View Full Version : Virtumonde and IS 2010 Infection
I'm sorry for posting a (somewhat) duplicate thread. I had a major update to make on my current status and nobody has yet responded, so I figured it was a good idea to re-post, rather than reply to my current topic and potentially be passed over for help due to the non-zero replies.
The old topic:
http://forums.spybot.info/showthread.php?t=55193
Feel free to close this. I've quoted my original post from there, as it is now only a part of my problem.
"Virtumonde Infection"
Looks like quite a bit of it going around lately, eh? :/
Symptoms started showing up Thursday with unusual pop-up windows while I'm browsing. I decided to run an immediate scan with Spybot to see what was going on and, lo and behold, it detects a bunch of Virtumonde variants. It says to visit this forum for help... so here I am. :P
I reviewed the TeaTimer log and noted this...
1/27/2010 11:36:56 PM Allowed (based on user decision) value "{06498afd-da80-48d6-9811-8a7d67d46f48}" (new data: "") added in Browser Helper Object!
1/27/2010 11:37:32 PM Allowed (based on user decision) value "lepekusiju" (new data: "Rundll32.exe "jivukubu.dll",s") added in System Startup global entry!
...looking back at my browsing history seems to confirm that I probably picked up the virus exactly where I suspected. I don't visit the website in question often but it's always been clean to my knowledge. Bad luck this time, perhaps? :( (Yes, that's late-night Wednesday. Why I would've seen symptoms starting Thursday evening is because that's when I next used the computer!)
Anyway, I allowed Spybot to finish the scan. It said to restart and perform a scan on startup to remove what it couldn't at the time, so I obliged. I ran an AVG Free 9.0 complete scan immediately after the Spybot scan (before reboot) and it detected nothing. I shut down my computer and rebooted in Safe Mode to run Spybot again. It again detected the Virtumonde viruses and claimed to fix them. I shut down, rebooted normally and Spybot started its on-startup scan... again detecting Virtumonde and "fixing" them. I was out of town Saturday, so I ran Spybot once more... same thing. I started another AVG complete scan before leaving but I'm not sure of the results. (My mother used my computer while I was gone and presumably closed it without my permission.) I can only assume it found nothing, though.
At any rate, Spybot seems to continually re-find the infection every time I run it and I'm still getting the pop-ups. Currently, that seems to be the only obvious symptom. The pop-ups open through Internet Explorer but come up with a faux-Firefox icon, presumably because I'm browsing with Firefox.
Backup stored by ERUNT.
Here in my HJT log. Version 2.0.2 would not download, so I used Version 2.0.3 (Beta):
[snip]
The Update:
I was tinkering with TeaTimer and temporarily turned it off (in anticipation for receiving help and fixing this problem, I suppose). Just a moment ago, Internet Security 2010 appeared on my computer, an extremely pervasive rogue antivirus of which I've seen a few other topics in this forum about. My desktop image was hijacked and I am unable to open the Task Manager. I am very worried about it now. :(
I immediately turned TeaTimer back on, which informed me of some malicious "smss" software present and prompted me to kill the process (which I did). I did another Spybot scan, which got rid of some things and got my desktop wallpaper back, but my Task Manager still cannot be opened.
Perhaps I could revert to the ERUNT backup just before IS-2010 took over?
And here is a new HJT logfile:
Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 1:06:55 PM, on 1/31/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\Trend Micro\HijackThis\TrendMicro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5061206
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
F2 - REG:system.ini: Shell=Explorer.exe logon.exe
O2 - BHO: (no name) - {06498afd-da80-48d6-9811-8a7d67d46f48} - yejukuya.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [zuyivudeg] Rundll32.exe "c:\windows\system32\rumepopo.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
O15 - Trusted Zone: http://*.buy-internet-security10.com
O15 - Trusted Zone: http://*.is-soft-download.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.is-software-download25.com
O15 - Trusted Zone: http://*.buy-internet-security10.com (HKLM)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) - http://www.kungfuchess.com/activex/web665.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165960990742
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{651F9C10-8AD0-4011-A45A-299F4FFAEB1D}: NameServer = 83.149.115.157,4.2.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3}: NameServer = 83.149.115.157,4.2.2.1,192.168.0.1
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: c:\windows\system32\luhawimu.dll titubeve.dll c:\windows\system32\nosogumi.dll c:\windows\system32\rumepopo.dll c:\windows\system32\hemokelu.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O21 - SSODL: zabazejiz - {c1f3a6ba-6587-42d1-84a2-7d77b3550a67} - c:\windows\system32\luhawimu.dll (file missing)
O21 - SSODL: wuhagaloy - {c9a37c57-c898-4369-9c55-0e10a7672415} - c:\windows\system32\nosogumi.dll (file missing)
O21 - SSODL: zivedepok - {34ee8cd0-0645-45a6-b85d-6a603fe1e46b} - c:\windows\system32\rumepopo.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: tokatiluy - {c1f3a6ba-6587-42d1-84a2-7d77b3550a67} - c:\windows\system32\luhawimu.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {c9a37c57-c898-4369-9c55-0e10a7672415} - c:\windows\system32\nosogumi.dll (file missing)
O22 - SharedTaskScheduler: gahurihor - {34ee8cd0-0645-45a6-b85d-6a603fe1e46b} - c:\windows\system32\rumepopo.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 12139 bytes
Hi,
Download DDS and save it to your desktop from here (http://www.techsupportforum.com/sectools/sUBs/dds) or here (http://download.bleepingcomputer.com/sUBs/dds.scr) or here (http://www.forospyware.com/sUBs/dds).
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt
Save both reports to your desktop. Post them back to your topic.
Looks like I was able to get to the computer lab at school today after all. Thank you for replying, I'll be home around 5:30pm EST (~4.5 hours) to follow your instructions, from my infected home computer.
Alrighty, here I am and here are the logs generated by DDS.
DDS.txt:
DDS (Ver_09-12-01.01) - NTFSx86
Run by Mr.E at 17:29:35.10 on Thu 02/04/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.494 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mr.E\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
mWinlogon: Shell=Explorer.exe logon.exe
BHO: {06498afd-da80-48d6-9811-8a7d67d46f48} - yejukuya.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [zuyivudeg] Rundll32.exe "c:\windows\system32\habemoya.dll",a
mRunOnce: [Spybot - Search & Destroy] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck
mRunOnce: [SpybotDeletingA1980] command.com /c del "c:\windows\system32\titubeve.dll_old"
mRunOnce: [SpybotDeletingC6638] cmd.exe /c del "c:\windows\system32\titubeve.dll_old"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: buy-internet-security10.com
Trusted Zone: gelbooru.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is-software-download25.com
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165960990742
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: c:\windows\system32\ titubeve.dll c:\windows\system32\nosogumi.dll c:\windows\system32\rumepopo.dll c:\windows\system32\bujumuto.dll c:\windows\system32\habemoya.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: nuwegukat - {6c60a125-7af9-40ee-adb7-f2602e6c30e2} - c:\windows\system32\bujumuto.dll
SSODL: zufunizov - {c6885b7d-dd0b-4b99-9eeb-c6c2da5a3ff9} - c:\windows\system32\habemoya.dll
STS: kupuhivus: {6c60a125-7af9-40ee-adb7-f2602e6c30e2} - c:\windows\system32\bujumuto.dll
STS: kupuhivus: {c6885b7d-dd0b-4b99-9eeb-c6c2da5a3ff9} - c:\windows\system32\habemoya.dll
LSA: Notification Packages = kubu.dll rojerobe.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\mr.e\applic~1\mozilla\firefox\profiles\vy89qukg.mr.e\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-5 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-12-12 28424]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-28 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-12 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-12-22 93320]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [2006-5-3 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2006-5-3 8960]
=============== Created Last 30 ================
2010-02-02 06:02:03 1530 ----a-w- C:\Your PC Protector.lnk
2010-02-02 06:02:03 0 d-----w- C:\Your PC Protector
2010-02-02 05:01:27 0 d-----w- c:\program files\schtml
2010-02-02 04:57:05 958464 ----a-w- c:\program files\adc32.dll
2010-02-02 04:57:05 43520 ----a-w- c:\program files\alggui.exe
2010-02-02 04:56:57 56 ----a-w- c:\program files\wp4.dat
2010-02-02 04:56:57 37376 ----a-w- c:\program files\svchost.exe
2010-02-02 04:56:57 36 ----a-w- c:\program files\skynet.dat
2010-02-02 04:56:57 2 ----a-w- c:\program files\wp3.dat
2010-02-02 04:56:49 0 d-----w- c:\program files\Your PC Protector
2010-02-01 04:36:09 0 d-----w- c:\program files\Magic Workstation
2010-01-31 16:24:37 0 d-----w- c:\program files\InternetSecurity2010
2010-01-31 16:24:23 0 ----a-w- c:\windows\system32\41.exe
2010-01-31 14:32:57 0 d-----w- c:\program files\Trend Micro
2010-01-30 09:14:23 39424 --sh--w- c:\windows\system32\yaromido.dll
2010-01-25 23:54:56 0 d-----w- c:\program files\MSECache
2010-01-13 04:21:32 0 d--h--w- C:\$AVG
2010-01-13 04:20:43 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-01-13 02:31:03 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
==================== Find3M ====================
2010-02-02 04:57:01 9 ----a-w- c:\program files\nuar.old
2010-01-13 04:21:25 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21:25 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21:08 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-31 15:33:06 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-12-17 22:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\dikuyeji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\dulosopi.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\fapumoke.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\fedotaba.dll
1601-01-01 00:03:28 53760 --sha-w- c:\windows\system32\ganazohe.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\habemoya.dll
1601-01-01 00:03:28 21504 --sha-w- c:\windows\system32\halihupe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\hatasefa.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\kuveyuke.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\lakezado.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\lotikiwi.dll
1601-01-01 00:03:52 53760 --sha-w- c:\windows\system32\luduvibu.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\mihapulo.dll
1601-01-01 00:03:52 53760 --sha-w- c:\windows\system32\rojerobe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\sekihoki.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\selutanu.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\susalade.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\vaditujo.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\varapaji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\wukojohe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\zisapese.dll
2008-08-05 01:03:12 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008080420080805\index.dat
============= FINISH: 17:30:30.57 ===============
Attach.txt:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 12/11/2006 6:45:50 PM
System Uptime: 2/4/2010 3:56:52 AM (14 hours ago)
Motherboard: Dell Inc | | 0UW457
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ | Socket M2 | 2004/1000mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 144 GiB total, 57.837 GiB free.
