This Notebook has SP2. Also thanks a ton for your time. I always appreciate it.
Here is the Combofix Log:
ComboFix 10-10-12.03 - Administrator 10/15/2010 11:09:18.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.874.66.1033.18.2038.1248 [GMT 7:00]
Running from: c:\documents and settings\Administrator\desktop\commy.exe
Command switches used :: /stepdel
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
FW: Outpost Firewall *disabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\d4s.hst
c:\windows\system32\msconfig.exe
.
((((((((((((((((((((((((( Files Created from 2010-09-15 to 2010-10-15 )))))))))))))))))))))))))))))))
.
2010-10-14 01:13 . 2010-10-14 01:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-10-14 01:13 . 2010-04-29 08:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-14 01:13 . 2010-10-14 01:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-14 01:13 . 2010-10-14 01:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-10-14 01:13 . 2010-04-29 08:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-11 03:47 . 2010-10-11 03:48 -------- d-----w- c:\windows\.jagex_cache_32
2010-10-11 03:21 . 2010-10-11 03:21 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-10-10 14:26 . 2010-10-10 14:26 -------- d-----w- c:\windows\system32\KB905474
2010-10-08 02:44 . 2010-02-24 12:31 454016 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-10-08 02:43 . 2008-07-03 13:16 8454656 ------w- c:\windows\system32\dllcache\shell32.dll
2010-10-07 20:53 . 2010-10-07 20:53 -------- d-----w- c:\windows\system32\XPSViewer
2010-10-07 20:53 . 2010-10-07 20:53 -------- d-----w- c:\program files\MSBuild
2010-10-07 20:53 . 2010-10-07 20:53 -------- d-----w- c:\program files\Reference Assemblies
2010-10-07 20:53 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-10-07 20:53 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-10-07 20:53 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-10-07 20:53 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-10-07 20:53 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-10-07 20:53 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-10-07 20:53 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-10-07 20:53 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-10-07 20:53 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-10-07 18:00 . 2010-01-29 15:08 683520 ------w- c:\windows\system32\dllcache\inetcomm.dll
2010-10-07 18:00 . 2010-01-29 15:08 1315840 ------w- c:\windows\system32\dllcache\msoe.dll
2010-10-07 12:48 . 2009-10-21 06:00 75776 ------w- c:\windows\system32\dllcache\strmfilt.dll
2010-10-07 12:48 . 2009-10-21 06:00 25088 ------w- c:\windows\system32\dllcache\httpapi.dll
2010-10-07 12:48 . 2009-10-20 14:58 263552 ------w- c:\windows\system32\dllcache\http.sys
2010-10-07 08:06 . 2009-12-16 12:58 343040 ------w- c:\windows\system32\dllcache\mspaint.exe
2010-10-07 08:06 . 2009-11-27 17:33 17920 ------w- c:\windows\system32\dllcache\msyuv.dll
2010-10-07 08:06 . 2008-06-12 14:16 91648 ------w- c:\windows\system32\dllcache\mtxoci.dll
2010-10-07 08:06 . 2008-06-12 14:16 66560 ------w- c:\windows\system32\dllcache\mtxclu.dll
2010-10-07 08:06 . 2008-06-12 14:16 58880 ------w- c:\windows\system32\dllcache\msdtclog.dll
2010-10-07 08:06 . 2008-06-12 14:16 161792 ------w- c:\windows\system32\dllcache\msdtcuiu.dll
2010-10-07 08:06 . 2008-06-12 14:16 956928 ------w- c:\windows\system32\dllcache\msdtctm.dll
2010-10-07 08:06 . 2008-06-12 14:16 428032 ------w- c:\windows\system32\dllcache\msdtcprx.dll
2010-10-07 08:03 . 2009-08-05 09:11 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
2010-10-07 08:02 . 2008-04-21 10:02 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2010-10-07 07:55 . 2010-10-07 07:55 -------- d-----w- c:\program files\MSXML 6.0
2010-10-07 07:54 . 2010-10-07 07:54 -------- d-----w- c:\windows\ServicePackFiles
2010-10-06 01:39 . 2009-11-21 16:36 470528 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-10-06 01:39 . 2008-06-24 16:23 74240 ------w- c:\windows\system32\dllcache\mscms.dll
