Thanks for looking at this for me... this was the last HJT log taken before the machine went over to safe mode only - run from C:/HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:47:18, on 02/12/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
D:\Programmes\ashDisp.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
D:\Programmes\BitTorrent\bittorrent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\HJT\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ashDisp.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [winlogon] C:\Windows\winlogon.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/actives.../as2stubie.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Programmes\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Programmes\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Programmes\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Programmes\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - (no file)
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Users\Danny\AppData\Local\TVersity\Media Server\MediaServer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: ePower Service (WMIService) - Unknown owner - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (file missing)
--
End of file - 7758 bytes
Combo fix log
ComboFix 09-12-02.05 - Danny 02/12/2009 21:58.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.44.1033.18.2038.1003 [GMT 0:00]
Running from: c:\users\Danny\Desktop\ComboFix.exe
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: ZoneAlarm Anti-Spyware *enabled* (Outdated) {F245A209-1085-48B4-B927-35D56015EC60}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2749466982-662175772-58541265-500
c:\programdata\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye Webcam Video Class Camera
c:\programdata\Microsoft\Windows\Start Menu\Programs\Acer Crystal Eye Webcam Video Class Camera \Uninstall.lnk
c:\users\Danny\AppData\Roaming\Desktopicon
c:\users\Danny\AppData\Roaming\Desktopicon\eBay.ico
c:\users\Danny\AppData\Roaming\Desktopicon\uninst.exe
c:\windows\system32\twain_32.dll
Infected copy of c:\windows\system32\DRIVERS\iaStor.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2009-11-02 to 2009-12-02 )))))))))))))))))))))))))))))))
.
2009-12-02 22:24 . 2009-12-02 22:25 -------- d-----w- c:\users\Danny\AppData\Local\temp
2009-12-02 22:24 . 2009-12-02 22:24 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-02 12:52 . 2009-12-02 12:52 -------- d-----w- c:\program files\Common Files\Macromedia
2009-12-02 12:52 . 2009-12-02 12:52 -------- d-----w- c:\program files\Macromedia
2009-12-01 11:38 . 2009-12-01 11:38 -------- d-----w- c:\users\Danny\DoctorWeb
2009-11-30 21:49 . 2009-12-02 10:46 -------- dc----w- C:\HJT
2009-11-30 21:09 . 2009-12-02 08:51 8192 d-----w- c:\program files\PhotomatixPro3
2009-11-30 19:37 . 2009-11-30 19:37 4096 d-----w- c:\program files\Unlocker
2009-11-30 18:29 . 2009-11-30 18:29 -------- d-----w- c:\windows\system32\log
2009-11-30 16:15 . 2009-11-30 13:37 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-11-30 13:38 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-11-30 13:34 . 2009-11-30 13:34 4096 dc-h--w- c:\programdata\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-30 13:34 . 2009-10-03 08:15 2924848 -c--a-w- c:\programdata\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-11-30 09:41 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-30 09:41 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-30 09:41 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-30 09:41 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-30 09:41 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-30 09:41 . 2009-11-24 23:49 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-30 09:41 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-30 09:39 . 2009-11-30 09:39 -------- d-----w- c:\users\Danny\AppData\Roaming\Malwarebytes
2009-11-30 09:39 . 2009-09-10 14:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-30 09:39 . 2009-11-30 09:39 4096 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-30 09:39 . 2009-11-30 09:39 -------- d-----w- c:\programdata\Malwarebytes
2009-11-30 09:39 . 2009-09-10 14:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 18:41 . 2009-11-29 18:41 -------- d-----w- c:\program files\ezLife
2009-11-29 09:22 . 2009-11-29 09:22 7680 ----a-w- c:\users\Danny\AppData\Roaming\Thinstall\Fireworks\1000000600002i\verclsid.exe
2009-11-25 03:01 . 2009-10-29 09:41 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-24 23:38 . 2009-08-10 11:01 1399296 ----a-w- c:\windows\system32\msxml6.dll
2009-11-24 23:38 . 2009-08-10 11:00 1257472 ----a-w- c:\windows\system32\msxml3.dll
2009-11-21 08:03 . 2009-11-21 08:03 -------- d-----w- c:\programdata\Research In Motion
2009-11-21 08:03 . 2009-11-21 08:03 4096 d-----w- c:\program files\Common Files\Research In Motion
2009-11-16 19:04 . 2009-11-16 19:04 -------- d-----w- c:\users\Danny\AppData\Local\Frameworkx.com
2009-11-16 18:25 . 2009-11-16 18:25 284147 ----a-r- c:\users\Danny\AppData\Roaming\Microsoft\Installer\{47609E69-4C5E-48B1-A889-24C6B82B5C04}\_93A0BD079836122C39D406.exe
