micro antivirus 2009 here is my hjt log

Discussion in 'Windows - Virus and spyware problems' started by chkinjoe, Sep 22, 2008.

  1. chkinjoe

    chkinjoe Member

    Joined:
    Jun 27, 2008
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    16
    ComboFix 08-09-22.06 - Theo Moor 2008-09-24 17:25:31.3 - NTFSx86
    Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.919 [GMT -7:00]
    Running from: C:\Users\Theo Moor\Desktop\combofix.exe
    Command switches used :: C:\Users\Theo Moor\Desktop\CFScript.txt
    * Created a new restore point

    FILE ::
    C:\Windows\system32\kejajumo.dll
    C:\Windows\System32\khfDwxxw.dll
    C:\Windows\system32\pojabese.dll
    C:\Windows\System32\yspqrdjp.ini2
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Windows\System32\khfDwxxw.dll
    C:\Windows\system32\pojabese.dll
    C:\Windows\System32\yspqrdjp.ini2

    .
    ((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
    .

    2008-09-24 00:05 . 2008-09-24 00:06 102,649,700 --a------ C:\Windows\MEMORY.DMP
    2008-09-23 18:11 . 2008-09-23 18:11 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
    2008-09-23 18:11 . 2008-09-23 18:11 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
    2008-09-23 18:10 . 2008-09-23 18:10 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\SUPERAntiSpyware.com
    2008-09-23 18:10 . 2008-09-23 18:10 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-09-23 18:10 . 2008-09-23 18:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2008-09-23 17:55 . 2008-09-23 17:55 <DIR> d-------- C:\DRIVERS
    2008-09-22 20:39 . 2008-09-22 20:39 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\Malwarebytes
    2008-09-22 20:39 . 2008-09-22 20:39 <DIR> d-------- C:\Users\All Users\Malwarebytes
    2008-09-22 20:39 . 2008-09-22 20:39 <DIR> d-------- C:\ProgramData\Malwarebytes
    2008-09-22 20:39 . 2008-09-23 23:58 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-09-22 20:39 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
    2008-09-22 20:39 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
    2008-09-22 16:07 . 2008-09-22 16:09 <DIR> d-------- C:\Users\All Users\Avira
    2008-09-22 16:07 . 2008-09-22 16:09 <DIR> d-------- C:\ProgramData\Avira
    2008-09-22 16:07 . 2008-09-22 16:07 <DIR> d-------- C:\Program Files\Avira
    2008-09-22 15:13 . 2008-09-22 15:13 <DIR> d-------- C:\Program Files\Zone Labs
    2008-09-22 15:13 . 2008-03-03 15:05 1,086,952 --a------ C:\Windows\System32\zpeng24.dll
    2008-09-22 15:12 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\~GLH0015.TMP
    2008-09-22 15:11 . 2008-09-24 20:43 352,615 --ah----- C:\Windows\System32\drivers\vsconfig.xml
    2008-09-22 15:11 . 2008-03-03 15:06 279,440 --------- C:\Windows\System32\drivers\vsdatant.sys
    2008-09-22 14:54 . 2008-09-22 14:54 <DIR> d-------- C:\Program Files\CCleaner
    2008-09-22 11:54 . 2008-09-22 11:54 <DIR> d-------- C:\Program Files\Trend Micro
    2008-09-22 01:37 . 2008-09-22 01:37 <DIR> d-------- C:\Users\All Users\CheckPoint
    2008-09-22 01:37 . 2008-09-22 01:37 <DIR> d-------- C:\ProgramData\CheckPoint
    2008-09-22 01:37 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\~GLH0014.TMP
    2008-09-22 01:36 . 2008-09-22 15:13 <DIR> d-------- C:\Windows\System32\ZoneLabs
    2008-09-22 01:35 . 2008-09-24 17:29 <DIR> d-------- C:\Windows\Internet Logs
    2008-09-22 01:25 . 2008-09-23 23:54 <DIR> d-a------ C:\Users\All Users\TEMP
    2008-09-22 01:25 . 2008-09-23 23:54 <DIR> d-a------ C:\ProgramData\TEMP
    2008-09-22 01:25 . 2008-09-23 00:57 <DIR> d-------- C:\Program Files\SpywareBlaster
    2008-09-09 11:23 . 2008-07-30 18:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
    2008-09-09 11:23 . 2008-08-01 18:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
    2008-09-09 11:23 . 2008-06-25 20:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
    2008-09-09 11:23 . 2008-06-25 20:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
    2008-09-09 11:23 . 2008-05-08 12:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
    2008-09-09 11:23 . 2008-05-19 19:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
    2008-09-09 11:23 . 2008-06-25 20:29 45,056 --a------ C:\Windows\System32\dataclen.dll
    2008-09-09 11:23 . 2008-08-01 20:26 36,864 --a------ C:\Windows\System32\cdd.dll
    2008-09-09 11:23 . 2008-07-30 20:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll
    2008-09-08 23:40 . 2008-09-08 23:40 <DIR> d-------- C:\Program Files\warlords battlecry
    2008-09-06 17:55 . 2008-09-06 17:55 <DIR> d-------- C:\Program Files\7-Zip
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\acccore
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Users\All Users\Viewpoint
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Users\All Users\acccore
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\ProgramData\Viewpoint
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\ProgramData\acccore
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Program Files\Viewpoint
    2008-09-05 23:16 . 2008-09-05 23:18 <DIR> d-------- C:\Users\All Users\AOL OCP
    2008-09-05 23:16 . 2008-09-05 23:16 <DIR> d-------- C:\Users\All Users\AOL
    2008-09-05 23:16 . 2008-09-05 23:18 <DIR> d-------- C:\ProgramData\AOL OCP
    2008-09-05 23:16 . 2008-09-05 23:16 <DIR> d-------- C:\ProgramData\AOL
    2008-09-05 23:16 . 2008-09-05 23:16 <DIR> d-------- C:\Program Files\Common Files\AOL
    2008-09-05 23:16 . 2008-09-05 23:17 <DIR> d-------- C:\Program Files\AIM6
    2008-09-05 23:16 . 2008-09-05 23:17 364 --ah----- C:\IPH.PH
    2008-09-05 15:45 . 2008-04-26 01:26 891,448 --a------ C:\Windows\System32\drivers\tcpip.original
    2008-09-05 13:49 . 2008-09-05 13:49 <DIR> d-------- C:\Program Files\support.com
    2008-09-05 13:49 . 2008-09-05 13:49 <DIR> d-------- C:\Program Files\Common Files\SupportSoft
    2008-09-04 23:52 . 2008-09-09 17:55 <DIR> d-------- C:\Users\Theo Moor\psp files
    2008-09-04 23:40 . 2008-09-04 23:41 <DIR> d-------- C:\Program Files\PSP Pandora Deluxe
    2008-08-30 09:56 . 2008-08-30 09:56 108,144 --a------ C:\Windows\System32\CmdLineExt.dll
    2008-08-30 09:48 . 2008-09-23 23:49 <DIR> d-------- C:\temp
    2008-08-30 01:29 . 2008-08-30 01:29 <DIR> d-------- C:\Program Files\THQ
    2008-08-30 01:29 . 2006-09-28 13:05 2,414,360 --a------ C:\Windows\System32\d3dx9_31.dll
    2008-08-30 01:29 . 2006-09-28 13:05 237,848 --a------ C:\Windows\System32\xactengine2_4.dll
    2008-08-30 01:29 . 2006-07-28 06:30 236,824 --a------ C:\Windows\System32\xactengine2_3.dll
    2008-08-30 01:29 . 2006-09-28 13:04 68,888 --a------ C:\Windows\System32\xinput1_3.dll
    2008-08-30 01:29 . 2006-07-28 06:30 62,744 --a------ C:\Windows\System32\xinput1_2.dll
    2008-08-30 01:29 . 2006-09-28 13:03 15,128 --a------ C:\Windows\System32\x3daudio1_1.dll
    2008-08-29 13:29 . 2008-08-29 16:26 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\WordWeb
    2008-08-29 13:23 . 2008-08-29 13:23 <DIR> d-------- C:\Program Files\Merriam-Webster
    2008-08-28 06:31 . 2008-08-28 06:31 <DIR> d-------- C:\Program Files\ffdshow
    2008-08-28 06:31 . 2008-06-08 20:58 60,273 --a------ C:\Windows\System32\pthreadGC2.dll
    2008-08-28 06:31 . 2008-06-12 17:36 7,680 --a------ C:\Windows\System32\ff_vfw.dll
    2008-08-28 06:31 . 2007-07-10 15:10 547 --a------ C:\Windows\System32\ff_vfw.dll.manifest
    2008-08-26 16:48 . 2008-08-26 16:48 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
    2008-08-26 16:09 . 2008-07-18 22:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll
    2008-08-26 16:09 . 2008-07-18 20:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll
    2008-08-26 16:09 . 2008-07-18 22:09 563,912 --a------ C:\Windows\System32\wuapi.dll
    2008-08-26 16:09 . 2008-07-18 19:08 163,904 --a------ C:\Windows\System32\wuwebv.dll
    2008-08-26 16:09 . 2008-07-18 20:44 83,456 --a------ C:\Windows\System32\wudriver.dll
    2008-08-26 16:09 . 2008-07-18 22:10 53,448 --a------ C:\Windows\System32\wuauclt.exe
    2008-08-26 16:09 . 2008-07-18 22:10 45,768 --a------ C:\Windows\System32\wups2.dll
    2008-08-26 16:09 . 2008-07-18 22:10 36,552 --a------ C:\Windows\System32\wups.dll
    2008-08-26 16:09 . 2008-07-18 17:44 31,232 --a------ C:\Windows\System32\wuapp.exe
    2008-08-25 17:53 . 2008-08-25 17:53 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\Xbins
    2008-08-25 17:07 . 2008-08-25 17:08 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\ImgBurn
    2008-08-25 17:05 . 2008-08-25 17:06 <DIR> d-------- C:\Program Files\ImgBurn
    2008-08-25 11:55 . 2008-08-25 11:55 <DIR> d-------- C:\Windows\Sun