2010-10-06 01:39 . 2008-07-07 20:32 253952 ------w- c:\windows\system32\dllcache\es.dll
2010-10-06 01:39 . 2010-03-05 14:57 65536 ------w- c:\windows\system32\dllcache\asycfilt.dll
2010-10-06 01:30 . 2010-01-13 14:10 85504 ------w- c:\windows\system32\dllcache\cabview.dll
2010-10-06 01:29 . 2009-08-26 08:16 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2010-10-06 01:29 . 2009-12-24 07:05 177664 ------w- c:\windows\system32\dllcache\wintrust.dll
2010-10-06 01:29 . 2009-09-11 14:33 133632 ------w- c:\windows\system32\dllcache\msv1_0.dll
2010-10-06 01:29 . 2009-06-25 08:44 56320 ------w- c:\windows\system32\dllcache\secur32.dll
2010-10-06 01:29 . 2009-06-22 11:34 92544 ------w- c:\windows\system32\dllcache\ksecdd.sys
2010-10-06 01:29 . 2009-06-25 08:44 724480 ------w- c:\windows\system32\dllcache\lsasrv.dll
2010-10-06 01:29 . 2009-06-25 08:44 59392 ------w- c:\windows\system32\dllcache\wdigest.dll
2010-10-06 01:29 . 2009-06-25 08:44 298496 ------w- c:\windows\system32\dllcache\kerberos.dll
2010-10-06 01:29 . 2009-06-25 08:44 168448 ------w- c:\windows\system32\dllcache\schannel.dll
2010-10-06 01:29 . 2009-12-31 16:14 352640 ------w- c:\windows\system32\dllcache\srv.sys
2010-10-06 01:28 . 2009-07-17 16:27 1435648 ------w- c:\windows\system32\dllcache\query.dll
2010-10-06 01:27 . 2008-08-14 09:51 138368 ------w- c:\windows\system32\dllcache\afd.sys
2010-10-06 01:27 . 2010-02-12 04:47 100864 ------w- c:\windows\system32\dllcache\6to4svc.dll
2010-10-06 01:27 . 2008-06-20 17:41 245248 ------w- c:\windows\system32\dllcache\mswsock.dll
2010-10-06 01:27 . 2008-06-20 10:45 360320 ------w- c:\windows\system32\dllcache\tcpip.sys
2010-10-06 01:27 . 2009-04-15 15:11 584192 ------w- c:\windows\system32\dllcache\rpcrt4.dll
2010-10-06 01:26 . 2008-05-08 12:28 202752 ------w- c:\windows\system32\dllcache\rmcast.sys
2010-10-05 21:12 . 2009-12-14 07:35 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll
2010-10-05 21:11 . 2010-05-02 05:56 1850880 ------w- c:\windows\system32\dllcache\win32k.sys
2010-10-05 21:11 . 2008-05-01 14:30 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2010-10-05 21:09 . 2009-06-10 06:32 132096 ------w- c:\windows\system32\dllcache\wkssvc.dll
2010-10-05 21:04 . 2009-09-04 20:45 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
2010-10-05 20:40 . 2009-03-21 14:18 986112 ------w- c:\windows\system32\dllcache\kernel32.dll
2010-10-05 20:40 . 2010-04-20 05:51 285696 ------w- c:\windows\system32\dllcache\atmfd.dll
2010-10-05 20:40 . 2009-06-12 11:50 80896 ------w- c:\windows\system32\dllcache\tlntsess.exe
2010-10-05 20:40 . 2009-06-12 11:50 76288 ------w- c:\windows\system32\dllcache\telnet.exe
2010-10-05 20:38 . 2009-06-09 15:06 1871872 ------w- c:\windows\system32\dllcache\mstscax.dll
2010-10-05 20:37 . 2009-10-23 14:27 3555328 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-10-05 20:37 . 2009-10-15 17:21 82432 ------w- c:\windows\system32\dllcache\fontsub.dll
2010-10-05 20:36 . 2009-10-12 13:54 69632 ------w- c:\windows\system32\dllcache\raschap.dll
2010-10-05 20:36 . 2009-10-12 13:54 112128 ------w- c:\windows\system32\dllcache\rastls.dll
2010-10-05 20:36 . 2009-05-07 15:44 344064 ------w- c:\windows\system32\dllcache\localspl.dll
2010-10-05 20:35 . 2009-06-21 22:04 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2010-10-05 20:30 . 2009-10-13 10:53 266752 ------w- c:\windows\system32\dllcache\oakley.dll
2010-10-05 20:30 . 2010-02-05 18:40 1291264 ------w- c:\windows\system32\dllcache\quartz.dll
2010-10-05 20:29 . 2009-11-27 16:37 8704 ------w- c:\windows\system32\dllcache\tsbyuv.dll
2010-10-05 20:29 . 2009-11-27 16:37 84992 ------w- c:\windows\system32\dllcache\avifil32.dll
2010-10-05 20:29 . 2009-11-27 16:37 48128 ------w- c:\windows\system32\dllcache\iyuv_32.dll
2010-10-05 20:29 . 2009-11-27 16:37 28672 ------w- c:\windows\system32\dllcache\msvidc32.dll
2010-10-05 20:29 . 2009-11-27 16:37 11264 ------w- c:\windows\system32\dllcache\msrle32.dll