D: is CDROM (CDFS)
E: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP298: 11/4/2009 12:50:08 AM - Installed Futuremark SystemInfo
RP299: 11/4/2009 2:27:34 PM - Software Distribution Service 3.0
RP300: 11/5/2009 2:33:16 PM - System Checkpoint
RP301: 11/6/2009 11:41:17 AM - Avg8 Update
RP302: 11/7/2009 12:33:12 PM - System Checkpoint
RP303: 11/8/2009 4:36:20 PM - System Checkpoint
RP304: 11/9/2009 7:29:49 PM - System Checkpoint
RP305: 11/11/2009 2:35:18 AM - System Checkpoint
RP306: 11/11/2009 5:04:05 PM - Software Distribution Service 3.0
RP307: 11/12/2009 8:37:03 PM - System Checkpoint
RP308: 11/13/2009 9:26:03 PM - System Checkpoint
RP309: 11/15/2009 6:42:10 AM - System Checkpoint
RP310: 11/16/2009 7:25:59 AM - System Checkpoint
RP311: 11/17/2009 8:25:58 AM - System Checkpoint
RP312: 11/18/2009 9:25:57 AM - System Checkpoint
RP313: 11/19/2009 10:25:57 AM - System Checkpoint
RP314: 11/20/2009 11:25:56 AM - System Checkpoint
RP315: 11/21/2009 12:33:11 PM - System Checkpoint
RP316: 11/22/2009 1:01:37 PM - System Checkpoint
RP317: 11/23/2009 1:25:52 PM - System Checkpoint
RP318: 11/24/2009 2:25:51 PM - System Checkpoint
RP319: 11/25/2009 10:58:24 AM - Avg8 Update
RP320: 11/25/2009 4:00:17 PM - Software Distribution Service 3.0
RP321: 11/26/2009 4:34:38 PM - System Checkpoint
RP322: 11/27/2009 4:39:45 PM - System Checkpoint
RP323: 11/28/2009 4:42:31 PM - System Checkpoint
RP324: 11/29/2009 5:28:01 PM - System Checkpoint
RP325: 11/30/2009 6:05:42 PM - System Checkpoint
RP326: 12/1/2009 9:23:48 PM - System Checkpoint
RP327: 12/2/2009 10:20:42 PM - System Checkpoint
RP328: 12/3/2009 11:24:25 PM - System Checkpoint
RP329: 12/5/2009 12:20:43 AM - System Checkpoint
RP330: 12/6/2009 5:10:15 AM - System Checkpoint
RP331: 12/7/2009 5:20:40 AM - System Checkpoint
RP332: 12/8/2009 6:20:43 AM - System Checkpoint
RP333: 12/9/2009 12:58:57 AM - Software Distribution Service 3.0
RP334: 12/9/2009 5:18:20 PM - Avg8 Update
RP335: 12/11/2009 3:42:38 AM - System Checkpoint
RP336: 12/11/2009 11:39:17 AM - Avg8 Update
RP337: 12/11/2009 11:40:02 AM - Avg8 Update
RP338: 12/12/2009 7:40:24 PM - System Checkpoint
RP339: 12/14/2009 2:02:26 AM - System Checkpoint
RP340: 12/15/2009 4:27:00 AM - System Checkpoint
RP341: 12/16/2009 5:19:15 AM - System Checkpoint
RP342: 12/17/2009 6:19:14 AM - System Checkpoint
RP343: 12/18/2009 7:19:12 AM - System Checkpoint
RP344: 12/19/2009 8:19:12 AM - System Checkpoint
RP345: 12/19/2009 4:00:19 PM - Software Distribution Service 3.0
RP346: 12/20/2009 10:15:20 PM - System Checkpoint
RP347: 12/22/2009 4:46:06 AM - Avg8 Update
RP348: 12/23/2009 5:06:50 AM - System Checkpoint
RP349: 12/24/2009 5:43:25 AM - System Checkpoint
RP350: 12/25/2009 9:37:25 PM - System Checkpoint
RP351: 12/27/2009 6:49:52 AM - System Checkpoint
RP352: 12/28/2009 7:18:27 AM - System Checkpoint
RP353: 12/28/2009 10:43:18 AM - Avg8 Update
RP354: 12/29/2009 11:18:23 AM - System Checkpoint
RP355: 12/30/2009 12:18:21 PM - System Checkpoint
RP356: 12/31/2009 1:18:21 PM - System Checkpoint
RP357: 1/1/2010 10:42:03 PM - System Checkpoint
RP358: 1/3/2010 7:30:17 AM - System Checkpoint
RP359: 1/4/2010 8:18:20 AM - System Checkpoint
RP360: 1/4/2010 10:52:20 AM - Avg8 Update
RP361: 1/5/2010 11:18:19 AM - System Checkpoint
RP362: 1/6/2010 12:18:15 PM - System Checkpoint
RP363: 1/7/2010 1:18:16 PM - System Checkpoint
RP364: 1/8/2010 2:18:17 PM - System Checkpoint
RP365: 1/10/2010 4:40:34 AM - System Checkpoint
RP366: 1/11/2010 5:18:14 AM - System Checkpoint
RP367: 1/12/2010 6:18:11 AM - System Checkpoint
RP368: 1/12/2010 9:38:02 PM - Software Distribution Service 3.0
RP369: 1/12/2010 11:20:28 PM - Installed AVG Free 9.0
RP370: 1/12/2010 11:35:30 PM - Avg8 Update
RP371: 1/14/2010 2:45:09 AM - System Checkpoint
RP372: 1/15/2010 3:25:50 AM - System Checkpoint
RP373: 1/16/2010 5:41:26 AM - System Checkpoint
RP374: 1/17/2010 6:52:26 AM - System Checkpoint
RP375: 1/18/2010 7:32:29 AM - System Checkpoint
RP376: 1/18/2010 9:58:24 AM - Avg8 Update
RP377: 1/21/2010 10:15:15 PM - Software Distribution Service 3.0
RP378: 1/23/2010 6:05:21 AM - System Checkpoint
RP379: 1/24/2010 7:36:08 AM - System Checkpoint
RP380: 1/25/2010 7:56:03 AM - System Checkpoint
RP381: 1/25/2010 6:55:17 PM - Installed Compatibility Pack for the 2007 Office system
RP382: 1/26/2010 11:21:37 PM - System Checkpoint
RP383: 1/27/2010 3:31:43 AM - Installed Java(TM) 6 Update 18
RP384: 1/27/2010 9:51:17 AM - Avg8 Update
RP385: 1/28/2010 11:01:01 AM - System Checkpoint
RP386: 1/29/2010 11:45:28 AM - System Checkpoint
RP387: 1/30/2010 11:54:48 AM - System Checkpoint
RP388: 1/31/2010 9:32:54 AM - Installed HiJackThis
RP389: 2/1/2010 10:34:29 AM - System Checkpoint
==== Installed Programs ======================
7-Zip 4.62
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 7.0.7
Adobe Reader 7.0.8
AIM 6
AiO_Scan_CDA
AiOSoftwareNPI
AOL Instant Messenger
AOL Uninstaller (Choose which Products to Remove)
AOLIcon
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Control Center
ATI Display Driver
AVG Free 9.0
Bioshock
Bonjour
Broadcom Management Programs
BufferChm
C4100
c4100_Help
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Continuum 0.40
Critical Update for Windows Media Player 11 (KB959772)
Dell CinePlayer
Dell Support 3.2.1
Dell System Restore
Destinations
DeviceManagementQFolder
Diablo II
Digital Content Portal
Digital Line Detect
DivX Content Uploader
DivX Web Player
DocProc
DocProcQFolder
Documentation & Support Launcher
DocumentViewer
DocumentViewerQFolder
Dofus-Arena
ERUNT 1.1j
eSupportQFolder
Fax_CDA
Games, Music, & Photos Launcher
GemMaster Mystic
Google Toolbar for Internet Explorer
Gunbound Revolution
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart, Officejet and Deskjet 7.0.A
HP Solution Center 7.0
HPPhotoSmartExpress
HPProductAssistant
ijji
ijji Auto Installer
ijji FireFox Launcher 1.0
InstantShareDevicesMFC
IrfanView (remove only)
iTunes
Java Auto Updater
Java(TM) 6 Update 18
Learn2 Player (Uninstall Only)
Logitech Print Service
Logitech QuickCam
Logitech® Camera Driver
Macromedia Shockwave Player
MapleStory
McAfee SiteAdvisor
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Small Business Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
mIRC
Modem Diagnostic Tool
Mozilla Firefox (3.5.7)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MultiRes (remove only)
NetBattle
NetWaiting
NewCopy_CDA
Nintendo Wi-Fi USB Connector Registration Tool
OCR Software by I.R.I.S 7.0
Otto
PanoStandAlone
PCmover
ProductContextNPI
PSP Video 9 2.25
QuickTime
Readme
RealPlayer
Road Runner Medic 5.4
RON Tool Adsoftinc
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
RPG Maker 2000 - #fftchallenge RPG
RTP for RM2K (Png, Wav, Midi, Fonts)
Scan
ScannerCopy
SearchAssist
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Shizmoo Web Games
Shoddy Battle
SolutionCenter
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SpywareBlaster 4.2
Starcraft
Status
Steam
System Requirements Lab
Team Fortress 2
Toolbox
TrayApp
Trillian
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
Ventrilo Client
WebFldrs XP
WebReg
WinAce Archiver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
World of Warcraft
World of Warcraft Public Test
XP Codec Pack
XviD MPEG-4 Video Codec
Yahoo! Messenger Explorer Bar
==== Event Viewer Messages From Past Week ========
2/2/2010 2:40:37 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McAfee SiteAdvisor Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
2/2/2010 2:39:46 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT nvatabus nvraid RasAcd Rdbss Tcpip WS2IFSL
1/31/2010 11:56:06 AM, error: ipnathlp [30013] - The DHCP allocator has disabled itself on IP address 192.168.1.1, since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, please change the scope to include the IP address, or change the IP address to fall within the scope.
1/31/2010 11:56:01 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: nvatabus nvraid
1/31/2010 11:55:32 AM, error: Print [23] - Printer hp deskjet 920c failed to initialize because a suitable hp deskjet 920c driver could not be found.
1/31/2010 11:55:32 AM, error: Print [23] - Printer hp deskjet 920c (Copy 1) failed to initialize because a suitable hp deskjet 920c driver could not be found.
1/31/2010 11:55:32 AM, error: Print [23] - Printer HP DeskJet 720C failed to initialize because a suitable HP DeskJet 720C driver could not be found.
1/31/2010 10:59:11 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
1/28/2010 12:26:04 AM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 1:40:19 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
1/28/2010 1:09:28 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT nvatabus nvraid RasAcd Rdbss Tcpip
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:23 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
==== End Of File ===========================
I noticed...
Trusted Zone: buy-internet-security10.com
Trusted Zone: gelbooru.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is-software-download25.com
...and manually deleted them from the Trusted Sites of my Internet Explorer settings. I'm not sure why gelbooru is listed since, even though it's legit, I don't use IE for browsing of any sort.
Hi,
Please visit this webpage for download links, and instructions for running ComboFix tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Please ensure you read this guide carefully first.
Please continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.
Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
New dds log.
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
ComboFix ComboFix Log:
ComboFix 10-02-05.01 - Mr.E 02/05/2010 15:47:51.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.562 [GMT -5:00]
Running from: c:\documents and settings\Mr.E\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Mr.E\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\program files\adc32.dll
c:\program files\alggui.exe
c:\program files\InternetSecurity2010
c:\program files\nuar.old
c:\program files\svchost.exe
c:\program files\wp3.dat
c:\program files\wp4.dat
c:\program files\Your PC Protector
c:\windows\kb913800.exe
c:\windows\system32\41.exe
c:\windows\system32\bebaroki.dll
c:\windows\system32\halihupe.dll
c:\windows\system32\rojerobe.dll
c:\windows\system32\yaromido.dll
c:\windows\Sysvxd.exe
c:\windows\unins000.dat
c:\windows\unins000.exe
----- BITS: Possible infected sites -----
hxxp://77.74.48.111
.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.
2010-02-02 06:02 . 2010-02-02 06:02 -------- d-----w- C:\Your PC Protector
2010-02-02 05:01 . 2010-02-02 07:31 -------- d-----w- c:\program files\schtml
2010-02-02 04:56 . 2010-02-02 04:57 36 ----a-w- c:\program files\skynet.dat
2010-02-01 04:36 . 2010-02-05 07:03 -------- d-----w- c:\program files\Magic Workstation
2010-01-31 14:32 . 2010-01-31 14:32 -------- d-----w- c:\program files\Trend Micro
2010-01-31 14:24 . 2010-01-31 14:25 -------- d-----w- c:\program files\ERUNT
2010-01-27 08:32 . 2010-01-27 08:32 -------- d-----w- c:\program files\Common Files\Java
2010-01-25 23:54 . 2010-01-25 23:54 -------- d-----w- c:\program files\MSECache
2010-01-13 04:21 . 2010-01-13 04:28 -------- d-----w- C:\$AVG
2010-01-13 04:20 . 2010-02-04 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-13 02:31 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 21:00 . 2008-07-27 19:22 -------- d-----w- c:\program files\Steam
2010-02-05 20:34 . 2006-12-12 11:34 -------- d-----w- c:\program files\mIRC
2010-02-05 06:42 . 2009-06-11 09:42 -------- d-----w- c:\program files\Wesnoth
2010-02-04 10:14 . 2006-12-07 00:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-04 10:11 . 2008-12-14 09:28 -------- d-----w- c:\program files\SpywareBlaster
2010-02-01 05:16 . 2006-12-07 00:29 78976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 16:52 . 2008-01-08 12:07 -------- d-----w- c:\program files\Trillian
2010-01-31 15:20 . 2006-12-12 11:57 -------- d-----w- c:\program files\NetBattle
2010-01-31 14:32 . 2010-01-31 14:32 388096 ----a-r- c:\documents and settings\Mr.E\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-27 08:32 . 2010-01-27 08:32 348160 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcr71.dll
2010-01-27 08:32 . 2010-01-27 08:32 61440 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-sse.dll
2010-01-27 08:32 . 2010-01-27 08:32 503808 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcp71.dll
2010-01-27 08:32 . 2010-01-27 08:32 499712 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\jmc.dll
2010-01-27 08:32 . 2010-01-27 08:32 12800 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-d3d.dll
2010-01-27 08:32 . 2009-03-11 20:44 -------- d-----w- c:\program files\Java
2010-01-18 14:58 . 2010-01-18 14:58 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-18 14:58 . 2010-01-13 04:35 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-13 04:35 . 2010-01-13 04:35 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-13 04:28 . 2008-12-23 04:20 -------- d-----w- c:\program files\McAfee
2010-01-13 04:21 . 2009-04-28 18:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21 . 2008-06-05 19:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21 . 2006-12-12 21:50 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-13 04:21 . 2008-06-05 19:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-13 04:21 . 2010-01-13 04:35 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-13 04:20 . 2010-01-13 04:35 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-13 04:20 . 2010-01-13 04:35 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-13 04:20 . 2010-01-13 04:35 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-13 04:20 . 2008-06-05 19:35 -------- d-----w- c:\program files\AVG
2010-01-05 10:00 . 2005-08-16 09:18 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-08-16 09:18 17408 ------w- c:\windows\system32\corpol.dll
2009-12-17 22:14 . 2008-12-14 08:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-21 15:51 . 2005-08-16 09:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\dikuyeji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\dulosopi.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\fapumoke.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\fedotaba.dll
1601-01-01 00:03 . 1601-01-01 00:03 53760 --sha-w- c:\windows\system32\ganazohe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\hatasefa.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\kuveyuke.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\lakezado.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\lotikiwi.dll
1601-01-01 00:03 . 1601-01-01 00:03 53760 --sha-w- c:\windows\system32\luduvibu.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\mihapulo.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\sekihoki.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\selutanu.dll
1601-01-01 00:03 . 1601-01-01 00:03 92672 --sha-w- c:\windows\system32\susalade.dll
1601-01-01 00:03 . 1601-01-01 00:03 92672 --sha-w- c:\windows\system32\vaditujo.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\varapaji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\vesujuji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\wukojohe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\zisapese.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1a45aee5-c4d2-407f-9a8c-5defddda9c1e}]
1601-01-01 00:03 53760 --sha-w- c:\windows\system32\luduvibu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-12-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-5-9 1073152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-13 04:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aim6.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/5/2008 2:35 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/28/2009 1:39 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/12/2010 11:20 PM 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/22/2008 11:21 PM 93320]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [5/3/2006 9:19 AM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [5/3/2006 9:19 AM 8960]
.
