Log for the second ComboFix run:
ComboFix 10-01-04.01 - ACER Custpmer 01/10/2010 6:58.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1007.494 [GMT 0:00]
Running from: c:\documents and settings\ACER Custpmer\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\ACER Custpmer\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GAGP440P
-------\Legacy_MEMSWEEP2
-------\Service_gAGP440p
-------\Service_MEMSWEEP2
((((((((((((((((((((((((( Files Created from 2009-12-10 to 2010-01-10 )))))))))))))))))))))))))))))))
.
2010-01-09 19:30 . 2010-01-09 19:30 -------- d-----w- c:\documents and settings\ACER Custpmer\Application Data\Malwarebytes
2010-01-09 19:30 . 2010-01-07 16:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-09 19:30 . 2010-01-09 19:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-09 19:30 . 2010-01-09 19:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-09 19:30 . 2010-01-07 16:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-09 12:06 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-09 11:31 . 2010-01-09 11:31 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-01-09 11:21 . 2010-01-09 11:21 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-09 11:20 . 2010-01-09 11:20 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2010-01-09 11:20 . 2010-01-09 11:20 -------- d-----w- c:\program files\McAfee Security Scan
2010-01-09 11:19 . 2010-01-09 11:28 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-01-09 11:19 . 2010-01-09 11:19 -------- d-----w- c:\program files\NOS
2010-01-09 10:45 . 2010-01-09 10:45 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-09 10:41 . 2010-01-09 10:41 -------- d-----w- c:\documents and settings\ACER Custpmer\.SunDownloadManager
2010-01-09 09:58 . 2003-01-20 19:00 13942408 ------w- c:\documents and settings\Jan2\MpSetup.exe
2010-01-09 09:57 . 2010-01-09 11:09 -------- d-----w- c:\documents and settings\Jan2
2010-01-09 08:23 . 2010-01-09 08:23 -------- d-----w- c:\program files\Sophos
2010-01-07 18:33 . 2010-01-07 18:37 -------- d-----w- c:\program files\Windows Live Safety Center
2009-12-24 10:41 . 2009-12-24 10:41 -------- d-----w- c:\program files\WLAN 802.11g mini-PCI Module
2009-12-23 23:22 . 2003-03-31 04:00 5632 ----a-w- c:\windows\system32\dllcache\smimsgif.dll
2009-12-23 23:22 . 2003-03-31 04:00 5632 ----a-w- c:\windows\system32\dllcache\smierrsy.dll
2009-12-23 23:22 . 2003-03-31 04:00 15872 ----a-w- c:\windows\system32\dllcache\smierrsm.dll
2009-12-23 23:22 . 2003-03-31 04:00 10240 ----a-w- c:\windows\system32\wbem\snmpstup.dll
2009-12-23 23:22 . 2003-03-31 04:00 10240 ----a-w- c:\windows\system32\dllcache\snmpstup.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-09 12:03 . 2009-11-11 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-09 11:34 . 2008-06-03 00:20 -------- d-----w- c:\program files\Azureus
2010-01-09 11:33 . 2008-06-03 00:20 -------- d-----w- c:\documents and settings\ACER Custpmer\Application Data\Azureus
2010-01-09 11:24 . 2004-08-13 08:07 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-09 11:19 . 2010-01-09 11:19 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-09 11:13 . 2004-02-09 09:01 -------- d-----w- c:\program files\Java
2010-01-09 08:20 . 2010-01-09 08:21 2621440 ----a-w- c:\windows\Internet Logs\xDBB.tmp
2010-01-07 23:59 . 2004-10-18 17:21 68968 ----a-w- c:\documents and settings\ACER Custpmer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-07 09:32 . 2004-11-16 12:58 -------- d-----w- c:\documents and settings\ACER Custpmer\Application Data\Skype
2010-01-07 08:48 . 2010-01-07 08:50 1629696 ----a-w- c:\windows\Internet Logs\xDBA.tmp
2010-01-07 08:30 . 2008-03-02 20:38 -------- d-----w- c:\documents and settings\ACER Custpmer\Application Data\skypePM
2010-01-06 17:15 . 2009-10-07 21:20 24244540 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-12-24 16:39 . 2009-12-24 16:40 4043544 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-24 16:39 . 2009-12-24 16:39 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-24 11:07 . 2008-12-26 15:04 -------- d-----w- c:\program files\DOSBox-0.72
2009-12-24 10:41 . 2004-02-09 08:50 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-19 09:00 . 2009-12-24 16:40 294656 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-17 16:37 . 2010-01-09 11:19 31936 ----a-w- c:\documents and settings\ACER Custpmer\Application Data\Mozilla\Firefox\Profiles\9u6wyzto.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-12-17 16:37 . 2010-01-09 11:19 29344 ----a-w- c:\documents and settings\ACER Custpmer\Application Data\Mozilla\Firefox\Profiles\9u6wyzto.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-12-12 16:02 . 2010-01-01 23:26 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-12-12 16:02 . 2009-12-24 16:40 3776280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-12 16:01 . 2009-12-19 09:00 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-09 23:44 . 2009-12-09 23:45 1574912 ----a-w- c:\windows\Internet Logs\xDB9.tmp
2009-11-22 13:08 . 2007-02-06 22:16 -------- d-----w- c:\program files\EndNote X
