Page 1 of 3 123 LastLast
Results 1 to 10 of 22

Thread: Spybot and Hijackthis installed, but blocked.

  1. #1
    Junior Member
    Join Date
    Jun 2009
    Posts
    21

    Default Spybot and Hijackthis installed, but blocked.

    For the past few months my laptop's been completely ridiculous.

    When using search engines like Google or Yahoo, instead of directing me to the the desired site, following links redirects me to some other random, obscure search engine.

    Some other online support forum directed me to download Malware removal programs to "fix" this problem but for the most part it seems I can install these programs, such as Spybot, I just can't run them.

    In browsing this forum I followed a link to the "Before You Post" post and I'm trying to follow the directions, but it's not working out.

    Even starting with the downloading ERUNT part doesn't seen right. It's turns out to be some program called RegCure, and there is no "System Registry" function. That I can see anyway! It this right?

    And then I downloaded the HijackThis program, seemingly installed it correctly, but it too, does not run.

    I had managed to download Ad-Aware (Free) and it's randomly running in the background (and not doing anything at all...) I'm not sure if this affects anything. I also have AVG Free 8.5, which also does random scans, but manages to fix nothing.

    Sorry if this post is too long, I just want to be as specific as possible!

    Do I have too many spyware programs running that it kind of cancels each other out? Should I uninstall them all, then try again?

    And again, sorry to be a bother! I really did try to do all that "Before You Post" stuff to make things easier, it just didn't work!

    And if it's at all convenient, can the solution be written in the simplest terms possible? I admit freely that I'm practically computer illiterate!

    Thank you.

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Download DDS and save it to your desktop from here or here or here.
    Disable any script blocker, and then double click dds.scr to run the tool.
    • When done, DDS will open two (2) logs:
      1. DDS.txt
      2. Attach.txt
    • Save both reports to your desktop. Post them back to your topic.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Junior Member
    Join Date
    Jun 2009
    Posts
    21

    Default

    Hey, I hope I did this right! Not sure if I managed to disable any script blockers (?) but I think it worked out okay. And my zipping skills are total fail, so if the Attach document doesn't work, let me know and I'll post the whole thing straight out. Thank you!



    DDS (Ver_09-06-26.01) - NTFSx86
    Run by School at 14:34:39.93 on 28/06/2009
    Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_03
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3062.2236 [GMT -6:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Zune\ZuneLauncher.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
    svchost.exe
    C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
    C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    c:\WINDOWS\system32\ZuneBusEnum.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\WINDOWS\system32\mqsvc.exe
    C:\WINDOWS\system32\mqtgsvc.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\School\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://www.ualberta.ca/
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: {3B236BEE-8200-421D-919D-CA17D5739D8F} - No File
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
    BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
    uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe"
    uRun: [kell] c:\program files\manson\liser.exe
    mRun: [ehTray] c:\windows\ehome\ehtray.exe
    mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_03\bin\jusched.exe"
    mRun: [igfxtray] c:\windows\system32\igfxtray.exe
    mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
    mRun: [igfxpers] c:\windows\system32\igfxpers.exe
    mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
    mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
    mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe
    mRun: [RecGuard] c:\windows\sminst\RecGuard.exe
    mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
    mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
    mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
    mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
    mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
    mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
    mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop elements 4.0\apdproxy.exe"
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    mRun: [net] "c:\windows\system32\net.net"
    mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    StartupFolder: c:\docume~1\school\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppavi~1.lnk - c:\program files\hewlett-packard\hp pavilion webcam\HPWebcam.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} - hxxp://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/3/d/83d1fe15-fe0f-4bdf-b09c-4e3c49808ec7/LegitCheckControl.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171605677359
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: avgrsstarter - avgrsstx.dll
    Notify: igfxcui - igfxdev.dll
    AppInit_DLLs: c:\progra~1\manson\liser.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\school\applic~1\mozilla\firefox\profiles\ph7vy5nn.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.ualberta.ca/
    FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
    FF - plugin: c:\documents and settings\school\application data\mozilla\firefox\profiles\ph7vy5nn.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-26 64160]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-24 327688]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-11-16 27784]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-24 108552]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-24 298776]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1003344]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    S1 podmenadrv;podmenadrv;\??\c:\program files\podmena\podmena.sys --> c:\program files\podmena\podmena.sys [?]
    S2 podmena;podmena;c:\windows\system32\svchost.exe -k podmena [2006-3-15 14336]
    S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-6-6 61952]

