shauna78
2007-08-06, 03:32
Hi
I am new to the forums and before I wasted anyone's time I have tried to fix the problem by reading other threads, but I' am still getting pop ups.. They have reduced in frequency but I have obviously not solved the problem. Also I am unable to install any updates for windows and some of my programmes wont launch as it is saying they are not installed. (Itunes and registry mechanic for instance)
I have downloaded Highjackthis and combofix and ATF cleaner I think it is. I have also recently installed AVG. S&D also keeps finding windows virus override I deleted it the first time but left it the last time I ran a search - I am unsure if this was the correct thing to do?
The other strange thing that is happening is my cookie settings keep defaulting back to "accept all" even when I change this back to medium?
Thank you in advance for any assistance you can offer me :)
logs to follow:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:25:12, on 8/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\highjackthis\scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {2264DEBB-85DF-4754-97C2-3DDB97C81E6F} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Windows Live OneCare (winss) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\winss.exe (file missing)
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
--
End of file - 3853 bytes
ComboFix 07-08-04.3 - "Shauna Holleran" 2007-08-06 0:28:52.1 [GMT 1:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.True
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Jacko\APPLIC~1\FunWebProducts
C:\DOCUME~1\Jacko\APPLIC~1\FunWebProducts\Data\Jacko\avatar.dat
C:\DOCUME~1\SHAUNA~1.SHO\MYDOCU~1.\fnts~1
C:\DOCUME~1\SHAUNA~1.SHO\MYDOCU~1.\sstem~1
C:\WINDOWS\system32\akmxmtmg.exe
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\byxuvuu.dll
C:\WINDOWS\system32\ddccy.dll
C:\WINDOWS\system32\dvctdmyq.exe
C:\WINDOWS\system32\eeyiamos.exe
C:\WINDOWS\system32\ehkbcudl.exe
C:\WINDOWS\system32\etnpmmin.exe
C:\WINDOWS\system32\etwykkcj.exe
C:\WINDOWS\system32\gjjlm.ini2
C:\WINDOWS\system32\gjjlm.tmp
C:\WINDOWS\system32\gsmosjeu.exe
C:\WINDOWS\system32\gyjhpnom.exe
C:\WINDOWS\system32\jskatapa.exe
C:\WINDOWS\system32\ljjkkhe.dll
C:\WINDOWS\system32\lowpdeqx.exe
C:\WINDOWS\system32\nfbhvbwm.exe
C:\WINDOWS\system32\nfpnlivn.dll
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\system32\nwcdtufx.exe
C:\WINDOWS\system32\olsbqdvc.exe
C:\WINDOWS\system32\pruxhcsa.exe
C:\WINDOWS\system32\qtibhusv.dll
C:\WINDOWS\system32\rflbvrjj.exe
C:\WINDOWS\system32\rlludflb.exe
C:\WINDOWS\system32\roegcnps.exe
C:\WINDOWS\system32\rrqlecei.exe
C:\WINDOWS\system32\rygtclbn.exe
C:\WINDOWS\system32\tpmxsdoi.exe
C:\WINDOWS\system32\vmlmxgfj.exe
C:\WINDOWS\system32\vvhtpxma.exe
C:\WINDOWS\system32\wctbrgke.exe
C:\WINDOWS\system32\xmlggivx.exe
C:\WINDOWS\system32\yccdd.bak1
C:\WINDOWS\system32\yccdd.bak2
C:\WINDOWS\system32\yccdd.ini
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 )))))))))))))))))))))))))))))))
2007-08-06 00:26 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-05 22:45 <DIR> d-------- C:\DOCUME~1\Jacko.SHO\Contacts
2007-08-05 12:11 125,504 --a------ C:\WINDOWS\system32\mckughuu.dll
2007-08-04 22:46 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-04 22:36 <DIR> d-------- C:\VundoFix Backups
2007-08-04 14:49 1,310,720 --ah----- C:\DOCUME~1\Guest.SHO\NTUSER.DAT
2007-08-04 14:22 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-08-04 14:07 <DIR> d-------- C:\{000039B2-0000-0000-ECE0-75F3478B6F0C}
2007-08-04 12:11 <DIR> d-------- C:\DOCUME~1\JACQUI~1.SHO\Contacts
2007-08-04 12:05 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-08-04 11:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
2007-08-04 11:18 <DIR> d-------- C:\DOCUME~1\Jacko.SHO\APPLIC~1\Google
2007-08-04 11:17 1,572,864 --ah----- C:\DOCUME~1\Jacko.SHO\NTUSER.DAT
2007-08-04 03:47 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-08-04 03:24 <DIR> d--hs---- C:\WINDOWS\CSC
2007-08-04 03:01 <DIR> d--hs---- C:\DOCUME~1\SHAUNA~1.SHO\UserData
2007-08-04 02:46 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-04 02:07 <DIR> d-------- C:\DOCUME~1\JACQUI~1.SHO\APPLIC~1\Google
2007-08-03 23:51 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Spybot - Search & Destroy
2007-08-03 23:31 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\APPLIC~1\Google
2007-08-03 23:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Google Updater
2007-08-03 23:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Google
2007-08-03 23:24 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\Contacts
2007-08-03 22:53 <DIR> d--hs---- C:\WINDOWS\U2hhdW5hIEhvbGxlcmFu
2007-08-03 22:50 <DIR> d-------- C:\Program Files\BitComet
2007-08-03 22:49 <DIR> d-------- C:\Program Files\BitTorrent
2007-08-03 22:49 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\APPLIC~1\BitTorrent
2007-08-03 21:58 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\APPLIC~1\Help
2007-08-03 20:16 <DIR> d-------- C:\WINDOWS\Prefetch
2007-08-03 20:13 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\TEMP
2007-08-03 20:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Apple Computer
2007-08-03 20:07 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\APPLIC~1\Apple Computer
2007-08-03 20:00 <DIR> d-------- C:\WINDOWS\Thomson.0008
2007-08-03 19:53 3,407,872 --ah----- C:\DOCUME~1\SHAUNA~1.SHO\NTUSER.DAT
2007-08-03 18:05 <DIR> d-------- C:\DOCUME~1\JACQUI~1.SHO\APPLIC~1\Yahoo!
2007-08-03 18:03 159,744 --a------ C:\WINDOWS\system32\igfxres.dll
2007-08-03 18:03 1,835,008 --ah----- C:\DOCUME~1\JACQUI~1.SHO\NTUSER.DAT
2007-08-03 18:03 1,146,880 --ah----- C:\DOCUME~1\LOCALS~1.NTA\NTUSER.DAT
2007-08-03 18:02 1,146,880 --ah----- C:\DOCUME~1\NETWOR~1.NTA\NTUSER.DAT
2007-08-03 18:00 9,728 --a--c--- C:\WINDOWS\system32\dllcache\rwnh.dll
2007-08-03 18:00 9,728 --a--c--- C:\WINDOWS\system32\dllcache\query.exe
2007-08-03 18:00 9,216 --a--c--- C:\WINDOWS\system32\dllcache\wamps51.dll
2007-08-03 18:00 86,073 --a--c--- C:\WINDOWS\system32\dllcache\voicesub.dll
2007-08-03 18:00 8,704 --a--c--- C:\WINDOWS\system32\dllcache\snmptrap.exe
2007-08-03 18:00 79,872 --a--c--- C:\WINDOWS\system32\dllcache\rwia330.dll
2007-08-03 18:00 79,872 --a--c--- C:\WINDOWS\system32\dllcache\rwia001.dll
2007-08-03 18:00 76,800 --a--c--- C:\WINDOWS\system32\dllcache\wam51.dll
2007-08-03 18:00 76,288 --a--c--- C:\WINDOWS\system32\dllcache\uniime.dll
2007-08-03 18:00 73,728 --a--c--- C:\WINDOWS\system32\dllcache\w3ext.dll
2007-08-03 18:00 70,144 --a--c--- C:\WINDOWS\system32\dllcache\pintlphr.exe
2007-08-03 18:00 7,680 --a--c--- C:\WINDOWS\system32\dllcache\pwsdata.dll
2007-08-03 18:00 7,168 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_snprfdll.dll
2007-08-03 18:00 67,584 --a--c--- C:\WINDOWS\system32\dllcache\pmigrate.dll
2007-08-03 18:00 6,144 --a--c--- C:\WINDOWS\system32\dllcache\snmpmib.dll
2007-08-03 18:00 6,144 --a--c--- C:\WINDOWS\system32\dllcache\pmxgl.dll