2009-11-16 18:25 . 2009-11-16 18:25 284147 ----a-r- c:\users\Danny\AppData\Roaming\Microsoft\Installer\{47609E69-4C5E-48B1-A889-24C6B82B5C04}\_6FEFF9B68218417F98F549.exe
2009-11-16 18:25 . 2009-11-16 18:25 284147 ----a-r- c:\users\Danny\AppData\Roaming\Microsoft\Installer\{47609E69-4C5E-48B1-A889-24C6B82B5C04}\_3207B59E601B5F75D71B21.exe
2009-11-16 18:25 . 2009-11-16 18:25 -------- d-----w- c:\program files\Frameworkx
2009-11-14 09:50 . 2009-11-14 09:50 -------- d-----w- c:\users\Danny\AppData\Roaming\Research In Motion
2009-11-14 09:47 . 2009-11-21 08:03 -------- d-----w- c:\program files\Research In Motion
2009-11-11 10:20 . 2006-11-29 13:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-11-11 10:19 . 2009-11-11 10:19 -------- d-----w- c:\program files\Microsoft
2009-11-10 21:49 . 2009-08-14 13:53 2035712 ----a-w- c:\windows\system32\win32k.sys
2009-11-10 21:49 . 2009-08-10 13:05 351232 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-09 07:22 . 2009-11-09 07:22 -------- d-----w- c:\program files\JL_Cmder
2009-11-08 16:55 . 2009-11-08 16:55 -------- d-----w- c:\program files\WinPcap
2009-11-07 11:09 . 2009-11-07 11:09 -------- d-----w- c:\users\Danny\AppData\Local\HP
2009-11-06 10:28 . 2009-11-06 10:28 -------- d-----w- c:\users\Danny\AppData\Roaming\Windows Live Writer
2009-11-06 10:28 . 2009-11-06 10:28 -------- d-----w- c:\users\Danny\AppData\Local\Windows Live Writer
2009-11-06 08:39 . 2007-08-13 14:51 446464 ----a-w- c:\windows\system32\wmvdmoe.dll
2009-11-06 08:38 . 2009-11-06 08:38 -------- d-----w- c:\programdata\PY_Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 21:54 . 2008-03-06 06:41 350192 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
2009-12-02 21:52 . 2008-04-26 19:26 12 ----a-w- c:\windows\bthservsdp.dat
2009-12-02 12:52 . 2007-08-02 09:23 8192 d--h--w- c:\program files\InstallShield Installation Information
2009-12-02 12:29 . 2008-03-16 10:43 4096 d-----w- c:\program files\Java
2009-12-02 11:13 . 2009-09-21 17:48 16384 d-----w- c:\users\Danny\AppData\Roaming\BitTorrent
2009-12-02 09:04 . 2008-08-11 12:20 4096 d-----w- c:\program files\Common Files\Adobe
2009-12-01 18:48 . 2007-08-02 09:23 304920 -c--a-w- c:\windows\system32\drivers\iaStor.sys
2009-12-01 09:37 . 2008-12-23 17:54 4096 d-----w- c:\programdata\Spybot - Search & Destroy
2009-11-30 13:33 . 2009-02-12 23:07 -------- d-----w- c:\program files\Lavasoft
2009-11-30 13:33 . 2008-08-26 17:50 -------- d-----w- c:\programdata\Lavasoft
2009-11-29 21:09 . 2009-09-20 20:39 1 ----a-w- c:\users\Danny\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-29 20:23 . 2008-12-23 17:54 8192 d-----w- c:\program files\Spybot - Search & Destroy
2009-11-29 20:04 . 2008-03-14 08:03 12959020 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-11-29 19:30 . 2009-09-20 16:49 8192 d-----w- c:\users\Danny\AppData\Roaming\LimeWire
2009-11-27 08:18 . 2009-03-22 00:55 256 ----a-w- c:\windows\system32\pool.bin
2009-11-24 07:39 . 2009-11-24 07:41 2119168 ----a-w- c:\windows\Internet Logs\xDBB9BF.tmp
2009-11-19 09:38 . 2009-11-19 09:39 2114560 ----a-w- c:\windows\Internet Logs\xDB98F9.tmp
2009-11-15 07:54 . 2008-03-05 13:45 81104 ----a-w- c:\users\Danny\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-14 11:00 . 2009-09-20 10:17 4096 d-----w- c:\users\Danny\AppData\Roaming\Winamp
2009-11-11 10:22 . 2008-03-05 14:32 4096 d-----w- c:\program files\Windows Live
2009-11-05 03:17 . 2009-11-05 03:19 2094592 ----a-w- c:\windows\Internet Logs\xDBA789.tmp
2009-11-02 20:42 . 2009-10-02 15:50 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-31 09:01 . 2008-03-05 17:01 680 ----a-w- c:\users\Danny\AppData\Local\d3d9caps.dat
2009-10-30 22:40 . 2009-10-30 22:39 4096 d-----w- c:\program files\LiteStep
2009-10-29 21:58 . 2009-01-29 16:40 -------- d-----w- c:\program files\Opanda
2009-10-23 19:39 . 2009-10-23 19:39 133724 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-23 19:38 . 2008-03-07 12:56 4096 d-----w- c:\program files\Google
2009-10-20 18:20 . 2009-10-20 18:20 96784 ----a-w- c:\windows\system32\Packet.dll
2009-10-20 18:19 . 2009-10-20 18:19 281104 ----a-w- c:\windows\system32\wpcap.dll
2009-10-20 18:19 . 2009-10-20 18:19 50704 ----a-w- c:\windows\system32\drivers\npf.sys
2009-10-20 18:19 . 2009-10-20 18:19 53299 ----a-w- c:\windows\system32\pthreadVC.dll
2009-10-15 08:31 . 2009-10-15 08:31 -------- d-----w- c:\users\Danny\AppData\Roaming\TomTom
2009-10-14 06:28 . 2009-10-14 06:28 4096 d-----w- c:\program files\Process Hacker
2009-10-12 08:37 . 2009-10-12 08:37 -------- d-----w- c:\users\Danny\AppData\Roaming\Media Player Classic
2009-09-20 18:40 . 2008-03-06 07:07 8224 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-09-20 17:00 . 2008-12-28 21:12 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-14 09:44 . 2009-10-15 04:44 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 17:30 . 2009-10-15 04:45 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 12:24 . 2009-10-15 04:44 61440 ----a-w- c:\windows\system32\msasn1.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-09 865840]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-20 149280]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-08-31 623960]