    =============== Created Last 30 ================

    2009-06-26 23:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
    2009-06-26 22:22 15,688 a------- c:\windows\system32\lsdelete.exe
    2009-06-26 22:12 64,160 a------- c:\windows\system32\drivers\Lbd.sys
    2009-06-26 22:08 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
    2009-06-26 22:08 <DIR> --d----- c:\program files\Lavasoft
    2009-06-12 13:02 206 a------- c:\windows\system32\MRT.INI
    2009-06-12 12:57 <DIR> --d----- c:\program files\podmena
    2009-06-12 12:57 2 ----h--- c:\windows\zaponce53290.dat
    2009-06-12 12:57 1 ----h--- c:\windows\bf23567.dat
    2009-06-12 12:57 2 ----h--- c:\windows\zaponce53198.dat
    2009-06-12 12:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\98772646
    2009-06-12 12:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\18762654
    2009-06-12 12:47 106 a------- C:\tj.vbs
    2009-06-12 12:47 <DIR> --dshr-- c:\program files\Manson
    2009-06-12 12:47 2,438 a------- c:\windows\system32\SKYNEThqjlenqs.dat
    2009-06-12 12:47 43,008 a------- c:\windows\system32\SKYNEToieomrhg.dll
    2009-06-12 12:47 68,608 -------- c:\windows\system32\drivers\SKYNETaewenvtl.sys

    ==================== Find3M ====================

    2009-06-24 12:23 327,688 a------- c:\windows\system32\drivers\avgldx86.sys
    2009-06-24 12:23 11,952 a------- c:\windows\system32\avgrsstx.dll
    2009-05-07 09:44 344,064 a------- c:\windows\system32\localspl.dll
    2009-05-07 09:44 344,064 -------- c:\windows\system32\dllcache\localspl.dll
    2009-05-04 22:07 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
    2009-04-28 22:56 827,392 a------- c:\windows\system32\wininet.dll
    2009-04-28 22:56 827,392 -------- c:\windows\system32\dllcache\wininet.dll
    2009-04-28 22:56 233,472 -------- c:\windows\system32\dllcache\webcheck.dll
    2009-04-28 22:56 1,159,680 -------- c:\windows\system32\dllcache\urlmon.dll
    2009-04-28 22:56 671,232 -------- c:\windows\system32\dllcache\mstime.dll
    2009-04-28 22:56 105,984 -------- c:\windows\system32\dllcache\url.dll
    2009-04-28 22:56 102,912 -------- c:\windows\system32\dllcache\occache.dll
    2009-04-28 22:56 44,544 -------- c:\windows\system32\dllcache\pngfilt.dll
    2009-04-28 22:56 3,596,288 -------- c:\windows\system32\dllcache\mshtml.dll
    2009-04-28 22:56 477,696 -------- c:\windows\system32\dllcache\mshtmled.dll
    2009-04-28 22:56 193,024 -------- c:\windows\system32\dllcache\msrating.dll
    2009-04-28 03:05 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
    2009-04-28 03:05 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
    2009-04-24 23:27 636,088 -------- c:\windows\system32\dllcache\iexplore.exe
    2009-04-24 23:26 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
    2009-04-17 03:58 1,846,656 a------- c:\windows\system32\win32k.sys
    2009-04-17 03:58 1,846,656 -------- c:\windows\system32\dllcache\win32k.sys
    2009-04-15 09:26 583,168 a------- c:\windows\system32\rpcrt4.dll
    2009-04-15 09:26 583,168 -------- c:\windows\system32\dllcache\rpcrt4.dll
    2007-10-20 05:07 976 a------- c:\docume~1\school\applic~1\wklnhst.dat
    2006-11-16 15:12 22 a--sh--- c:\windows\sminst\HPCD.sys