2007-08-03 18:00 57,856 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_scripto.dll
2007-08-03 18:00 53,760 --a--c--- C:\WINDOWS\system32\dllcache\pintlcsd.dll
2007-08-03 18:00 53,248 --a--c--- C:\WINDOWS\system32\dllcache\wamreg51.dll
2007-08-03 18:00 53,248 --a--c--- C:\WINDOWS\system32\dllcache\nextlink.dll
2007-08-03 18:00 5,632 --a--c--- C:\WINDOWS\system32\dllcache\w3svapi.dll
2007-08-03 18:00 5,632 --a--c--- C:\WINDOWS\system32\dllcache\smimsgif.dll
2007-08-03 18:00 5,632 --a--c--- C:\WINDOWS\system32\dllcache\smierrsy.dll
2007-08-03 18:00 48,256 --a--c--- C:\WINDOWS\system32\dllcache\w32.dll
2007-08-03 18:00 46,592 --a--c--- C:\WINDOWS\system32\dllcache\svcext51.dll
2007-08-03 18:00 46,592 --a--c--- C:\WINDOWS\system32\dllcache\sspifilt.dll
2007-08-03 18:00 456,704 --a--c--- C:\WINDOWS\system32\dllcache\smtpsvc.dll
2007-08-03 18:00 455,168 --a--c--- C:\WINDOWS\system32\dllcache\tintsetp.exe
2007-08-03 18:00 45,056 --a--c--- C:\WINDOWS\system32\dllcache\ssinc51.dll
2007-08-03 18:00 44,544 --a--c--- C:\WINDOWS\system32\dllcache\nsepm.dll
2007-08-03 18:00 44,032 --a--c--- C:\WINDOWS\system32\dllcache\tintlphr.exe
2007-08-03 18:00 426,041 --a--c--- C:\WINDOWS\system32\dllcache\voicepad.dll
2007-08-03 18:00 41,600 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.dll
2007-08-03 18:00 40,448 --a--c--- C:\WINDOWS\system32\dllcache\snmpthrd.dll
2007-08-03 18:00 4,608 --a--c--- C:\WINDOWS\system32\dllcache\w3ctrs51.dll
2007-08-03 18:00 4,096 --a--c--- C:\WINDOWS\system32\dllcache\rpcref.dll
2007-08-03 18:00 38,912 --a--c--- C:\WINDOWS\system32\dllcache\sm9aw.dll
2007-08-03 18:00 38,912 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_ntfsdrv.dll
2007-08-03 18:00 363,520 --a--c--- C:\WINDOWS\system32\dllcache\w3svc.dll
2007-08-03 18:00 36,927 --a--c--- C:\WINDOWS\system32\dllcache\padrs411.dll
2007-08-03 18:00 358,400 --a--c--- C:\WINDOWS\system32\dllcache\snmpincl.dll
2007-08-03 18:00 32,768 --a--c--- C:\WINDOWS\system32\dllcache\snmp.exe
2007-08-03 18:00 31,744 --a--c--- C:\WINDOWS\system32\dllcache\smb6w.dll
2007-08-03 18:00 31,744 --a--c--- C:\WINDOWS\system32\dllcache\sma3w.dll
2007-08-03 18:00 31,744 --a--c--- C:\WINDOWS\system32\dllcache\pagecnt.dll
2007-08-03 18:00 31,232 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.sys
2007-08-03 18:00 31,232 --a--c--- C:\WINDOWS\system32\dllcache\tools.dll
2007-08-03 18:00 30,208 --a--c--- C:\WINDOWS\system32\dllcache\sm87w.dll
2007-08-03 18:00 30,208 --a--c--- C:\WINDOWS\system32\dllcache\sm81w.dll
2007-08-03 18:00 29,184 --a--c--- C:\WINDOWS\system32\dllcache\sm8cw.dll
2007-08-03 18:00 26,624 --a--c--- C:\WINDOWS\system32\dllcache\sm93w.dll
2007-08-03 18:00 26,624 --a--c--- C:\WINDOWS\system32\dllcache\sm92w.dll
2007-08-03 18:00 26,624 --a--c--- C:\WINDOWS\system32\dllcache\rw330ext.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\sm90w.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\sm8dw.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\sm8aw.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\sm89w.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_seos.dll
2007-08-03 18:00 259,072 --a--c--- C:\WINDOWS\system32\dllcache\snmpcl.dll
2007-08-03 18:00 25,088 --a--c--- C:\WINDOWS\system32\dllcache\sm59w.dll
2007-08-03 18:00 24,576 --a--c--- C:\WINDOWS\system32\dllcache\rw001ext.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-03 23:30 --------- d-------- C:\Program Files\Google
2007-08-03 23:23 --------- d-------- C:\Program Files\MSN Messenger