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-25 00:20 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\uTorrent
    2008-09-22 23:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-09-22 23:28 --------- d-----w C:\ProgramData\Symantec
    2008-09-21 02:11 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\LimeWire
    2008-09-10 04:32 --------- d-----w C:\ProgramData\Microsoft Help
    2008-09-09 04:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-09-06 05:34 --------- d-----w C:\Program Files\NoAdware
    2008-08-24 03:53 --------- d-----w C:\Program Files\Java
    2008-08-24 03:50 --------- d-----w C:\Program Files\Common Files\Java
    2008-08-24 03:25 --------- d-----w C:\Program Files\LimeWire
    2008-08-22 04:26 --------- d-----w C:\Program Files\LucasArts
    2008-08-22 04:22 --------- d-----w C:\Program Files\DAEMON Tools Lite
    2008-08-22 04:20 --------- d-----w C:\Users\Administrator\AppData\Roaming\ATI
    2008-08-22 04:16 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys
    2008-08-22 04:16 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\DAEMON Tools
    2008-08-21 01:36 --------- d-----w C:\Program Files\uTorrent
    2008-08-20 04:03 --------- d-----w C:\Program Files\Microsoft Silverlight
    2008-08-20 03:02 --------- d-----w C:\Program Files\Yahoo!
    2008-08-19 22:24 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
    2008-08-17 02:02 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\Ceedo
    2008-08-16 03:46 --------- d-----w C:\Program Files\Windows Mail
    2008-08-08 15:20 --------- d-----w C:\Program Files\Spotmau WinCares 2007
    2008-08-01 20:54 --------- d-----w C:\ProgramData\Yahoo!
    2008-08-01 20:53 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\Yahoo!
    2008-08-01 20:39 --------- d-----w C:\ProgramData\Apple Computer
    2008-08-01 20:39 --------- d-----w C:\Program Files\QuickTime
    2008-08-01 20:05 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-08-01 19:51 --------- d-----w C:\Program Files\Microsoft Works
    2008-08-01 19:50 --------- d-----w C:\Program Files\MSBuild
    2008-08-01 19:48 --------- d-----w C:\Program Files\Microsoft.NET
    2008-08-01 19:44 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
    2008-07-31 11:00 --------- d-----w C:\Program Files\ThinkPad
    2008-07-31 11:00 --------- d-----w C:\Program Files\Lenovo
    2008-07-31 10:56 --------- d-----w C:\Program Files\Windows Sidebar
    2008-07-31 10:52 --------- d-----w C:\Program Files\Common Files\InstallShield
    2008-07-31 10:03 174 --sha-w C:\Program Files\desktop.ini
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Photo Gallery
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Journal
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Defender
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Collaboration
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Calendar
    2008-07-31 09:43 82,432 ----a-w C:\Windows\System32\axaltocm.dll
    2008-07-31 09:43 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
    2008-07-31 08:51 47,560 ----a-w C:\Windows\System32\SPReview.exe
    2008-07-31 08:51 152,576 ----a-w C:\Windows\System32\SPWizUI.dll
    2008-07-31 08:09 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\ATI
    2008-07-31 08:06 --------- d-----w C:\Program Files\ThinkVantage Fingerprint Software
    2008-07-31 08:03 --------- d-----w C:\ProgramData\UIB
    2008-07-31 08:03 --------- d-----w C:\Program Files\Common Files\ThinkVantage Fingerprint Software
    2008-07-31 08:01 --------- d-----w C:\Program Files\ATI Technologies
    2008-07-31 08:00 --------- d-----w C:\Program Files\ATI
    2008-07-31 07:37 --------- d-----w C:\Program Files\Common Files\Lenovo
    2008-07-31 07:23 233,888 ----a-w C:\Windows\System32\DreamScene.dll
    2008-07-31 07:21 --------- d-----w C:\Program Files\UPEK
    2008-07-31 07:20 --------- d-----w C:\Program Files\BitLocker
    2008-07-31 07:19 1,171,848 ----a-w C:\Windows\System32\SecureKeyBackupCPL.dll
    2008-07-31 07:17 678,408 ----a-w C:\Windows\System32\gpprefcl.dll
    2008-07-31 07:16 --------- d-----w C:\Program Files\Microsoft Games
    2008-07-31 07:15 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
    2008-07-31 07:15 --------- d-----w C:\Program Files\Synaptics
    2008-07-31 07:15 --------- d-----w C:\Program Files\CONEXANT
    2008-07-31 06:28 9,847,296 ----a-w C:\Windows\System32\NlsData000a.dll
    2008-07-31 06:26 2,032,128 ----a-w C:\Windows\System32\win32k.sys
    2008-07-31 06:25 295,936 ----a-w C:\Windows\System32\gdi32.dll
    2008-07-31 06:22 14,848 ----a-w C:\Windows\System32\wshrm.dll
    2008-07-31 06:22 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
    2008-07-31 06:20 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
    2008-07-31 06:20 1,695,744 ----a-w C:\Windows\System32\gameux.dll
    2008-07-31 06:17 1,314,816 ----a-w C:\Windows\System32\quartz.dll
    2008-07-31 06:16 428,544 ----a-w C:\Windows\System32\EncDec.dll
    2008-07-31 06:16 293,376 ----a-w C:\Windows\System32\psisdecd.dll
    2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
    2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
    2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
    2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
    2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-09-23_ 0.32.07.96 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-09-24 01:11:05 18,944 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
    + 2008-09-24 01:11:05 65,024 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
    - 2008-09-23 07:29:29 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
    + 2008-09-25 03:43:30 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
    - 2008-09-23 07:29:29 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    + 2008-09-25 03:43:30 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    - 2008-09-23 07:29:15 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-09-25 03:43:06 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-09-24 05:01:20 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008092320080924\index.dat
    - 2008-09-23 07:29:15 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-09-25 03:43:06 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-09-23 07:29:15 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-09-25 03:43:06 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2008-09-23 07:24:25 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
    + 2008-09-24 05:06:38 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
    - 2008-09-23 06:56:50 106,796 ----a-w C:\Windows\System32\perfc009.dat
    + 2008-09-24 15:45:37 106,796 ----a-w C:\Windows\System32\perfc009.dat
    - 2008-09-23 06:56:50 611,788 ----a-w C:\Windows\System32\perfh009.dat
    + 2008-09-24 15:45:37 611,788 ----a-w C:\Windows\System32\perfh009.dat
    - 2008-09-22 22:19:50 6,604 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2498408150-3981597196-2587865111-1000_UserData.bin
    + 2008-09-24 01:06:23 6,856 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2498408150-3981597196-2587865111-1000_UserData.bin
    - 2008-09-22 22:19:50 59,240 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-09-24 01:06:23 60,132 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2008-09-23 03:26:37 34,256 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-09-24 06:59:48 34,460 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-09-22 266497]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
    "TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-03-24 68464]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "EnableInstallerDetection"= 0 (0x0)
    "EnableLUA"= 0 (0x0)
    "EnableSecureUIAPaths"= 0 (0x0)
    "EnableVirtualization"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "DisableCAD"= 1 (0x1)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "LogonHoursAction"= 2 (0x2)
    "DontDisplayLogonHoursWarnings"= 1 (0x1)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
    2007-08-14 15:54 89600 C:\Windows\System32\psqlpwd.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages REG_MULTI_SZ scecli psqlpwd C:\Windows\system32\pojabese.dll C:\Windows\system32\pojabese.dll

    [HKLM\~\startupfolder\C:^Users^Theo Moor^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CCC.lnk]
    path=C:\Users\Theo Moor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CCC.lnk
    backup=C:\Windows\pss\CCC.lnk.Startup
    backupExtension=.Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BLOG]
    --------- 2008-06-13 02:30 214576 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLOGEX.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZEJMNAP]
    --------- 2008-06-05 02:36 242976 C:\PROGRA~1\ThinkPad\UTILIT~1\EZEJMNAP.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    --a------ 2007-08-24 07:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWMTRV]
    --------- 2008-06-13 02:30 591136 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    --a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
    --a------ 2007-11-21 18:08 820520 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
    --a------ 2008-03-04 10:34 487424 C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    --a------ 2008-01-18 23:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    --a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2498408150-3981597196-2587865111-1000]
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{14C99733-4468-449F-AB4D-7CB22BDA2F19}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
    "{31EADDE9-E2AD-4510-A8C7-D6BE7691CB5C}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{3DA5929B-C65D-49A4-A870-E70FC95C4EED}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{3E49912C-6B00-4DB5-B24E-EFD6CAF97AD6}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{5066E27B-0873-4BA2-9B5D-CA2FBE6BA843}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{994B4A53-2A8E-4B10-BCE3-7C38486C36FD}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{09159D92-EA6A-4D82-9A2A-6AB4D7D72E3F}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{BEB6BFDE-56E4-4F55-B505-AAC495B1344A}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
    "{E94EADD5-AA7A-4487-80FD-0E80AA5461B8}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
    "{9F97F662-2B3A-4DB6-B2CE-FA2D2482BF5C}"= UDP:990:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdSync.exe,-4001
    "{C0862004-5E5C-43F9-B5F5-DE6D0496A394}"= UDP:990:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdSync.exe,-4001
    "{EF61FAD2-4E03-424B-8FED-040BCE8C8699}"= UDP:5721:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4002
    "{6BF31B32-A0E6-467E-856D-33A27E555335}"= UDP:1034:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4003
    "{56BDB850-4D1D-4364-A053-53F1926542D7}"= UDP:5678:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4004
    "{62244E3E-F731-42C5-A10E-C37B5AE9C60C}"= UDP:999:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4005
    "{CBF2E472-9B7E-46A1-8732-C3B520B63FE2}"= UDP:26675:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4006
    "{FCA69773-1341-4A43-A42D-FD75AF173083}"= UDP:990:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdc.exe,-4001
    "{FA61575D-0DBF-4B1B-94EE-11C6CA413E3E}"= UDP:5721:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4002
    "{C0275CA5-3711-4887-93D8-2235D68075D9}"= UDP:1034:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4003
    "{CEAE717D-9660-4906-8F94-E52C9B4C62E9}"= UDP:5678:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4004
    "{096C14BC-7EAB-49B8-8536-0379D118B857}"= UDP:999:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4005
    "{952340F9-65E5-4544-AA58-90C9F29699C5}"= UDP:26675:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4006
    "{33EA85A1-8F53-4BE7-9E5A-EBE4619379AB}"= UDP:990:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdc.exe,-4001
    "{4E9731CD-6D92-49F5-8AD6-FCE70BDEADB3}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
    "{EDF13208-E6B8-44CD-83BF-87ACD83751F2}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
    "{224B317F-9D86-4EB4-9B26-455BCAE2774D}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
    "{141B6876-88C0-4085-9DDF-FD24F7076100}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
    "{6448E642-07C8-4AF5-A5C4-0C76D9B1FB8E}"= UDP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
    "{1B94555C-451E-4970-B9DA-DAE44AD99BF9}"= TCP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
    "{8F4F7A7B-08AD-46B9-B33C-9623F1E51B3A}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{1BB56A87-F810-40DA-9616-0BD3F85B053F}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{431C8773-0CCD-4077-9506-7678D8C7C678}"= UDP:C:\Program Files\AIM6\aim6.exe:AIM
    "{D2C19758-638C-4B8A-901C-3FA609D145F7}"= TCP:C:\Program Files\AIM6\aim6.exe:AIM
    "TCP Query User{60E15E31-81F5-4238-8184-601ED071D8D3}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:µTorrent
    "UDP Query User{F618D534-A0E9-406F-A44A-B60998F08498}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:µTorrent

