Here is the latest combo fix log.
ComboFix 11-11-17.03 - Willy 11/20/2011 8:47.4.2 - x86
Running from: c:\documents and settings\Willy\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Willy\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
ADS - explorer.exe: deleted 26 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Willy\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\explorer.exe
c:\windows\CSC\d6
C:\wuauclt.exe
.
.
--------------- FCopy ---------------
.
c:\explorer.exe --> c:\WINDOWS\explorer.exe
c:\explorer.exe --> c:\WINDOWS\ERDNT\cache\explorer.exe
c:\explorer.exe --> c:\WINDOWS\system32\dllcache\explorer.exe
c:\wuauclt.exe --> c:\WINDOWS\system32\wuauclt.exe
c:\wuauclt.exe --> c:\WINDOWS\ERDNT\cache\wuauclt.exe
.
((((((((((((((((((((((((( Files Created from 2011-10-20 to 2011-11-20 )))))))))))))))))))))))))))))))
.
.
2011-11-15 12:49 . 2011-11-15 12:49 30208 ----a-w- c:\windows\system32\asr_fmt.exe.kav
2011-11-15 03:49 . 2011-11-15 10:56 133208 ----a-w- c:\windows\system32\drivers\06344987.sys
2011-11-14 04:07 . 2011-11-14 04:07 -------- d-----w- c:\program files\ESET
2011-11-14 01:17 . 2011-11-18 05:37 -------- d-----w- C:\ff73cd1785e82edb873a9ba1864eec01
2011-11-13 13:28 . 2011-11-13 13:28 -------- d-----w- c:\documents and settings\Willy\Application Data\Malwarebytes
2011-11-13 13:28 . 2011-11-13 13:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-13 01:48 . 2011-07-11 05:14 24272 ----a-w- c:\windows\system32\drivers\AVGIDSFilter.sys
2011-11-13 01:48 . 2011-07-11 05:14 23120 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2011-11-13 01:48 . 2011-07-11 05:14 134608 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2011-11-13 01:48 . 2011-10-04 11:21 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-11-13 01:48 . 2011-07-11 05:14 295248 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2011-11-13 01:48 . 2011-08-08 10:08 40016 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2011-11-13 01:48 . 2011-10-07 11:23 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-11-13 01:48 . 2011-09-13 10:30 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-11-13 01:38 . 2011-11-15 02:59 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-19 14:05 . 2008-04-25 21:27 53472 ----a-w- c:\windows\system32\wuauclt.exe
2011-11-19 14:05 . 2008-04-25 16:16 1033728 ----a-w- c:\windows\explorer.exe
2011-11-15 13:00 . 2006-10-15 04:44 597504 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-11-15 12:55 . 2010-05-05 02:38 146432 ----a-w- c:\windows\system32\WudfHost.exe
2011-11-15 12:55 . 2009-10-09 19:56 14848 ----a-w- c:\windows\system32\wsmprovhost.exe
2011-11-15 12:55 . 2009-10-09 19:56 225280 ----a-w- c:\windows\system32\wsmanhttpconfig.exe
2011-11-15 12:54 . 2010-05-05 02:38 17408 ----a-w- c:\windows\system32\wpdshextautoplay.exe
2011-11-15 12:54 . 2010-05-05 02:38 293376 ----a-w- c:\windows\system32\WISPTIS.EXE
2011-11-15 12:54 . 2009-10-19 18:06 223232 ----a-w- c:\windows\system32\wksprt.exe
2011-11-15 12:54 . 2009-10-09 19:56 22528 ----a-w- c:\windows\system32\winrshost.exe
2011-11-15 12:54 . 2009-10-09 21:22 69632 ----a-w- c:\windows\system32\winrs.exe
2011-11-15 12:54 . 2010-05-05 02:38 8704 ----a-w- c:\windows\system32\wdfmgr.exe
2011-11-15 12:54 . 2008-04-25 16:16 28672 ----a-w- c:\windows\system32\verclsid.exe
2011-11-15 12:54 . 2010-05-05 02:38 8704 ----a-w- c:\windows\system32\uwdf.exe
2011-11-15 12:54 . 2009-10-19 18:06 46080 ----a-w- c:\windows\system32\TSWbPrxy.exe
2011-11-15 12:53 . 2010-05-05 02:38 184832 ----a-w- c:\windows\system32\searchprotocolhost.exe
2011-11-15 12:53 . 2010-05-05 02:38 439808 ----a-w- c:\windows\system32\searchindexer.exe