2007-08-03 22:51 359040 --a--c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2007-08-03 22:51 359040 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2007-08-03 17:55 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-08-03 17:55 --------- d-------- C:\Program Files\Messenger
2007-07-24 21:59 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-10 20:30 --------- d-------- C:\Program Files\Avanquest update
2007-07-10 20:28 22768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys
2007-07-08 21:41 --------- d-------- C:\Program Files\iTunes
2007-07-02 20:41 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-02 20:41 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-06-20 17:30 --------- d-------- C:\Program Files\IVT Corporation
2007-06-12 15:45 --------- d-------- C:\Program Files\Windows Media Connect 2
2007-06-08 11:41 --------- d-------- C:\Program Files\Apple Software Update
2007-05-25 18:40 444 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-05-25 17:54 0 -rahs---- C:\MSDOS.SYS
2007-05-25 17:54 0 -rahs---- C:\IO.SYS
2007-05-25 17:54 0 --a------ C:\CONFIG.SYS
2007-05-25 17:54 0 --a------ C:\AUTOEXEC.BAT
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2264DEBB-85DF-4754-97C2-3DDB97C81E6F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 15:55]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 15:51]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-25 20:23]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-08-03 23:30:06]
R0 BTHidMgr;Bluetooth HID Manager Service;C:\WINDOWS\system32\Drivers\BTHidMgr.sys
R3 BT;Bluetooth PAN Network Adapter;C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
R3 BTHidEnum;Bluetooth HID Enumerator;C:\WINDOWS\system32\DRIVERS\vbtenum.sys
R3 USB_RNDIS;Thomson ST Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys
S3 BlueletAudio;Bluetooth Audio Service;C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
S3 Btcsrusb;Bluetooth USB For Bluetooth Service;C:\WINDOWS\system32\Drivers\btcusb.sys
S3 BTNetFilter;Bluetooth Network Filter;\??\C:\WINDOWS\system32\drivers\BTNetFilter.sys
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys
S3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32\Drivers\RootMdm.sys
S3 usbsermpt;Motorola USB Modem Driver for MPT;C:\WINDOWS\system32\DRIVERS\usbsermpt.sys
S3 VComm;Virtual Serial port driver;C:\WINDOWS\system32\DRIVERS\VComm.sys
S3 VcommMgr;Bluetooth VComm Manager Service;C:\WINDOWS\system32\Drivers\VcommMgr.sys
S3 VM30xx86;Vimicro USB PC Camera (ZC0301);C:\WINDOWS\system32\Drivers\vm30xx86.sys
Contents of the 'Scheduled Tasks' folder
2007-07-27 10:40:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-06 01:12:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-06 1:13:56 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-06 01:13
--- E O F ---
I am new to the forums and before I wasted anyone's time I have tried to fix the problem by reading other threads, but I' am still getting pop ups.. They have reduced in frequency but I have obviously not solved the problem. Also I am unable to install any updates for windows and some of my programmes wont launch as it is saying they are not installed. (Itunes and registry mechanic for instance)
I have downloaded Highjackthis and combofix and ATF cleaner I think it is. I have also recently installed AVG. S&D also keeps finding windows virus override I deleted it the first time but left it the last time I ran a search - I am unsure if this was the correct thing to do?