2010-10-05 20:29 . 2009-08-25 09:47 352256 ------w- c:\windows\system32\dllcache\winhttp.dll
2010-10-05 20:29 . 2009-07-17 18:55 58880 ------w- c:\windows\system32\dllcache\atl.dll
2010-10-05 20:27 . 2010-05-04 17:20 459264 ------w- c:\windows\system32\dllcache\msfeeds.dll
2010-10-05 20:27 . 2010-05-04 17:20 52224 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-10-05 20:27 . 2010-05-04 17:20 268288 ------w- c:\windows\system32\dllcache\iertutil.dll
2010-10-05 20:27 . 2010-05-04 17:20 380928 ------w- c:\windows\system32\dllcache\ieapfltr.dll
2010-10-05 20:27 . 2010-05-04 17:20 63488 ------w- c:\windows\system32\dllcache\icardie.dll
2010-10-05 20:27 . 2010-04-16 13:24 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2010-10-05 20:27 . 2010-02-22 22:04 2452872 ------w- c:\windows\system32\dllcache\ieapfltr.dat
2010-10-05 20:27 . 2010-05-04 17:20 6067200 ------w- c:\windows\system32\dllcache\ieframe.dll
2010-10-05 20:27 . 2008-10-15 16:57 332800 ------w- c:\windows\system32\dllcache\netapi32.dll
2010-10-05 20:26 . 2009-07-31 04:57 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2010-10-05 20:26 . 2008-10-23 13:01 283648 ------w- c:\windows\system32\dllcache\gdi32.dll
2010-10-04 22:26 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-10-04 22:26 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2010-10-04 20:32 . 2010-10-04 20:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2010-10-04 20:32 . 2010-10-04 20:32 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-10-04 17:24 . 2009-04-06 04:37 704384 ----a-w- c:\windows\system32\drivers\SandBox.sys
2010-10-04 17:23 . 2009-02-10 09:15 257432 ----a-w- c:\windows\system32\drivers\afwcore.sys
2010-10-04 17:22 . 2009-02-18 10:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys
2010-10-04 17:22 . 2010-10-04 17:22 -------- d-----w- c:\program files\Agnitum
2010-10-04 17:22 . 2010-10-04 17:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Agnitum
2010-10-02 21:03 . 2010-10-02 22:56 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2010-10-02 20:49 . 2010-10-02 20:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Grisoft
2010-10-02 20:49 . 2007-05-30 12:10 10872 ----a-w- c:\windows\system32\drivers\AvgAsCln.sys
2010-10-02 20:49 . 2010-10-02 20:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Grisoft
2010-09-30 19:53 . 2010-09-30 19:53 -------- d-----w- C:\found.000
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
------- Sigcheck -------
[-] 2007-04-05 . 7179AC3F4258AEC9627590A842FDA1D6 . 574976 . . [5.1.2600.3113] . . c:\windows\system32\drivers\ntfs.sys
[-] 2007-11-28 . 39128B5A743545BAEDD3984C210F00A8 . 77824 . . [5.1.2600.2586] . . c:\windows\system32\browser.dll
[-] 2007-11-28 . 3516D8A18B36784B1005B950B84232E1 . 197632 . . [5.1.2600.2743] . . c:\windows\system32\netman.dll
[-] 2007-11-28 . 17A0D43C80DB5348759C649835A78CFC . 408064 . . [6.7.2600.3143] . . c:\windows\system32\qmgr.dll
[-] 2007-11-28 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\system32\spoolsv.exe
[-] 2007-11-28 . B0124CB21D28B1C9F678B566B6B57D92 . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2006-08-25 . C4E80875C1CF1222FC5EFD0314AE5C01 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
[7] 2001-08-23 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[-] 2007-11-28 . 87F3E2D2A3231F820F9248DB90090F42 . 62464 . . [5.1.2600.2845] . . c:\windows\system32\cryptsvc.dll
[-] 2007-11-28 . 212DEC5056523F8727C7B4E7E86782D5 . 19968 . . [5.1.2600.2839] . . c:\windows\system32\linkinfo.dll
[-] 2007-11-28 . 154C00AE9C017C3650E33CE75116A312 . 343040 . . [7.0.2600.3085] . . c:\windows\system32\msvcrt.dll
[-] 2007-02-19 . 4295F398C188D02DC7A5899EAC121914 . 343040 . . [7.0.2600.3085] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.3085_x-ww_e059201c\msvcrt.dll
[7] 2001-08-23 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll
[7] 2009-02-06 . 6C476D33D82F1054849790181E8F7772 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[7] 2009-02-06 . 6C476D33D82F1054849790181E8F7772 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[7] 2009-02-06 . 6C476D33D82F1054849790181E8F7772 . 408064 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\SP2QFE\netlogon.dll
[7] 2009-02-06 . 6C476D33D82F1054849790181E8F7772 . 408064 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\SP2QFE\netlogon.dll
[-] 2007-11-28 . 5FD8684F1C5DD26509383F6CCDAEE3A3 . 407040 . . [5.1.2600.3175] . . c:\windows\system32\netlogon.dll
[-] 2007-11-28 . 1418A3A6E76E5A2E3F5E43866E793A8B . 249344 . . [5.1.2600.2716] . . c:\windows\system32\tapisrv.dll
[-] 2007-11-28 . 7AA4F6C00405DFC4B70ED4214E7D687B . 578048 . . [5.1.2600.3099] . . c:\windows\system32\user32.dll
[-] 2007-11-28 . 31EC9657D9C76143F6E61FC19851445F . 975360 . . [6.00.2900.3156] . . c:\windows\explorer.exe
[-] 2007-11-28 . C7BDF67819BCA03DA1B832AF3C826093 . 1287168 . . [5.1.2600.3124] . . c:\windows\system32\ole32.dll
[-] 2007-11-28 . 53D9184A21C5CBF600D918E51EF3A7E5 . 135168 . . [6.00.2900.3051] . . c:\windows\system32\shsvcs.dll
[-] 2007-11-28 . C29A5286E64D97385178452D5F307B98 . 295424 . . [5.1.2600.2627] . . c:\windows\system32\termsrv.dll
[-] 2005-05-27 04:14 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\system32\drivers\aec.sys
[-] 2007-11-28 06:28 . 925F8B61ED301A317BA850EBEECBDAA0 . 927504 . . [4.1.0.61] . . c:\windows\system32\mfc40u.dll
[-] 2007-11-28 06:31 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
[-] 2007-11-28 . 36ACA6CDC19C95FF468A1426EB7F32F0 . 185344 . . [5.1.2600.3077] . . c:\windows\system32\upnphost.dll
[-] 1999-03-08 07:00 . CE0155405EA902797E88B92A78443AEB . 164112 . . [5.0.4275] . . c:\windows\system32\olepro32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0b876028-b388-4f6d-922f-f52faec8535f}]
2010-10-13 04:59 2735200 ----a-w- c:\program files\WeFiBar\tbWeF1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4B0FAF5A-67C4-4625-AE07-B0DBADA16EBF}]
2008-11-04 19:33 147456 ----a-w- c:\documents and settings\All Users\Application Data\uPlayMe\plugins\MSIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{0b876028-b388-4f6d-922f-f52faec8535f}"= "c:\program files\WeFiBar\tbWeF1.dll" [2010-10-13 2735200]
[HKEY_CLASSES_ROOT\clsid\{0b876028-b388-4f6d-922f-f52faec8535f}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{0B876028-B388-4F6D-922F-F52FAEC8535F}"= "c:\program files\WeFiBar\tbWeF1.dll" [2010-10-13 2735200]
[HKEY_CLASSES_ROOT\clsid\{0b876028-b388-4f6d-922f-f52faec8535f}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-05-17 1230848]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456]
"slide.exe"="c:\program files\slide\slide.exe" [2007-06-08 37760]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-18 68856]
"wefi"="c:\program files\WeFi\WeFi.exe" [2010-03-16 531800]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-06-16 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2007-11-28 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"VisualTooltip"="c:\program files\Utilities\VisualTooltip\VisualToolTip.exe" [2007-04-25 956928]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-28 16132608]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"PLFSet"="c:\windows\PLFSet.dll" [2007-04-25 45056]
"LManager"="c:\progra~1\Launch Manager\QtZgAcer.EXE" [2007-10-16 707080]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-24 851968]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-12 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-12 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-12 138008]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-05-18 49152]
"WinampAgent"="c:\progra~1\Winamp\winampa.exe" [2008-01-15 37376]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-28 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-07-31 271672]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"WebcamMaxMoniter"="c:\program files\WebcamMax\wcmmon.exe" [2008-02-12 456024]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-10 40048]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall\feedback.exe" [2009-04-14 428032]