Contents of the 'Scheduled Tasks' folder
2010-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-06-02 20:31]
2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-02-11 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
FF - ProfilePath - c:\documents and settings\Mr.E\Application Data\Mozilla\Firefox\Profiles\vy89qukg.Mr.E\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\Mr.E\Local Settings\Application Data\{319C574E-35A9-4388-832A-88C8995655F5}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{06498afd-da80-48d6-9811-8a7d67d46f48} - yejukuya.dll
HKLM-Run-zuyivudeg - c:\windows\system32\bebaroki.dll
HKLM-Run-lepekusiju - rojerobe.dll
SharedTaskScheduler-{6c60a125-7af9-40ee-adb7-f2602e6c30e2} - c:\windows\system32\bujumuto.dll
SharedTaskScheduler-{31573857-ef41-4bb4-9719-0d57114051d3} - c:\windows\system32\bebaroki.dll
SSODL-nuwegukat-{6c60a125-7af9-40ee-adb7-f2602e6c30e2} - c:\windows\system32\bujumuto.dll
SSODL-gapefifes-{31573857-ef41-4bb4-9719-0d57114051d3} - c:\windows\system32\bebaroki.dll
AddRemove-gkctpvrqly - c:\windows\system32\gkctpvrqly.exe
AddRemove-NetBattle_is1 - c:\program files\NetBattle\unins001.exe
AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe
AddRemove-ijji.com - c:\ijji\ENGLISH\ijjiUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-05 16:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3364)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\stsystra.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\HPZipm12.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\eHome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-02-05 16:12:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-05 21:12
ComboFix2.txt 2008-12-17 20:16
Pre-Run: 61,955,387,392 bytes free
Post-Run: 61,655,736,320 bytes free
- - End Of File - - B90EEE6110388B7B55671282C35049EE
New DDS DDS.txt:
DDS (Ver_09-12-01.01) - NTFSx86
Run by Mr.E at 16:15:43.35 on Fri 02/05/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.344 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\HPZipm12.exe
svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mr.E\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: {1a45aee5-c4d2-407f-9a8c-5defddda9c1e} - luduvibu.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165960990742
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\mr.e\applic~1\mozilla\firefox\profiles\vy89qukg.mr.e\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-5 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-12-12 28424]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-28 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-12 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-12-22 93320]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [2006-5-3 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2006-5-3 8960]
=============== Created Last 30 ================
2010-02-05 20:46:56 98816 ----a-w- c:\windows\sed.exe
2010-02-05 20:46:56 77312 ----a-w- c:\windows\MBR.exe
2010-02-05 20:46:56 261632 ----a-w- c:\windows\PEV.exe
2010-02-05 20:46:56 161792 ----a-w- c:\windows\SWREG.exe
2010-02-02 06:02:03 1530 ----a-w- C:\Your PC Protector.lnk
2010-02-02 06:02:03 0 d-----w- C:\Your PC Protector
2010-02-02 05:01:27 0 d-----w- c:\program files\schtml
2010-02-02 04:56:57 36 ----a-w- c:\program files\skynet.dat
2010-02-01 04:36:09 0 d-----w- c:\program files\Magic Workstation
2010-01-31 14:32:57 0 d-----w- c:\program files\Trend Micro
2010-01-25 23:54:56 0 d-----w- c:\program files\MSECache
2010-01-13 04:21:32 0 d-----w- C:\$AVG
2010-01-13 04:20:43 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-01-13 02:31:03 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
==================== Find3M ====================
2010-01-13 04:21:25 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21:25 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21:08 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-31 15:33:06 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-12-17 22:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\dikuyeji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\dulosopi.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\fapumoke.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\fedotaba.dll
1601-01-01 00:03:28 53760 --sha-w- c:\windows\system32\ganazohe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\hatasefa.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\kuveyuke.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\lakezado.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\lotikiwi.dll
1601-01-01 00:03:52 53760 --sha-w- c:\windows\system32\luduvibu.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\mihapulo.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\sekihoki.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\selutanu.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\susalade.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\vaditujo.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\varapaji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\vesujuji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\wukojohe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\zisapese.dll
2008-08-05 01:03:12 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008080420080805\index.dat
============= FINISH: 16:16:16.13 ===============
New DDS Attach.txt:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 12/11/2006 6:45:50 PM
System Uptime: 2/5/2010 3:59:17 PM (1 hours ago)
Motherboard: Dell Inc | | 0UW457
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ | Socket M2 | 2004/1000mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 144 GiB total, 57.449 GiB free.
D: is CDROM (CDFS)
E: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP298: 11/4/2009 12:50:08 AM - Installed Futuremark SystemInfo
RP299: 11/4/2009 2:27:34 PM - Software Distribution Service 3.0
RP300: 11/5/2009 2:33:16 PM - System Checkpoint
RP301: 11/6/2009 11:41:17 AM - Avg8 Update
RP302: 11/7/2009 12:33:12 PM - System Checkpoint
RP303: 11/8/2009 4:36:20 PM - System Checkpoint
RP304: 11/9/2009 7:29:49 PM - System Checkpoint
RP305: 11/11/2009 2:35:18 AM - System Checkpoint
RP306: 11/11/2009 5:04:05 PM - Software Distribution Service 3.0
RP307: 11/12/2009 8:37:03 PM - System Checkpoint
RP308: 11/13/2009 9:26:03 PM - System Checkpoint
RP309: 11/15/2009 6:42:10 AM - System Checkpoint
RP310: 11/16/2009 7:25:59 AM - System Checkpoint
RP311: 11/17/2009 8:25:58 AM - System Checkpoint
RP312: 11/18/2009 9:25:57 AM - System Checkpoint
RP313: 11/19/2009 10:25:57 AM - System Checkpoint
RP314: 11/20/2009 11:25:56 AM - System Checkpoint
RP315: 11/21/2009 12:33:11 PM - System Checkpoint
RP316: 11/22/2009 1:01:37 PM - System Checkpoint
RP317: 11/23/2009 1:25:52 PM - System Checkpoint
RP318: 11/24/2009 2:25:51 PM - System Checkpoint
RP319: 11/25/2009 10:58:24 AM - Avg8 Update
RP320: 11/25/2009 4:00:17 PM - Software Distribution Service 3.0
RP321: 11/26/2009 4:34:38 PM - System Checkpoint
RP322: 11/27/2009 4:39:45 PM - System Checkpoint
RP323: 11/28/2009 4:42:31 PM - System Checkpoint
RP324: 11/29/2009 5:28:01 PM - System Checkpoint
RP325: 11/30/2009 6:05:42 PM - System Checkpoint
RP326: 12/1/2009 9:23:48 PM - System Checkpoint
RP327: 12/2/2009 10:20:42 PM - System Checkpoint
RP328: 12/3/2009 11:24:25 PM - System Checkpoint
RP329: 12/5/2009 12:20:43 AM - System Checkpoint
RP330: 12/6/2009 5:10:15 AM - System Checkpoint
RP331: 12/7/2009 5:20:40 AM - System Checkpoint
RP332: 12/8/2009 6:20:43 AM - System Checkpoint
RP333: 12/9/2009 12:58:57 AM - Software Distribution Service 3.0
RP334: 12/9/2009 5:18:20 PM - Avg8 Update
RP335: 12/11/2009 3:42:38 AM - System Checkpoint
RP336: 12/11/2009 11:39:17 AM - Avg8 Update
RP337: 12/11/2009 11:40:02 AM - Avg8 Update
RP338: 12/12/2009 7:40:24 PM - System Checkpoint
RP339: 12/14/2009 2:02:26 AM - System Checkpoint
RP340: 12/15/2009 4:27:00 AM - System Checkpoint
RP341: 12/16/2009 5:19:15 AM - System Checkpoint
RP342: 12/17/2009 6:19:14 AM - System Checkpoint
RP343: 12/18/2009 7:19:12 AM - System Checkpoint
RP344: 12/19/2009 8:19:12 AM - System Checkpoint
RP345: 12/19/2009 4:00:19 PM - Software Distribution Service 3.0
RP346: 12/20/2009 10:15:20 PM - System Checkpoint
RP347: 12/22/2009 4:46:06 AM - Avg8 Update
RP348: 12/23/2009 5:06:50 AM - System Checkpoint
RP349: 12/24/2009 5:43:25 AM - System Checkpoint
RP350: 12/25/2009 9:37:25 PM - System Checkpoint
RP351: 12/27/2009 6:49:52 AM - System Checkpoint
RP352: 12/28/2009 7:18:27 AM - System Checkpoint
RP353: 12/28/2009 10:43:18 AM - Avg8 Update
RP354: 12/29/2009 11:18:23 AM - System Checkpoint
RP355: 12/30/2009 12:18:21 PM - System Checkpoint
RP356: 12/31/2009 1:18:21 PM - System Checkpoint
RP357: 1/1/2010 10:42:03 PM - System Checkpoint
RP358: 1/3/2010 7:30:17 AM - System Checkpoint
RP359: 1/4/2010 8:18:20 AM - System Checkpoint
RP360: 1/4/2010 10:52:20 AM - Avg8 Update
RP361: 1/5/2010 11:18:19 AM - System Checkpoint
RP362: 1/6/2010 12:18:15 PM - System Checkpoint
RP363: 1/7/2010 1:18:16 PM - System Checkpoint
RP364: 1/8/2010 2:18:17 PM - System Checkpoint
RP365: 1/10/2010 4:40:34 AM - System Checkpoint
RP366: 1/11/2010 5:18:14 AM - System Checkpoint
RP367: 1/12/2010 6:18:11 AM - System Checkpoint
RP368: 1/12/2010 9:38:02 PM - Software Distribution Service 3.0
RP369: 1/12/2010 11:20:28 PM - Installed AVG Free 9.0
RP370: 1/12/2010 11:35:30 PM - Avg8 Update
RP371: 1/14/2010 2:45:09 AM - System Checkpoint
RP372: 1/15/2010 3:25:50 AM - System Checkpoint
RP373: 1/16/2010 5:41:26 AM - System Checkpoint
RP374: 1/17/2010 6:52:26 AM - System Checkpoint
RP375: 1/18/2010 7:32:29 AM - System Checkpoint
RP376: 1/18/2010 9:58:24 AM - Avg8 Update
RP377: 1/21/2010 10:15:15 PM - Software Distribution Service 3.0
RP378: 1/23/2010 6:05:21 AM - System Checkpoint
RP379: 1/24/2010 7:36:08 AM - System Checkpoint
RP380: 1/25/2010 7:56:03 AM - System Checkpoint
RP381: 1/25/2010 6:55:17 PM - Installed Compatibility Pack for the 2007 Office system
RP382: 1/26/2010 11:21:37 PM - System Checkpoint
RP383: 1/27/2010 3:31:43 AM - Installed Java(TM) 6 Update 18
RP384: 1/27/2010 9:51:17 AM - Avg8 Update
RP385: 1/28/2010 11:01:01 AM - System Checkpoint
RP386: 1/29/2010 11:45:28 AM - System Checkpoint
RP387: 1/30/2010 11:54:48 AM - System Checkpoint
RP388: 1/31/2010 9:32:54 AM - Installed HiJackThis
RP389: 2/1/2010 10:34:29 AM - System Checkpoint
==== Installed Programs ======================
7-Zip 4.62
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 7.0.7
Adobe Reader 7.0.8
AIM 6
AiO_Scan_CDA
AiOSoftwareNPI
AOL Instant Messenger
AOL Uninstaller (Choose which Products to Remove)
AOLIcon
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Control Center
ATI Display Driver
AVG Free 9.0
Bioshock
Bonjour
Broadcom Management Programs
BufferChm
C4100
c4100_Help
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Continuum 0.40
Critical Update for Windows Media Player 11 (KB959772)
Dell CinePlayer
Dell Support 3.2.1
Dell System Restore
Destinations
DeviceManagementQFolder
Diablo II
Digital Content Portal
Digital Line Detect
DivX Content Uploader
DivX Web Player
DocProc
DocProcQFolder
Documentation & Support Launcher
DocumentViewer
DocumentViewerQFolder
Dofus-Arena
ERUNT 1.1j
eSupportQFolder
Fax_CDA
Games, Music, & Photos Launcher
GemMaster Mystic
Google Toolbar for Internet Explorer
Gunbound Revolution
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart, Officejet and Deskjet 7.0.A
HP Solution Center 7.0
HPPhotoSmartExpress
HPProductAssistant
ijji Auto Installer
ijji FireFox Launcher 1.0
InstantShareDevicesMFC
IrfanView (remove only)
iTunes
Java Auto Updater
Java(TM) 6 Update 18
Learn2 Player (Uninstall Only)
Logitech Print Service
Logitech QuickCam
Logitech® Camera Driver
Macromedia Shockwave Player
MapleStory
McAfee SiteAdvisor
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Small Business Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
mIRC
Modem Diagnostic Tool
Mozilla Firefox (3.5.7)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MultiRes (remove only)
NetWaiting
NewCopy_CDA
Nintendo Wi-Fi USB Connector Registration Tool
OCR Software by I.R.I.S 7.0
Otto
PanoStandAlone
PCmover
ProductContextNPI
PSP Video 9 2.25
QuickTime
Readme
RealPlayer
Road Runner Medic 5.4
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
RPG Maker 2000 - #fftchallenge RPG
RTP for RM2K (Png, Wav, Midi, Fonts)
Scan
ScannerCopy
SearchAssist
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Shizmoo Web Games
Shoddy Battle
SolutionCenter
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
Spybot - Search & Destroy
SpywareBlaster 4.2
Starcraft
Status
Steam
System Requirements Lab
Team Fortress 2
Toolbox
TrayApp
Trillian
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
Ventrilo Client
WebFldrs XP
WebReg
WinAce Archiver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
World of Warcraft
World of Warcraft Public Test
XP Codec Pack
XviD MPEG-4 Video Codec
Yahoo! Messenger Explorer Bar
==== Event Viewer Messages From Past Week ========
2/5/2010 3:54:35 PM, error: PlugPlayManager [11] - The device Root\LEGACY_GMER\0000 disappeared from the system without first being prepared for removal.
2/5/2010 3:45:44 PM, error: Service Control Manager [7031] - The AVG Free WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
2/2/2010 2:40:37 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McAfee SiteAdvisor Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
2/2/2010 2:39:46 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT nvatabus nvraid RasAcd Rdbss Tcpip WS2IFSL
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/2/2010 2:39:43 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
2/2/2010 1:30:16 AM, error: ipnathlp [30013] - The DHCP allocator has disabled itself on IP address 192.168.1.1, since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, please change the scope to include the IP address, or change the IP address to fall within the scope.