    ============= FINISH: 14:36:49.46 ===============

  4. #4
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Zip was properly created


    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:

    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.


    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New dds.txt log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #5
    Junior Member
    Join Date
    Jun 2009
    Posts
    21

    Default

    Hi!

    Okay. So, thank you so much for all your help, but, I swear, I followed the instructions exactly... It just doesn't work! I have no idea why, and it's driving me crazy. Same deal, I can download it, I just can't run it.

    Tried all three links. Did the whole manually-restore-Recovery-Console-drag-and-drop thing. Tried to run it without the Recovery Console installed first. Downloaded one, then again (2), did the drag and drop thing on (2), seemed to start to work, then had Windows inform me that it was a "read only" file... (What?!?)

    At first I thought I was just too impatient, and that maybe it doesn't pop up right away, because when I try to delete it Windows would be like "Hey, this file is currently in use, close it first!" But nope, it just doesn't run.

    Very sorry for the inconvenience! What should I be doing now?

    And sorry for the rambling, I guess I could have just summed it up with a very simple: It just doesn't run.

    By the way, I'm going to be traveling for the next week and half, using random available wireless networks. Is that going to completely screw up everything even more? Or am I going to be okay as long as I don't go on any sketchy websites?

    Should I not be using, letting alone bringing my laptop for field-trips, during this VERY frustrating time?

    Thanks again!

    (Oh, and please let me know if I've overstepped with the problem sharing and the many silly questions, and I'll stop!)

  6. #6
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    It would be recommended to use system as little as possible until infection is cleaned. Let's try following:

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

    Download Combofix*from any of the links below. You must*rename it before saving it. Save it to your desktop.

    Link 1
    Link 2
    Link 3





    --------------------------------------------------------------------

    Double click on Combo-Fix.exe*& follow the prompts (let it install recovery console if asked permission for it).
    • When finished, it will produce a report for you.
    • Please post the C:\ComboFix.txt along with a dds.txt log*so we can continue cleaning the system.


    Note:
    Do not mouseclick combofix's window while it's running. That may cause it to stall
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #7
    Junior Member
    Join Date
    Jun 2009
    Posts
    21

    Default

    Hey,

    Such a simple solution, renaming the file... Wish I knew that before!

    Here's the Combofix, and I ran a new DDS, I hope that's okay, right underneath:

    ComboFix 09-06-29.04 - School 30/06/2009 1:30.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3062.2577 [GMT -6:00]
    Running from: c:\documents and settings\School\Desktop\Combo-Fix.exe
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\podmena
    C:\tj.vbs
    c:\windows\kb913800.exe
    c:\windows\system32\drivers\SKYNETaewenvtl.sys
    c:\windows\system32\drivers\UACrqujoymxenfoewm.sys
    c:\windows\system32\SKYNEThqjlenqs.dat
    c:\windows\system32\SKYNEToieomrhg.dll
    c:\windows\system32\UACfulckvagbsmtkfb.dll
    c:\windows\system32\UAChghfimneeamdbud.log
    c:\windows\system32\uacinit.dll
    c:\windows\system32\UACiriltiqerkwnemh.dll
    c:\windows\system32\UACiydxetfpavbdwyb.dll
    c:\windows\system32\UACkauprqoblpdwwcj.dll
    c:\windows\system32\UAClvlpaltibvpkhjy.log
    c:\windows\system32\UACpesknerlvrsthky.dat
    c:\windows\system32\UACqkwortsnemsglik.log
    c:\windows\system32\uactmp.db
    c:\windows\system32\UACxmantrkykavoopq.db
    c:\windows\system32\UACxyvolhkkvjxpwty.dll
    c:\windows\system32\UACycijubodpkkpeji.dll
    c:\windows\zaponce53198.dat
    c:\windows\zaponce53290.dat
    D:\Autorun.inf
    D:\Desktop.ini