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiif32.sys [2008-05-12 13480]
    R1 TPPWRIF;TPPWRIF;C:\Windows\system32\drivers\Tppwr32v.sys [2008-06-13 12080]
    R2 smihlp;SMI Helper Driver (smihlp);C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-08-14 10896]
    R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-04-05 2464768]
    R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-05-02 179712]
    R3 HSXHWICH;HSXHWICH;C:\Windows\system32\DRIVERS\HSXHWICH.sys [2006-10-18 248320]
    S3 NETw2v32;Intel(R) PRO/Wireless 2915ABG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
    bthsvcs REG_MULTI_SZ BthServ

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b32395b-7001-11dd-9017-000000000000}]
    \shell\AutoRun\command - E:\autorun.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
    msiexec /fums {CCA08FFD-3F64-A525-170F-FB2D73CDC661} /qb

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
    %SystemRoot%\system32\soundschemes.exe /AddRegistration
    .
    Contents of the 'Scheduled Tasks' folder
    .
    - - - - ORPHANS REMOVED - - - -

    MSConfigStartUp-buvuzodala - C:\Windows\system32\kejajumo.dll



    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-24 20:43:40
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    PROCESS: C:\Windows\Explorer.exe
    -> ?:\Windows\system32\MLANG.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Windows\System32\ibmpmsvc.exe
    C:\Windows\System32\Ati2evxx.exe
    C:\Windows\System32\audiodg.exe
    C:\Windows\System32\Ati2evxx.exe
    C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
    C:\Windows\System32\ZoneLabs\vsmon.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe
    C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    C:\Windows\System32\drivers\XAudio.exe
    C:\Program Files\Lenovo\System Update\SUService.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avwebgrd.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\ZOOM\TpScrex.exe
    C:\Windows\System32\dllhost.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avwsc.exe
    .
    **************************************************************************
    .
    Completion time: 2008-09-24 20:46:54 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-09-25 03:46:42
    ComboFix2.txt 2008-09-23 07:33:31

    Pre-Run: 45,926,862,848 bytes free
    Post-Run: 45,781,835,776 bytes free

    394 --- E O F --- 2008-09-23 07:00:06

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:52:42 PM, on 9/24/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\Zoom\TpScrex.exe
    C:\Windows\System32\mobsync.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\NOTEPAD.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
    O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
    O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe
    O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
    O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
    O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
    O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 5690 bytes
     
  2. chkinjoe

    chkinjoe Member

    Joined:
    Jun 27, 2008
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    16
    ComboFix 08-09-22.06 - Theo Moor 2008-09-24 17:25:31.3 - NTFSx86
    Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.919 [GMT -7:00]
    Running from: C:\Users\Theo Moor\Desktop\combofix.exe
    Command switches used :: C:\Users\Theo Moor\Desktop\CFScript.txt
    * Created a new restore point

    FILE ::
    C:\Windows\system32\kejajumo.dll
    C:\Windows\System32\khfDwxxw.dll
    C:\Windows\system32\pojabese.dll
    C:\Windows\System32\yspqrdjp.ini2
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Windows\System32\khfDwxxw.dll
    C:\Windows\system32\pojabese.dll
    C:\Windows\System32\yspqrdjp.ini2

    .
    ((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
    .

    2008-09-24 00:05 . 2008-09-24 00:06 102,649,700 --a------ C:\Windows\MEMORY.DMP
    2008-09-23 18:11 . 2008-09-23 18:11 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
    2008-09-23 18:11 . 2008-09-23 18:11 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
    2008-09-23 18:10 . 2008-09-23 18:10 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\SUPERAntiSpyware.com
    2008-09-23 18:10 . 2008-09-23 18:10 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-09-23 18:10 . 2008-09-23 18:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2008-09-23 17:55 . 2008-09-23 17:55 <DIR> d-------- C:\DRIVERS
    2008-09-22 20:39 . 2008-09-22 20:39 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\Malwarebytes
    2008-09-22 20:39 . 2008-09-22 20:39 <DIR> d-------- C:\Users\All Users\Malwarebytes
    2008-09-22 20:39 . 2008-09-22 20:39 <DIR> d-------- C:\ProgramData\Malwarebytes
    2008-09-22 20:39 . 2008-09-23 23:58 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-09-22 20:39 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
    2008-09-22 20:39 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
    2008-09-22 16:07 . 2008-09-22 16:09 <DIR> d-------- C:\Users\All Users\Avira
    2008-09-22 16:07 . 2008-09-22 16:09 <DIR> d-------- C:\ProgramData\Avira
    2008-09-22 16:07 . 2008-09-22 16:07 <DIR> d-------- C:\Program Files\Avira
    2008-09-22 15:13 . 2008-09-22 15:13 <DIR> d-------- C:\Program Files\Zone Labs
    2008-09-22 15:13 . 2008-03-03 15:05 1,086,952 --a------ C:\Windows\System32\zpeng24.dll
    2008-09-22 15:12 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\~GLH0015.TMP
    2008-09-22 15:11 . 2008-09-24 20:43 352,615 --ah----- C:\Windows\System32\drivers\vsconfig.xml
    2008-09-22 15:11 . 2008-03-03 15:06 279,440 --------- C:\Windows\System32\drivers\vsdatant.sys
    2008-09-22 14:54 . 2008-09-22 14:54 <DIR> d-------- C:\Program Files\CCleaner
    2008-09-22 11:54 . 2008-09-22 11:54 <DIR> d-------- C:\Program Files\Trend Micro
    2008-09-22 01:37 . 2008-09-22 01:37 <DIR> d-------- C:\Users\All Users\CheckPoint
    2008-09-22 01:37 . 2008-09-22 01:37 <DIR> d-------- C:\ProgramData\CheckPoint
    2008-09-22 01:37 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\~GLH0014.TMP
    2008-09-22 01:36 . 2008-09-22 15:13 <DIR> d-------- C:\Windows\System32\ZoneLabs
    2008-09-22 01:35 . 2008-09-24 17:29 <DIR> d-------- C:\Windows\Internet Logs
    2008-09-22 01:25 . 2008-09-23 23:54 <DIR> d-a------ C:\Users\All Users\TEMP
    2008-09-22 01:25 . 2008-09-23 23:54 <DIR> d-a------ C:\ProgramData\TEMP
    2008-09-22 01:25 . 2008-09-23 00:57 <DIR> d-------- C:\Program Files\SpywareBlaster
    2008-09-09 11:23 . 2008-07-30 18:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
    2008-09-09 11:23 . 2008-08-01 18:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
    2008-09-09 11:23 . 2008-06-25 20:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
    2008-09-09 11:23 . 2008-06-25 20:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
    2008-09-09 11:23 . 2008-05-08 12:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
    2008-09-09 11:23 . 2008-05-19 19:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
    2008-09-09 11:23 . 2008-06-25 20:29 45,056 --a------ C:\Windows\System32\dataclen.dll
    2008-09-09 11:23 . 2008-08-01 20:26 36,864 --a------ C:\Windows\System32\cdd.dll
    2008-09-09 11:23 . 2008-07-30 20:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll
    2008-09-08 23:40 . 2008-09-08 23:40 <DIR> d-------- C:\Program Files\warlords battlecry
    2008-09-06 17:55 . 2008-09-06 17:55 <DIR> d-------- C:\Program Files\7-Zip
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\acccore
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Users\All Users\Viewpoint
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Users\All Users\acccore
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\ProgramData\Viewpoint
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\ProgramData\acccore
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Program Files\Viewpoint
    2008-09-05 23:16 . 2008-09-05 23:18 <DIR> d-------- C:\Users\All Users\AOL OCP
    2008-09-05 23:16 . 2008-09-05 23:16 <DIR> d-------- C:\Users\All Users\AOL
    2008-09-05 23:16 . 2008-09-05 23:18 <DIR> d-------- C:\ProgramData\AOL OCP
    2008-09-05 23:16 . 2008-09-05 23:16 <DIR> d-------- C:\ProgramData\AOL
    2008-09-05 23:16 . 2008-09-05 23:16 <DIR> d-------- C:\Program Files\Common Files\AOL
    2008-09-05 23:16 . 2008-09-05 23:17 <DIR> d-------- C:\Program Files\AIM6
    2008-09-05 23:16 . 2008-09-05 23:17 364 --ah----- C:\IPH.PH
    2008-09-05 15:45 . 2008-04-26 01:26 891,448 --a------ C:\Windows\System32\drivers\tcpip.original
    2008-09-05 13:49 . 2008-09-05 13:49 <DIR> d-------- C:\Program Files\support.com
    2008-09-05 13:49 . 2008-09-05 13:49 <DIR> d-------- C:\Program Files\Common Files\SupportSoft
    2008-09-04 23:52 . 2008-09-09 17:55 <DIR> d-------- C:\Users\Theo Moor\psp files
    2008-09-04 23:40 . 2008-09-04 23:41 <DIR> d-------- C:\Program Files\PSP Pandora Deluxe
    2008-08-30 09:56 . 2008-08-30 09:56 108,144 --a------ C:\Windows\System32\CmdLineExt.dll
    2008-08-30 09:48 . 2008-09-23 23:49 <DIR> d-------- C:\temp
    2008-08-30 01:29 . 2008-08-30 01:29 <DIR> d-------- C:\Program Files\THQ
    2008-08-30 01:29 . 2006-09-28 13:05 2,414,360 --a------ C:\Windows\System32\d3dx9_31.dll
    2008-08-30 01:29 . 2006-09-28 13:05 237,848 --a------ C:\Windows\System32\xactengine2_4.dll
    2008-08-30 01:29 . 2006-07-28 06:30 236,824 --a------ C:\Windows\System32\xactengine2_3.dll
    2008-08-30 01:29 . 2006-09-28 13:04 68,888 --a------ C:\Windows\System32\xinput1_3.dll
    2008-08-30 01:29 . 2006-07-28 06:30 62,744 --a------ C:\Windows\System32\xinput1_2.dll
    2008-08-30 01:29 . 2006-09-28 13:03 15,128 --a------ C:\Windows\System32\x3daudio1_1.dll
    2008-08-29 13:29 . 2008-08-29 16:26 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\WordWeb
    2008-08-29 13:23 . 2008-08-29 13:23 <DIR> d-------- C:\Program Files\Merriam-Webster
    2008-08-28 06:31 . 2008-08-28 06:31 <DIR> d-------- C:\Program Files\ffdshow
    2008-08-28 06:31 . 2008-06-08 20:58 60,273 --a------ C:\Windows\System32\pthreadGC2.dll
    2008-08-28 06:31 . 2008-06-12 17:36 7,680 --a------ C:\Windows\System32\ff_vfw.dll
    2008-08-28 06:31 . 2007-07-10 15:10 547 --a------ C:\Windows\System32\ff_vfw.dll.manifest
    2008-08-26 16:48 . 2008-08-26 16:48 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
    2008-08-26 16:09 . 2008-07-18 22:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll
    2008-08-26 16:09 . 2008-07-18 20:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll
    2008-08-26 16:09 . 2008-07-18 22:09 563,912 --a------ C:\Windows\System32\wuapi.dll
    2008-08-26 16:09 . 2008-07-18 19:08 163,904 --a------ C:\Windows\System32\wuwebv.dll
    2008-08-26 16:09 . 2008-07-18 20:44 83,456 --a------ C:\Windows\System32\wudriver.dll
    2008-08-26 16:09 . 2008-07-18 22:10 53,448 --a------ C:\Windows\System32\wuauclt.exe
    2008-08-26 16:09 . 2008-07-18 22:10 45,768 --a------ C:\Windows\System32\wups2.dll
    2008-08-26 16:09 . 2008-07-18 22:10 36,552 --a------ C:\Windows\System32\wups.dll
    2008-08-26 16:09 . 2008-07-18 17:44 31,232 --a------ C:\Windows\System32\wuapp.exe
    2008-08-25 17:53 . 2008-08-25 17:53 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\Xbins
    2008-08-25 17:07 . 2008-08-25 17:08 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\ImgBurn
    2008-08-25 17:05 . 2008-08-25 17:06 <DIR> d-------- C:\Program Files\ImgBurn
    2008-08-25 11:55 . 2008-08-25 11:55 <DIR> d-------- C:\Windows\Sun