2/2/2010 1:30:14 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: nvatabus nvraid
2/2/2010 1:29:44 AM, error: Print [23] - Printer hp deskjet 920c failed to initialize because a suitable hp deskjet 920c driver could not be found.
2/2/2010 1:29:44 AM, error: Print [23] - Printer hp deskjet 920c (Copy 1) failed to initialize because a suitable hp deskjet 920c driver could not be found.
2/2/2010 1:29:44 AM, error: Print [23] - Printer HP DeskJet 720C failed to initialize because a suitable HP DeskJet 720C driver could not be found.
1/31/2010 10:59:11 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
==== End Of File ===========================
Hi,
Please download Malwarebytes' Anti-Malware (http://www.besttechie.net/tools/mbam-setup.exe) to your desktop.
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Please post contents of that file in your next reply.
I downloaded MBAM, updated, and was in the middle of the Quick Scan when it suddenly stop running and closed itself.
I tried to restart it but Windows said mbam.exe doesn't exist. I went to Control Panel and uninstalled it using Add/Remove Programs. I was prompted to restart the computer to complete uninstallation, so I rebooted.
I downloaded MBAM again, started installing it, and while it was downloading the update it closed. An error window popped up:
[Setup]
Unable to execute file:
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
CreateProcess failed; code 2.
The system cannot find the file specified.
The error window popped up twice and, again, the MBAM program has completely disappeared from the computer.
OK. Please run ComboFix again and post back its log.
Got snowed in out of town last night and just got home, heh. ;o
I started up ComboFix and, as it started to run, it said there was a new update available and asked if I wanted to update. Afraid it was some sort of trick by the virus to make it disable it, I closed out of ComboFix and redownloaded it from bleepingcomputer.com myself just in case.
The new install of ComboFix would not run. I restarted in Safe Mode and ran the old install of ComboFix. When it was finished, it rebooted my computer in normal operation and TeaTimer came back on by itself too.
So here is the new [ComboFix log:
ComboFix 10-02-05.01 - Mr.E 02/06/2010 15:10:58.5.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.769 [GMT -5:00]
Running from: c:\documents and settings\Mr.E\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\napuruya.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-06 to 2010-02-06 )))))))))))))))))))))))))))))))
.
2010-02-05 23:21 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-05 23:21 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\Mr.E\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-02 06:02 . 2010-02-02 06:02 -------- d-----w- C:\Your PC Protector
2010-02-02 05:01 . 2010-02-02 07:31 -------- d-----w- c:\program files\schtml
2010-02-02 04:56 . 2010-02-02 04:57 36 ----a-w- c:\program files\skynet.dat
2010-02-01 04:36 . 2010-02-05 07:03 -------- d-----w- c:\program files\Magic Workstation
2010-01-31 14:32 . 2010-01-31 14:32 388096 ----a-r- c:\documents and settings\Mr.E\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-31 14:32 . 2010-01-31 14:32 -------- d-----w- c:\program files\Trend Micro
2010-01-31 14:24 . 2010-01-31 14:25 -------- d-----w- c:\program files\ERUNT
2010-01-27 08:32 . 2010-01-27 08:32 -------- d-----w- c:\program files\Common Files\Java
2010-01-27 08:32 . 2010-01-27 08:32 348160 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcr71.dll
2010-01-27 08:32 . 2010-01-27 08:32 61440 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-sse.dll
2010-01-27 08:32 . 2010-01-27 08:32 503808 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcp71.dll
2010-01-27 08:32 . 2010-01-27 08:32 499712 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\jmc.dll
2010-01-27 08:32 . 2010-01-27 08:32 12800 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-d3d.dll
2010-01-25 23:54 . 2010-01-25 23:54 -------- d-----w- c:\program files\MSECache
2010-01-18 14:58 . 2010-01-18 14:58 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-13 04:35 . 2010-01-18 14:58 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-13 04:35 . 2010-01-13 04:20 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-13 04:35 . 2010-01-13 04:20 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-13 04:35 . 2010-01-13 04:21 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-13 04:35 . 2010-01-13 04:20 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-13 04:35 . 2010-01-13 04:35 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-13 04:21 . 2010-01-13 04:28 -------- d-----w- C:\$AVG
2010-01-13 04:20 . 2010-02-04 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-13 02:31 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-06 20:21 . 2008-07-27 19:22 -------- d-----w- c:\program files\Steam
2010-02-06 16:36 . 2009-05-02 20:49 124 ----a-w- c:\documents and settings\Mr.E\Application Data\wklnhst.dat
2010-02-05 23:12 . 2008-01-08 12:07 -------- d-----w- c:\program files\Trillian
2010-02-05 23:11 . 2006-12-12 11:34 -------- d-----w- c:\program files\mIRC
2010-02-05 06:42 . 2009-06-11 09:42 -------- d-----w- c:\program files\Wesnoth
2010-02-04 10:14 . 2006-12-07 00:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-04 10:11 . 2008-12-14 09:28 -------- d-----w- c:\program files\SpywareBlaster
2010-02-01 05:16 . 2006-12-07 00:29 78976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 15:20 . 2006-12-12 11:57 -------- d-----w- c:\program files\NetBattle
2010-01-27 08:32 . 2009-03-11 20:44 -------- d-----w- c:\program files\Java
2010-01-13 04:28 . 2008-12-23 04:20 -------- d-----w- c:\program files\McAfee
2010-01-13 04:21 . 2009-04-28 18:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21 . 2008-06-05 19:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21 . 2006-12-12 21:50 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-13 04:21 . 2008-06-05 19:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-13 04:20 . 2008-06-05 19:35 -------- d-----w- c:\program files\AVG
2010-01-05 10:00 . 2005-08-16 09:18 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-08-16 09:18 17408 ------w- c:\windows\system32\corpol.dll
2009-12-17 22:14 . 2008-12-14 08:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-21 15:51 . 2005-08-16 09:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\dikuyeji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\dulosopi.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\fapumoke.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\fedotaba.dll
1601-01-01 00:03 . 1601-01-01 00:03 53760 --sha-w- c:\windows\system32\ganazohe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\hatasefa.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\kuveyuke.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\lakezado.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\lotikiwi.dll
1601-01-01 00:03 . 1601-01-01 00:03 53760 --sha-w- c:\windows\system32\luduvibu.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\mihapulo.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\parahuri.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\sekihoki.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\sekikawe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\selutanu.dll
1601-01-01 00:03 . 1601-01-01 00:03 92672 --sha-w- c:\windows\system32\susalade.dll
1601-01-01 00:03 . 1601-01-01 00:03 92672 --sha-w- c:\windows\system32\vaditujo.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\varapaji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\vesujuji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\wukojohe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\zisapese.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1a45aee5-c4d2-407f-9a8c-5defddda9c1e}]
1601-01-01 00:03 53760 --sha-w- c:\windows\system32\luduvibu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"zuyivudeg"="c:\windows\system32\napuruya.dll" [BU]
"lepekusiju"="rojerobe.dll" [BU]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-12-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-5-9 1073152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-13 04:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aim6.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/5/2008 2:35 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/28/2009 1:39 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/12/2010 11:20 PM 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/22/2008 11:21 PM 93320]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [5/3/2006 9:19 AM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [5/3/2006 9:19 AM 8960]
.
Contents of the 'Scheduled Tasks' folder
2010-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-06-02 20:31]
2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-02-11 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
FF - ProfilePath - c:\documents and settings\Mr.E\Application Data\Mozilla\Firefox\Profiles\vy89qukg.Mr.E\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\Mr.E\Local Settings\Application Data\{319C574E-35A9-4388-832A-88C8995655F5}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{06498afd-da80-48d6-9811-8a7d67d46f48} - (no file)
SharedTaskScheduler-{eaf453f0-faa5-4afd-8ff2-55ba42304270} - c:\windows\system32\napuruya.dll
SSODL-negaminiv-{eaf453f0-faa5-4afd-8ff2-55ba42304270} - c:\windows\system32\napuruya.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-06 15:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(964)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\stsystra.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\HPZipm12.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\eHome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-02-06 15:29:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-06 20:29
ComboFix2.txt 2010-02-05 21:12
ComboFix3.txt 2008-12-17 20:16
Pre-Run: 62,620,733,440 bytes free
Post-Run: 61,530,468,352 bytes free
- - End Of File - - E6BE3F0B5E1F01FE0FFD6340CCB16B65
Hi again,
Got snowed in out of town last night and just got home, heh. ;o
Doesn't sound nice. Anyway, glad you got back :)
Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
Run Spybot-S&D in Advanced Mode
If it is not already set to do this, go to the Mode menu
select
Advanced Mode
On the left hand side, click on Tools
Then click on the Resident icon in the list
Uncheck
Resident TeaTimer
and OK any prompts.
Restart your computer
Open notepad and copy/paste the text in the quotebox below into it:
DDS::
BHO: {1a45aee5-c4d2-407f-9a8c-5defddda9c1e} - luduvibu.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
Firefox::
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}
File::
C:\Your PC Protector.lnk
c:\program files\skynet.dat
c:\windows\system32\dikuyeji.dll
c:\windows\system32\dulosopi.dll
c:\windows\system32\fapumoke.dll
c:\windows\system32\fedotaba.dll
c:\windows\system32\ganazohe.dll
c:\windows\system32\hatasefa.dll
c:\windows\system32\kuveyuke.dll
c:\windows\system32\lakezado.dll
c:\windows\system32\lotikiwi.dll
c:\windows\system32\luduvibu.dll
c:\windows\system32\mihapulo.dll
c:\windows\system32\sekihoki.dll
c:\windows\system32\selutanu.dll
c:\windows\system32\susalade.dll
c:\windows\system32\vaditujo.dll
c:\windows\system32\varapaji.dll
c:\windows\system32\vesujuji.dll
c:\windows\system32\wukojohe.dll
c:\windows\system32\zisapese.dll
Folder::
C:\Your PC Protector
c:\program files\schtml
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"zuyivudeg"=-
"lepekusiju"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"KernelFaultCheck"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000
Save this as
CFScript
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
Uninstall old Adobe Reader versions and get the latest one (9.3) here (http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows) or get Foxit Reader here (http://www.foxitsoftware.com/pdf/reader_2/down_reader.htm). Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here (http://pdfreaders.org/).
Uninstall your current Macromedia Shockwave Player and get the fresh one here (http://get.adobe.com/shockwave/) if needed.
Uninstall vulnerable Flash versions by following instructions here (http://kb2.adobe.com/cps/141/tn_14157.html). Fresh version can be obtained here (http://get.adobe.com/flashplayer/).
Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.
Double-click ATF Cleaner.exe to open it
Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.
If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
Click Exit on the Main menu to close the program.
Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).
Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
1) TeaTimer disabled. Don't worry, I remembered to do that previously too!
2) Restarted computer.
3) CFScript copied into Notepad and ComboFix ran with the given script. LOG BELOW. After ComboFix rebooted the computer, a Windows Security Alert showed up in the taskbar. It popped up a couple warnings at me because the firewall and my antivirus (AVG) was turned off.
4) Turned TeaTimer back on.
5) Adobe 7.0.7 and Adobe 7.0.8 removed. Downloaded the latest version (9.3).
6) Macromedia Shockwave Player could not be removed via Add or Remove Programs, kept getting an error message about WISE UNINSTALLER. I was able to remove it using the Uninstaller from the Adobe site. Downloaded the latest version (11.5.6.606).
7) Downloaded the Flash Player uninstaller and ran it... then I remembered to close Firefox and ran it again, just in case. It said two of the elements would be deleted on computer restart. I did not reboot yet. Downloaded the latest version (10.0.42.34).
8) Downloaded ATF Cleaner and ran it. Empty Selected from Main and freed up 26.xxx MB. Empty Selected from Firefox (Select All, clicked NO to keep saved passwords) and freed up 62.xxx MB.
9) Kaspersky Online Scanner ran as instructed by the picture. Wow, that took a long time. :( LOG BELOW.
10) Ran DDS and saved both DDS.txt and Attach.txt. LOG BELOW.
...And that's it I think! Here you go.