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_UACd.sys
    -------\Legacy_PODMENA
    -------\Legacy_PODMENADRV
    -------\Service_podmena
    -------\Service_podmenadrv
    -------\Service_SKYNETkrcbgmqr


    ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-30 )))))))))))))))))))))))))))))))
    .

    2009-06-28 21:07 . 2009-06-28 21:07 494 ---ha-w- C:\aaw7boot.cmd
    2009-06-28 20:46 . 2009-06-28 20:46 -------- d-----w- c:\documents and settings\School\Local Settings\Application Data\WinZip
    2009-06-27 05:47 . 2009-06-27 09:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-06-27 04:08 . 2009-06-28 21:11 -------- d-----w- c:\program files\Lavasoft
    2009-06-27 04:08 . 2009-06-27 04:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-06-12 18:57 . 2009-06-12 18:57 1 ---h--w- c:\windows\bf23567.dat
    2009-06-12 18:47 . 2009-06-12 19:01 -------- d-----w- c:\documents and settings\All Users\Application Data\98772646
    2009-06-12 18:47 . 2009-06-12 19:01 -------- d-----w- c:\documents and settings\All Users\Application Data\18762654
    2009-06-12 18:47 . 2009-06-27 07:20 -------- d-sh--r- c:\program files\Manson

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-30 06:59 . 2006-11-26 23:14 -------- d-----w- c:\documents and settings\School\Application Data\U3
    2009-06-28 21:29 . 2007-04-03 22:03 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
    2009-06-24 18:23 . 2009-03-25 00:00 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-06-24 18:23 . 2009-03-25 00:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-06-24 18:23 . 2006-11-16 08:32 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-06-24 11:05 . 2006-11-16 19:15 -------- d-----w- c:\program files\Google
    2009-06-23 01:13 . 2006-09-14 05:27 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-06-16 06:41 . 2009-03-24 23:59 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
    2009-06-15 08:36 . 2006-11-23 03:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-05-07 15:44 . 2006-03-16 04:00 344064 ----a-w- c:\windows\system32\localspl.dll
    2009-05-05 04:07 . 2009-03-25 00:00 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-04-29 04:56 . 2006-03-16 04:00 827392 ----a-w- c:\windows\system32\wininet.dll
    2009-04-29 04:55 . 2006-03-16 04:00 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-04-23 03:42 . 2007-01-23 06:00 1324 ----a-w- c:\windows\system32\d3d9caps.dat
    2009-04-17 09:58 . 2006-03-16 04:00 1846656 ----a-w- c:\windows\system32\win32k.sys
    2009-04-15 15:26 . 2006-03-16 04:00 583168 ----a-w- c:\windows\system32\rpcrt4.dll
    2006-11-16 21:12 . 2006-11-16 21:12 22 --sha-w- c:\windows\SMINST\HPCD.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-03-16 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-22 68856]
    "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
    "CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 700416]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
    "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
    "igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-22 94208]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-22 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-22 118784]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
    "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
    "Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
    "RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-15 208952]
    "IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2006-03-15 44032]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-15 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344]
    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-09-13 160160]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-24 1948440]
    "MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2007-07-06 177152]
    "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-06-02 61952]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]

    c:\documents and settings\School\Start Menu\Programs\Startup\
    OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
    HP Pavilion Webcam Tray Icon.lnk - c:\program files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe [2006-11-16 102400]
    HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-06-24 18:23 11952 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\system32\\mqsvc.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\StubInstaller.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\MSN Messenger\\livecall.exe"=
    "c:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "8085:TCP"= 8085:TCP:podmena