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-25 00:20 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\uTorrent
    2008-09-22 23:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-09-22 23:28 --------- d-----w C:\ProgramData\Symantec
    2008-09-21 02:11 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\LimeWire
    2008-09-10 04:32 --------- d-----w C:\ProgramData\Microsoft Help
    2008-09-09 04:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-09-06 05:34 --------- d-----w C:\Program Files\NoAdware
    2008-08-24 03:53 --------- d-----w C:\Program Files\Java
    2008-08-24 03:50 --------- d-----w C:\Program Files\Common Files\Java
    2008-08-24 03:25 --------- d-----w C:\Program Files\LimeWire
    2008-08-22 04:26 --------- d-----w C:\Program Files\LucasArts
    2008-08-22 04:22 --------- d-----w C:\Program Files\DAEMON Tools Lite
    2008-08-22 04:20 --------- d-----w C:\Users\Administrator\AppData\Roaming\ATI
    2008-08-22 04:16 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys
    2008-08-22 04:16 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\DAEMON Tools
    2008-08-21 01:36 --------- d-----w C:\Program Files\uTorrent
    2008-08-20 04:03 --------- d-----w C:\Program Files\Microsoft Silverlight
    2008-08-20 03:02 --------- d-----w C:\Program Files\Yahoo!
    2008-08-19 22:24 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
    2008-08-17 02:02 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\Ceedo
    2008-08-16 03:46 --------- d-----w C:\Program Files\Windows Mail
    2008-08-08 15:20 --------- d-----w C:\Program Files\Spotmau WinCares 2007
    2008-08-01 20:54 --------- d-----w C:\ProgramData\Yahoo!
    2008-08-01 20:53 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\Yahoo!
    2008-08-01 20:39 --------- d-----w C:\ProgramData\Apple Computer
    2008-08-01 20:39 --------- d-----w C:\Program Files\QuickTime
    2008-08-01 20:05 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-08-01 19:51 --------- d-----w C:\Program Files\Microsoft Works
    2008-08-01 19:50 --------- d-----w C:\Program Files\MSBuild
    2008-08-01 19:48 --------- d-----w C:\Program Files\Microsoft.NET
    2008-08-01 19:44 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
    2008-07-31 11:00 --------- d-----w C:\Program Files\ThinkPad
    2008-07-31 11:00 --------- d-----w C:\Program Files\Lenovo
    2008-07-31 10:56 --------- d-----w C:\Program Files\Windows Sidebar
    2008-07-31 10:52 --------- d-----w C:\Program Files\Common Files\InstallShield
    2008-07-31 10:03 174 --sha-w C:\Program Files\desktop.ini
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Photo Gallery
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Journal
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Defender
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Collaboration
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Calendar
    2008-07-31 09:43 82,432 ----a-w C:\Windows\System32\axaltocm.dll
    2008-07-31 09:43 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
    2008-07-31 08:51 47,560 ----a-w C:\Windows\System32\SPReview.exe
    2008-07-31 08:51 152,576 ----a-w C:\Windows\System32\SPWizUI.dll
    2008-07-31 08:09 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\ATI
    2008-07-31 08:06 --------- d-----w C:\Program Files\ThinkVantage Fingerprint Software
    2008-07-31 08:03 --------- d-----w C:\ProgramData\UIB
    2008-07-31 08:03 --------- d-----w C:\Program Files\Common Files\ThinkVantage Fingerprint Software
    2008-07-31 08:01 --------- d-----w C:\Program Files\ATI Technologies
    2008-07-31 08:00 --------- d-----w C:\Program Files\ATI
    2008-07-31 07:37 --------- d-----w C:\Program Files\Common Files\Lenovo
    2008-07-31 07:23 233,888 ----a-w C:\Windows\System32\DreamScene.dll
    2008-07-31 07:21 --------- d-----w C:\Program Files\UPEK
    2008-07-31 07:20 --------- d-----w C:\Program Files\BitLocker
    2008-07-31 07:19 1,171,848 ----a-w C:\Windows\System32\SecureKeyBackupCPL.dll
    2008-07-31 07:17 678,408 ----a-w C:\Windows\System32\gpprefcl.dll
    2008-07-31 07:16 --------- d-----w C:\Program Files\Microsoft Games
    2008-07-31 07:15 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
    2008-07-31 07:15 --------- d-----w C:\Program Files\Synaptics
    2008-07-31 07:15 --------- d-----w C:\Program Files\CONEXANT
    2008-07-31 06:28 9,847,296 ----a-w C:\Windows\System32\NlsData000a.dll
    2008-07-31 06:26 2,032,128 ----a-w C:\Windows\System32\win32k.sys
    2008-07-31 06:25 295,936 ----a-w C:\Windows\System32\gdi32.dll
    2008-07-31 06:22 14,848 ----a-w C:\Windows\System32\wshrm.dll
    2008-07-31 06:22 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
    2008-07-31 06:20 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
    2008-07-31 06:20 1,695,744 ----a-w C:\Windows\System32\gameux.dll
    2008-07-31 06:17 1,314,816 ----a-w C:\Windows\System32\quartz.dll
    2008-07-31 06:16 428,544 ----a-w C:\Windows\System32\EncDec.dll
    2008-07-31 06:16 293,376 ----a-w C:\Windows\System32\psisdecd.dll
    2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
    2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
    2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
    2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
    2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-09-23_ 0.32.07.96 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-09-24 01:11:05 18,944 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
    + 2008-09-24 01:11:05 65,024 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
    - 2008-09-23 07:29:29 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
    + 2008-09-25 03:43:30 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
    - 2008-09-23 07:29:29 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    + 2008-09-25 03:43:30 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    - 2008-09-23 07:29:15 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-09-25 03:43:06 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-09-24 05:01:20 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008092320080924\index.dat
    - 2008-09-23 07:29:15 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-09-25 03:43:06 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-09-23 07:29:15 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-09-25 03:43:06 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2008-09-23 07:24:25 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
    + 2008-09-24 05:06:38 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
    - 2008-09-23 06:56:50 106,796 ----a-w C:\Windows\System32\perfc009.dat
    + 2008-09-24 15:45:37 106,796 ----a-w C:\Windows\System32\perfc009.dat
    - 2008-09-23 06:56:50 611,788 ----a-w C:\Windows\System32\perfh009.dat
    + 2008-09-24 15:45:37 611,788 ----a-w C:\Windows\System32\perfh009.dat
    - 2008-09-22 22:19:50 6,604 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2498408150-3981597196-2587865111-1000_UserData.bin
    + 2008-09-24 01:06:23 6,856 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2498408150-3981597196-2587865111-1000_UserData.bin
    - 2008-09-22 22:19:50 59,240 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-09-24 01:06:23 60,132 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2008-09-23 03:26:37 34,256 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-09-24 06:59:48 34,460 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-09-22 266497]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
    "TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-03-24 68464]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "EnableInstallerDetection"= 0 (0x0)
    "EnableLUA"= 0 (0x0)
    "EnableSecureUIAPaths"= 0 (0x0)
    "EnableVirtualization"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "DisableCAD"= 1 (0x1)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "LogonHoursAction"= 2 (0x2)
    "DontDisplayLogonHoursWarnings"= 1 (0x1)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
    2007-08-14 15:54 89600 C:\Windows\System32\psqlpwd.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages REG_MULTI_SZ scecli psqlpwd C:\Windows\system32\pojabese.dll C:\Windows\system32\pojabese.dll