The other strange thing that is happening is my cookie settings keep defaulting back to "accept all" even when I change this back to medium?
Thank you in advance for any assistance you can offer me :)
logs to follow:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:25:12, on 8/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\highjackthis\scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {2264DEBB-85DF-4754-97C2-3DDB97C81E6F} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Windows Live OneCare (winss) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\winss.exe (file missing)
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
--
End of file - 3853 bytes
ComboFix 07-08-04.3 - "Shauna Holleran" 2007-08-06 0:28:52.1 [GMT 1:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.True
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Jacko\APPLIC~1\FunWebProducts
C:\DOCUME~1\Jacko\APPLIC~1\FunWebProducts\Data\Jacko\avatar.dat
C:\DOCUME~1\SHAUNA~1.SHO\MYDOCU~1.\fnts~1
C:\DOCUME~1\SHAUNA~1.SHO\MYDOCU~1.\sstem~1
C:\WINDOWS\system32\akmxmtmg.exe
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\byxuvuu.dll
C:\WINDOWS\system32\ddccy.dll
C:\WINDOWS\system32\dvctdmyq.exe
C:\WINDOWS\system32\eeyiamos.exe
C:\WINDOWS\system32\ehkbcudl.exe
C:\WINDOWS\system32\etnpmmin.exe
C:\WINDOWS\system32\etwykkcj.exe
C:\WINDOWS\system32\gjjlm.ini2
C:\WINDOWS\system32\gjjlm.tmp
C:\WINDOWS\system32\gsmosjeu.exe
C:\WINDOWS\system32\gyjhpnom.exe
C:\WINDOWS\system32\jskatapa.exe
C:\WINDOWS\system32\ljjkkhe.dll
C:\WINDOWS\system32\lowpdeqx.exe
C:\WINDOWS\system32\nfbhvbwm.exe
C:\WINDOWS\system32\nfpnlivn.dll
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\system32\nwcdtufx.exe
C:\WINDOWS\system32\olsbqdvc.exe
C:\WINDOWS\system32\pruxhcsa.exe
C:\WINDOWS\system32\qtibhusv.dll
C:\WINDOWS\system32\rflbvrjj.exe
C:\WINDOWS\system32\rlludflb.exe
C:\WINDOWS\system32\roegcnps.exe
C:\WINDOWS\system32\rrqlecei.exe
C:\WINDOWS\system32\rygtclbn.exe
C:\WINDOWS\system32\tpmxsdoi.exe
C:\WINDOWS\system32\vmlmxgfj.exe
C:\WINDOWS\system32\vvhtpxma.exe
C:\WINDOWS\system32\wctbrgke.exe
C:\WINDOWS\system32\xmlggivx.exe
C:\WINDOWS\system32\yccdd.bak1
C:\WINDOWS\system32\yccdd.bak2
C:\WINDOWS\system32\yccdd.ini
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 )))))))))))))))))))))))))))))))
2007-08-06 00:26 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-05 22:45 <DIR> d-------- C:\DOCUME~1\Jacko.SHO\Contacts
2007-08-05 12:11 125,504 --a------ C:\WINDOWS\system32\mckughuu.dll
2007-08-04 22:46 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-04 22:36 <DIR> d-------- C:\VundoFix Backups
2007-08-04 14:49 1,310,720 --ah----- C:\DOCUME~1\Guest.SHO\NTUSER.DAT
2007-08-04 14:22 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-08-04 14:07 <DIR> d-------- C:\{000039B2-0000-0000-ECE0-75F3478B6F0C}
2007-08-04 12:11 <DIR> d-------- C:\DOCUME~1\JACQUI~1.SHO\Contacts
2007-08-04 12:05 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-08-04 11:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
2007-08-04 11:18 <DIR> d-------- C:\DOCUME~1\Jacko.SHO\APPLIC~1\Google
2007-08-04 11:17 1,572,864 --ah----- C:\DOCUME~1\Jacko.SHO\NTUSER.DAT