"OutpostMonitor"="c:\progra~1\Agnitum\Outpost Firewall\op_mon.exe" [2009-04-14 2374464]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-05-17 1230848]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2010-05-04 124928]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2008-4-4 295606]
Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-4-4 113664]
Auto run of VideoCam Suite 1.0.lnk - c:\program files\Panasonic\VideoCamSuite\VideoCamSuiteAutoStart.exe [2008-11-13 161160]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\RUNSAS.EXE"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcstart.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:UDP"= 443:UDP:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:ooVoo UDP port 37675
"57145:TCP"= 57145:TCP:Pando P2P TCP Listening Port
"57145:UDP"= 57145:UDP:Pando P2P UDP Listening Port
"443:TCP"= 443:TCP:ooVoo TCP port 443
R0 iastor76;iastor76;c:\windows\system32\drivers\iastor76.sys [28/11/2550 14:15 305176]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [5/10/2553 0:24 704384]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [18/2/2553 1:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/5/2553 1:41 67656]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\Outpost Firewall\acs.exe [5/10/2553 0:22 1195008]
R2 CamthWDM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\CamthWDM.sys [9/2/2551 11:58 941784]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [5/10/2553 0:22 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [5/10/2553 0:23 257432]
R3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\drivers\hidshim.sys [19/3/2551 18:31 5632]
R3 WefiEngSvc;WeFi Engine Service;c:\program files\WeFi\WefiEngSvc.exe [16/3/2553 22:23 133976]
R3 winbondhidcir;Winbond HID CIR Receiver;c:\windows\system32\drivers\winbondhidcir.sys [19/3/2551 18:31 21504]
S2 gupdate;บริการอัปเดตของ Google (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [13/2/2553 13:15 135664]
S4 Netsipksa;Netsipksa;
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34A19196-274E-4D75-9D30-D7A45A0A4178}]
2004-08-04 00:56 11776 ----a-w- c:\program files\Windows Sidebar\regsvr32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6B9228DA-9C15-419e-856C-19E768A13BDC}]
2004-08-04 00:56 11776 ----a-w- c:\program files\Windows Sidebar\regsvr32.exe
.
Contents of the 'Scheduled Tasks' folder
2010-10-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 06:15]
2010-10-15 c:\windows\Tasks\At1.job
- c:\documents and settings\All Users\Application Data\uPlayMe\upm_updater.exe [2008-11-04 10:57]
2010-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 06:15]
2010-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 06:15]
2010-10-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-823518204-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-14 00:31]
2010-10-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-823518204-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-14 00:31]
2010-10-15 c:\windows\Tasks\User_Feed_Synchronization-{35027088-877E-4750-AFDC-82F9A98F483B}.job
- c:\windows\system32\msfeedssync.exe [2008-03-19 16:58]
2010-10-15 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-10-10 15:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Administrator\Start Menu\Programs\IMVU\Run IMVU.lnk
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKCU-Run-PoivY - c:\program files\PoivY.com\PoivY\PoivY.exe
HKLM-Run-BroadcomWireless - c:\program files\Broadcom\Wireless\Utility\WlanUtil.exe
HKLM-Run-uPlayMe - c:\program files\uPlayMe\uPlayMe.exe
SafeBoot-AVG Anti-Spyware Driver
ActiveSetup-{D58F39FF-953E-4F45-898F-59F243B9A523} - HIDEC
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1412)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2010-10-15 11:15:10
ComboFix-quarantined-files.txt 2010-10-15 04:15
Pre-Run: 38,747,570,176 bytes free
Post-Run: 38,793,187,328 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - C6C8A719FA11F49AD0C642469BDEBE4D