HijackThis won't run on the laptop and I'm having trouble trying to download a new copy. But here is the ComboFix log:
ComboFix 09-09-30.06 - Katie 10/01/2009 10:43.2.1 - NTFSx86
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-09-01 to 2009-10-01 )))))))))))))))))))))))))))))))
.
2009-09-29 21:45 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-09-29 15:52 . 2009-09-29 15:52 -------- d-----w- c:\program files\ESET
2009-09-24 19:33 . 2009-09-29 22:09 120 ----a-w- c:\windows\Rgugitulo.dat
2009-09-24 19:33 . 2009-09-24 19:33 -------- d-----w- c:\documents and settings\Katie\Local Settings\Application Data\{502F6885-21DD-489F-8843-E40236F69A7C}
2009-09-21 21:40 . 2009-09-21 21:43 -------- d-----w- c:\program files\Rhapsody
2009-09-21 21:14 . 2009-09-21 21:14 36192 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-21 20:49 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-21 20:49 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-21 20:46 . 2009-09-21 20:46 -------- d-----w- c:\program files\iPod
2009-09-21 20:44 . 2009-09-21 20:48 -------- d-----w- c:\program files\iTunes
2009-09-21 20:44 . 2009-09-21 20:48 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-21 20:43 . 2009-09-21 20:43 -------- d-----w- c:\program files\Bonjour
2009-09-21 20:41 . 2009-09-21 20:43 -------- d-----w- c:\program files\QuickTime
2009-09-21 20:40 . 2009-09-21 20:40 -------- d-----w- c:\documents and settings\Katie\Local Settings\Application Data\Apple
2009-09-21 20:40 . 2009-09-21 20:40 -------- d-----w- c:\program files\Apple Software Update
2009-09-21 20:38 . 2009-09-21 20:45 -------- d-----w- c:\program files\Common Files\Apple
2009-09-21 20:38 . 2009-09-21 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-09-12 21:10 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-02 05:02 . 2009-09-02 16:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-01 15:50 . 2009-08-07 00:21 681226272 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-01 15:49 . 2009-08-04 19:37 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-01 15:36 . 2006-09-04 18:43 -------- d-----w- c:\documents and settings\Katie\Application Data\stickies
2009-10-01 15:26 . 2009-08-07 00:21 7979300 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-30 15:42 . 2006-09-04 18:34 -------- d-----w- c:\program files\Lavasoft
2009-09-30 15:42 . 2008-12-08 21:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-29 23:46 . 2009-08-07 00:11 -------- d-----w- c:\program files\UnHackMe
2009-09-29 22:39 . 2009-08-04 19:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-29 22:15 . 2009-08-07 03:02 24416 ----a-w- c:\windows\system32\drivers\regguard.sys
2009-09-29 14:44 . 2009-08-04 21:44 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-29 14:36 . 2009-09-24 19:33 0 ----a-r- c:\windows\Bjepofowacehezu.bin
2009-09-28 18:38 . 2009-09-28 18:38 -------- d-----w- c:\program files\Windows Live Safety Center
2009-09-28 18:20 . 2009-09-28 18:20 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer
2009-09-28 15:15 . 2006-09-04 18:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-28 14:21 . 2009-09-28 14:21 53136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-24 23:49 . 2008-12-08 21:29 -------- d-----w- c:\documents and settings\Katie\Application Data\MSNInstaller
2009-09-24 23:33 . 2009-08-14 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-09-24 21:00 . 2009-08-04 18:53 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-24 20:45 . 2006-01-19 04:38 -------- d-----w- c:\program files\Java
2009-09-24 20:23 . 2009-09-24 20:23 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-09-22 19:57 . 2009-08-14 19:43 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-09-21 21:28 . 2006-01-19 04:48 -------- d-----w- c:\program files\Real
2009-09-21 20:54 . 2006-09-04 17:39 53136 ----a-w- c:\documents and settings\Katie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-21 20:54 . 2006-12-25 13:22 -------- d-----w- c:\documents and settings\Katie\Application Data\Apple Computer
2009-09-21 20:41 . 2006-12-25 13:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-09-16 07:28 . 2009-08-07 00:11 34760 ----a-w- c:\windows\system32\drivers\Partizan.sys
2009-09-16 07:28 . 2009-08-07 00:11 35040 ----a-w- c:\windows\system32\Partizan.exe
2009-09-10 19:54 . 2009-08-04 19:49 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2009-08-04 19:49 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-02 05:02 . 2007-02-13 21:37 -------- d-----w- c:\documents and settings\All Users\Application Data\yahoo!