2007-08-04 03:47 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-08-04 03:24 <DIR> d--hs---- C:\WINDOWS\CSC
2007-08-04 03:01 <DIR> d--hs---- C:\DOCUME~1\SHAUNA~1.SHO\UserData
2007-08-04 02:46 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-04 02:07 <DIR> d-------- C:\DOCUME~1\JACQUI~1.SHO\APPLIC~1\Google
2007-08-03 23:51 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Spybot - Search & Destroy
2007-08-03 23:31 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\APPLIC~1\Google
2007-08-03 23:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Google Updater
2007-08-03 23:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Google
2007-08-03 23:24 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\Contacts
2007-08-03 22:53 <DIR> d--hs---- C:\WINDOWS\U2hhdW5hIEhvbGxlcmFu
2007-08-03 22:50 <DIR> d-------- C:\Program Files\BitComet
2007-08-03 22:49 <DIR> d-------- C:\Program Files\BitTorrent
2007-08-03 22:49 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\APPLIC~1\BitTorrent
2007-08-03 21:58 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\APPLIC~1\Help
2007-08-03 20:16 <DIR> d-------- C:\WINDOWS\Prefetch
2007-08-03 20:13 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\TEMP
2007-08-03 20:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Apple Computer
2007-08-03 20:07 <DIR> d-------- C:\DOCUME~1\SHAUNA~1.SHO\APPLIC~1\Apple Computer
2007-08-03 20:00 <DIR> d-------- C:\WINDOWS\Thomson.0008
2007-08-03 19:53 3,407,872 --ah----- C:\DOCUME~1\SHAUNA~1.SHO\NTUSER.DAT
2007-08-03 18:05 <DIR> d-------- C:\DOCUME~1\JACQUI~1.SHO\APPLIC~1\Yahoo!
2007-08-03 18:03 159,744 --a------ C:\WINDOWS\system32\igfxres.dll
2007-08-03 18:03 1,835,008 --ah----- C:\DOCUME~1\JACQUI~1.SHO\NTUSER.DAT
2007-08-03 18:03 1,146,880 --ah----- C:\DOCUME~1\LOCALS~1.NTA\NTUSER.DAT
2007-08-03 18:02 1,146,880 --ah----- C:\DOCUME~1\NETWOR~1.NTA\NTUSER.DAT
2007-08-03 18:00 9,728 --a--c--- C:\WINDOWS\system32\dllcache\rwnh.dll
2007-08-03 18:00 9,728 --a--c--- C:\WINDOWS\system32\dllcache\query.exe
2007-08-03 18:00 9,216 --a--c--- C:\WINDOWS\system32\dllcache\wamps51.dll
2007-08-03 18:00 86,073 --a--c--- C:\WINDOWS\system32\dllcache\voicesub.dll
2007-08-03 18:00 8,704 --a--c--- C:\WINDOWS\system32\dllcache\snmptrap.exe
2007-08-03 18:00 79,872 --a--c--- C:\WINDOWS\system32\dllcache\rwia330.dll
2007-08-03 18:00 79,872 --a--c--- C:\WINDOWS\system32\dllcache\rwia001.dll
2007-08-03 18:00 76,800 --a--c--- C:\WINDOWS\system32\dllcache\wam51.dll
2007-08-03 18:00 76,288 --a--c--- C:\WINDOWS\system32\dllcache\uniime.dll
2007-08-03 18:00 73,728 --a--c--- C:\WINDOWS\system32\dllcache\w3ext.dll
2007-08-03 18:00 70,144 --a--c--- C:\WINDOWS\system32\dllcache\pintlphr.exe
2007-08-03 18:00 7,680 --a--c--- C:\WINDOWS\system32\dllcache\pwsdata.dll
2007-08-03 18:00 7,168 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_snprfdll.dll
2007-08-03 18:00 67,584 --a--c--- C:\WINDOWS\system32\dllcache\pmigrate.dll
2007-08-03 18:00 6,144 --a--c--- C:\WINDOWS\system32\dllcache\snmpmib.dll
2007-08-03 18:00 6,144 --a--c--- C:\WINDOWS\system32\dllcache\pmxgl.dll
2007-08-03 18:00 57,856 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_scripto.dll