2009-11-21 15:51 . 1979-12-31 16:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-20 11:08 . 2010-01-09 11:22 38784 ----a-w- c:\documents and settings\ACER Custpmer\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-15 12:48 . 2007-02-06 22:15 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-15 12:48 . 2008-04-14 21:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-13 19:55 . 2009-11-13 19:53 -------- d-----w- c:\program files\CheckPoint
2009-11-11 08:59 . 2009-09-30 17:47 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-11 08:59 . 2009-09-30 17:47 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-11 08:59 . 2009-09-30 17:47 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-11 08:59 . 2009-09-30 17:47 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-11 08:58 . 2009-09-30 17:45 -------- d-----w- c:\program files\AVG
2009-11-05 23:33 . 2009-11-05 23:34 1442816 ----a-w- c:\windows\Internet Logs\xDB8.tmp
2009-10-31 23:17 . 2009-10-31 23:18 1437184 ----a-w- c:\windows\Internet Logs\xDB7.tmp
2009-10-30 22:27 . 2009-10-30 22:30 1436672 ----a-w- c:\windows\Internet Logs\xDB6.tmp
2009-10-29 07:45 . 2004-02-06 11:05 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ------w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 1979-12-31 16:00 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-13 08:05 . 2009-10-13 16:23 1414144 -c--a-w- c:\windows\Internet Logs\xDB5.tmp
2009-10-12 13:38 . 1979-12-31 16:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 1979-12-31 16:00 79872 ----a-w- c:\windows\system32\raschap.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SoundMan"="SOUNDMAN.EXE" [2003-12-19 65024]
"AGRSMMSG"="AGRSMMSG.exe" [2003-08-20 88363]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2003-04-28 184320]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-04-18 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-04-18 610304]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-01-07 3051520]
"nwiz"="nwiz.exe" [2004-01-07 753664]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-08-27 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-08-27 118784]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 40960]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-09 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-11 08:59 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2008-06-18 13:47 24692 ----a-w- c:\windows\system32\ckpNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2003-11-28 10:21 335872 ----a-w- c:\program files\Launch Manager\QtDTAcer.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2003-06-30 20:56 188416 ----a-w- c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2003-06-30 21:00 65536 ----a-w- c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
2004-11-12 17:24 106557 ----a-w- c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/30/2009 5:47 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/30/2009 5:47 PM 360584]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [11/11/2009 8:58 AM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/11/2009 8:58 AM 285392]
R2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32\drivers\omdrv.sys [6/18/2008 1:46 PM 47504]
R2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\system32\drivers\vnasc.sys [6/18/2008 1:46 PM 121136]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [6/18/2008 1:46 PM 673872]
R3 {5C8B2B62-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-A;c:\windows\system32\drivers\a311.sys [2/9/2004 9:48 AM 33335]
R3 {5C8B2B65-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-B;c:\windows\system32\drivers\a310.sys [2/9/2004 9:48 AM 33335]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [6/18/2008 1:46 PM 2235760]
S3 QCPro;Logitech QuickCam Pro USB(PID_D001);c:\windows\system32\drivers\p35u.sys [12/20/2006 10:28 PM 116480]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.be/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\ACER Custpmer\Application Data\Mozilla\Firefox\Profiles\9u6wyzto.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\ACER Custpmer\Application Data\Mozilla\Firefox\Profiles\9u6wyzto.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-10 07:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"3140110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2868)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\snmp.exe
c:\windows\SOUNDMAN.EXE
c:\windows\AGRSMMSG.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wltrysvc.exe
c:\windows\system32\bcmwltry.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-01-10 07:12:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-10 07:12
Pre-Run: 38,410,424,320 bytes free
Post-Run: 38,280,183,808 bytes free
- - End Of File - - F8A0CBC27168B4F7D567A83540CCD702
ComboFix 10-01-04.01 - ACER Custpmer 01/10/2010 6:58.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1007.494 [GMT 0:00]
Running from: c:\documents and settings\ACER Custpmer\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\ACER Custpmer\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GAGP440P
-------\Legacy_MEMSWEEP2
-------\Service_gAGP440p
-------\Service_MEMSWEEP2
((((((((((((((((((((((((( Files Created from 2009-12-10 to 2010-01-10 )))))))))))))))))))))))))))))))
.