Going in chronological order, ComboFix Log first:
ComboFix 10-02-05.01 - Mr.E 02/06/2010 19:00:25.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.401 [GMT -5:00]
Running from: c:\documents and settings\Mr.E\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mr.E\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"c:\program files\skynet.dat"
"c:\windows\system32\dikuyeji.dll"
"c:\windows\system32\dulosopi.dll"
"c:\windows\system32\fapumoke.dll"
"c:\windows\system32\fedotaba.dll"
"c:\windows\system32\ganazohe.dll"
"c:\windows\system32\hatasefa.dll"
"c:\windows\system32\kuveyuke.dll"
"c:\windows\system32\lakezado.dll"
"c:\windows\system32\lotikiwi.dll"
"c:\windows\system32\luduvibu.dll"
"c:\windows\system32\mihapulo.dll"
"c:\windows\system32\sekihoki.dll"
"c:\windows\system32\selutanu.dll"
"c:\windows\system32\susalade.dll"
"c:\windows\system32\vaditujo.dll"
"c:\windows\system32\varapaji.dll"
"c:\windows\system32\vesujuji.dll"
"c:\windows\system32\wukojohe.dll"
"c:\windows\system32\zisapese.dll"
"C:\Your PC Protector.lnk"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\chrome.manifest
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\chrome\content\_cfg.js
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\chrome\content\c.js
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\chrome\content\overlay.xul
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\install.rdf
c:\program files\schtml
c:\program files\schtml\dbsinit.exe
c:\program files\schtml\images\i1.gif
c:\program files\schtml\images\i2.gif
c:\program files\schtml\images\i3.gif
c:\program files\schtml\images\j1.gif
c:\program files\schtml\images\j2.gif
c:\program files\schtml\images\j3.gif
c:\program files\schtml\images\jj1.gif
c:\program files\schtml\images\jj2.gif
c:\program files\schtml\images\jj3.gif
c:\program files\schtml\images\l1.gif
c:\program files\schtml\images\l2.gif
c:\program files\schtml\images\l3.gif
c:\program files\schtml\images\pix.gif
c:\program files\schtml\images\t1.gif
c:\program files\schtml\images\t2.gif
c:\program files\schtml\images\Thumbs.db
c:\program files\schtml\images\up1.gif
c:\program files\schtml\images\up2.gif
c:\program files\schtml\images\w1.gif
c:\program files\schtml\images\w11.gif
c:\program files\schtml\images\w2.gif
c:\program files\schtml\images\w3.gif
c:\program files\schtml\images\w3.jpg
c:\program files\schtml\images\word.doc
c:\program files\schtml\images\wt1.gif
c:\program files\schtml\images\wt2.gif
c:\program files\schtml\images\wt3.gif
c:\program files\schtml\wispex.html
c:\program files\skynet.dat
c:\windows\system32\dikuyeji.dll
c:\windows\system32\dulosopi.dll
c:\windows\system32\fapumoke.dll
c:\windows\system32\fedotaba.dll
c:\windows\system32\ganazohe.dll
c:\windows\system32\hatasefa.dll
c:\windows\system32\kuveyuke.dll
c:\windows\system32\lakezado.dll
c:\windows\system32\lotikiwi.dll
c:\windows\system32\luduvibu.dll
c:\windows\system32\mihapulo.dll
c:\windows\system32\sekihoki.dll
c:\windows\system32\selutanu.dll
c:\windows\system32\susalade.dll
c:\windows\system32\vaditujo.dll
c:\windows\system32\varapaji.dll
c:\windows\system32\vesujuji.dll
c:\windows\system32\wukojohe.dll
c:\windows\system32\zisapese.dll
C:\Your PC Protector
C:\Your PC Protector.lnk
c:\your pc protector\Your PC Protector.lnk
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_W32TIME
-------\Service_w32time
((((((((((((((((((((((((( Files Created from 2010-01-07 to 2010-02-07 )))))))))))))))))))))))))))))))
.
2010-02-05 23:21 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-05 23:21 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\Mr.E\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 04:36 . 2010-02-05 07:03 -------- d-----w- c:\program files\Magic Workstation
2010-01-31 14:32 . 2010-01-31 14:32 388096 ----a-r- c:\documents and settings\Mr.E\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-31 14:32 . 2010-01-31 14:32 -------- d-----w- c:\program files\Trend Micro
2010-01-31 14:24 . 2010-01-31 14:25 -------- d-----w- c:\program files\ERUNT
2010-01-27 08:32 . 2010-01-27 08:32 -------- d-----w- c:\program files\Common Files\Java
2010-01-27 08:32 . 2010-01-27 08:32 348160 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcr71.dll
2010-01-27 08:32 . 2010-01-27 08:32 61440 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-sse.dll
2010-01-27 08:32 . 2010-01-27 08:32 503808 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcp71.dll
2010-01-27 08:32 . 2010-01-27 08:32 499712 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\jmc.dll
2010-01-27 08:32 . 2010-01-27 08:32 12800 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-d3d.dll
2010-01-25 23:54 . 2010-01-25 23:54 -------- d-----w- c:\program files\MSECache
2010-01-18 14:58 . 2010-01-18 14:58 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-13 04:35 . 2010-01-18 14:58 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-13 04:35 . 2010-01-13 04:20 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-13 04:35 . 2010-01-13 04:20 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-13 04:35 . 2010-01-13 04:21 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-13 04:35 . 2010-01-13 04:20 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-13 04:35 . 2010-01-13 04:35 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-13 04:21 . 2010-01-13 04:28 -------- d-----w- C:\$AVG
2010-01-13 04:20 . 2010-02-04 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-13 02:31 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 00:12 . 2008-07-27 19:22 -------- d-----w- c:\program files\Steam
2010-02-06 23:53 . 2008-01-08 12:07 -------- d-----w- c:\program files\Trillian
2010-02-06 23:50 . 2006-12-12 11:34 -------- d-----w- c:\program files\mIRC
2010-02-06 20:37 . 2006-12-07 00:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-06 20:37 . 2008-12-14 09:28 -------- d-----w- c:\program files\SpywareBlaster
2010-02-06 16:36 . 2009-05-02 20:49 124 ----a-w- c:\documents and settings\Mr.E\Application Data\wklnhst.dat
2010-02-05 06:42 . 2009-06-11 09:42 -------- d-----w- c:\program files\Wesnoth
2010-02-01 05:16 . 2006-12-07 00:29 78976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 15:20 . 2006-12-12 11:57 -------- d-----w- c:\program files\NetBattle
2010-01-27 08:32 . 2009-03-11 20:44 -------- d-----w- c:\program files\Java
2010-01-13 04:28 . 2008-12-23 04:20 -------- d-----w- c:\program files\McAfee
2010-01-13 04:21 . 2009-04-28 18:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21 . 2008-06-05 19:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21 . 2006-12-12 21:50 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-13 04:21 . 2008-06-05 19:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-13 04:20 . 2008-06-05 19:35 -------- d-----w- c:\program files\AVG
2010-01-05 10:00 . 2005-08-16 09:18 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-08-16 09:18 17408 ------w- c:\windows\system32\corpol.dll
2009-12-17 22:14 . 2008-12-14 08:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-21 15:51 . 2005-08-16 09:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\parahuri.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\sekikawe.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-12-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-5-9 1073152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-13 04:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
"lepekusiju"=Rundll32.exe "rojerobe.dll",s
"zuyivudeg"=Rundll32.exe "c:\windows\system32\napuruya.dll",a
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/5/2008 2:35 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/28/2009 1:39 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/12/2010 11:20 PM 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/22/2008 11:21 PM 93320]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [5/3/2006 9:19 AM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [5/3/2006 9:19 AM 8960]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
FastUserSwitchingCompatibility
HidServ
LanmanServer
LanmanWorkstation
Messenger
Nla
NWCWorkstation
Schedule
Seclogon
SRService
Themes
TrkWks
Wmi
WmdmPmSp
winmgmt
wscsvc
xmlprov
MHN
BITS
wuauserv
ShellHWDetection
helpsvc
napagent
hkmsvc
.
Contents of the 'Scheduled Tasks' folder
2010-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-06-02 20:31]
2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-02-11 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
FF - ProfilePath - c:\documents and settings\Mr.E\Application Data\Mozilla\Firefox\Profiles\vy89qukg.Mr.E\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{06498afd-da80-48d6-9811-8a7d67d46f48} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-06 19:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2572)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\stsystra.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-02-06 19:18:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-07 00:18
ComboFix2.txt 2010-02-06 20:29
ComboFix3.txt 2010-02-05 21:12
ComboFix4.txt 2008-12-17 20:16
Pre-Run: 61,772,849,152 bytes free
Post-Run: 61,738,446,848 bytes free
- - End Of File - - 1C7904DEF87C6BFFBCFB0EF86619A6D8
Kaspersky Report:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, February 6, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, February 07, 2010 01:19:21
Records in database: 3442979
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
Scan statistics:
Objects scanned: 144351
Threats found: 2
Infected objects found: 19
Suspicious objects found: 0
Scan duration: 03:07:25
File name / Threat / Threats count
C:\Documents and Settings\Mr.E\My Documents\My Received Files\Backup.ace Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\rojerobe.dll.vir Infected: Packed.Win32.TDSS.aa 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\yaromido.dll.vir Infected: Packed.Win32.TDSS.aa 1
C:\Qoobox\Quarantine\[4]-Submit_2010-02-06_18.59.59.zip Infected: Packed.Win32.TDSS.aa 10
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP389\A0052404.dll Infected: Packed.Win32.TDSS.aa 1
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP389\A0052537.dll Infected: Packed.Win32.TDSS.aa 1
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP389\A0052538.dll Infected: Packed.Win32.TDSS.aa 1
C:\WINDOWS\system32\sekikawe.dll Infected: Packed.Win32.TDSS.aa 1
C:\WINDOWS\system32\titubeve.dll_old Infected: Packed.Win32.TDSS.aa 1
Selected area has been scanned.
After everything else, DDS.txt:
DDS (Ver_09-12-01.01) - NTFSx86
Run by Mr.E at 23:41:38.09 on Sat 02/06/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.489 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Magic Workstation\MagicWorkstation.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Mr.E\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: {06498afd-da80-48d6-9811-8a7d67d46f48} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {1a45aee5-c4d2-407f-9a8c-5defddda9c1e} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165960990742
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\mr.e\applic~1\mozilla\firefox\profiles\vy89qukg.mr.e\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\mr.e\application data\mozilla\firefox\profiles\vy89qukg.mr.e\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-5 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-12-12 28424]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-28 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-12 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-12-22 93320]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [2006-5-3 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2006-5-3 8960]
=============== Created Last 30 ================
2010-02-07 00:40:02 0 d-----w- c:\windows\system32\Adobe
2010-02-05 23:21:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-05 23:21:21 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-05 23:02:46 0 d-----w- c:\docume~1\mr.e\applic~1\Malwarebytes
2010-02-05 23:02:41 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-05 23:02:40 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-05 20:46:56 98816 ----a-w- c:\windows\sed.exe
2010-02-05 20:46:56 77312 ----a-w- c:\windows\MBR.exe
2010-02-05 20:46:56 261632 ----a-w- c:\windows\PEV.exe
2010-02-05 20:46:56 161792 ----a-w- c:\windows\SWREG.exe
2010-02-01 04:36:09 0 d-----w- c:\program files\Magic Workstation
2010-01-31 14:32:57 0 d-----w- c:\program files\Trend Micro
2010-01-25 23:54:56 0 d-----w- c:\program files\MSECache
2010-01-13 04:21:32 0 d-----w- C:\$AVG
2010-01-13 04:20:43 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-01-13 02:31:03 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
==================== Find3M ====================
2010-02-06 16:36:18 124 ----a-w- c:\docume~1\mr.e\applic~1\wklnhst.dat
2010-01-13 04:21:25 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21:25 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21:08 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-31 15:33:06 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-12-17 22:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\parahuri.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\sekikawe.dll
2008-08-05 01:03:12 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008080420080805\index.dat
============= FINISH: 23:42:28.18 ===============
I did not post Attach.txt because you did not ask for it. Let me know if you wanted that too.
Thanks for the logs :)
Open notepad and copy/paste the text in the quotebox below into it:
File::
c:\windows\system32\parahuri.dll
c:\windows\system32\sekikawe.dll
C:\WINDOWS\system32\titubeve.dll_old
DDS::
BHO: {06498afd-da80-48d6-9811-8a7d67d46f48} - No File
BHO: {1a45aee5-c4d2-407f-9a8c-5defddda9c1e} - No File
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"lepekusiju"=-
"zuyivudeg"=-
Save this as
CFScript
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
See if you're able to run updated MBAM now.
ComboFix did not appear to reboot my computer this time. Only the desktop shut off as ComboFix reported the log file. Two unusual error lines showed up in ComboFix and it said I should submit the malware files for further analysis. I let it do that and my desktop was restored after it finished. Not sure what's up with all that...
I will try to download/run updated MBAM momentarily. Here is ComboFix Log #4:
ComboFix 10-02-05.01 - Mr.E 02/07/2010 6:26.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.622 [GMT -5:00]
Running from: c:\documents and settings\Mr.E\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mr.E\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"c:\windows\system32\parahuri.dll"
"c:\windows\system32\sekikawe.dll"
"c:\windows\system32\titubeve.dll_old"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\parahuri.dll
c:\windows\system32\sekikawe.dll
c:\windows\system32\titubeve.dll_old
.
((((((((((((((((((((((((( Files Created from 2010-01-07 to 2010-02-07 )))))))))))))))))))))))))))))))
.