    [HKLM\~\startupfolder\C:^Users^Theo Moor^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CCC.lnk]
    path=C:\Users\Theo Moor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CCC.lnk
    backup=C:\Windows\pss\CCC.lnk.Startup
    backupExtension=.Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BLOG]
    --------- 2008-06-13 02:30 214576 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLOGEX.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZEJMNAP]
    --------- 2008-06-05 02:36 242976 C:\PROGRA~1\ThinkPad\UTILIT~1\EZEJMNAP.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    --a------ 2007-08-24 07:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWMTRV]
    --------- 2008-06-13 02:30 591136 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    --a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
    --a------ 2007-11-21 18:08 820520 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
    --a------ 2008-03-04 10:34 487424 C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    --a------ 2008-01-18 23:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    --a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2498408150-3981597196-2587865111-1000]
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{14C99733-4468-449F-AB4D-7CB22BDA2F19}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
    "{31EADDE9-E2AD-4510-A8C7-D6BE7691CB5C}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{3DA5929B-C65D-49A4-A870-E70FC95C4EED}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{3E49912C-6B00-4DB5-B24E-EFD6CAF97AD6}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{5066E27B-0873-4BA2-9B5D-CA2FBE6BA843}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{994B4A53-2A8E-4B10-BCE3-7C38486C36FD}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{09159D92-EA6A-4D82-9A2A-6AB4D7D72E3F}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{BEB6BFDE-56E4-4F55-B505-AAC495B1344A}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
    "{E94EADD5-AA7A-4487-80FD-0E80AA5461B8}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
    "{9F97F662-2B3A-4DB6-B2CE-FA2D2482BF5C}"= UDP:990:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdSync.exe,-4001
    "{C0862004-5E5C-43F9-B5F5-DE6D0496A394}"= UDP:990:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdSync.exe,-4001
    "{EF61FAD2-4E03-424B-8FED-040BCE8C8699}"= UDP:5721:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4002
    "{6BF31B32-A0E6-467E-856D-33A27E555335}"= UDP:1034:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4003
    "{56BDB850-4D1D-4364-A053-53F1926542D7}"= UDP:5678:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4004
    "{62244E3E-F731-42C5-A10E-C37B5AE9C60C}"= UDP:999:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4005
    "{CBF2E472-9B7E-46A1-8732-C3B520B63FE2}"= UDP:26675:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4006
    "{FCA69773-1341-4A43-A42D-FD75AF173083}"= UDP:990:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdc.exe,-4001
    "{FA61575D-0DBF-4B1B-94EE-11C6CA413E3E}"= UDP:5721:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4002
    "{C0275CA5-3711-4887-93D8-2235D68075D9}"= UDP:1034:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4003
    "{CEAE717D-9660-4906-8F94-E52C9B4C62E9}"= UDP:5678:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4004
    "{096C14BC-7EAB-49B8-8536-0379D118B857}"= UDP:999:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4005
    "{952340F9-65E5-4544-AA58-90C9F29699C5}"= UDP:26675:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4006
    "{33EA85A1-8F53-4BE7-9E5A-EBE4619379AB}"= UDP:990:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdc.exe,-4001
    "{4E9731CD-6D92-49F5-8AD6-FCE70BDEADB3}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
    "{EDF13208-E6B8-44CD-83BF-87ACD83751F2}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
    "{224B317F-9D86-4EB4-9B26-455BCAE2774D}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
    "{141B6876-88C0-4085-9DDF-FD24F7076100}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
    "{6448E642-07C8-4AF5-A5C4-0C76D9B1FB8E}"= UDP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
    "{1B94555C-451E-4970-B9DA-DAE44AD99BF9}"= TCP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
    "{8F4F7A7B-08AD-46B9-B33C-9623F1E51B3A}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{1BB56A87-F810-40DA-9616-0BD3F85B053F}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{431C8773-0CCD-4077-9506-7678D8C7C678}"= UDP:C:\Program Files\AIM6\aim6.exe:AIM
    "{D2C19758-638C-4B8A-901C-3FA609D145F7}"= TCP:C:\Program Files\AIM6\aim6.exe:AIM
    "TCP Query User{60E15E31-81F5-4238-8184-601ED071D8D3}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:µTorrent
    "UDP Query User{F618D534-A0E9-406F-A44A-B60998F08498}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:µTorrent

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiif32.sys [2008-05-12 13480]
    R1 TPPWRIF;TPPWRIF;C:\Windows\system32\drivers\Tppwr32v.sys [2008-06-13 12080]
    R2 smihlp;SMI Helper Driver (smihlp);C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-08-14 10896]
    R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-04-05 2464768]
    R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-05-02 179712]
    R3 HSXHWICH;HSXHWICH;C:\Windows\system32\DRIVERS\HSXHWICH.sys [2006-10-18 248320]
    S3 NETw2v32;Intel(R) PRO/Wireless 2915ABG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
    bthsvcs REG_MULTI_SZ BthServ

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b32395b-7001-11dd-9017-000000000000}]
    \shell\AutoRun\command - E:\autorun.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
    msiexec /fums {CCA08FFD-3F64-A525-170F-FB2D73CDC661} /qb

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
    %SystemRoot%\system32\soundschemes.exe /AddRegistration
    .
    Contents of the 'Scheduled Tasks' folder
    .
    - - - - ORPHANS REMOVED - - - -

    MSConfigStartUp-buvuzodala - C:\Windows\system32\kejajumo.dll



    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-24 20:43:40
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    PROCESS: C:\Windows\Explorer.exe
    -> ?:\Windows\system32\MLANG.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Windows\System32\ibmpmsvc.exe
    C:\Windows\System32\Ati2evxx.exe
    C:\Windows\System32\audiodg.exe
    C:\Windows\System32\Ati2evxx.exe
    C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
    C:\Windows\System32\ZoneLabs\vsmon.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe
    C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    C:\Windows\System32\drivers\XAudio.exe
    C:\Program Files\Lenovo\System Update\SUService.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avwebgrd.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\ZOOM\TpScrex.exe
    C:\Windows\System32\dllhost.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avwsc.exe
    .
    **************************************************************************
    .
    Completion time: 2008-09-24 20:46:54 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-09-25 03:46:42
    ComboFix2.txt 2008-09-23 07:33:31

    Pre-Run: 45,926,862,848 bytes free
    Post-Run: 45,781,835,776 bytes free

    394 --- E O F --- 2008-09-23 07:00:06

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:52:42 PM, on 9/24/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\Zoom\TpScrex.exe
    C:\Windows\System32\mobsync.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\NOTEPAD.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
    O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
    O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe
    O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
    O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
    O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
    O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 5690 bytes
     
  3. chkinjoe

    chkinjoe Member

    Joined:
    Jun 27, 2008
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    16
    ComboFix 08-09-22.06 - Theo Moor 2008-09-24 17:25:31.3 - NTFSx86
    Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.919 [GMT -7:00]
    Running from: C:\Users\Theo Moor\Desktop\combofix.exe
    Command switches used :: C:\Users\Theo Moor\Desktop\CFScript.txt
    * Created a new restore point

    FILE ::
    C:\Windows\system32\kejajumo.dll
    C:\Windows\System32\khfDwxxw.dll
    C:\Windows\system32\pojabese.dll
    C:\Windows\System32\yspqrdjp.ini2
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Windows\System32\khfDwxxw.dll
    C:\Windows\system32\pojabese.dll
    C:\Windows\System32\yspqrdjp.ini2

    .
    ((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
    .