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [24/03/2009 6:00 PM 327688]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [24/03/2009 6:00 PM 108552]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [24/03/2009 5:59 PM 298776]
    R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 7:19 PM 13592]
    S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [06/06/2006 2:39 PM 61952]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-06-01 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

    2009-06-30 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-net - c:\windows\system32\net.net
    Notify-WgaLogon - (no file)


    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://www.ualberta.ca/
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    FF - ProfilePath - c:\documents and settings\School\Application Data\Mozilla\Firefox\Profiles\ph7vy5nn.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.ualberta.ca/
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
    FF - plugin: c:\documents and settings\School\Application Data\Mozilla\Firefox\Profiles\ph7vy5nn.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-30 01:37
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????L?@? ???PP??????`?@?????L?@

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(2356)
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\msdtc.exe
    c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\CTSVCCDA.EXE
    c:\windows\ehome\ehrecvr.exe
    c:\windows\ehome\ehSched.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\windows\system32\ZuneBusEnum.exe
    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
    c:\windows\ehome\mcrdsvc.exe
    c:\windows\system32\mqsvc.exe
    c:\windows\system32\mqtgsvc.exe
    c:\windows\system32\dllhost.exe
    c:\windows\ehome\ehmsas.exe
    c:\program files\AVG\AVG8\avgtray.exe
    c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\program files\Java\jre1.6.0_03\bin\jucheck.exe
    .
    **************************************************************************
    .
    Completion time: 2009-06-30 1:42 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-06-30 07:42

    Pre-Run: 34,024,603,648 bytes free
    Post-Run: 35,127,242,752 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

    231 --- E O F --- 2009-06-30 01:18




    DDS (Ver_09-06-26.01) - NTFSx86
    Run by School at 1:54:24.25 on 30/06/2009
    Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_03
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3062.2398 [GMT -6:00]

    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    c:\WINDOWS\system32\ZuneBusEnum.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\WINDOWS\system32\mqsvc.exe
    C:\WINDOWS\system32\mqtgsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Zune\ZuneLauncher.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
    C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\School\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://www.ualberta.ca/
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
    BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
    uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe"
    mRun: [ehTray] c:\windows\ehome\ehtray.exe
    mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_03\bin\jusched.exe"
    mRun: [igfxtray] c:\windows\system32\igfxtray.exe
    mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
    mRun: [igfxpers] c:\windows\system32\igfxpers.exe
    mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
    mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
    mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe
    mRun: [RecGuard] c:\windows\sminst\RecGuard.exe
    mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
    mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
    mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
    mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
    mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
    mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop elements 4.0\apdproxy.exe"
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    StartupFolder: c:\docume~1\school\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppavi~1.lnk - c:\program files\hewlett-packard\hp pavilion webcam\HPWebcam.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} - hxxp://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/3/d/83d1fe15-fe0f-4bdf-b09c-4e3c49808ec7/LegitCheckControl.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171605677359
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: avgrsstarter - avgrsstx.dll
    Notify: igfxcui - igfxdev.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\school\applic~1\mozilla\firefox\profiles\ph7vy5nn.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.ualberta.ca/
    FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
    FF - plugin: c:\documents and settings\school\application data\mozilla\firefox\profiles\ph7vy5nn.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-24 327688]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-11-16 27784]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-24 108552]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-24 298776]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-6-6 61952]