"avast!"="d:\progra~1\ashDisp.exe" [2009-11-24 81000]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872]
c:\users\Danny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^Danny^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\users\Danny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [30/11/2009 13:38 64288]
R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [02/10/2009 09:33 28552]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [30/11/2009 09:41 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [30/11/2009 09:41 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [30/11/2009 09:41 53328]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 11:17 1184912]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [20/10/2009 18:19 50704]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [29/11/2009 18:51 1153368]
S4 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe --> c:\program files\AskBarDis\bar\bin\AskService.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-12-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:37]
2009-12-02 c:\windows\Tasks\User_Feed_Synchronization-{1D68AA82-5C3C-4FE5-96F3-8FB21F4DE243}.job
- c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
HKLM-Run-eRecoveryService - (no file)
AddRemove-Active WebCam - d:\programmes\PY_UNINSTAL.EXE SOFTWARE\PySoft\Act_WebCam
AddRemove-Ad-Aware - c:\programdata\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-eBay Icon - c:\users\Danny\AppData\Roaming\Desktopicon\uninst.exe
AddRemove-HijackThis - f:\downloads\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-02 22:25
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{76a65ab9-8e5a-46ce-a536-0cfc92f4de21}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0d0017c4
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{8063b8bf-e98a-4896-b59a-0ac70752649b}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:07001422
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{8090b7dd-f32b-485a-9ad4-1678df03bbc2}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0c0016d3
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{adeb0ee5-2503-499d-919b-1a72ca369385}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:11020054
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{ba9e677f-0ef8-4bb2-a3e5-3ba5c63d1e87}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:06001422
"Dhcpv6State"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{f1cff720-a663-4770-8649-f2a005371c56}]
@DACL=(02 0000)
"Dhcpv6Iaid"=dword:0c0016d3
"Dhcpv6State"=dword:00000000
.
Completion time: 2009-12-02 22:31
ComboFix-quarantined-files.txt 2009-12-02 22:31
Pre-Run: 11,170,320,384 bytes free
Post-Run: 12,040,712,192 bytes free
- - End Of File - - 88DD9DF2E4D3890638EEF5F1E2E21B43
And finally Malwarebytes first log - that cleaned located a lot of infections
Malwarebytes' Anti-Malware 1.41
Database version: 3260
Windows 6.0.6001 Service Pack 1
30/11/2009 11:32:39
mbam-log-2009-11-30 (11-32-39).txt
Scan type: Full Scan (C:\|D:\|F:\|)
Objects scanned: 242321
Time elapsed: 1 hour(s), 51 minute(s), 42 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 13
Memory Processes Infected:
C:\Windows\System32\lyjp.exe (Worm.Autorun) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cftmon (Worm.Autorun) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sshnas (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Winlogon (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Users\Danny\AppData\Roaming\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Danny\AppData\Roaming\RegistrySmart\Log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Users\Danny\AppData\Roaming\RegistrySmart\Registry Backups (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Program Files\runit (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Smart-Ads-Solutions (Adware.SmartAds) -> Quarantined and deleted successfully.
C:\Program Files\Smart-Ads-Solutions\SmartAds (Adware.SmartAds) -> Quarantined and deleted successfully.
Files Infected:
C:\Windows\System32\lyjp.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\Users\Danny\AppData\Local\Temp\a.exe (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Users\Danny\AppData\Local\Temp\cv4B2E8.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\clju6768.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\dsww06562.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Windows\phnbb68452.exe (Worm.Autorun) -> Quarantined and deleted successfully.
C:\Windows\System32\sshnas.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\Temp\wntu.tmp\svchost.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Danny\AppData\Roaming\RegistrySmart\Registry Backups\2008-09-08_10-28-07.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Program Files\runit\config.txt (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Danny\AppData\Local\Temp\b.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
I have a more recent Malwarebytes log?
Many many thanks for having a look at this... it's total chaos here :-)