here is the report. thinks seem to be running better no longer have the problem with google. what do you think the problem was?
ComboFix 08-09-28.03 - e 2008-09-30 2:16:31.2 - NTFSx86
Running from: C:\Documents and Settings\e\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\system32\TDSSadw.dll
C:\WINDOWS\system32\TDSSerrors.log
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\TDSSserf1.dll
C:\WINDOWS\system32\tdssservers.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV
-------\Service_TDSSserv
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-30 )))))))))))))))))))))))))))))))
.
2008-09-30 01:43 . 2008-09-30 01:43 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-30 01:42 . 2008-09-30 01:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-30 01:39 . 2008-09-30 01:39 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-30 01:39 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-30 01:24 . 2008-09-30 01:24 61,440 --a------ C:\WINDOWS\system32\drivers\sbalb.sys
2008-09-30 00:04 . 2008-09-30 02:16 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-28 18:29 . 2008-09-28 18:29 <DIR> d-------- C:\Program Files\Ares
2008-09-28 12:52 . 2008-09-30 02:00 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-28 12:52 . 2008-09-28 12:52 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-24 09:00 . 2008-09-24 09:00 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-09-17 15:45 . 2008-09-17 15:45 <DIR> d-------- C:\Program Files\Cucusoft
2008-09-17 15:45 . 2008-09-17 15:45 <DIR> d-------- C:\ConverterOutput
2008-09-17 15:45 . 2003-03-30 20:08 372,736 --a------ C:\WINDOWS\system32\xvid.ax
2008-09-17 13:45 . 2008-09-17 15:36 <DIR> d-------- C:\Documents and Settings\e\Application Data\Creative
2008-09-17 13:35 . 2006-10-05 23:17 53,248 --------- C:\WINDOWS\Ctregrun.exe
2008-09-17 13:34 . 2008-09-17 13:34 <DIR> d-------- C:\Program Files\Audible
2008-09-17 13:34 . 2008-09-17 13:34 417,792 --a------ C:\WINDOWS\system32\awrdscdc.ax
2008-09-17 13:33 . 2008-09-17 13:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Creative
2008-09-17 13:31 . 2008-09-17 13:33 <DIR> d--h----- C:\Program Files\Creative Installation Information
2008-09-17 13:31 . 2008-09-17 13:35 <DIR> d-------- C:\Program Files\Creative
2008-09-17 13:31 . 2008-09-17 13:31 <DIR> d-------- C:\Program Files\Common Files\Creative
2008-09-17 13:31 . 1999-12-12 18:01 44,032 --------- C:\WINDOWS\system32\CTSVCCDA.EXE
2008-09-17 13:31 . 1999-11-17 18:00 25,088 --------- C:\WINDOWS\system32\CTSVCCTL.EXE
2008-09-17 00:36 . 2008-09-17 00:36 <DIR> d-------- C:\Program Files\Alwil Software
2008-09-16 22:41 . 2007-05-02 09:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterVideo
2008-09-16 22:41 . 2008-09-16 22:54 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-16 17:17 . 2008-09-16 17:17 <DIR> d-------- C:\Program Files\NCH Software
2008-09-16 11:09 . 2008-09-29 23:45 <DIR> d-------- C:\Program Files\a-squared Free
2008-09-16 10:59 . 2008-09-16 10:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-09-16 10:59 . 2008-04-24 16:52 12,608 --a------ C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-09-16 10:58 . 2008-09-16 10:58 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-16 10:58 . 2008-09-16 10:58 <DIR> d-------- C:\Documents and Settings\e\Application Data\Malwarebytes
2008-09-16 10:58 . 2008-09-16 10:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-16 10:58 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-16 10:58 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-16 10:54 . 2008-09-16 10:54 <DIR> d-------- C:\Documents and Settings\e\Application Data\SUPERAntiSpyware.com
2008-09-16 10:54 . 2008-09-16 10:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-16 10:31 . 2008-09-16 22:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-09-10 18:01 . 2008-09-17 15:11 <DIR> d-------- C:\Program Files\FlashGet
2008-09-10 17:31 . 2008-09-17 15:10 <DIR> d-------- C:\downloads
2008-09-10 17:31 . 2008-09-10 17:58 <DIR> d-------- C:\Documents and Settings\e\Application Data\Orbit
2008-09-10 17:31 . 2008-09-10 17:43 <DIR> d-------- C:\Documents and Settings\e\Application Data\GrabPro
2008-09-09 11:58 . 2008-09-09 11:58 <DIR> d-------- C:\Program Files\7-Zip
2008-09-09 10:04 . 2008-09-09 10:04 <DIR> d-------- C:\Program Files\uTorrent
2008-09-09 10:04 . 2008-09-27 12:04 <DIR> d-------- C:\Documents and Settings\e\Application Data\uTorrent
2008-09-08 18:18 . 2008-04-08 00:16 9,200 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-08 18:18 . 2008-04-08 00:16 9,072 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-08 18:17 . 2008-09-08 18:17 <DIR> d-------- C:\WINDOWS\system32\IOSUBSYS
2008-09-08 15:11 . 2008-09-08 15:11 <DIR> d-------- C:\Program Files\Siber Systems
2008-09-08 15:11 . 2008-09-08 15:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\RoboForm
2008-09-08 14:46 . 2008-09-08 16:35 <DIR> d-------- C:\Documents and Settings\e\Pavark
2008-09-07 14:32 . 2008-09-07 14:35 <DIR> d-------- C:\Program Files\JkDefragGUI
2008-09-07 14:32 . 2008-08-31 21:47 238,592 --a------ C:\WINDOWS\system32\JkDefragScreenSaver.exe