    =============== Created Last 30 ================

    2009-06-30 01:41 <DIR> --d----- c:\windows\system32\dllcache\cache
    2009-06-30 01:22 <DIR> a-dshr-- C:\cmdcons
    2009-06-30 01:20 161,792 a------- c:\windows\SWREG.exe
    2009-06-30 01:20 155,136 a------- c:\windows\PEV.exe
    2009-06-30 01:20 98,816 a------- c:\windows\sed.exe
    2009-06-28 15:29 <DIR> --d----- c:\windows\system32\appmgmt
    2009-06-28 15:07 494 a---h--- C:\aaw7boot.cmd
    2009-06-26 23:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
    2009-06-26 22:08 <DIR> --d----- c:\program files\Lavasoft
    2009-06-12 13:02 206 a------- c:\windows\system32\MRT.INI
    2009-06-12 12:57 1 ----h--- c:\windows\bf23567.dat
    2009-06-12 12:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\98772646
    2009-06-12 12:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\18762654
    2009-06-12 12:47 <DIR> --dshr-- c:\program files\Manson

    ==================== Find3M ====================

    2009-06-24 12:23 327,688 a------- c:\windows\system32\drivers\avgldx86.sys
    2009-06-24 12:23 11,952 a------- c:\windows\system32\avgrsstx.dll
    2009-05-07 09:44 344,064 a------- c:\windows\system32\localspl.dll
    2009-05-07 09:44 344,064 -------- c:\windows\system32\dllcache\localspl.dll
    2009-05-04 22:07 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
    2009-04-28 22:56 827,392 a------- c:\windows\system32\wininet.dll
    2009-04-28 22:56 827,392 a------- c:\windows\system32\dllcache\cache\wininet.dll
    2009-04-28 22:56 827,392 -------- c:\windows\system32\dllcache\wininet.dll
    2009-04-28 22:56 233,472 -------- c:\windows\system32\dllcache\webcheck.dll
    2009-04-28 22:56 1,159,680 -------- c:\windows\system32\dllcache\urlmon.dll
    2009-04-28 22:56 671,232 -------- c:\windows\system32\dllcache\mstime.dll
    2009-04-28 22:56 105,984 -------- c:\windows\system32\dllcache\url.dll
    2009-04-28 22:56 102,912 -------- c:\windows\system32\dllcache\occache.dll
    2009-04-28 22:56 44,544 -------- c:\windows\system32\dllcache\pngfilt.dll
    2009-04-28 22:56 3,596,288 -------- c:\windows\system32\dllcache\mshtml.dll
    2009-04-28 22:56 477,696 -------- c:\windows\system32\dllcache\mshtmled.dll
    2009-04-28 22:56 193,024 -------- c:\windows\system32\dllcache\msrating.dll
    2009-04-28 03:05 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
    2009-04-28 03:05 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
    2009-04-24 23:27 636,088 -------- c:\windows\system32\dllcache\iexplore.exe
    2009-04-24 23:26 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
    2009-04-17 03:58 1,846,656 a------- c:\windows\system32\win32k.sys
    2009-04-17 03:58 1,846,656 -------- c:\windows\system32\dllcache\win32k.sys
    2009-04-15 09:26 583,168 a------- c:\windows\system32\rpcrt4.dll
    2009-04-15 09:26 583,168 -------- c:\windows\system32\dllcache\rpcrt4.dll
    2007-10-20 05:07 976 a------- c:\docume~1\school\applic~1\wklnhst.dat
    2006-11-16 15:12 22 a--sh--- c:\windows\sminst\HPCD.sys

    ============= FINISH: 1:54:34.90 ===============


    Thanks!

    Oh, and if I don't get back to you, or do the next step right away, that probably means I've decided to leave my laptop at home, to be on the safe side, so I won't be able to do any more stuff for the next 10 days or so.

    When I get back can I just continue on on this thread doing the next step, or do I have to post a new one?

    Thanks again!

  8. #8
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi again,


    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    File::
    c:\windows\bf23567.dat
    c:\StubInstaller.exe
    
    Folder::
    c:\documents and settings\All Users\Application Data\98772646
    c:\documents and settings\All Users\Application Data\18762654
    c:\program files\Manson
    c:\Program Files\LimeWire
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=-
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\StubInstaller.exe"=-
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=-

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.