2007-08-03 18:00 53,760 --a--c--- C:\WINDOWS\system32\dllcache\pintlcsd.dll
2007-08-03 18:00 53,248 --a--c--- C:\WINDOWS\system32\dllcache\wamreg51.dll
2007-08-03 18:00 53,248 --a--c--- C:\WINDOWS\system32\dllcache\nextlink.dll
2007-08-03 18:00 5,632 --a--c--- C:\WINDOWS\system32\dllcache\w3svapi.dll
2007-08-03 18:00 5,632 --a--c--- C:\WINDOWS\system32\dllcache\smimsgif.dll
2007-08-03 18:00 5,632 --a--c--- C:\WINDOWS\system32\dllcache\smierrsy.dll
2007-08-03 18:00 48,256 --a--c--- C:\WINDOWS\system32\dllcache\w32.dll
2007-08-03 18:00 46,592 --a--c--- C:\WINDOWS\system32\dllcache\svcext51.dll
2007-08-03 18:00 46,592 --a--c--- C:\WINDOWS\system32\dllcache\sspifilt.dll
2007-08-03 18:00 456,704 --a--c--- C:\WINDOWS\system32\dllcache\smtpsvc.dll
2007-08-03 18:00 455,168 --a--c--- C:\WINDOWS\system32\dllcache\tintsetp.exe
2007-08-03 18:00 45,056 --a--c--- C:\WINDOWS\system32\dllcache\ssinc51.dll
2007-08-03 18:00 44,544 --a--c--- C:\WINDOWS\system32\dllcache\nsepm.dll
2007-08-03 18:00 44,032 --a--c--- C:\WINDOWS\system32\dllcache\tintlphr.exe
2007-08-03 18:00 426,041 --a--c--- C:\WINDOWS\system32\dllcache\voicepad.dll
2007-08-03 18:00 41,600 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.dll
2007-08-03 18:00 40,448 --a--c--- C:\WINDOWS\system32\dllcache\snmpthrd.dll
2007-08-03 18:00 4,608 --a--c--- C:\WINDOWS\system32\dllcache\w3ctrs51.dll
2007-08-03 18:00 4,096 --a--c--- C:\WINDOWS\system32\dllcache\rpcref.dll
2007-08-03 18:00 38,912 --a--c--- C:\WINDOWS\system32\dllcache\sm9aw.dll
2007-08-03 18:00 38,912 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_ntfsdrv.dll
2007-08-03 18:00 363,520 --a--c--- C:\WINDOWS\system32\dllcache\w3svc.dll
2007-08-03 18:00 36,927 --a--c--- C:\WINDOWS\system32\dllcache\padrs411.dll
2007-08-03 18:00 358,400 --a--c--- C:\WINDOWS\system32\dllcache\snmpincl.dll
2007-08-03 18:00 32,768 --a--c--- C:\WINDOWS\system32\dllcache\snmp.exe
2007-08-03 18:00 31,744 --a--c--- C:\WINDOWS\system32\dllcache\smb6w.dll
2007-08-03 18:00 31,744 --a--c--- C:\WINDOWS\system32\dllcache\sma3w.dll
2007-08-03 18:00 31,744 --a--c--- C:\WINDOWS\system32\dllcache\pagecnt.dll
2007-08-03 18:00 31,232 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.sys
2007-08-03 18:00 31,232 --a--c--- C:\WINDOWS\system32\dllcache\tools.dll
2007-08-03 18:00 30,208 --a--c--- C:\WINDOWS\system32\dllcache\sm87w.dll
2007-08-03 18:00 30,208 --a--c--- C:\WINDOWS\system32\dllcache\sm81w.dll
2007-08-03 18:00 29,184 --a--c--- C:\WINDOWS\system32\dllcache\sm8cw.dll
2007-08-03 18:00 26,624 --a--c--- C:\WINDOWS\system32\dllcache\sm93w.dll
2007-08-03 18:00 26,624 --a--c--- C:\WINDOWS\system32\dllcache\sm92w.dll
2007-08-03 18:00 26,624 --a--c--- C:\WINDOWS\system32\dllcache\rw330ext.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\sm90w.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\sm8dw.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\sm8aw.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\sm89w.dll
2007-08-03 18:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_seos.dll
2007-08-03 18:00 259,072 --a--c--- C:\WINDOWS\system32\dllcache\snmpcl.dll
