uStart Page = hxxp://eeepc.asus.com/global uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program

dvk01, Mar 1, 2013 #6 KillerAggie Thread Starter Joined: Apr 6, 2004 Messages: 67 # AdwCleaner v2.113 - Logfile created 03/01/2013 at 16:08:12 # Updated 23/02/2013 by Xplode # Operating system

To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC by OldTimer: Save it to your Desktop.

The best way to eliminate these risks is to avoid using P2P applications.P2P Software User AdvisoriesRisks of File-Sharing TechnologyP2P file sharing: Anticipate the risks....Since the nature of P2P programs is counter CF disconnects your machine from the internet.

Run Combofix ONCE only!! When finished, it will produce a log.

Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exeO4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exeO4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exeO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run:

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If not, an attacker may get the new passwords and transaction information.

If that does not restore the connection, then follow the instructions for Manually restoring the Internet connection provided in the "How to Guide" you printed out earlier.-- Do not touch your

Important: Do not mouseclick ComboFix's window while it is running. scanning hidden files ...

c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\program files\AVG\AVG8\avgrsx.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\program files\AVG\AVG8\avgcsrvx.exe c:\windows\system32\wscntfy.exe c:\windows\system32\igfxsrvc.exe c:\windows\system32\igfxext.exe c:\program files\HP\hpcoretech\comp\hptskmgr.exe c:\program files\HP\Digital Imaging\bin\hpqgalry.exe c:\windows\system32\wbem\wmiadap.exe . ************************************************************************** . Alternate DDS download link Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds

It has done this 1 time(s). 13/10/2010 16:37:26, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:19:10 p.m., on 6/01/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe

R1 SABKUTIL;SABKUTIL;c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys [x] R2 AsusService;Asus Launcher Service;c:\windows\System32\AsusService.exe [x] R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] S1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [x] S2 OberonGameConsoleService;Oberon Media Game With the help of this automatic analyzer you are able to get some additional support. iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast!

KillerAggie, Mar 2, 2013 #9 KillerAggie Thread Starter Joined: Apr 6, 2004 Messages: 67 ComboFix 13-03-01.01 - owner 03/02/2013 13:51:33.2.2 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.1014.358 [GMT -6:00] Running from: