I am posting the log from combofix and gmer. I will copy and paste the file instead of using the attachment. Please let me know, if this is not the right way to post the logs. Again, thanks for your help. I am not using the internet except to try and fix the computer.
ComboFix 09-06-15.04 - Compaq_Owner 06/15/2009 18:14.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.703.249 [GMT -4:00]
Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\Compaq_Owner\Local Settings\Temp\IadHide5.dll
c:\windows\system32\UACcltksoexyluwpbo.dat
c:\windows\system32\UACroldgsvmchddmwi.log
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-06-16 17:43:17
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xF7DC887E]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xF7DC8BFE]
Code \??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\catchme.sys pIofCallDriver
---- Kernel code sections - GMER 1.0.15 ----
? Combo-Fix.sys The system cannot find the file specified. !
? C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!??2@YAPAXI@Z 77C29CC5 5 Bytes JMP 0A93C080 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!??3@YAXPAX@Z 77C29CDD 5 Bytes JMP 0A93C0E0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C29D9F 5 Bytes JMP 0A93C110 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_aligned_offset_malloc 77C29DAF 5 Bytes JMP 0A93BFE0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_aligned_free 77C29E33 5 Bytes JMP 0A93C0E0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_aligned_malloc 77C29E52 5 Bytes JMP 0A93BFC0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_aligned_offset_realloc 77C29E6E 5 Bytes JMP 0A93C020 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_aligned_realloc 77C29FC6 5 Bytes JMP 0A93C000 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_expand 77C29FE5 5 Bytes JMP 0A93BFA0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_heapadd 77C2BC9F 5 Bytes JMP 0A93C160 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_heapchk 77C2BCB3 5 Bytes JMP 0A93C170 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_heapset + 1 77C2BD83 4 Bytes JMP 0A93C191 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_heapmin 77C2BD8C 5 Bytes JMP 0A93C260 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_heapused 77C2BE3A 5 Bytes JMP 0A93C230 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_heapwalk 77C2BE4D 5 Bytes JMP 0A93C1A0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!_msize 77C2BF6C 5 Bytes JMP 0A93BEB0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!calloc 77C2C0C3 5 Bytes JMP 0A93BE50 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!free 77C2C21B 5 Bytes JMP 0A93C0E0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!malloc 77C2C407 5 Bytes JMP 0A93BE10 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[3464] msvcrt.dll!realloc 77C2C437 5 Bytes JMP 0A93BE90 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- EOF - GMER 1.0.15 ----
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
.
2009-06-12 14:27 . 2009-06-12 14:27 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2009-06-12 14:27 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-12 14:27 . 2009-06-12 14:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-12 14:27 . 2009-06-12 14:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-12 14:27 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-12 13:41 . 2009-06-02 17:37 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-12 12:32 . 2009-06-12 13:41 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-12 12:32 . 2009-06-12 12:32 -------- d-----w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-12 12:30 . 2009-05-17 12:37 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-06-10 07:16 . 2009-06-10 07:16 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\InterMute
2009-06-10 05:44 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 05:44 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-05 01:23 . 2009-06-05 01:23 -------- d-----w- c:\program files\iPod
2009-06-05 01:22 . 2009-06-05 01:23 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-05 01:17 . 2009-05-29 17:36 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 01:13 . 2009-06-05 01:13 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-04 21:33 . 2009-06-04 21:33 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-02 18:26 . 2009-06-02 18:26 -------- d-sh--w- c:\documents and settings\Compaq_Owner\PrivacIE
2009-06-02 18:25 . 2009-06-02 18:25 -------- d-sh--w- c:\documents and settings\Compaq_Owner\IETldCache
2009-06-02 18:22 . 2009-06-02 18:22 -------- d-----w- c:\windows\ie8updates
2009-06-02 18:22 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-02 18:19 . 2009-06-02 18:21 -------- dc-h--w- c:\windows\ie8
2009-05-29 22:19 . 2009-05-29 22:19 -------- d-----w- c:\program files\Common Files\Diskeeper Corporation
2009-05-29 22:19 . 2009-05-29 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Diskeeper Corporation
2009-05-29 22:19 . 2009-05-29 22:19 -------- d-----w- c:\program files\Diskeeper Corporation