    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.


    Uninstall old Adobe Reader versions and get the latest one (9.1 + 9.1.2 update) here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.


    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 14.
    • Click the
      Download
      button to the right.
    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u14-windows-i586-p.exe to install the newest version. Uncheck MSN toolbar if it's offered there.




    Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    If you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    If you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.


    Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


    Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.


    When I get back can I just continue on on this thread doing the next step, or do I have to post a new one?
    I'll monitor this topic for two weeks and if you haven't replied back then I'll archive it. You may send me a message if you of some reason are not able to reply back within that time
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  9. #9
    Junior Member
    Join Date
    Jun 2009
    Posts
    21

    Default

    Hi!

    Here are the logs you asked for!

    ComboFix 09-07-09.08 - School 11/07/2009 6:37.2.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3062.2468 [GMT -6:00]
    Running from: c:\documents and settings\School\Desktop\Combo-Fix.exe
    Command switches used :: c:\documents and settings\School\Desktop\CFScript.txt
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    FILE ::
    "c:\StubInstaller.exe"
    "c:\windows\bf23567.dat"
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\18762654
    c:\documents and settings\All Users\Application Data\18762654\18762654.glu
    c:\documents and settings\All Users\Application Data\18762654\pc18762654cnf
    c:\documents and settings\All Users\Application Data\18762654\pc18762654ins
    c:\documents and settings\All Users\Application Data\98772646
    c:\documents and settings\All Users\Application Data\98772646.ini
    C:\Microsoft
    c:\microsoft\IMJP8_1\imjp81u.dic
    c:\program files\LimeWire
    c:\program files\LimeWire\.NetworkShare\LimeWirePackedJars4.12.11.7z
    c:\program files\LimeWire\.NetworkShare\LimeWireWin4.12.11.exe
    c:\program files\LimeWire\.NetworkShare\LimeWireWin4.16.6.exe
    c:\program files\LimeWire\COPYING
    c:\program files\LimeWire\data.ser
    c:\program files\LimeWire\hs_err_pid1416.log
    c:\program files\LimeWire\hs_err_pid2036.log
    c:\program files\LimeWire\hs_err_pid2152.log
    c:\program files\LimeWire\hs_err_pid2276.log
    c:\program files\LimeWire\hs_err_pid228.log
    c:\program files\LimeWire\hs_err_pid2652.log
    c:\program files\LimeWire\hs_err_pid2672.log
    c:\program files\LimeWire\hs_err_pid2708.log
    c:\program files\LimeWire\hs_err_pid2716.log
    c:\program files\LimeWire\hs_err_pid3044.log
    c:\program files\LimeWire\hs_err_pid3084.log
    c:\program files\LimeWire\hs_err_pid3548.log
    c:\program files\LimeWire\hs_err_pid3656.log
    c:\program files\LimeWire\hs_err_pid4072.log
    c:\program files\LimeWire\hs_err_pid4744.log
    c:\program files\LimeWire\hs_err_pid4804.log
    c:\program files\LimeWire\hs_err_pid4848.log
    c:\program files\LimeWire\hs_err_pid4952.log
    c:\program files\LimeWire\hs_err_pid5048.log
    c:\program files\LimeWire\hs_err_pid5436.log
    c:\program files\LimeWire\hs_err_pid5784.log