2010-01-09 19:30 . 2010-01-09 19:30 -------- d-----w- c:\documents and settings\ACER Custpmer\Application Data\Malwarebytes
2010-01-09 19:30 . 2010-01-07 16:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-09 19:30 . 2010-01-09 19:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-09 19:30 . 2010-01-09 19:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-09 19:30 . 2010-01-07 16:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-09 12:06 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-09 11:31 . 2010-01-09 11:31 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-01-09 11:21 . 2010-01-09 11:21 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-09 11:20 . 2010-01-09 11:20 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2010-01-09 11:20 . 2010-01-09 11:20 -------- d-----w- c:\program files\McAfee Security Scan
2010-01-09 11:19 . 2010-01-09 11:28 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-01-09 11:19 . 2010-01-09 11:19 -------- d-----w- c:\program files\NOS
2010-01-09 10:45 . 2010-01-09 10:45 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-09 10:41 . 2010-01-09 10:41 -------- d-----w- c:\documents and settings\ACER Custpmer\.SunDownloadManager
2010-01-09 09:58 . 2003-01-20 19:00 13942408 ------w- c:\documents and settings\Jan2\MpSetup.exe
2010-01-09 09:57 . 2010-01-09 11:09 -------- d-----w- c:\documents and settings\Jan2
2010-01-09 08:23 . 2010-01-09 08:23 -------- d-----w- c:\program files\Sophos
2010-01-07 18:33 . 2010-01-07 18:37 -------- d-----w- c:\program files\Windows Live Safety Center
2009-12-24 10:41 . 2009-12-24 10:41 -------- d-----w- c:\program files\WLAN 802.11g mini-PCI Module
2009-12-23 23:22 . 2003-03-31 04:00 5632 ----a-w- c:\windows\system32\dllcache\smimsgif.dll
2009-12-23 23:22 . 2003-03-31 04:00 5632 ----a-w- c:\windows\system32\dllcache\smierrsy.dll
2009-12-23 23:22 . 2003-03-31 04:00 15872 ----a-w- c:\windows\system32\dllcache\smierrsm.dll
2009-12-23 23:22 . 2003-03-31 04:00 10240 ----a-w- c:\windows\system32\wbem\snmpstup.dll
2009-12-23 23:22 . 2003-03-31 04:00 10240 ----a-w- c:\windows\system32\dllcache\snmpstup.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-09 12:03 . 2009-11-11 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-09 11:34 . 2008-06-03 00:20 -------- d-----w- c:\program files\Azureus
2010-01-09 11:33 . 2008-06-03 00:20 -------- d-----w- c:\documents and settings\ACER Custpmer\Application Data\Azureus
2010-01-09 11:24 . 2004-08-13 08:07 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-09 11:19 . 2010-01-09 11:19 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-09 11:13 . 2004-02-09 09:01 -------- d-----w- c:\program files\Java
2010-01-09 08:20 . 2010-01-09 08:21 2621440 ----a-w- c:\windows\Internet Logs\xDBB.tmp
2010-01-07 23:59 . 2004-10-18 17:21 68968 ----a-w- c:\documents and settings\ACER Custpmer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-07 09:32 . 2004-11-16 12:58 -------- d-----w- c:\documents and settings\ACER Custpmer\Application Data\Skype
2010-01-07 08:48 . 2010-01-07 08:50 1629696 ----a-w- c:\windows\Internet Logs\xDBA.tmp
2010-01-07 08:30 . 2008-03-02 20:38 -------- d-----w- c:\documents and settings\ACER Custpmer\Application Data\skypePM
2010-01-06 17:15 . 2009-10-07 21:20 24244540 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-12-24 16:39 . 2009-12-24 16:40 4043544 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-24 16:39 . 2009-12-24 16:39 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-24 11:07 . 2008-12-26 15:04 -------- d-----w- c:\program files\DOSBox-0.72
2009-12-24 10:41 . 2004-02-09 08:50 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-19 09:00 . 2009-12-24 16:40 294656 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-17 16:37 . 2010-01-09 11:19 31936 ----a-w- c:\documents and settings\ACER Custpmer\Application Data\Mozilla\Firefox\Profiles\9u6wyzto.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-12-17 16:37 . 2010-01-09 11:19 29344 ----a-w- c:\documents and settings\ACER Custpmer\Application Data\Mozilla\Firefox\Profiles\9u6wyzto.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-12-12 16:02 . 2010-01-01 23:26 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-12-12 16:02 . 2009-12-24 16:40 3776280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-12 16:01 . 2009-12-19 09:00 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-09 23:44 . 2009-12-09 23:45 1574912 ----a-w- c:\windows\Internet Logs\xDB9.tmp
2009-11-22 13:08 . 2007-02-06 22:16 -------- d-----w- c:\program files\EndNote X