    2008-09-24 00:05 . 2008-09-24 00:06 102,649,700 --a------ C:\Windows\MEMORY.DMP
    2008-09-23 18:11 . 2008-09-23 18:11 <DIR> d-------- C:\Users\All Users\SUPERAntiSpyware.com
    2008-09-23 18:11 . 2008-09-23 18:11 <DIR> d-------- C:\ProgramData\SUPERAntiSpyware.com
    2008-09-23 18:10 . 2008-09-23 18:10 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\SUPERAntiSpyware.com
    2008-09-23 18:10 . 2008-09-23 18:10 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-09-23 18:10 . 2008-09-23 18:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2008-09-23 17:55 . 2008-09-23 17:55 <DIR> d-------- C:\DRIVERS
    2008-09-22 20:39 . 2008-09-22 20:39 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\Malwarebytes
    2008-09-22 20:39 . 2008-09-22 20:39 <DIR> d-------- C:\Users\All Users\Malwarebytes
    2008-09-22 20:39 . 2008-09-22 20:39 <DIR> d-------- C:\ProgramData\Malwarebytes
    2008-09-22 20:39 . 2008-09-23 23:58 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-09-22 20:39 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
    2008-09-22 20:39 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
    2008-09-22 16:07 . 2008-09-22 16:09 <DIR> d-------- C:\Users\All Users\Avira
    2008-09-22 16:07 . 2008-09-22 16:09 <DIR> d-------- C:\ProgramData\Avira
    2008-09-22 16:07 . 2008-09-22 16:07 <DIR> d-------- C:\Program Files\Avira
    2008-09-22 15:13 . 2008-09-22 15:13 <DIR> d-------- C:\Program Files\Zone Labs
    2008-09-22 15:13 . 2008-03-03 15:05 1,086,952 --a------ C:\Windows\System32\zpeng24.dll
    2008-09-22 15:12 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\~GLH0015.TMP
    2008-09-22 15:11 . 2008-09-24 20:43 352,615 --ah----- C:\Windows\System32\drivers\vsconfig.xml
    2008-09-22 15:11 . 2008-03-03 15:06 279,440 --------- C:\Windows\System32\drivers\vsdatant.sys
    2008-09-22 14:54 . 2008-09-22 14:54 <DIR> d-------- C:\Program Files\CCleaner
    2008-09-22 11:54 . 2008-09-22 11:54 <DIR> d-------- C:\Program Files\Trend Micro
    2008-09-22 01:37 . 2008-09-22 01:37 <DIR> d-------- C:\Users\All Users\CheckPoint
    2008-09-22 01:37 . 2008-09-22 01:37 <DIR> d-------- C:\ProgramData\CheckPoint
    2008-09-22 01:37 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\~GLH0014.TMP
    2008-09-22 01:36 . 2008-09-22 15:13 <DIR> d-------- C:\Windows\System32\ZoneLabs
    2008-09-22 01:35 . 2008-09-24 17:29 <DIR> d-------- C:\Windows\Internet Logs
    2008-09-22 01:25 . 2008-09-23 23:54 <DIR> d-a------ C:\Users\All Users\TEMP
    2008-09-22 01:25 . 2008-09-23 23:54 <DIR> d-a------ C:\ProgramData\TEMP
    2008-09-22 01:25 . 2008-09-23 00:57 <DIR> d-------- C:\Program Files\SpywareBlaster
    2008-09-09 11:23 . 2008-07-30 18:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
    2008-09-09 11:23 . 2008-08-01 18:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
    2008-09-09 11:23 . 2008-06-25 20:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
    2008-09-09 11:23 . 2008-06-25 20:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
    2008-09-09 11:23 . 2008-05-08 12:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
    2008-09-09 11:23 . 2008-05-19 19:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
    2008-09-09 11:23 . 2008-06-25 20:29 45,056 --a------ C:\Windows\System32\dataclen.dll
    2008-09-09 11:23 . 2008-08-01 20:26 36,864 --a------ C:\Windows\System32\cdd.dll
    2008-09-09 11:23 . 2008-07-30 20:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll
    2008-09-08 23:40 . 2008-09-08 23:40 <DIR> d-------- C:\Program Files\warlords battlecry
    2008-09-06 17:55 . 2008-09-06 17:55 <DIR> d-------- C:\Program Files\7-Zip
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\acccore
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Users\All Users\Viewpoint
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Users\All Users\acccore
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\ProgramData\Viewpoint
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\ProgramData\acccore
    2008-09-05 23:17 . 2008-09-05 23:17 <DIR> d-------- C:\Program Files\Viewpoint
    2008-09-05 23:16 . 2008-09-05 23:18 <DIR> d-------- C:\Users\All Users\AOL OCP
    2008-09-05 23:16 . 2008-09-05 23:16 <DIR> d-------- C:\Users\All Users\AOL
    2008-09-05 23:16 . 2008-09-05 23:18 <DIR> d-------- C:\ProgramData\AOL OCP
    2008-09-05 23:16 . 2008-09-05 23:16 <DIR> d-------- C:\ProgramData\AOL
    2008-09-05 23:16 . 2008-09-05 23:16 <DIR> d-------- C:\Program Files\Common Files\AOL
    2008-09-05 23:16 . 2008-09-05 23:17 <DIR> d-------- C:\Program Files\AIM6
    2008-09-05 23:16 . 2008-09-05 23:17 364 --ah----- C:\IPH.PH
    2008-09-05 15:45 . 2008-04-26 01:26 891,448 --a------ C:\Windows\System32\drivers\tcpip.original
    2008-09-05 13:49 . 2008-09-05 13:49 <DIR> d-------- C:\Program Files\support.com
    2008-09-05 13:49 . 2008-09-05 13:49 <DIR> d-------- C:\Program Files\Common Files\SupportSoft
    2008-09-04 23:52 . 2008-09-09 17:55 <DIR> d-------- C:\Users\Theo Moor\psp files
    2008-09-04 23:40 . 2008-09-04 23:41 <DIR> d-------- C:\Program Files\PSP Pandora Deluxe
    2008-08-30 09:56 . 2008-08-30 09:56 108,144 --a------ C:\Windows\System32\CmdLineExt.dll
    2008-08-30 09:48 . 2008-09-23 23:49 <DIR> d-------- C:\temp
    2008-08-30 01:29 . 2008-08-30 01:29 <DIR> d-------- C:\Program Files\THQ
    2008-08-30 01:29 . 2006-09-28 13:05 2,414,360 --a------ C:\Windows\System32\d3dx9_31.dll
    2008-08-30 01:29 . 2006-09-28 13:05 237,848 --a------ C:\Windows\System32\xactengine2_4.dll
    2008-08-30 01:29 . 2006-07-28 06:30 236,824 --a------ C:\Windows\System32\xactengine2_3.dll
    2008-08-30 01:29 . 2006-09-28 13:04 68,888 --a------ C:\Windows\System32\xinput1_3.dll
    2008-08-30 01:29 . 2006-07-28 06:30 62,744 --a------ C:\Windows\System32\xinput1_2.dll
    2008-08-30 01:29 . 2006-09-28 13:03 15,128 --a------ C:\Windows\System32\x3daudio1_1.dll
    2008-08-29 13:29 . 2008-08-29 16:26 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\WordWeb
    2008-08-29 13:23 . 2008-08-29 13:23 <DIR> d-------- C:\Program Files\Merriam-Webster
    2008-08-28 06:31 . 2008-08-28 06:31 <DIR> d-------- C:\Program Files\ffdshow
    2008-08-28 06:31 . 2008-06-08 20:58 60,273 --a------ C:\Windows\System32\pthreadGC2.dll
    2008-08-28 06:31 . 2008-06-12 17:36 7,680 --a------ C:\Windows\System32\ff_vfw.dll
    2008-08-28 06:31 . 2007-07-10 15:10 547 --a------ C:\Windows\System32\ff_vfw.dll.manifest
    2008-08-26 16:48 . 2008-08-26 16:48 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
    2008-08-26 16:09 . 2008-07-18 22:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll
    2008-08-26 16:09 . 2008-07-18 20:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll
    2008-08-26 16:09 . 2008-07-18 22:09 563,912 --a------ C:\Windows\System32\wuapi.dll
    2008-08-26 16:09 . 2008-07-18 19:08 163,904 --a------ C:\Windows\System32\wuwebv.dll
    2008-08-26 16:09 . 2008-07-18 20:44 83,456 --a------ C:\Windows\System32\wudriver.dll
    2008-08-26 16:09 . 2008-07-18 22:10 53,448 --a------ C:\Windows\System32\wuauclt.exe
    2008-08-26 16:09 . 2008-07-18 22:10 45,768 --a------ C:\Windows\System32\wups2.dll
    2008-08-26 16:09 . 2008-07-18 22:10 36,552 --a------ C:\Windows\System32\wups.dll
    2008-08-26 16:09 . 2008-07-18 17:44 31,232 --a------ C:\Windows\System32\wuapp.exe
    2008-08-25 17:53 . 2008-08-25 17:53 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\Xbins
    2008-08-25 17:07 . 2008-08-25 17:08 <DIR> d-------- C:\Users\Theo Moor\AppData\Roaming\ImgBurn
    2008-08-25 17:05 . 2008-08-25 17:06 <DIR> d-------- C:\Program Files\ImgBurn
    2008-08-25 11:55 . 2008-08-25 11:55 <DIR> d-------- C:\Windows\Sun