2011-11-15 12:53 . 2010-05-05 02:38 87552 ----a-w- c:\windows\system32\searchfilterhost.exe
2011-11-15 12:53 . 2010-09-08 23:52 1503232 ----a-w- c:\windows\system32\ptj.exe
2011-11-15 12:53 . 2010-03-31 04:10 289280 ----a-w- c:\windows\system32\PresentationHost.exe
2011-11-15 12:52 . 2010-05-03 16:20 24576 ----a-w- c:\windows\system32\OEM02Srv.exe
2011-11-15 12:52 . 2010-05-05 05:17 356352 ----a-w- c:\windows\system32\nvudisp.exe
2011-11-15 12:52 . 2010-05-03 16:20 1339392 ----a-w- c:\windows\system32\nvdspsch.exe
2011-11-15 12:52 . 2010-05-03 16:20 753664 ----a-w- c:\windows\system32\nvcplui.exe
2011-11-15 12:52 . 2010-05-03 16:20 442368 ----a-w- c:\windows\system32\nvappbar.exe
2011-11-15 12:51 . 2008-04-25 16:16 51712 ----a-w- c:\windows\system32\migpwd.exe
2011-11-15 12:51 . 2010-05-03 16:20 425984 ----a-w- c:\windows\system32\keystone.exe
2011-11-15 12:51 . 2008-07-30 07:24 612864 ----a-w- c:\windows\system32\icardagt.exe
2011-11-15 12:50 . 2008-04-25 16:16 15872 ----a-w- c:\windows\system32\expand.exe
2011-11-15 12:50 . 2010-05-03 16:23 24576 ----a-w- c:\windows\system32\DSRIRREM.EXE
2011-11-15 12:50 . 2010-05-05 02:37 249856 ----a-w- c:\windows\system32\drmupgds.exe
2011-11-15 12:50 . 2008-04-25 16:16 20480 ----a-w- c:\windows\system32\cliconfg.exe
2011-11-15 12:49 . 2010-05-04 22:28 356352 ----a-w- c:\windows\system32\AegisI5Installer.exe
2011-11-15 12:23 . 2010-06-06 21:59 86016 ----a-w- c:\windows\unvise32qt.exe
2011-11-15 12:23 . 2010-05-05 05:16 405504 ----a-w- c:\windows\stsystra.exe
2011-11-15 12:23 . 2010-05-03 16:20 77824 ----a-w- c:\windows\setpwr32.exe
2011-11-15 12:22 . 2010-05-03 16:20 28672 ----a-w- c:\windows\OEM02Cfg.exe
2011-11-15 12:22 . 2010-05-03 16:20 90112 ----a-w- c:\windows\CtDrvIns.exe
2011-11-15 11:21 . 2008-04-25 16:16 11776 ----a-w- c:\windows\system32\regsvr32.exe
2011-11-15 11:11 . 2008-04-25 16:16 124928 ----a-w- c:\windows\system32\net1.exe
2011-11-15 11:11 . 2008-04-25 16:16 39424 ----a-w- c:\windows\system32\grpconv.exe
2011-11-15 03:13 . 2008-04-25 16:16 146432 ------w- c:\windows\regedit.exe
2011-11-15 03:13 . 2008-04-25 16:16 69120 ----a-w- c:\windows\system32\notepad.exe
2011-11-15 03:13 . 2008-04-25 16:16 389120 ----a-w- c:\windows\system32\cmd.exe
2011-11-15 03:13 . 2008-04-25 16:16 420864 ----a-w- c:\windows\system32\ntvdm.exe
2011-11-15 03:13 . 2008-04-25 16:16 514560 ----a-w- c:\windows\system32\logonui.exe
2011-11-15 03:12 . 2008-04-25 21:26 62976 ----a-w- c:\windows\system32\rdpclip.exe
2011-11-15 03:12 . 2008-04-25 16:16 135168 ----a-w- c:\windows\system32\cscript.exe
2011-11-15 02:26 . 2010-05-03 16:20 36864 ----a-w- c:\windows\OEM02Mon.exe
2011-11-15 02:26 . 2010-05-03 16:20 1626112 ----a-w- c:\windows\system32\nwiz.exe
2011-11-15 02:26 . 2008-04-25 16:16 26112 ----a-w- c:\windows\system32\userinit.exe
2011-11-15 02:26 . 2008-04-25 16:16 45568 ----a-w- c:\windows\system32\drwtsn32.exe
2011-10-18 23:04 . 2011-08-10 14:27 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2008-04-25 21:27 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2008-04-25 16:16 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-30 07:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2008-04-25 16:16 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2008-04-25 16:16 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:25 . 2008-04-25 16:16 1867904 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2008-04-25 16:16 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2008-04-25 16:16 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2008-04-25 16:16 1469440 ------w- c:\windows\system32\inetcpl.cpl
