03-17 07:51 65,536 ----a-w C:\WINDOWS\DUMPab39.tmp
2008-03-17 07:48 65,536 ----a-w C:\WINDOWS\DUMPb080.tmp
2008-03-17 07:46 65,536 ----a-w C:\WINDOWS\DUMPa4ec.tmp
2008-03-17 07:44 65,536 ----a-w C:\WINDOWS\DUMPa578.tmp
2008-03-17 07:42 65,536 ----a-w C:\WINDOWS\DUMPb1ad.tmp
2008-03-17 07:39 65,536 ----a-w C:\WINDOWS\DUMPabf7.tmp
2008-03-17 07:37 65,536 ----a-w C:\WINDOWS\DUMPb103.tmp
2008-03-17 07:35 65,536 ----a-w C:\WINDOWS\DUMPa60f.tmp
2008-03-17 07:33 65,536 ----a-w C:\WINDOWS\DUMPaaf2.tmp
2008-03-17 07:31 65,536 ----a-w C:\WINDOWS\DUMPaa02.tmp
2008-03-17 07:29 65,536 ----a-w C:\WINDOWS\DUMPa7f9.tmp
2008-03-17 07:27 65,536 ----a-w C:\WINDOWS\DUMPaeaa.tmp
2008-03-17 07:25 65,536 ----a-w C:\WINDOWS\DUMPaa16.tmp
2008-03-17 07:22 65,536 ----a-w C:\WINDOWS\DUMPa41a.tmp
2008-03-17 07:20 65,536 ----a-w C:\WINDOWS\DUMPad37.tmp
2008-03-17 07:18 65,536 ----a-w C:\WINDOWS\DUMPb2e3.tmp
2008-03-17 07:16 65,536 ----a-w C:\WINDOWS\DUMPb442.tmp
2008-03-17 07:13 65,536 ----a-w C:\WINDOWS\DUMPaf9a.tmp
2008-03-17 07:11 65,536 ----a-w C:\WINDOWS\DUMPb3de.tmp
2008-03-17 07:09 65,536 ----a-w C:\WINDOWS\DUMPad55.tmp
2008-03-17 07:07 65,536 ----a-w C:\WINDOWS\DUMPadcd.tmp
2008-03-17 07:05 65,536 ----a-w C:\WINDOWS\DUMPaee6.tmp
2008-03-17 07:03 65,536 ----a-w C:\WINDOWS\DUMPa44c.tmp
2008-03-17 07:00 65,536 ----a-w C:\WINDOWS\DUMPc347.tmp
2008-03-17 06:58 65,536 ----a-w C:\WINDOWS\DUMPb53c.tmp
2008-03-17 06:55 65,536 ----a-w C:\WINDOWS\DUMPb803.tmp
2008-03-03 02:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-03 02:23 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-08 19:17 --------- d-----w C:\Documents and Settings\Samara\Application Data\AdobeUM
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
.
((((((((((((((((((((((((((((( snapshot@2008-03-29_ 2.00.11.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-07-01 22:08:18 361,984 ----a-w C:\WINDOWS\LastGood\system32\bits\qmgr.dll
+ 2003-03-31 12:00:00 14,848 ----a-w C:\WINDOWS\LastGood\system32\cdm.dll
+ 2002-12-12 08:14:32 130,304 ----a-w C:\WINDOWS\LastGood\system32\drivers\ks.sys
+ 2003-04-07 20:22:02 43,984 ----a-w C:\WINDOWS\LastGood\system32\drivers\snyluvcc.sys
+ 2003-04-07 20:22:12 424,143 ----a-w C:\WINDOWS\LastGood\system32\drivers\SonyVcc.sys
+ 2002-08-29 01:48:52 14,208 ----a-w C:\WINDOWS\LastGood\system32\drivers\usbscan.sys
+ 2001-08-17 22:36:18 45,568 ----a-w C:\WINDOWS\LastGood\system32\iyuv_32.dll
+ 2002-12-12 08:14:32 4,096 ----a-w C:\WINDOWS\LastGood\system32\ksuser.dll
+ 2002-08-29 03:41:32 286,720 ----a-w C:\WINDOWS\LastGood\system32\msh263.drv
+ 2003-02-17 18:16:28 16,896 ----a-w C:\WINDOWS\LastGood\system32\msyuv.dll
+ 2003-03-31 12:00:00 221,696 ----a-w C:\WINDOWS\LastGood\system32\qmgr.dll
+ 2003-03-31 12:00:00 17,408 ----a-w C:\WINDOWS\LastGood\system32\qmgrprxy.dll
+ 2001-08-17 22:36:34 8,192 ----a-w C:\WINDOWS\LastGood\system32\tsbyuv.dll
+ 2002-08-29 03:41:18 49,664 ----a-w C:\WINDOWS\LastGood\system32\vfwwdm32.dll
+ 2003-03-31 12:00:00 310,272 ----a-w C:\WINDOWS\LastGood\system32\winhttp.dll
+ 2003-03-31 12:00:00 139,776 ----a-w C:\WINDOWS\LastGood\system32\wuauclt.exe
+ 2003-03-31 12:00:00 189,440 ----a-w C:\WINDOWS\LastGood\system32\wuaueng.dll
+ 2004-07-01 22:08:18 361,984 ------w C:\WINDOWS\system32\bits\qmgr.dll
- 2003-03-31 12:00:00 14,848 ----a-w C:\WINDOWS\system32\cdm.dll
+ 2007-07-31 00:19:20 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
- 2008-03-29 03:16:46 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-03-30 18:09:09 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-03-29 03:16:46 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-03-30 18:09:09 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-03-29 03:16:46 49,152 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-30 18:09:09 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-29 06:08:00 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT
+ 2008-03-30 18:46:48 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT
+ 2007-07-31 00:19:20 92,504 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2002-12-12 08:14:32 130,304 -c--a-w C:\WINDOWS\system32\dllcache\ks.sys
+ 2002-12-12 08:14:32 4,096 -c--a-w C:\WINDOWS\system32\dllcache\ksuser.dll
+ 2003-02-17 18:16:28 16,896 -c--a-w C:\WINDOWS\system32\dllcache\msyuv.dll
+ 2007-07-31 00:19:16 53,080 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2007-07-31 00:19:42 1,712,984 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
- 2007-12-04 14:56:02 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2007-07-11 18:37:26 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
+ 2007-08-07 17:58:08 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
+ 2007-08-07 17:56:58 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
+ 2005-05-24 17:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-10-11 19:12:48 1,468,968 ------w C:\WINDOWS\system32\LegitCheckControl.dll
- 2007-10-30 15:46:25 40,394 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-29 07:05:31 40,394 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-10-30 15:46:25 312,172 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-29 07:05:31 312,172 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2003-03-31 12:00:00 221,696 ----a-w C:\WINDOWS\system32\qmgr.dll