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-09-25 00:20 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\uTorrent
    2008-09-22 23:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-09-22 23:28 --------- d-----w C:\ProgramData\Symantec
    2008-09-21 02:11 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\LimeWire
    2008-09-10 04:32 --------- d-----w C:\ProgramData\Microsoft Help
    2008-09-09 04:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-09-06 05:34 --------- d-----w C:\Program Files\NoAdware
    2008-08-24 03:53 --------- d-----w C:\Program Files\Java
    2008-08-24 03:50 --------- d-----w C:\Program Files\Common Files\Java
    2008-08-24 03:25 --------- d-----w C:\Program Files\LimeWire
    2008-08-22 04:26 --------- d-----w C:\Program Files\LucasArts
    2008-08-22 04:22 --------- d-----w C:\Program Files\DAEMON Tools Lite
    2008-08-22 04:20 --------- d-----w C:\Users\Administrator\AppData\Roaming\ATI
    2008-08-22 04:16 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys
    2008-08-22 04:16 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\DAEMON Tools
    2008-08-21 01:36 --------- d-----w C:\Program Files\uTorrent
    2008-08-20 04:03 --------- d-----w C:\Program Files\Microsoft Silverlight
    2008-08-20 03:02 --------- d-----w C:\Program Files\Yahoo!
    2008-08-19 22:24 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
    2008-08-17 02:02 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\Ceedo
    2008-08-16 03:46 --------- d-----w C:\Program Files\Windows Mail
    2008-08-08 15:20 --------- d-----w C:\Program Files\Spotmau WinCares 2007
    2008-08-01 20:54 --------- d-----w C:\ProgramData\Yahoo!
    2008-08-01 20:53 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\Yahoo!
    2008-08-01 20:39 --------- d-----w C:\ProgramData\Apple Computer
    2008-08-01 20:39 --------- d-----w C:\Program Files\QuickTime
    2008-08-01 20:05 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-08-01 19:51 --------- d-----w C:\Program Files\Microsoft Works
    2008-08-01 19:50 --------- d-----w C:\Program Files\MSBuild
    2008-08-01 19:48 --------- d-----w C:\Program Files\Microsoft.NET
    2008-08-01 19:44 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
    2008-07-31 11:00 --------- d-----w C:\Program Files\ThinkPad
    2008-07-31 11:00 --------- d-----w C:\Program Files\Lenovo
    2008-07-31 10:56 --------- d-----w C:\Program Files\Windows Sidebar
    2008-07-31 10:52 --------- d-----w C:\Program Files\Common Files\InstallShield
    2008-07-31 10:03 174 --sha-w C:\Program Files\desktop.ini
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Photo Gallery
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Journal
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Defender
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Collaboration
    2008-07-31 09:55 --------- d-----w C:\Program Files\Windows Calendar
    2008-07-31 09:43 82,432 ----a-w C:\Windows\System32\axaltocm.dll
    2008-07-31 09:43 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
    2008-07-31 08:51 47,560 ----a-w C:\Windows\System32\SPReview.exe
    2008-07-31 08:51 152,576 ----a-w C:\Windows\System32\SPWizUI.dll
    2008-07-31 08:09 --------- d-----w C:\Users\Theo Moor\AppData\Roaming\ATI
    2008-07-31 08:06 --------- d-----w C:\Program Files\ThinkVantage Fingerprint Software
    2008-07-31 08:03 --------- d-----w C:\ProgramData\UIB
    2008-07-31 08:03 --------- d-----w C:\Program Files\Common Files\ThinkVantage Fingerprint Software
    2008-07-31 08:01 --------- d-----w C:\Program Files\ATI Technologies
    2008-07-31 08:00 --------- d-----w C:\Program Files\ATI
    2008-07-31 07:37 --------- d-----w C:\Program Files\Common Files\Lenovo
    2008-07-31 07:23 233,888 ----a-w C:\Windows\System32\DreamScene.dll
    2008-07-31 07:21 --------- d-----w C:\Program Files\UPEK
    2008-07-31 07:20 --------- d-----w C:\Program Files\BitLocker
    2008-07-31 07:19 1,171,848 ----a-w C:\Windows\System32\SecureKeyBackupCPL.dll
    2008-07-31 07:17 678,408 ----a-w C:\Windows\System32\gpprefcl.dll
    2008-07-31 07:16 --------- d-----w C:\Program Files\Microsoft Games
    2008-07-31 07:15 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
    2008-07-31 07:15 --------- d-----w C:\Program Files\Synaptics
    2008-07-31 07:15 --------- d-----w C:\Program Files\CONEXANT
    2008-07-31 06:28 9,847,296 ----a-w C:\Windows\System32\NlsData000a.dll
    2008-07-31 06:26 2,032,128 ----a-w C:\Windows\System32\win32k.sys
    2008-07-31 06:25 295,936 ----a-w C:\Windows\System32\gdi32.dll
    2008-07-31 06:22 14,848 ----a-w C:\Windows\System32\wshrm.dll
    2008-07-31 06:22 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
    2008-07-31 06:20 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
    2008-07-31 06:20 1,695,744 ----a-w C:\Windows\System32\gameux.dll
    2008-07-31 06:17 1,314,816 ----a-w C:\Windows\System32\quartz.dll
    2008-07-31 06:16 428,544 ----a-w C:\Windows\System32\EncDec.dll
    2008-07-31 06:16 293,376 ----a-w C:\Windows\System32\psisdecd.dll
    2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
    2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
    2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
    2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
    2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-09-23_ 0.32.07.96 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-09-24 01:11:05 18,944 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
    + 2008-09-24 01:11:05 65,024 ----a-r C:\Windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
    - 2008-09-23 07:29:29 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
    + 2008-09-25 03:43:30 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
    - 2008-09-23 07:29:29 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    + 2008-09-25 03:43:30 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    - 2008-09-23 07:29:15 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-09-25 03:43:06 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-09-24 05:01:20 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008092320080924\index.dat
    - 2008-09-23 07:29:15 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-09-25 03:43:06 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-09-23 07:29:15 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-09-25 03:43:06 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2008-09-23 07:24:25 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
    + 2008-09-24 05:06:38 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
    - 2008-09-23 06:56:50 106,796 ----a-w C:\Windows\System32\perfc009.dat
    + 2008-09-24 15:45:37 106,796 ----a-w C:\Windows\System32\perfc009.dat
    - 2008-09-23 06:56:50 611,788 ----a-w C:\Windows\System32\perfh009.dat
    + 2008-09-24 15:45:37 611,788 ----a-w C:\Windows\System32\perfh009.dat
    - 2008-09-22 22:19:50 6,604 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2498408150-3981597196-2587865111-1000_UserData.bin
    + 2008-09-24 01:06:23 6,856 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2498408150-3981597196-2587865111-1000_UserData.bin
    - 2008-09-22 22:19:50 59,240 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-09-24 01:06:23 60,132 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2008-09-23 03:26:37 34,256 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-09-24 06:59:48 34,460 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-09-22 266497]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
    "TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-03-24 68464]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "EnableInstallerDetection"= 0 (0x0)
    "EnableLUA"= 0 (0x0)
    "EnableSecureUIAPaths"= 0 (0x0)
    "EnableVirtualization"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "DisableCAD"= 1 (0x1)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "LogonHoursAction"= 2 (0x2)
    "DontDisplayLogonHoursWarnings"= 1 (0x1)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
    2007-08-14 15:54 89600 C:\Windows\System32\psqlpwd.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages REG_MULTI_SZ scecli psqlpwd C:\Windows\system32\pojabese.dll C:\Windows\system32\pojabese.dll

    [HKLM\~\startupfolder\C:^Users^Theo Moor^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CCC.lnk]
    path=C:\Users\Theo Moor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CCC.lnk
    backup=C:\Windows\pss\CCC.lnk.Startup
    backupExtension=.Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BLOG]
    --------- 2008-06-13 02:30 214576 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLOGEX.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZEJMNAP]
    --------- 2008-06-05 02:36 242976 C:\PROGRA~1\ThinkPad\UTILIT~1\EZEJMNAP.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    --a------ 2007-08-24 07:00 33648 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWMTRV]
    --------- 2008-06-13 02:30 591136 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    --a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
    --a------ 2007-11-21 18:08 820520 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
    --a------ 2008-03-04 10:34 487424 C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    --a------ 2008-01-18 23:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    --a------ 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2498408150-3981597196-2587865111-1000]
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{14C99733-4468-449F-AB4D-7CB22BDA2F19}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
    "{31EADDE9-E2AD-4510-A8C7-D6BE7691CB5C}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{3DA5929B-C65D-49A4-A870-E70FC95C4EED}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
    "{3E49912C-6B00-4DB5-B24E-EFD6CAF97AD6}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{5066E27B-0873-4BA2-9B5D-CA2FBE6BA843}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{994B4A53-2A8E-4B10-BCE3-7C38486C36FD}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{09159D92-EA6A-4D82-9A2A-6AB4D7D72E3F}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{BEB6BFDE-56E4-4F55-B505-AAC495B1344A}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
    "{E94EADD5-AA7A-4487-80FD-0E80AA5461B8}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
    "{9F97F662-2B3A-4DB6-B2CE-FA2D2482BF5C}"= UDP:990:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdSync.exe,-4001
    "{C0862004-5E5C-43F9-B5F5-DE6D0496A394}"= UDP:990:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdSync.exe,-4001
    "{EF61FAD2-4E03-424B-8FED-040BCE8C8699}"= UDP:5721:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4002
    "{6BF31B32-A0E6-467E-856D-33A27E555335}"= UDP:1034:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4003
    "{56BDB850-4D1D-4364-A053-53F1926542D7}"= UDP:5678:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4004
    "{62244E3E-F731-42C5-A10E-C37B5AE9C60C}"= UDP:999:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4005
    "{CBF2E472-9B7E-46A1-8732-C3B520B63FE2}"= UDP:26675:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4006
    "{FCA69773-1341-4A43-A42D-FD75AF173083}"= UDP:990:LocalSubnet:LocalSubnet|IF={3F4D0C69-B544-4D8D-927E-E2EAFB598D3A}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdc.exe,-4001
    "{FA61575D-0DBF-4B1B-94EE-11C6CA413E3E}"= UDP:5721:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4002
    "{C0275CA5-3711-4887-93D8-2235D68075D9}"= UDP:1034:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4003
    "{CEAE717D-9660-4906-8F94-E52C9B4C62E9}"= UDP:5678:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4004
    "{096C14BC-7EAB-49B8-8536-0379D118B857}"= UDP:999:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%systemroot%\WindowsMobile\wmdHost.exe:mad:%systemroot%\WindowsMobile\wmdc.exe,-4005
    "{952340F9-65E5-4544-AA58-90C9F29699C5}"= UDP:26675:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}:mad:%systemroot%\WindowsMobile\wmdc.exe,-4006
    "{33EA85A1-8F53-4BE7-9E5A-EBE4619379AB}"= UDP:990:LocalSubnet:LocalSubnet|IF={B9EA0412-E9F4-4760-9C11-B1FEC00561A0}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:mad:%systemroot%\WindowsMobile\wmdc.exe,-4001
    "{4E9731CD-6D92-49F5-8AD6-FCE70BDEADB3}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
    "{EDF13208-E6B8-44CD-83BF-87ACD83751F2}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
    "{224B317F-9D86-4EB4-9B26-455BCAE2774D}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
    "{141B6876-88C0-4085-9DDF-FD24F7076100}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
    "{6448E642-07C8-4AF5-A5C4-0C76D9B1FB8E}"= UDP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
    "{1B94555C-451E-4970-B9DA-DAE44AD99BF9}"= TCP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
    "{8F4F7A7B-08AD-46B9-B33C-9623F1E51B3A}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{1BB56A87-F810-40DA-9616-0BD3F85B053F}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{431C8773-0CCD-4077-9506-7678D8C7C678}"= UDP:C:\Program Files\AIM6\aim6.exe:AIM
    "{D2C19758-638C-4B8A-901C-3FA609D145F7}"= TCP:C:\Program Files\AIM6\aim6.exe:AIM
    "TCP Query User{60E15E31-81F5-4238-8184-601ED071D8D3}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:µTorrent
    "UDP Query User{F618D534-A0E9-406F-A44A-B60998F08498}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:µTorrent