2010-02-07 00:46 . 2010-02-07 00:46 1924200 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2010-02-07 00:40 . 2010-02-07 00:40 -------- d-----w- c:\windows\system32\Adobe
2010-02-07 00:38 . 2010-02-07 00:38 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-02-07 00:37 . 2010-02-07 00:37 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-07 00:36 . 2009-11-20 11:08 38784 ----a-w- c:\documents and settings\Mr.E\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-07 00:36 . 2009-11-20 11:08 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-07 00:36 . 2010-02-07 00:36 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-07 00:34 . 2010-02-07 00:34 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-02-07 00:34 . 2010-02-07 11:25 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-02-05 23:21 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-05 23:21 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\Mr.E\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 04:36 . 2010-02-07 11:07 -------- d-----w- c:\program files\Magic Workstation
2010-01-31 14:32 . 2010-01-31 14:32 388096 ----a-r- c:\documents and settings\Mr.E\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-31 14:32 . 2010-01-31 14:32 -------- d-----w- c:\program files\Trend Micro
2010-01-31 14:24 . 2010-01-31 14:25 -------- d-----w- c:\program files\ERUNT
2010-01-27 08:32 . 2010-01-27 08:32 -------- d-----w- c:\program files\Common Files\Java
2010-01-27 08:32 . 2010-01-27 08:32 348160 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcr71.dll
2010-01-27 08:32 . 2010-01-27 08:32 61440 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-sse.dll
2010-01-27 08:32 . 2010-01-27 08:32 503808 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcp71.dll
2010-01-27 08:32 . 2010-01-27 08:32 499712 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\jmc.dll
2010-01-27 08:32 . 2010-01-27 08:32 12800 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-d3d.dll
2010-01-25 23:54 . 2010-01-25 23:54 -------- d-----w- c:\program files\MSECache
2010-01-18 14:58 . 2010-01-18 14:58 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-13 04:35 . 2010-01-18 14:58 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-13 04:35 . 2010-01-13 04:20 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-13 04:35 . 2010-01-13 04:20 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-13 04:35 . 2010-01-13 04:21 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-13 04:35 . 2010-01-13 04:20 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-13 04:35 . 2010-01-13 04:35 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-13 04:21 . 2010-01-13 04:28 -------- d-----w- C:\$AVG
2010-01-13 04:20 . 2010-02-04 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-13 02:31 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 11:20 . 2006-12-12 11:34 -------- d-----w- c:\program files\mIRC
2010-02-07 00:12 . 2008-07-27 19:22 -------- d-----w- c:\program files\Steam
2010-02-06 23:53 . 2008-01-08 12:07 -------- d-----w- c:\program files\Trillian
2010-02-06 20:37 . 2006-12-07 00:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-06 20:37 . 2008-12-14 09:28 -------- d-----w- c:\program files\SpywareBlaster
2010-02-06 16:36 . 2009-05-02 20:49 124 ----a-w- c:\documents and settings\Mr.E\Application Data\wklnhst.dat
2010-02-05 06:42 . 2009-06-11 09:42 -------- d-----w- c:\program files\Wesnoth
2010-02-01 05:16 . 2006-12-07 00:29 78976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 15:20 . 2006-12-12 11:57 -------- d-----w- c:\program files\NetBattle
2010-01-27 08:32 . 2009-03-11 20:44 -------- d-----w- c:\program files\Java
2010-01-13 04:28 . 2008-12-23 04:20 -------- d-----w- c:\program files\McAfee
2010-01-13 04:21 . 2009-04-28 18:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21 . 2008-06-05 19:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21 . 2006-12-12 21:50 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-13 04:21 . 2008-06-05 19:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-13 04:20 . 2008-06-05 19:35 -------- d-----w- c:\program files\AVG
2010-01-05 10:00 . 2005-08-16 09:18 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-08-16 09:18 17408 ------w- c:\windows\system32\corpol.dll
2009-12-17 22:14 . 2008-12-14 08:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-21 15:51 . 2005-08-16 09:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-12-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-5-9 1073152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-13 04:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aim6.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/5/2008 2:35 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/28/2009 1:39 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/12/2010 11:20 PM 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/22/2008 11:21 PM 93320]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [5/3/2006 9:19 AM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [5/3/2006 9:19 AM 8960]
.
Contents of the 'Scheduled Tasks' folder
2010-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-06-02 20:31]
2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-02-11 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
FF - ProfilePath - c:\documents and settings\Mr.E\Application Data\Mozilla\Firefox\Profiles\vy89qukg.Mr.E\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-02-07 06:34:16
ComboFix-quarantined-files.txt 2010-02-07 11:34
ComboFix2.txt 2010-02-07 00:18
ComboFix3.txt 2010-02-06 20:29
ComboFix4.txt 2010-02-05 21:12
ComboFix5.txt 2010-02-07 11:25
Pre-Run: 67,710,521,344 bytes free
Post-Run: 67,857,899,520 bytes free
- - End Of File - - A4231D765D3233453AAA25DC60F6A326
Running MBAM... was a success! I followed the instructions given to me the first time you wanted me to run it. It found six infected files. Here is the MBAM log:
Malwarebytes' Anti-Malware 1.44
Database version: 3700
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
2/7/2010 6:56:39 AM
mbam-log-2010-02-07 (06-56-39).txt
Scan type: Quick Scan
Objects scanned: 128733
Time elapsed: 4 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77dc0baa-3235-4ba9-8be8-aa9eb678fa02} (Rogue.ASCAntispyware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Great. Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions :)
THESE STEPS ARE VERY IMPORTANT
Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
2. Reboot.
3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis
Now lets uninstall ComboFix:
Click START then RUN
Now copy-paste Combofix /uninstall in the runbox and click OK
Please download OTC (http://oldtimer.geekstogo.com/OTC.exe) and save it to desktop.
Double-click OTC.exe.
Click the CleanUp! button.
Select Yes when the
Begin cleanup Process?
prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.
Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.
UPDATING WINDOWS AND INTERNET EXPLORER
IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.
If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.
Make your Internet Explorer more secure
This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.
hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok
Run Secunia vulnerability check here (http://secunia.com/vulnerability_scanning/online/) and fix its findings.
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this (http://www.bleepingcomputer.com/forums/tutorial60.html) webpage out.
If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free (http://www.tallemu.com/free-firewall-protection-software.html) or Comodo Firewall Pro (http://www.personalfirewall.comodo.com/download_firewall.html#fw3.0) (If you choose Comodo: Uncheck during installation Install Comodo HopSurf.., Make Comodo my default search provider and Make Comodo Search my homepage and install firewall ONLY!). Both providers have support forums that help with configuration related questions.
Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Once again, please post and tell me how things are going with your system... problems etc.
Have a great day,
Blade :cool:
I believe I stopped having symptoms after the third ComboFix run or so but that doesn't mean something malicious isn't still lurking. :fear: I assume this Windows Security Alert in my taskbar is legit and I can tinker to make it go away again, then?
1) Reset System Restore.
2) Uninstalled ComboFix. The second install, of the updated version, did not go away, so I deleted it manually if that's ok.
3) Used OTC cleaner.
4) Downloaded IE8. I never bothered before, as I use Firefox for browsing, but I suppose it is still important to keep up-to-date because of Explorer's general integration with the OS.
5) My IE already had those things set under Security, except "Navigate sub-frames across different domains" had been set to Disable.
6) Downloaded the only security update available, something related to Javascript.
Lastly, I did the Secunia scan. My computer froze up about 10 minutes into a thorough scan but the three things it listed up to that point as vulnerable:
**Heavily outdated version of AIM, as I no longer use it. I suppose I'll update it anyway, I access my AIM account through Trillian.
**Slightly out-of-date RealPlayer. I'll take care of that for the rare occasion a website still actually uses RealPlayer to display video...
**Macromedia Flash Player (version 8.x). Looks like this might've been missed by the uninstaller I ran before? There's no uninstaller in Add/Remove Programs and I generally can find no trace of it, short of searching for individual files on the C:\ drive. What should I do here?
And that's about it. That whole "logon.exe" error message when booting up is also gone and my computer shuts down much, much faster, so woohoo!
Hi,
2) Uninstalled ComboFix. The second install, of the updated version, did not go away, so I deleted it manually if that's ok.
ComboFix should be properly uninstalled. Please download a fresh copy to your desktop and then do the following:
1. Click start->run->copy-paste following bolded command in it and press ok (ComboFix will run):
"%userprofile\desktop\ComboFix.exe" /skipfix
2. When finished, click start->run->copy-paste the following bolded command and press ok (that should uninstall ComboFix properly):
"%userprofile\desktop\ComboFix.exe" /uninstall
**Macromedia Flash Player (version 8.x). Looks like this might've been missed by the uninstaller I ran before? There's no uninstaller in Add/Remove Programs and I generally can find no trace of it, short of searching for individual files on the C:\ drive. What should I do here?
See if C:\WINDOWS\system32\Macromed\Flash folder holds any 8.x version Flash components (Flash8X.ocx files where X is some alphabet)
The ComboFix thing worked. I had to use "%userprofile%" instead of "%userprofile" as given, however.
The C:\WINDOWS\system32\Macromed\Flash folder does contain Flash8b.ocx. It also has an uninstall_plugin file, if that's what I need to run to get rid of it.
I had to use "%userprofile%" instead of "%userprofile" as given, however.
Yeah, I had a typo there. Sorry.
Simple delete for that ocx file should be enough. If you use uninstall that will remove also other versions.
I cannot delete it because it is marked as read-only. It won't let me remove the write protection so I can delete it and "uninstall_plugin" only removed the latest Flash version (10.0.42.34), making me have to redownload it. :scratch:
Hi,
Does it allow to delete the file in safe mode?
...Nope. Same as before, won't let me delete it because of write protection, won't let me remove write protection (Read-Only status) so I *can* delete it.
Hi,
Move C:\WINDOWS\system32\Macromed\Flash folder to your desktop. Delete the stubborn file and then move the Flash folder back to C:\WINDOWS\system32\Macromed folder.
:bigthumb: That'll do it.
Good. Any other issues? :)
All symptoms are gone -- Flash is loading normally and no more popups -- but Spybot said it found one Virtumonde.sdn when I scanned this morning and removed it. (I have Spybot/AVG do automatic scans on Wednesday because I have classes early on Wed.) Is this anything to look into?
Hi,
Do you have Spybot log of that run handy? Monitor situation for a few days and let me know if problem returns :)
It's really a shame that we have to be on such different schedules/timezones, it makes correspondence so slow. :(
How do I get the log of a previous scan from Spybot? Is it the report I get through Tools -> View Report -> View Report? If so, here is that from yesterday's scan:
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2008-01-28 SDDelFile.exe (1.0.2.4)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDUpdate.exe (1.6.0.12)
2008-08-14 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2005-06-02 unins000.exe (51.41.0.0)
2009-02-23 unins001.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2009-10-08 Includes\Adware.sbi
2010-02-09 Includes\AdwareC.sbi
2010-01-25 Includes\Cookies.sbi
2009-11-03 Includes\Dialer.sbi
2010-02-09 Includes\DialerC.sbi
2010-01-25 Includes\HeavyDuty.sbi
2009-05-26 Includes\Hijackers.sbi
2010-02-09 Includes\HijackersC.sbi
2010-01-20 Includes\Keyloggers.sbi
2010-02-09 Includes\KeyloggersC.sbi
2004-11-29 Includes\LSP.sbi
2010-02-10 Includes\Malware.sbi
2010-02-10 Includes\MalwareC.sbi
2009-03-25 Includes\PUPS.sbi
2010-02-09 Includes\PUPSC.sbi
2010-01-25 Includes\Revision.sbi
2009-01-13 Includes\Security.sbi
2010-02-10 Includes\SecurityC.sbi
2008-06-03 Includes\Spybots.sbi
2008-06-03 Includes\SpybotsC.sbi
2009-11-03 Includes\Spyware.sbi
2010-02-09 Includes\SpywareC.sbi
2009-06-08 Includes\Tracks.uti
2009-12-08 Includes\Trojans.sbi
2010-02-10 Includes\TrojansC.sbi
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--- System information ---
Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB887998)
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB930494)
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB953295)
/ .NETFramework / 1.0: Microsoft .NET Framework 1.0 Service Pack 3
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Security Update (KB953297)
/ .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
/ Media Center 2005 / SP4: Update Rollup 2 for Windows XP Media Center Edition 2005
/ MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
/ MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
/ MSXML4SP2: Security update for MSXML4 SP2 (KB973688)
/ Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
/ Windows / SP1: Microsoft National Language Support Downlevel APIs
/ Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
/ Windows Media Player: Security Update for Windows Media Player (KB952069)
/ Windows Media Player: Security Update for Windows Media Player (KB954155)
/ Windows Media Player: Security Update for Windows Media Player (KB968816)
/ Windows Media Player: Security Update for Windows Media Player (KB973540)
/ Windows Media Player 10: Security Update for Windows Media Player 10 (KB911565)
/ Windows Media Player 10: Update for Windows Media Player 10 (KB913800)
/ Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734)
/ Windows Media Player 10: Update for Windows Media Player 10 (KB926251)
/ Windows Media Player 10 / SP0: Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
/ Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
/ Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)
/ Windows Media Player 11: Critical Update for Windows Media Player 11 (KB959772)
/ Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
/ Windows XP: Security Update for Windows XP (KB923689)
/ Windows XP: Security Update for Windows XP (KB941569)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB928090)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB929969)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB931768)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB933566)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB937143)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB939653)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB942615)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB944533)
/ Windows XP / SP0: Hotfix for Windows Internet Explorer 7 (KB947864)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB950759)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB953838)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB956390)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB958215)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB960714)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB961260)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB963027)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB969897)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB971961)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB972260)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB974455)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB976325)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB976325)
/ Windows XP / SP0: Update for Windows Internet Explorer 7 (KB976749)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB978207)
/ Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB978207)
/ Windows XP / SP0: Update for Windows Internet Explorer 8 (KB978506)
/ Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
/ Windows XP / SP3: Windows XP Hotfix - KB873333
/ Windows XP / SP3: Security Update for Windows XP (KB883939)
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890175
/ Windows XP / SP3: Windows XP Hotfix - KB890923
/ Windows XP / SP3: Security Update for Windows XP (KB893066)
/ Windows XP / SP3: Windows XP Hotfix - KB893086