2009-05-29 19:59 . 2009-05-29 19:59 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-05-28 01:34 . 2009-05-28 01:34 314200 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-05-28 01:34 . 2009-05-28 01:34 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-05-28 01:34 . 2009-05-28 01:34 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-05-28 01:34 . 2009-05-28 01:34 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-05-26 02:17 . 2009-05-28 01:34 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-05-26 01:20 . 2009-05-26 01:20 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-05-26 01:08 . 2009-05-29 20:10 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-26 01:08 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-05-26 01:08 . 2009-05-26 01:08 -------- d-----w- c:\program files\Lavasoft
2009-05-24 17:07 . 2009-05-24 17:07 32 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-05-24 17:07 . 2009-05-24 19:33 2102048 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-05-24 16:45 . 2009-05-24 19:56 -------- d-----w- c:\program files\Common Files\ParetoLogic
2009-05-24 16:45 . 2009-05-24 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-05-24 16:43 . 2009-05-24 16:43 -------- d-----w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Downloaded Installations
2009-05-22 13:48 . 2009-05-22 14:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-22 13:43 . 2009-05-17 12:53 2051864 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-05-22 13:43 . 2009-05-17 12:52 354584 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgxch32.dll
2009-05-22 13:43 . 2009-05-22 13:42 3288856 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-05-22 13:43 . 2009-05-17 12:52 424472 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwdwsc.dll
2009-05-22 13:43 . 2009-05-17 12:52 312088 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avglngx.dll
2009-05-22 13:43 . 2009-05-17 12:52 177432 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmail.dll
2009-05-22 13:43 . 2009-05-17 12:53 486168 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgrsx.exe
2009-05-22 13:41 . 2009-05-22 13:41 1439488 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-05-22 13:41 . 2009-05-17 12:36 755992 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll
2009-05-18 16:34 . 2009-05-18 16:34 34656 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-18 16:30 . 2009-05-18 16:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Lavasoft
2009-05-18 16:30 . 2009-05-18 16:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools
2009-05-18 15:12 . 2009-05-18 15:12 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Motive
2009-05-18 14:14 . 2009-05-22 18:33 -------- d-----w- c:\program files\PC Tools AntiVirus
2009-05-17 22:53 . 2009-05-17 22:53 -------- d-----w- c:\program files\interMute
2009-05-17 22:15 . 2009-05-22 13:44 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Lavasoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-12 12:31 . 2008-06-15 02:40 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-12 12:31 . 2009-06-12 12:33 826624 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-05 01:23 . 2007-11-30 04:28 -------- d-----w- c:\program files\iTunes
2009-06-05 01:22 . 2007-11-30 04:23 -------- d-----w- c:\program files\Common Files\Apple
2009-06-05 01:19 . 2007-11-30 04:25 -------- d-----w- c:\program files\QuickTime
2009-05-29 19:57 . 2004-08-10 15:43 3888 -c--a-w- c:\windows\viassary-hp.reg
2009-05-29 17:36 . 2008-08-01 01:16 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-26 12:20 . 2007-11-29 15:43 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-24 19:58 . 2004-08-10 15:11 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-24 17:07 . 2009-05-24 17:07 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-05-24 17:07 . 2009-05-24 17:07 32 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-05-23 02:24 . 2007-11-28 16:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-23 02:24 . 2007-11-28 16:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-22 18:29 . 2009-05-16 21:10 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-17 18:17 . 2008-09-30 00:46 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Move Networks
2009-05-17 15:13 . 2008-06-15 02:39 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\AVGTOOLBAR
2009-05-17 12:53 . 2009-06-12 12:33 325896 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-05-17 12:53 . 2008-06-15 02:40 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-17 12:53 . 2008-02-28 01:18 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-17 12:53 . 2008-06-15 02:40 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-17 12:53 . 2009-06-12 12:33 487704 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtbapi.dll
2009-05-17 12:52 . 2009-06-12 12:33 2301208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-05-17 12:52 . 2009-06-12 12:33 3401496 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-05-17 12:52 . 2009-06-12 12:33 1947928 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-05-17 12:52 . 2009-06-12 12:33 1217816 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgfrw.exe