+ 2004-07-01 22:08:18 361,984 ----a-w C:\WINDOWS\system32\qmgr.dll
+ 2001-08-17 22:36:18 45,568 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\iyuv_32.dll
+ 2002-12-12 08:14:32 130,304 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\ks.sys
+ 2002-12-12 08:14:32 4,096 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\ksuser.dll
+ 2002-08-29 03:41:32 286,720 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\msh263.drv
+ 2003-02-17 18:16:28 16,896 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\msyuv.dll
+ 2001-08-17 22:36:34 8,192 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\tsbyuv.dll
+ 2002-08-29 01:48:52 14,208 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\usbscan.sys
+ 2002-08-29 03:41:18 49,664 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\i386\vfwwdm32.dll
+ 2003-04-07 20:22:02 43,984 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\snyluvcc.sys
+ 2003-04-07 20:22:12 424,143 ----a-w C:\WINDOWS\system32\ReinstallBackups\
0004\DriverFiles\SonyVcc.sys
- 2005-05-04 19:45:26 13,536 ----a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-10-08 19:46:18 14,640 ------w C:\WINDOWS\system32\spmsg.dll
- 2003-03-31 12:00:00 139,776 ----a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-07-31 00:19:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
- 2003-03-31 12:00:00 189,440 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-31 00:19:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-31 00:19:46 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2008-03-30 18:09:57 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_738.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\Avast4\ashDisp.exe" [2008-03-29 13:37 79224]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2003-11-29 07:23 135168]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 00:08 28672]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-12-20 19:54 278528]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"HostManager"="C:\Program Files\Common Files\AOL\1110064663\ee\AOLSoftware.exe" [2006-03-08 13:38 48280]
"HKSERV.EXE"="C:\Program Files\Sony\HotKey Utility\HKserv.exe" [2003-08-14 13:00 90112]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2003-11-07 17:21 114688]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2005-04-18 13:38 71256]
"RegistryMechanic"="" []
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 13:16 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-02 09:38 282624]
"OpwareSE4"="D:\ScanSoft OmniPage\OpwareSE4.exe" [2006-10-11 12:45 75304]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 19:46 45056 C:\WINDOWS\system32\ico.exe]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-03-27 10:57 126104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyxxw]
fccyxxw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PowerPanel.lnk]
backup=C:\WINDOWS\pss\PowerPanel.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"nvcoi"=C:\Program Files\nvcoi\nvcoi.exe
R1 aswSP;avast! Self Protection;C:\WINDOWS\System32\drivers\aswSP.sys [2008-03-29 13:31]
R3 DVccUSBSony1;Sony Visual Communication Camera VCC-U01;C:\WINDOWS\System32\DRIVERS\SonyVcc.sys [2003-04-07 13:22]
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\System32\DRIVERS\SonyPI.sys [2002-08-20 14:59]
S1 NwlsAcd;NwlsAcd;C:\WINDOWS\System32\drivers\mfmkaud.sys []
S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;C:\WINDOWS\System32\DRIVERS\fa410nd5.sys [2001-08-17 07:12]
*Newly Created Service* - ASWSP
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-30 14:10:04
Windows 5.1.2600 Service Pack 1 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-03-30 14:12:41
ComboFix-quarantined-files.txt 2008-03-30 19:11:37
ComboFix2.txt 2008-03-29 07:01:31
Pre-Run: 4,230,197,248 bytes free
Post-Run: 4,213,768,192 bytes free
.
2008-03-30 18:17:55 --- E O F ---
>>>>>>>>>>>>>>>>>>here is my fresh hijackthis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:14:29 PM, on 3/30/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Avast4\aswUpdSv.exe
C:\Avast4\ashServ.exe
C:\Avast4\ashDisp.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\AOL\1110064663\ee\AOLSoftware.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\Program Files\Apoint\Apntex.exe
D:\ScanSoft OmniPage\OpwareSE4.exe
C:\WINDOWS\System32\ICO.EXE
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\SoftwareDistribution\Download\eb5ff0ae9fdaa24285c4924997a7aa90\update\update.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avast!] C:\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1110064663\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OpwareSE4] "D:\ScanSoft OmniPage\OpwareSE4.exe"
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\System32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) -
http://o.aolcdn.com/...ns.10.6.0.4.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://appldnld.m7z....iTunesSetup.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1206891611613O16 - DPF: {6BAB93B7-1917-4214-A7D2-874FA6DB4740} (AOL Newport Editor Ctrl) -
http://o.aolcdn.com/...ns.10.6.0.6.cabO20 - Winlogon Notify: fccyxxw - fccyxxw.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
--
End of file - 8934 bytes
Thanks again for your help...Am I finally clean?