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Security Update for Windows XP (KB896422)
/ Windows XP / SP3: Security Update for Windows XP (KB896688)
/ Windows XP / SP3: Update for Windows XP (KB896727)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899589)
/ Windows XP / SP3: Security Update for Windows XP (KB903235)
/ Windows XP / SP3: Security Update for Windows XP (KB905915)
/ Windows XP / SP3: Security Update for Windows XP (KB912812)
/ Windows XP / SP3: Security Update for Windows XP (KB913446)
/ Windows XP / SP3: Windows XP Service Pack 3
/ Windows XP / SP3: Microsoft .NET Framework 1.0 Hotfix (KB953295)
/ Windows XP / SP4: Security Update for Windows XP (KB923561)
/ Windows XP / SP4: Security Update for Windows XP (KB938464)
/ Windows XP / SP4: Security Update for Windows XP (KB946648)
/ Windows XP / SP4: Security Update for Windows XP (KB950760)
/ Windows XP / SP4: Security Update for Windows XP (KB950762)
/ Windows XP / SP4: Security Update for Windows XP (KB950974)
/ Windows XP / SP4: Security Update for Windows XP (KB951066)
/ Windows XP / SP4: Update for Windows XP (KB951072-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951376)
/ Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB951698)
/ Windows XP / SP4: Security Update for Windows XP (KB951748)
/ Windows XP / SP4: Update for Windows XP (KB951978)
/ Windows XP / SP4: Security Update for Windows XP (KB952004)
/ Windows XP / SP4: Hotfix for Windows XP (KB952287)
/ Windows XP / SP4: Security Update for Windows XP (KB952954)
/ Windows XP / SP4: Security Update for Windows XP (KB953839)
/ Windows XP / SP4: Security Update for Windows XP (KB954211)
/ Windows XP / SP4: Security Update for Windows XP (KB954459)
/ Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
/ Windows XP / SP4: Security Update for Windows XP (KB954600)
/ Windows XP / SP4: Security Update for Windows XP (KB955069)
/ Windows XP / SP4: Update for Windows XP (KB955759)
/ Windows XP / SP4: Update for Windows XP (KB955839)
/ Windows XP / SP4: Security Update for Windows XP (KB956391)
/ Windows XP / SP4: Security Update for Windows XP (KB956572)
/ Windows XP / SP4: Security Update for Windows XP (KB956744)
/ Windows XP / SP4: Security Update for Windows XP (KB956802)
/ Windows XP / SP4: Security Update for Windows XP (KB956803)
/ Windows XP / SP4: Security Update for Windows XP (KB956841)
/ Windows XP / SP4: Security Update for Windows XP (KB956844)
/ Windows XP / SP4: Security Update for Windows XP (KB957095)
/ Windows XP / SP4: Security Update for Windows XP (KB957097)
/ Windows XP / SP4: Security Update for Windows XP (KB958644)
/ Windows XP / SP4: Security Update for Windows XP (KB958687)
/ Windows XP / SP4: Security Update for Windows XP (KB958690)
/ Windows XP / SP4: Security Update for Windows XP (KB958869)
/ Windows XP / SP4: Security Update for Windows XP (KB959426)
/ Windows XP / SP4: Security Update for Windows XP (KB960225)
/ Windows XP / SP4: Security Update for Windows XP (KB960715)
/ Windows XP / SP4: Security Update for Windows XP (KB960803)
/ Windows XP / SP4: Security Update for Windows XP (KB960859)
/ Windows XP / SP4: Hotfix for Windows XP (KB961118)
/ Windows XP / SP4: Security Update for Windows XP (KB961371)
/ Windows XP / SP4: Security Update for Windows XP (KB961373)
/ Windows XP / SP4: Security Update for Windows XP (KB961501)
/ Windows XP / SP4: Update for Windows XP (KB967715)
/ Windows XP / SP4: Update for Windows XP (KB968389)
/ Windows XP / SP4: Security Update for Windows XP (KB968537)
/ Windows XP / SP4: Security Update for Windows XP (KB969059)
/ Windows XP / SP4: Security Update for Windows XP (KB969898)
/ Windows XP / SP4: Security Update for Windows XP (KB969947)
/ Windows XP / SP4: Security Update for Windows XP (KB970238)
/ Windows XP / SP4: Security Update for Windows XP (KB970430)
/ Windows XP / SP4: Hotfix for Windows XP (KB970653-v3)
/ Windows XP / SP4: Security Update for Windows XP (KB971468)
/ Windows XP / SP4: Security Update for Windows XP (KB971486)
/ Windows XP / SP4: Security Update for Windows XP (KB971557)
/ Windows XP / SP4: Security Update for Windows XP (KB971633)
/ Windows XP / SP4: Security Update for Windows XP (KB971657)
/ Windows XP / SP4: Update for Windows XP (KB971737)
/ Windows XP / SP4: Security Update for Windows XP (KB971961)
/ Windows XP / SP4: Security Update for Windows XP (KB972270)
/ Windows XP / SP4: Security Update for Windows XP (KB973346)
/ Windows XP / SP4: Security Update for Windows XP (KB973354)
/ Windows XP / SP4: Security Update for Windows XP (KB973507)
/ Windows XP / SP4: Security Update for Windows XP (KB973525)
/ Windows XP / SP4: Update for Windows XP (KB973687)
/ Windows XP / SP4: Update for Windows XP (KB973815)
/ Windows XP / SP4: Security Update for Windows XP (KB973869)
/ Windows XP / SP4: Security Update for Windows XP (KB973904)
/ Windows XP / SP4: Security Update for Windows XP (KB974112)
/ Windows XP / SP4: Security Update for Windows XP (KB974318)
/ Windows XP / SP4: Security Update for Windows XP (KB974392)
/ Windows XP / SP4: Security Update for Windows XP (KB974571)
/ Windows XP / SP4: Security Update for Windows XP (KB975025)
/ Windows XP / SP4: Security Update for Windows XP (KB975467)
/ Windows XP / SP4: Security Update for Windows XP (KB975560)
/ Windows XP / SP4: Security Update for Windows XP (KB975713)
/ Windows XP / SP4: Hotfix for Windows XP (KB976098-v2)
/ Windows XP / SP4: Security Update for Windows XP (KB977165)
/ Windows XP / SP4: Security Update for Windows XP (KB977914)
/ Windows XP / SP4: Security Update for Windows XP (KB978037)
/ Windows XP / SP4: Security Update for Windows XP (KB978251)
/ Windows XP / SP4: Security Update for Windows XP (KB978262)
/ Windows XP / SP4: Security Update for Windows XP (KB978706)
/ Windows XP OOB / SP10: High Definition Audio Driver Package - KB835221
--- Startup entries list ---
Located: HK_LM:Run, Adobe ARM
command: "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
file: C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
size: 948672
MD5: 73BB442A717B9BB0097C243374C14A3E
Located: HK_LM:Run, Adobe Reader Speed Launcher
command: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
file: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
size: 35760
MD5: 466CE40EAA865752F4930A472563E4E1
Located: HK_LM:Run, ATICCC
command: "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
file: C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
size: 45056
MD5: 64C4C17BF6A40FF1CD21205E6FD415B8
Located: HK_LM:Run, DLA
command: C:\WINDOWS\System32\DLA\DLACTRLW.EXE
file: C:\WINDOWS\System32\DLA\DLACTRLW.EXE
size: 122940
MD5: CEFD0E35B35AFD9D1C2FEC9AF81AFDB8
Located: HK_LM:Run, ehTray
command: C:\WINDOWS\ehome\ehtray.exe
file: C:\WINDOWS\ehome\ehtray.exe
size: 67584
MD5: 7E48B4958C131E9643DDCD2E7CA3FE9F
Located: HK_LM:Run, HP Software Update
command: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
file: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
size: 49152
MD5: 926A397334FE426A6C7657096FE681DB
Located: HK_LM:Run, ISUSPM Startup
command: C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
file: C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
size: 221184
MD5: FB9E5C251CF6C37749F296BACB34A69B
Located: HK_LM:Run, ISUSScheduler
command: "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
file: C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
size: 81920
MD5: 763DAB43BDAB27316DBF3373192823D7
Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files\iTunes\iTunesHelper.exe"
file: C:\Program Files\iTunes\iTunesHelper.exe
size: 141608
MD5: 8DC7685764B22DB97891012026FA7ED1
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\QTTask.exe" -atboottime
file: C:\Program Files\QuickTime\QTTask.exe
size: 417792
MD5: 55D7A219AD8D0DB8980528944152A6FD
Located: HK_LM:Run, SigmatelSysTrayApp
command: stsystra.exe
file: C:\WINDOWS\stsystra.exe
size: 282624
MD5: 289BDC9E5681BD1BE0FB871C460BD254
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
file: C:\Program Files\Common Files\Java\Java Update\jusched.exe
size: 246504
MD5: E0D6538B62C79FCBF0B27F95FAF3208B
Located: HK_LM:Run, TkBellExe
command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
size: 198160
MD5: 29BE51557A3E686B297BE273EB17CA67
Located: HK_LM:Run, DMXLauncher (DISABLED)
command: C:\Program Files\Dell\Media Experience\DMXLauncher.exe
file: C:\Program Files\Dell\Media Experience\DMXLauncher.exe
size: 94208
MD5: C24B51FAF9BAAEF67C484D60866693B1
Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-1908293018-4181019595-1031187214-1006...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-1908293018-4181019595-1031187214-1006...
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2260480
MD5: 390679F7A217A5E73D756276C40AE887
Located: HK_CU:Run, Steam
where: S-1-5-21-1908293018-4181019595-1031187214-1006...
command: "c:\program files\steam\steam.exe" -silent
file: c:\program files\steam\steam.exe
size: 1217808
MD5: A740B005ADD7DEBEAF922C4AE86F7C2D
Located: HK_CU:Run, DellSupport
where: S-1-5-21-1908293018-4181019595-1031187214-500...
command: "C:\Program Files\Dell Support\DSAgnt.exe" /startup
file: C:\Program Files\Dell Support\DSAgnt.exe
size: 395776
MD5: 825EDDDB0521EB2183C7E3C45BB5FE97
Located: Startup (common), Digital Line Detect.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Digital Line Detect\DLG.exe
file: C:\Program Files\Digital Line Detect\DLG.exe
size: 24576
MD5: B66E56733E2CD6A10FDA5919625FBF46
Located: Startup (common), HP Digital Imaging Monitor.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
file: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
size: 288472
MD5: 4543367E50BD35E7D1269D42841B156E
Located: Startup (common), Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\WiFiConnector\NintendoWFCReg.exe
file: C:\Program Files\WiFiConnector\NintendoWFCReg.exe
size: 1073152
MD5: E7F99344C5C441C0B7771E40C9E1E8C7
Located: WinLogon, AtiExtEvent
command: Ati2evxx.dll
file: Ati2evxx.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, avgrsstarter
command: avgrsstx.dll
file: avgrsstx.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, dimsntfy
command: %SystemRoot%\System32\dimsntfy.dll
file: %SystemRoot%\System32\dimsntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, WgaLogon
command: WgaLogon.dll
file: WgaLogon.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
--- Browser helper object list ---
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: AcroIEHelperStub
CLSID name: Adobe PDF Link Helper
Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
Long name: AcroIEHelperShim.dll
Short name: ACROIE~2.DLL
Date (created): 12/21/2009 6:27:44 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 12/21/2009 6:27:44 PM
Filesize: 75200
Attributes: archive
MD5: DC1E56092CC57FB4605B088D3DCCBF7A
CRC32: FF82C62B
Version: 9.3.0.148
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (WormRadar.com IESiteBlocker.NavFilter)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: WormRadar.com IESiteBlocker.NavFilter
CLSID name: AVG Safe Search
Path: C:\Program Files\AVG\AVG9\
Long name: avgssie.dll
Short name:
Date (created): 1/12/2010 11:21:08 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 1/12/2010 11:21:08 PM
Filesize: 1484056
Attributes: archive
MD5: F7CC657F40C56C9BA7C189066D259F9E
CRC32: DBEFFA87
Version: 9.0.0.713
{53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Spybot-S&D IE Protection
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name:
Date (created): 6/2/2005 2:52:16 PM
Date (last access): 2/11/2010 10:19:30 AM
Date (last write): 1/26/2009 3:31:02 PM
Filesize: 1879896
Attributes: archive
MD5: 022C2F6DCCDFA0AD73024D254E62AFAC
CRC32: 5BA24007
Version: 1.6.2.14
{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll
info link: http://toolbar.google.com/
info source: TonyKlein
Path: C:\Program Files\Google\Google Toolbar\
Long name: GoogleToolbar_32.dll
Short name: GOOGLE~2.DLL
Date (created): 11/27/2009 8:04:38 AM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 1/12/2010 11:09:28 PM
Filesize: 263280
Attributes: archive
MD5: 6CAC864C230B5E520AD054CF2DD66D59
CRC32: 7E94DC92
Version: 6.3.1014.1517
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Google Toolbar Notifier BHO
Path: C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\
Long name: swg.dll
Short name:
Date (created): 1/12/2010 11:20:18 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 1/12/2010 11:20:18 PM
Filesize: 764912
Attributes: archive
MD5: CD91E666B2446530583FBFFCF537BE4C
CRC32: 34534F50
Version: 5.4.4525.1752
{B164E929-A1B6-4A06-B104-2CD0E90A88FF} (McAfee SiteAdvisor BHO)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: McAfee SiteAdvisor BHO
Path: c:\PROGRA~1\mcafee\SITEAD~1\
Long name: McIEPlg.dll
Short name:
Date (created): 12/22/2008 11:20:50 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 12/23/2009 3:59:04 PM
Filesize: 251416
Attributes: archive
MD5: 5F53D3BBF941C6F502C101DDDBEE3FAA
CRC32: FA368854
Version: 3.1.0.134
{DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name:
CLSID name: Java(tm) Plug-In 2 SSV Helper
Path: C:\Program Files\Java\jre6\bin\
Long name: jp2ssv.dll
Short name:
Date (created): 1/11/2010 8:42:48 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 1/11/2010 8:42:48 PM
Filesize: 41760
Attributes: archive
MD5: 883EF2DD3C9F68691CE02DAAC7267D41
CRC32: C0FCD56C
Version: 6.0.180.7
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (JQSIEStartDetectorImpl)
location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
BHO name: JQSIEStartDetectorImpl
CLSID name: JQSIEStartDetectorImpl Class
Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\
Long name: jqs_plugin.dll
Short name: JQS_PL~1.DLL
Date (created): 1/11/2010 8:42:48 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 1/11/2010 8:42:48 PM
Filesize: 79648
Attributes: archive
MD5: FD60844F7DC0CF7C7AFA70B7EC6D0A7E
CRC32: 386E7BEE
Version: 6.0.180.7
--- ActiveX list ---
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://active.macromedia.com/director/cabs/sw.cab
description: Macromedia ShockWave Flash Player 7
classification: Legitimate
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Adobe\Director\
Long name: SwDir.dll
Short name:
Date (created): 1/18/2010 2:24:44 AM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 1/18/2010 2:24:44 AM
Filesize: 213272
Attributes: archive
MD5: 9E6DEA101212D0244FA3F08945482413
CRC32: E3B3F3BE
Version: 11.5.6.606
{215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6)
DPF name:
CLSID name: Trend Micro ActiveX Scan Agent 6.6
Installer: C:\WINDOWS\Downloaded Program Files\hcImpl.inf
Codebase: http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
description:
classification: Legitimate
known filename: Housecall_ActiveX.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: Housecall_ActiveX.dll
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine)
DPF name:
CLSID name: Office Update Installation Engine
Installer: C:\WINDOWS\Downloaded Program Files\opuc.inf
Codebase: http://office.microsoft.com/officeupdate/content/opuc2.cab
description:
classification: Legitimate
known filename: opuc.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\
Long name: opuc.dll
Short name:
Date (created): 1/18/2005 3:07:18 AM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 1/18/2005 3:07:18 AM
Filesize: 326656
Attributes: archive
MD5: 20393D64F69F26361A97FD9AFB3C9243
CRC32: 0B4DBA7F
Version: 11.0.6466.0
{58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class)
DPF name:
CLSID name: shizmoo Class
Installer: C:\WINDOWS\Downloaded Program Files\webmoo.inf
Codebase: http://www.kungfuchess.com/activex/web665.cab
description:
classification: Open for discussion
known filename:
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\shizmoo\webgames\
Long name: webmoo665.dll
Short name: WEBMOO~1.DLL
Date (created): 1/15/2008 1:19:14 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 10/29/2003 4:06:34 AM
Filesize: 90112
Attributes: archive
MD5: 9BED4027BC3EFC880C450ACF81F48781
CRC32: 6424EA65
Version: 665.0.0.1
{5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class)
DPF name:
CLSID name: ijjiPlugin2 Class
Installer: C:\WINDOWS\Downloaded Program Files\ijjiPlugin2.inf
Codebase: http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
Path: C:\WINDOWS\system32\
Long name: ijjiPlugin2.dll
Short name: IJJIPL~1.DLL
Date (created): 9/12/2007 5:49:32 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 6/21/2007 5:59:50 PM
Filesize: 58776
Attributes: archive
MD5: B5101674241FB89A35B16F278EBE088A
CRC32: C8B835AA
Version: 2.0.0.0
{6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
DPF name:
CLSID name: WUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf
Codebase: http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165960990742
description:
classification: Legitimate
known filename: wuweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: wuweb.dll
Short name:
Date (created): 8/16/2005 4:40:18 AM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 8/6/2009 6:24:18 PM
Filesize: 209632
Attributes: archive
MD5: 033AF4CE25B6D871F0DE2C982658E049
CRC32: 2C204902
Version: 7.4.7600.226
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_18
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_18.dll
Short name: NPJPI1~1.DLL
Date (created): 12/17/2009 3:02:50 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 12/17/2009 5:14:02 PM
Filesize: 136992
Attributes: archive
MD5: FD681B5B1CEC8B3181E63A3CC9A8C5EF
CRC32: 23BC9EDD
Version: 6.0.180.7
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
description:
classification: Open for discussion
known filename:
info link:
info source: Safer Networking Ltd.