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiif32.sys [2008-05-12 13480]
    R1 TPPWRIF;TPPWRIF;C:\Windows\system32\drivers\Tppwr32v.sys [2008-06-13 12080]
    R2 smihlp;SMI Helper Driver (smihlp);C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-08-14 10896]
    R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-04-05 2464768]
    R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-05-02 179712]
    R3 HSXHWICH;HSXHWICH;C:\Windows\system32\DRIVERS\HSXHWICH.sys [2006-10-18 248320]
    S3 NETw2v32;Intel(R) PRO/Wireless 2915ABG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
    bthsvcs REG_MULTI_SZ BthServ

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b32395b-7001-11dd-9017-000000000000}]
    \shell\AutoRun\command - E:\autorun.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
    msiexec /fums {CCA08FFD-3F64-A525-170F-FB2D73CDC661} /qb

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
    %SystemRoot%\system32\soundschemes.exe /AddRegistration
    .
    Contents of the 'Scheduled Tasks' folder
    .
    - - - - ORPHANS REMOVED - - - -

    MSConfigStartUp-buvuzodala - C:\Windows\system32\kejajumo.dll



    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-24 20:43:40
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    PROCESS: C:\Windows\Explorer.exe
    -> ?:\Windows\system32\MLANG.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Windows\System32\ibmpmsvc.exe
    C:\Windows\System32\Ati2evxx.exe
    C:\Windows\System32\audiodg.exe
    C:\Windows\System32\Ati2evxx.exe
    C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
    C:\Windows\System32\ZoneLabs\vsmon.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe
    C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    C:\Windows\System32\drivers\XAudio.exe
    C:\Program Files\Lenovo\System Update\SUService.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avwebgrd.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\ZOOM\TpScrex.exe
    C:\Windows\System32\dllhost.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avwsc.exe
    .
    **************************************************************************
    .
    Completion time: 2008-09-24 20:46:54 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-09-25 03:46:42
    ComboFix2.txt 2008-09-23 07:33:31

    Pre-Run: 45,926,862,848 bytes free
    Post-Run: 45,781,835,776 bytes free

    394 --- E O F --- 2008-09-23 07:00:06

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:52:42 PM, on 9/24/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\Zoom\TpScrex.exe
    C:\Windows\System32\mobsync.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\NOTEPAD.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
    O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
    O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe
    O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
    O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
    O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
    O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
    O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 5690 bytes
     
  4. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Talk to me.....

    Your Log is CLEAN.. Any more problems????

    2OG
     
  5. chkinjoe

    chkinjoe Member

    Joined:
    Jun 27, 2008
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    16
    ye asorry about that the posting was messed up but thanks for your help and no theers no more problems. i would just like to know one thing were can i go to learn how to read whats legit and whats not, and be able to do this for myself and help others too?
     
  6. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Congratulations chkinjoe, your log now looks CLEAN [​IMG]




    Check out Malwareremoval.com they have a program called MRU (Malware Removal University). You can learn a lot there….



    Here are a few other things you must do once you are completely clean:

    1. Time for some housekeeping

    • Click START then RUN
    • Now type (or Copy/Paste) Combofix /u in the runbox and click OK
    [​IMG]




    2. Now Set a New Restore Point to prevent possible re-infection from an old one.
    Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can re-infect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

    The easiest and safest way to do this is:

    • Go to Start > Programs > Accessories > System Tools and click "System Restore".

    • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.

    • Then go to Start > Run and type: Cleanmgr
    • Click "OK"
    Select the drive you want to clean usually C:
    Click OK
    When it completes the scan:
    • Click the "More Options" Tab.
    • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.


    3. Defragment your Hard Drive

    1.Open My Computer.
    2.Right-click the local disk volume that you want to defragment, and then click Properties.
    3.On the Tools tab, click Defragment Now.
    4.Click Defragment.




    And here are some tips to reduce the potential for spyware infection in the future:


    Make sure you keep your Windows OS current by visiting Windows update
    regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.


    I strongly recommend installing the following applications:


    To protect your machine, I highly recommend BOClean. It’s FREE and it works. I use it and never get one of these infections.

    In order to prevent the installation of Trojans and Malware on your machine:
    Download and install: Comodo BOClean

    Comodo BOClean protects your computer against trojans, malware and other threats. It constantly scans your system in the background and intercepts any recognized trojan activity. The program can ask the user what to do, or run in unattended mode and automatically shutdown and remove any suspected Trojan application. Comodo BOClean currently supports more than 60,000 malware items and offers automatic daily updates. Other features include updating via network share, tamper protection and stealth mode.

    Spywareblaster <= SpywareBlaster will prevent spyware from being installed.



    See Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.


    And also see Tony Klein's good advice
    So how did I get infected in the first place?




    Enjoy your clean computer. Any more questions?



    2OG
     
  7. chkinjoe

    chkinjoe Member

    Joined:
    Jun 27, 2008
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    16
    is there a free virtual environment i can download for my comp so i can test out exe files im unsure of?
     
  8. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
  9. chkinjoe

    chkinjoe Member

    Joined:
    Jun 27, 2008
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    16
    oh yea sry but one last thing, everytime i restart my computer it goes to the vista loading screen then it will go to the menu that lets you choose safemode,last know configuration. the only way i can boot into vista is if i select the last known configuration. whats up with that?
     
  10. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    MSCONFIG may have gotten set wrong.
    If the Safeboot got checked it will cause this action.


    • Click Start, Run and type MSCONFIG in the box and click OK
    • The System Configuration Utility appears, On the BOOT.INI tab, Un-Check the "/SAFEBOOT" option, and then click OK and Restart your computer when prompted
     
  11. chkinjoe

    chkinjoe Member

    Joined:
    Jun 27, 2008
    Messages:
    32
    Likes Received:
    0
    Trophy Points:
    16
    thank you for all the help sir
     
  12. jimrush51

    jimrush51 Member

    Joined:
    Oct 27, 2008
    Messages:
    13
    Likes Received:
    0
    Trophy Points:
    11
    would this work for a xp as i am suffering from the same virus?
     
  13. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Hi jimrush51,

    You may or may not have the same virus, so first, let’s do a little Pre-Cleaning and Post some Logs so we can see what’s going on…


    Download TrendMicro HijackThis.exe (HJT)

    • Double-click on HJTInstall.
    • Click on the Install button.
    • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
    • Upon install, HijackThis should open for you.
    • From the desktop open Hijackthis.
    • Click on the Do a system scan and save a log file button
    • Hijackthis will scan and then a log will open in notepad.
    Copy and then paste the entire contents of the log in your post.
    Do not have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.


    Please download ATF Cleaner by Atribune & save it to your desktop. DO NOT use yet.

    Please download and install SUPERAntiSpyware Free

    • Double-click SUPERAntiSypware.exe and use the default settings for installation.
    • An icon will be created on your desktop. Double-click that icon to launch the program.
    • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here and unzip into the program's folder.)
    • Under the "Configuration and Preferences", click the Preferences... button.
    • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
    • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):
    o Close browsers before scanning.
    o Scan for tracking cookies.
    o Terminate memory threats before quarantining.

    • Click the "Close" button to leave the control center screen and exit the program.
    Do not run a scan just yet.


    Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

    Double-click ATF-Cleaner.exe to run the program.

    • Under Main "Select Files to Delete" choose: Select All.
    • Click the Empty Selected button.

    • If you use Firefox browser click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.

    • If you use Opera browser click Opera at the top and choose: Select All
    • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.

    • Click Exit on the Main menu to close the program.

    Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".


    Scan with SUPERAntiSpyware as follows:

    • Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    • On the left, make sure you check C:\Fixed Drive.
    • On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
    • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    • Make sure everything has a checkmark next to it and click "Next".
    • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    • If asked if you want to reboot, click "Yes" and reboot normally.
    • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    o Click Preferences, then click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    o Please copy and paste the Scan Log results in your next reply.

    • Click Close to exit the program.

    Reboot to Normal Mode


    Please post the HijackThis log and SUPERAntiSpyware Log in your next reply.




    2OG
     

Share This Page