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2011-11-15 . 7C562E4506C257CE1A730084D62DE857 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\wscntfy.exe
[-] 2011-11-15 . 7C562E4506C257CE1A730084D62DE857 . 13824 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\wscntfy.exe
[-] 2011-11-14 04:19 . !HASH: COULD NOT OPEN FILE !!!!! . 161280 . . [------] . . c:\windows\system32\wscntfy.exe
.
[-] 2011-11-15 . 1778EDDF5B6221F97D4F52A393311401 . 632832 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe
.
((((((((((((((((((((((((((((( SnapShot@2011-11-18_05.39.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-25 21:27 . 2011-11-19 14:05 53472 c:\windows\system32\dllcache\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SansaDispatch"="c:\documents and settings\Willy\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-11-15 1024000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-05-05 8491008]
"nwiz"="nwiz.exe" [2011-11-15 1626112]
"NVHotkey"="nvHotkey.dll" [2007-11-06 81920]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-06 81920]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2011-11-15 36864]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-11-15 242176]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2011-11-15 823296]
"Launch LCDMon"="c:\program files\Common Files\Logitech\LCD Manager\LCDMon.exe" [2011-11-15 770560]
"EZGigMonitor.exe"="c:\program files\Apricorn\EZ Gig II\EZGigMonitor.exe" [2007-10-09 1169264]
"AcronisTimounterMonitor"="c:\program files\Apricorn\EZ Gig II\TimounterMonitor.exe" [2007-10-09 1949480]
.
c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\
desktop.ini~CL29UPQL [2010-5-4 84]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
desktop.ini~29G9CGMH [2010-5-4 84]
.
c:\documents and settings\Willy\Start Menu\Programs\Startup\
desktop.ini~NFDCDVNA [2010-5-4 84]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [N/A]
_uninst_86641713.lnk - c:\documents and settings\Willy\Local Settings\temp\_uninst_86641713.bat [N/A]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [N/A]
desktop.ini~QAQP9CP6 [2010-5-4 84]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [N/A]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
desktop.ini~H762R46B [2010-5-4 84]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*
isabled:Windows Remote Management
.
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
R3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe [2008-04-14 14336]
S0 06344987;06344987;c:\windows\system32\DRIVERS\06344987.sys [2011-11-15 133208]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2010-05-04 23:40]
.
2011-11-13 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Swift Sound\Switch\switch.exe [2010-07-25 18:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-20 08:55
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SansaDispatch = c:\documents and settings\Willy\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe?????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(1316)
c:\windows\system32\relog_ap.dll
.
- - - - - - - > 'explorer.exe'(3124)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
c:\program files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
c:\program files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe~PGRH68QI
.
**************************************************************************
.
Completion time: 2011-11-20 08:58:28 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-20 13:58
ComboFix2.txt 2011-11-18 05:42
ComboFix3.txt 2011-11-14 03:26
ComboFix4.txt 2011-11-13 22:11
.
Pre-Run: 334,606,921,728 bytes free
Post-Run: 334,585,384,960 bytes free
.
- - End Of File - - DD9A11BDFD2A459F064B8A07891F79C5