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_18
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_18.dll
Short name: NPJPI1~1.DLL
Date (created): 12/17/2009 3:02:50 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 12/17/2009 5:14:02 PM
Filesize: 136992
Attributes: archive
MD5: FD681B5B1CEC8B3181E63A3CC9A8C5EF
CRC32: 23BC9EDD
Version: 6.0.180.7
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
DPF name: Java Runtime Environment 1.6.0
CLSID name: Java Plug-in 1.6.0_18
Installer:
Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
description:
classification: Legitimate
known filename: npjpi150_06.dll
info link:
info source: Safer Networking Ltd.
Path: C:\Program Files\Java\jre6\bin\
Long name: npjpi160_18.dll
Short name: NPJPI1~1.DLL
Date (created): 12/17/2009 3:02:50 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 12/17/2009 5:14:02 PM
Filesize: 136992
Attributes: archive
MD5: FD681B5B1CEC8B3181E63A3CC9A8C5EF
CRC32: 23BC9EDD
Version: 6.0.180.7
{CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class)
DPF name:
CLSID name: HGPlugin9USA Class
Installer: C:\WINDOWS\Downloaded Program Files\HGPlugin9USA.inf
Codebase: http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
description:
classification: Legitimate
known filename: HGPlugin9USA.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: HGPlugin9USA.dll
Short name: HGPLUG~1.DLL
Date (created): 8/9/2006 8:56:06 PM
Date (last access): 2/11/2010 10:19:32 AM
Date (last write): 8/9/2006 8:56:06 PM
Filesize: 53248
Attributes: archive
MD5: D075F38B14A69362897FA1010A676A7B
CRC32: A87C7F44
Version: 9.0.0.0
{D27CDB6E-AE6D-11CF-96B8-444553540000} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
Codebase: http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
--- Process list ---
PID: 0 ( 0) [System]
PID: 764 ( 4) \SystemRoot\System32\smss.exe
size: 50688
PID: 816 ( 764) \??\C:\WINDOWS\system32\csrss.exe
size: 6144
PID: 848 ( 764) \??\C:\WINDOWS\system32\winlogon.exe
size: 507904
PID: 892 ( 848) C:\WINDOWS\system32\services.exe
size: 110592
MD5: 65DF52F5B8B6E9BBD183505225C37315
PID: 904 ( 848) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: BF2466B3E18E970D8A976FB95FC1CA85
PID: 1120 ( 892) C:\WINDOWS\system32\Ati2evxx.exe
size: 561152
MD5: 3C94E4E7983EFF03E7E128325891EA80
PID: 1136 ( 892) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1188 ( 892) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1548 ( 892) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1628 ( 892) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1696 ( 848) C:\WINDOWS\system32\Ati2evxx.exe
size: 561152
MD5: 3C94E4E7983EFF03E7E128325891EA80
PID: 1724 ( 848) C:\Program Files\AVG\AVG9\avgchsvx.exe
size: 1055000
MD5: 5BB7141D64039953C82CF1BFAC0072C8
PID: 1732 ( 848) C:\Program Files\AVG\AVG9\avgrsx.exe
size: 503576
MD5: 66A153463F0435369E8291DCCD152C2F
PID: 1892 ( 892) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 1968 (1732) C:\Program Files\AVG\AVG9\avgcsrvx.exe
size: 702744
MD5: 64B2872A01F80FD3EC5E3AE111451DB0
PID: 496 ( 468) C:\WINDOWS\Explorer.EXE
size: 1033728
MD5: 12896823FB95BFB3DC9B46BCAEDC9923
PID: 648 ( 892) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
PID: 1316 ( 496) C:\WINDOWS\stsystra.exe
size: 282624
MD5: 289BDC9E5681BD1BE0FB871C460BD254
PID: 1324 ( 496) C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
size: 45056
MD5: 64C4C17BF6A40FF1CD21205E6FD415B8
PID: 1332 ( 496) C:\WINDOWS\System32\DLA\DLACTRLW.EXE
size: 122940
MD5: CEFD0E35B35AFD9D1C2FEC9AF81AFDB8
PID: 1348 ( 496) C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
size: 81920
MD5: 763DAB43BDAB27316DBF3373192823D7
PID: 1356 ( 496) C:\WINDOWS\ehome\ehtray.exe
size: 67584
MD5: 7E48B4958C131E9643DDCD2E7CA3FE9F
PID: 1380 ( 496) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
size: 49152
MD5: 926A397334FE426A6C7657096FE681DB
PID: 1388 ( 496) C:\Program Files\Common Files\Java\Java Update\jusched.exe
size: 246504
MD5: E0D6538B62C79FCBF0B27F95FAF3208B
PID: 1440 ( 496) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
size: 198160
MD5: 29BE51557A3E686B297BE273EB17CA67
PID: 1504 ( 496) C:\Program Files\iTunes\iTunesHelper.exe
size: 141608
MD5: 8DC7685764B22DB97891012026FA7ED1
PID: 1520 ( 496) C:\program files\steam\steam.exe
size: 1217808
MD5: A740B005ADD7DEBEAF922C4AE86F7C2D
PID: 1580 ( 496) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2260480
MD5: 390679F7A217A5E73D756276C40AE887
PID: 1664 ( 496) C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
PID: 1824 ( 496) C:\Program Files\Digital Line Detect\DLG.exe
size: 24576
MD5: B66E56733E2CD6A10FDA5919625FBF46
PID: 248 ( 496) C:\Program Files\WiFiConnector\NintendoWFCReg.exe
size: 1073152
MD5: E7F99344C5C441C0B7771E40C9E1E8C7
PID: 976 ( 892) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 908 ( 892) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
size: 144712
MD5: 7E94E567C1AA5ABE6174032B3DAB6C23
PID: 1604 ( 892) C:\Program Files\AVG\AVG9\avgwdsvc.exe
size: 285392
MD5: 7E7B5FA964F578ACD655E8BEEAE2A5CA
PID: 1716 ( 892) C:\Program Files\Bonjour\mDNSResponder.exe
size: 238888
MD5: 3F56903E124E820AEECE6D471583C6C1
PID: 2084 ( 892) C:\WINDOWS\eHome\ehRecvr.exe
size: 237568
MD5: 5D1347AA5AE6E2F77D7F4F8372D95AC9
PID: 2224 ( 892) C:\WINDOWS\eHome\ehSched.exe
size: 102912
MD5: A53243709439AC2A4C216B817F8D7411
PID: 2420 ( 892) C:\Program Files\Java\jre6\bin\jqs.exe
size: 153376
MD5: 77AC10DB097DFD0CD3071465B644D0AB
PID: 2476 ( 892) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
size: 93320
MD5: 6457A49B09540FE1054099CA0A5F741F
PID: 2832 ( 892) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
size: 322120
MD5: 11F714F85530A2BD134074DC30E99FCA
PID: 2916 (1604) C:\Program Files\AVG\AVG9\avgnsx.exe
size: 600344
MD5: 43E406C4660125C003DC898AE936157F
PID: 2968 ( 892) C:\WINDOWS\system32\HPZipm12.exe
size: 69632
MD5: D31F88C5F19EEFA366A415D6BC5F2ABC
PID: 3268 ( 892) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 3392 ( 892) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 3664 ( 892) C:\WINDOWS\ehome\mcrdsvc.exe
size: 99328
MD5: DF0A511F38F16016BF658FCA0090CB87
PID: 1596 ( 892) C:\Program Files\iPod\bin\iPodService.exe
size: 545576
MD5: 1E6F080D5EDB4C3B4C4EB787A0848DCC
PID: 2148 ( 892) C:\WINDOWS\system32\dllhost.exe
size: 5120
MD5: 0A9BA6AF531AFE7FA5E4FB973852D863
PID: 3624 ( 892) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: 8C515081584A38AA007909CD02020B3D
PID: 4036 ( 892) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
PID: 3724 (1136) C:\WINDOWS\eHome\ehmsas.exe
size: 46592
MD5: 03A905FBA1D62317087DB5C21C0F8F62
PID: 2724 (1324) C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
size: 45056
MD5: 64C4C17BF6A40FF1CD21205E6FD415B8
PID: 3240 ( 496) C:\Program Files\Trillian\trillian.exe
size: 1873280
MD5: D5A9CF972E155A10AD68D5C1866C3124
PID: 2440 ( 496) C:\Program Files\mIRC\mirc.exe
size: 1949696
MD5: 0471108D25398E9F200FD7C580082A8E
PID: 1460 ( 496) C:\Program Files\Mozilla Firefox\firefox.exe
size: 908248
MD5: B4A8CA9A1EEEE32A4DC5D323A002ED3F
PID: 4500 ( 496) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 5365592
MD5: 0477C2F9171599CA5BC3307FDFBA8D89
PID: 4 ( 0) System
--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 2/11/2010 10:22:57 AM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
about:blank
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip
Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip
Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip
Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EF83F386-2883-46A3-AA2E-9EDA4B34CE7C}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EF83F386-2883-46A3-AA2E-9EDA4B34CE7C}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{ACF728AF-8BFB-419C-A62C-7F6420D4E44F}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{ACF728AF-8BFB-419C-A62C-7F6420D4E44F}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{651F9C10-8AD0-4011-A45A-299F4FFAEB1D}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{651F9C10-8AD0-4011-A45A-299F4FFAEB1D}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{29B39846-0902-49E5-B96A-2F1FC54E9A72}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{29B39846-0902-49E5-B96A-2F1FC54E9A72}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2F9FBC39-C724-4E7B-AEFD-EDFE1FAC9BF8}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2F9FBC39-C724-4E7B-AEFD-EDFE1FAC9BF8}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
Namespace Provider 3: mdnsNSP
GUID: {B600E6E9-553B-4A19-8696-335E5C896153}
Filename: C:\Program Files\Bonjour\mdnsNSP.dll
Description: Apple Rendezvous protocol
DB filename: %ProgramFiles%\Rendezvous\bin\mdnsNSP.dll
DB protocol: mdnsNSP
Yeah I know, logs should just go directly to the textbox of the post... I figured this would make the rest of my post easier to read since I'm not even sure yet if this is what you wanted. If it is, great! We just saved ourselves a day of waiting. :P If not, I'll get what you're looking for or I'll do another scan if necessary. As I said, I haven't had any issues since around the third ComboFix run but there could always be some asymptomatic evil still lurking.
Well, off to class, where I will be gone all day and completely miss you when you're active. :slap:
Oh, and for what it's worth, AVG didn't find anything in yesterday's scan either. Sorry I forgot to mention that previously.
Hi,
That's different report. Better run a fresh scan with Spybot and see if it finds anything.
I ran another Spybot scan and it did not find anything this time. Where can I find the log file you want, just for future reference?
It probably requires that you save the results after the scan.
Since Spybot didn't find anything the second time, does that mean we might finally be done here? :) If you want, I can scan again and see if I can save a log.
Yes, I believe we're done here :)
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)
Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.
If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.