2008-09-07 14:32 . 2008-08-31 21:47 98,304 --a------ C:\WINDOWS\system32\JkDefragScreenSaver.scr
2008-08-29 18:18 . 2008-08-29 18:18 2,302,017 --a------ C:\WINDOWS\system32\GPhotos.scr
2008-08-15 18:07 . 2008-08-15 18:07 31,232 --a------ C:\WINDOWS\system\vdremote.dll
2008-08-15 18:07 . 2008-08-15 18:07 25,088 --a------ C:\WINDOWS\system\vdsvrlnk.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-30 01:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-09-30 00:39 --------- d-----w C:\Program Files\Java
2008-09-29 22:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 18:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-16 23:16 --------- d-----w C:\Documents and Settings\e\Application Data\Skype
2008-09-16 23:13 --------- d-----w C:\Documents and Settings\e\Application Data\skypePM
2008-09-16 22:24 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-16 22:24 --------- d-----w C:\Program Files\SpywareBlaster
2008-09-16 22:03 --------- d-----w C:\Program Files\RegScrubXP
2008-09-16 09:32 --------- d-----w C:\Program Files\DivX
2008-09-16 09:28 --------- d-----w C:\Program Files\Yahoo!
2008-09-16 09:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-09-08 17:17 --------- d-----w C:\Program Files\Google
2008-09-07 11:49 --------- d-----w C:\Documents and Settings\e\Application Data\DNA
2008-09-06 14:40 --------- d-----w C:\Program Files\DNA
2008-03-11 23:21 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 158208]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
"vidc.CDVC"= cdvccodc.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Printkey2000.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
backup=C:\WINDOWS\pss\Printkey2000.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]
--a------ 2007-11-27 12:58 1032376 C:\Program Files\Kontiki\KHost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-09-09 01:18 57344 C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
--a------ 2006-12-01 18:10 286720 C:\Program Files\BlazeVideo\BlazeDTV 2.5a\MediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTCheck]
--------- 2007-11-06 11:08 397312 C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTRegRun]
--------- 2006-10-05 23:17 53248 C:\WINDOWS\Ctregrun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
--------- 2007-07-17 11:03 868352 C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-01-04 15:43 1838592 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
--a------ 2007-11-27 12:58 1032376 C:\Program Files\Kontiki\KHost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 11:56 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-02-01 18:22 21898024 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
--a------ 2006-11-02 13:43 472632 C:\PROGRA~1\Sony\SONICS~1\SSAAD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2008-09-03 14:07 1576176 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-01-04 15:42 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2007-11-13 16:48 3411968 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2005-11-10 04:44 557056 C:\WINDOWS\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2007-04-16 16:28 577536 C:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
--a------ 2005-03-08 03:33 53248 C:\WINDOWS\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
--a------ 2005-11-01 04:15 163840 C:\WINDOWS\system32\VTTrayp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SSScsiSV"=3 (0x3)
"avg8wd"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\WINDOWS\\system32\\java.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 StkASSrv;Syntek STK1160 Service;C:\WINDOWS\System32\StkASv2K.exe [2006-05-23 24576]
R3 EKBfltr;ENE Keyboard Controller;C:\WINDOWS\system32\DRIVERS\EKBfltr.sys [2005-01-14 5504]
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service [ ]
S3 Mouqmmr;Mouqmmr;C:\WINDOWS\system32\blastcln.exe [2004-08-04 71680]
S3 StkAMini;Syntek STK1160;C:\WINDOWS\system32\Drivers\StkAMini.sys [2006-11-15 242139]
S3 StkScan;Syntek STK1160 Still Image;C:\WINDOWS\system32\Drivers\StkScan.sys [2006-06-27 4772]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-!AVG Anti-Spyware - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
MSConfigStartUp-AVG8_TRAY - C:\PROGRA~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-ThreatFire - C:\Program Files\ThreatFire\TFTray.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\e\Application Data\Mozilla\Firefox\Profiles\o83xzkld.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.co.uk/
FF -: plugin - C:\Documents and Settings\e\Application Data\Mozilla\Firefox\Profiles\o83xzkld.default\extensions\
[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\Google\Picasa3\npPicasa3.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
FF -: plugin - C:\Program Files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-30 02:21:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-30 2:28:22
ComboFix-quarantined-files.txt 2008-09-30 01:28:15
Pre-Run: 20,696,715,264 bytes free
Post-Run: 21,159,137,280 bytes free
214 --- E O F --- 2008-09-29 23:07:00