2007-08-03 18:00 25,088 --a--c--- C:\WINDOWS\system32\dllcache\sm59w.dll
2007-08-03 18:00 24,576 --a--c--- C:\WINDOWS\system32\dllcache\rw001ext.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-03 23:30 --------- d-------- C:\Program Files\Google
2007-08-03 23:23 --------- d-------- C:\Program Files\MSN Messenger
2007-08-03 22:51 359040 --a--c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2007-08-03 22:51 359040 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2007-08-03 17:55 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-08-03 17:55 --------- d-------- C:\Program Files\Messenger
2007-07-24 21:59 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-10 20:30 --------- d-------- C:\Program Files\Avanquest update
2007-07-10 20:28 22768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys
2007-07-08 21:41 --------- d-------- C:\Program Files\iTunes
2007-07-02 20:41 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-02 20:41 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-06-20 17:30 --------- d-------- C:\Program Files\IVT Corporation
2007-06-12 15:45 --------- d-------- C:\Program Files\Windows Media Connect 2
2007-06-08 11:41 --------- d-------- C:\Program Files\Apple Software Update
2007-05-25 18:40 444 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-05-25 17:54 0 -rahs---- C:\MSDOS.SYS
2007-05-25 17:54 0 -rahs---- C:\IO.SYS
2007-05-25 17:54 0 --a------ C:\CONFIG.SYS
2007-05-25 17:54 0 --a------ C:\AUTOEXEC.BAT
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2264DEBB-85DF-4754-97C2-3DDB97C81E6F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 15:55]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 15:51]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-25 20:23]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-08-03 23:30:06]
R0 BTHidMgr;Bluetooth HID Manager Service;C:\WINDOWS\system32\Drivers\BTHidMgr.sys
R3 BT;Bluetooth PAN Network Adapter;C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
R3 BTHidEnum;Bluetooth HID Enumerator;C:\WINDOWS\system32\DRIVERS\vbtenum.sys
R3 USB_RNDIS;Thomson ST Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys
S3 BlueletAudio;Bluetooth Audio Service;C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
S3 Btcsrusb;Bluetooth USB For Bluetooth Service;C:\WINDOWS\system32\Drivers\btcusb.sys
S3 BTNetFilter;Bluetooth Network Filter;\??\C:\WINDOWS\system32\drivers\BTNetFilter.sys
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI);C:\WINDOWS\system32\DRIVERS\rfcomm.sys
S3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32\Drivers\RootMdm.sys
S3 usbsermpt;Motorola USB Modem Driver for MPT;C:\WINDOWS\system32\DRIVERS\usbsermpt.sys
S3 VComm;Virtual Serial port driver;C:\WINDOWS\system32\DRIVERS\VComm.sys
S3 VcommMgr;Bluetooth VComm Manager Service;C:\WINDOWS\system32\Drivers\VcommMgr.sys
S3 VM30xx86;Vimicro USB PC Camera (ZC0301);C:\WINDOWS\system32\Drivers\vm30xx86.sys
Contents of the 'Scheduled Tasks' folder
2007-07-27 10:40:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-06 01:12:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-06 1:13:56 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-06 01:13
--- E O F ---