2009-05-17 12:52 . 2009-06-12 12:33 1205528 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgabout.dll
2009-05-17 12:52 . 2009-06-12 12:33 681752 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgsrmx.dll
2009-05-17 12:52 . 2009-06-12 12:33 1262880 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-05-17 12:52 . 2009-06-12 12:33 761112 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgscanx.exe
2009-05-17 12:52 . 2009-06-12 12:33 341272 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgsrmax.exe
2009-05-17 12:52 . 2009-06-12 12:33 830232 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-05-16 17:37 . 2008-06-15 02:39 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-05-13 05:15 . 2007-11-28 17:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2007-11-28 16:59 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-17 12:26 . 2007-11-28 17:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2007-11-28 17:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-03-19 20:32 . 2009-03-19 20:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-18 22:22 . 2007-11-29 15:23 34656 ----a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-11-28 12:17 . 2007-11-28 17:30 0 -csha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2004-08-10 14:57 . 2003-02-12 03:02 61440 c:\hp\KBD\bak\KBD.EXE
2007-10-11 00:51 . 2007-10-11 00:51 39792 c:\program files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
2008-01-12 02:16 . 2008-01-12 02:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
2007-11-30 02:22 . 2007-12-22 16:46 579072 c:\program files\Grisoft\AVG7\bak\avgcc.exe
2008-01-15 08:22 . 2008-01-15 08:22 267048 c:\program files\iTunes\bak\iTunesHelper.exe
2009-05-30 16:30 . 2009-05-30 16:30 292136 c:\program files\iTunes\iTunesHelper.exe
2004-08-10 14:09 . 2004-08-10 14:09 32881 c:\program files\Java\j2re1.4.2_03\bin\bak\jusched.exe
2008-01-10 20:27 . 2008-01-10 20:27 385024 c:\program files\QuickTime\bak\QTTask.exe
2009-05-26 21:18 . 2009-05-26 21:18 413696 c:\program files\QuickTime\QTTask.exe
2004-04-15 03:43 . 2004-04-15 03:43 233472 c:\windows\SMINST\bak\RECGUARD.EXE
2004-08-10 14:24 . 1998-05-07 23:04 52736 c:\windows\system\bak\hpsysdrv.exe
2007-11-28 16:58 . 2004-08-03 19:00 15360 c:\windows\system32\bak\ctfmon.exe
2007-11-28 16:58 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe
2004-08-10 14:57 . 2003-09-13 03:13 98304 c:\windows\system32\bak\ps2.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-02 17:37 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-29 518488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-08 53248]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-30 88363]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]
c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2009-5-22 225280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2004-6-9 471040]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-7-22 151552]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]
Photo Loader supervisory.lnk - c:\program files\CASIO\Photo Loader\Plauto.exe [2008-8-31 229376]
SpySubtract.lnk - c:\program files\interMute\SpySubtract\SpySub.exe [2009-5-17 1183744]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}"= "c:\program files\interMute\SpySubtract\sshook.dll" [2009-05-17 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-17 12:53 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0autocheck lsdelete\
0autocheck lsdelete\
0autocheck lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/25/2009 9:21 PM 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/14/2008 10:40 PM 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/14/2008 10:40 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/7/2008 10:03 AM 908568]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/7/2008 10:03 AM 298776]
R3 Belkin Belkin 11Mbps Wireless USB Network Adapter®;Belkin Belkin 11Mbps Wireless USB Network Adapter® Service for Belkin 11Mbps Wireless USB Network Adapter;c:\windows\system32\drivers\bkusbxp.sys [1/2/2009 3:34 PM 98432]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1005904]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-15 c:\windows\Tasks\Ad-Aware Scan (Daily).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 01:21]
2009-06-15 c:\windows\Tasks\Ad-Aware Update (Daily).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 01:21]
2009-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
.
.
------- Supplementary Scan -------
.
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: Add To Compaq Organize... - c:\progra~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-15 18:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\docume~1\COMPAQ~1\LOCALS~1\Temp\JETDB28.tmp 0 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(720)
c:\windows\system32\WININET.dll
c:\docume~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\CF1345.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-06-15 18:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-15 22:27
Pre-Run: 15,663,968,256 bytes free
Post-Run: 16,074,891,264 bytes free
250 --- E O F --- 2009-06-10 07:08