2009-11-21 15:51 . 1979-12-31 16:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-20 11:08 . 2010-01-09 11:22 38784 ----a-w- c:\documents and settings\ACER Custpmer\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-15 12:48 . 2007-02-06 22:15 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-15 12:48 . 2008-04-14 21:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-13 19:55 . 2009-11-13 19:53 -------- d-----w- c:\program files\CheckPoint
2009-11-11 08:59 . 2009-09-30 17:47 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-11 08:59 . 2009-09-30 17:47 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-11 08:59 . 2009-09-30 17:47 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-11 08:59 . 2009-09-30 17:47 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-11 08:58 . 2009-09-30 17:45 -------- d-----w- c:\program files\AVG
2009-11-05 23:33 . 2009-11-05 23:34 1442816 ----a-w- c:\windows\Internet Logs\xDB8.tmp
2009-10-31 23:17 . 2009-10-31 23:18 1437184 ----a-w- c:\windows\Internet Logs\xDB7.tmp
2009-10-30 22:27 . 2009-10-30 22:30 1436672 ----a-w- c:\windows\Internet Logs\xDB6.tmp
2009-10-29 07:45 . 2004-02-06 11:05 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ------w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 1979-12-31 16:00 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-13 08:05 . 2009-10-13 16:23 1414144 -c--a-w- c:\windows\Internet Logs\xDB5.tmp
2009-10-12 13:38 . 1979-12-31 16:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 1979-12-31 16:00 79872 ----a-w- c:\windows\system32\raschap.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SoundMan"="SOUNDMAN.EXE" [2003-12-19 65024]
"AGRSMMSG"="AGRSMMSG.exe" [2003-08-20 88363]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2003-04-28 184320]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-04-18 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-04-18 610304]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-01-07 3051520]
"nwiz"="nwiz.exe" [2004-01-07 753664]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-08-27 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-08-27 118784]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 40960]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-09 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-28 199184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-11 08:59 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2008-06-18 13:47 24692 ----a-w- c:\windows\system32\ckpNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2003-11-28 10:21 335872 ----a-w- c:\program files\Launch Manager\QtDTAcer.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2003-06-30 20:56 188416 ----a-w- c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2003-06-30 21:00 65536 ----a-w- c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
2004-11-12 17:24 106557 ----a-w- c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/30/2009 5:47 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/30/2009 5:47 PM 360584]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [11/11/2009 8:58 AM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/11/2009 8:58 AM 285392]
R2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32\drivers\omdrv.sys [6/18/2008 1:46 PM 47504]
R2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\system32\drivers\vnasc.sys [6/18/2008 1:46 PM 121136]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [6/18/2008 1:46 PM 673872]
R3 {5C8B2B62-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-A;c:\windows\system32\drivers\a311.sys [2/9/2004 9:48 AM 33335]
R3 {5C8B2B65-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-B;c:\windows\system32\drivers\a310.sys [2/9/2004 9:48 AM 33335]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [6/18/2008 1:46 PM 2235760]
S3 QCPro;Logitech QuickCam Pro USB(PID_D001);c:\windows\system32\drivers\p35u.sys [12/20/2006 10:28 PM 116480]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.be/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\ACER Custpmer\Application Data\Mozilla\Firefox\Profiles\9u6wyzto.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\ACER Custpmer\Application Data\Mozilla\Firefox\Profiles\9u6wyzto.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-10 07:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"3140110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2868)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\snmp.exe
c:\windows\SOUNDMAN.EXE
c:\windows\AGRSMMSG.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wltrysvc.exe
c:\windows\system32\bcmwltry.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-01-10 07:12:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-10 07:12
Pre-Run: 38,410,424,320 bytes free
Post-Run: 38,280,183,808 bytes free
- - End Of File - - F8A0CBC27168B4F7D567A83540CCD702