2009-09-02 05:02 . 2006-01-19 04:53 -------- d-----w- c:\program files\Yahoo!
2009-09-02 05:02 . 2007-02-14 00:01 -------- d--h--r- c:\documents and settings\Katie\Application Data\yahoo!
2009-08-24 21:10 . 2009-08-24 21:09 -------- d-----w- c:\documents and settings\Katie\Application Data\Snapfish
2009-08-14 19:16 . 2009-08-14 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-14 19:16 . 2009-08-14 19:16 -------- d-----w- c:\program files\NortonInstaller
2009-08-14 19:16 . 2009-08-14 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-08-09 04:27 . 2009-08-09 04:27 -------- d-----w- c:\program files\MSBuild
2009-08-09 04:27 . 2009-08-09 04:27 -------- d-----w- c:\program files\Reference Assemblies
2009-08-07 16:52 . 2009-08-05 22:08 -------- d-----w- c:\program files\CCleaner
2009-08-07 00:11 . 2009-08-07 00:11 2 --shatr- c:\windows\winstart.bat
2009-08-06 22:06 . 2009-08-06 22:05 15 ----a-w- c:\documents and settings\Administrator\settings.dat
2009-08-05 09:01 . 2006-01-19 02:02 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 04:19 . 2009-08-05 04:19 -------- d-----w- c:\program files\Trend Micro
2009-08-05 02:43 . 2009-08-05 02:43 1152 ----a-w- c:\windows\system32\windrv.sys
2009-08-05 02:28 . 2007-10-12 15:50 -------- d-----w- c:\program files\Outspark
2009-08-04 23:13 . 2006-09-04 18:39 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-04 23:08 . 2009-08-04 23:08 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-08-04 21:45 . 2009-09-24 22:04 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-08-04 21:24 . 2009-08-04 21:24 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-08-04 21:16 . 2009-08-04 21:16 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-04 20:41 . 2009-08-04 20:41 -------- d-----w- c:\program files\Alwil Software
2009-08-04 19:49 . 2009-08-04 19:49 -------- d-----w- c:\documents and settings\Katie\Application Data\Malwarebytes
2009-08-04 19:49 . 2009-08-04 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-04 19:37 . 2009-08-04 19:37 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-04 19:37 . 2009-08-04 19:37 -------- d-----w- c:\documents and settings\Katie\Application Data\SUPERAntiSpyware.com
2009-08-04 19:37 . 2009-08-04 19:37 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-04 18:52 . 2009-08-04 18:52 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-03 21:09 . 2006-01-19 03:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-28 00:51 . 2009-08-07 00:11 12728 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
2009-07-17 19:01 . 2006-01-19 02:01 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2006-01-19 02:03 286208 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-29_21.47.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-01-19 03:50 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2006-01-19 03:50 . 2007-07-27 15:41 26488 c:\windows\system32\spupdsvc.exe
+ 2008-12-09 03:23 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UnHackMe Monitor"="c:\program files\UnHackMe\hackmon.exe" [2009-09-25 238304]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-20 1998576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1343488]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-24 149280]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 122880]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-08-18 184320]
"IVPServiceMgr"="c:\toshiba\ivp\ism\ivpsvmgr.exe" [2003-10-20 475136]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-10-06 122940]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624]
"TFncKy"="TFncKy.exe" [BU]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-05-05 16206848]
"NDSTray.exe"="NDSTray.exe" [BU]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-15 88203]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Katie\Start Menu\Programs\Startup\
Stickies.lnk - c:\program files\stickies\stickies.exe [2008-8-28 765952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-1-18 155648]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-20 18:51 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\stickies\\stickies.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
R0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2009-09-16 34760]
R3 RegGuard;RegGuard;c:\windows\system32\Drivers\regguard.sys [2009-09-29 24416]
R3 rspSanity;rspSanity;c:\windows\system32\DRIVERS\rspSanity32.sys [2009-03-08 30136]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-07-28 7408]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
S1 is-MIETPdrv;is-MIETPdrv;c:\windows\system32\DRIVERS\45939495.sys [2008-07-08 148496]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-07-28 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-08-07 74480]
.
Contents of the 'Scheduled Tasks' folder
2009-09-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-01 10:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@DACL=(02 0000)
@SACL=
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(848)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2824)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
Completion time: 2009-10-01 10:54
ComboFix-quarantined-files.txt 2009-10-01 15:54
ComboFix2.txt 2009-09-29 21:52
Pre-Run: 35,609,038,848 bytes free
Post-Run: 35,651,022,848 bytes free
222 --- E O F --- 2009-10-01 15:18