    c:\program files\LimeWire\hs_err_pid5848.log
    c:\program files\LimeWire\hs_err_pid5940.log
    c:\program files\LimeWire\hs_err_pid5984.log
    c:\program files\LimeWire\hs_err_pid6088.log
    c:\program files\LimeWire\hs_err_pid896.log
    c:\program files\LimeWire\hs_err_pid920.log
    c:\program files\LimeWire\hs_err_pid924.log
    c:\program files\LimeWire\inspection.props
    c:\program files\LimeWire\install.log
    c:\program files\LimeWire\language.prop
    c:\program files\LimeWire\lib\aopalliance.jar
    c:\program files\LimeWire\lib\clink.jar
    c:\program files\LimeWire\lib\commons-httpclient.jar
    c:\program files\LimeWire\lib\commons-logging.jar
    c:\program files\LimeWire\lib\commons-net.jar
    c:\program files\LimeWire\lib\commons-pool.jar
    c:\program files\LimeWire\lib\daap.jar
    c:\program files\LimeWire\lib\forms.jar
    c:\program files\LimeWire\lib\foxtrot.jar
    c:\program files\LimeWire\lib\gettext-commons.jar
    c:\program files\LimeWire\lib\guice-1.0.jar
    c:\program files\LimeWire\lib\hashes
    c:\program files\LimeWire\lib\httpcore-nio.jar
    c:\program files\LimeWire\lib\httpcore.jar
    c:\program files\LimeWire\lib\icu4j.jar
    c:\program files\LimeWire\lib\id3v2.jar
    c:\program files\LimeWire\lib\jcraft.jar
    c:\program files\LimeWire\lib\jdic.dll
    c:\program files\LimeWire\lib\jdic.jar
    c:\program files\LimeWire\lib\jdic_stub.jar
    c:\program files\LimeWire\lib\jflac.jar
    c:\program files\LimeWire\lib\jl.jar
    c:\program files\LimeWire\lib\jmdns.jar
    c:\program files\LimeWire\lib\jogg.jar
    c:\program files\LimeWire\lib\jorbis.jar
    c:\program files\LimeWire\lib\LimeWire.ico
    c:\program files\LimeWire\lib\LimeWire.jar
    c:\program files\LimeWire\lib\log4j.jar
    c:\program files\LimeWire\lib\log4j.properties
    c:\program files\LimeWire\lib\looks.jar
    c:\program files\LimeWire\lib\messages.jar
    c:\program files\LimeWire\lib\mp3spi.jar
    c:\program files\LimeWire\lib\ProgressTabs.jar
    c:\program files\LimeWire\lib\swt.jar
    c:\program files\LimeWire\lib\SystemUtilities.dll
    c:\program files\LimeWire\lib\SystemUtilitiesA.dll
    c:\program files\LimeWire\lib\themes.jar
    c:\program files\LimeWire\lib\tray.dll
    c:\program files\LimeWire\lib\tritonus.jar
    c:\program files\LimeWire\lib\vorbisspi.jar
    c:\program files\LimeWire\LimeWire On Startup.lnk
    c:\program files\LimeWire\LimeWire.exe
    c:\program files\LimeWire\LimeWire.ico
    c:\program files\LimeWire\pmf.ico
    c:\program files\LimeWire\root\magnet10\badge.img
    c:\program files\LimeWire\root\magnet10\canHandle.img
    c:\program files\LimeWire\root\magnet10\limewire.gif
    c:\program files\LimeWire\root\magnet10\options.js
    c:\program files\LimeWire\root\magnet10\silentdetect.js
    c:\program files\LimeWire\SOURCE
    c:\program files\LimeWire\spacer.gif
    c:\program files\LimeWire\uninstall.exe
    c:\program files\LimeWire\unpack.log
    c:\program files\Manson
    c:\StubInstaller.exe
    c:\windows\bf23567.dat
    c:\windows\Installer\249f32c.msp
    c:\windows\Installer\6c6a55.msp

    .
    ((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
    .

    2009-06-28 21:07 . 2009-06-28 21:07 494 ---ha-w- C:\aaw7boot.cmd
    2009-06-28 20:46 . 2009-06-28 20:46 -------- d-----w- c:\documents and settings\School\Local Settings\Application Data\WinZip
    2009-06-27 05:47 . 2009-06-27 09:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-06-27 04:08 . 2009-06-28 21:11 -------- d-----w- c:\program files\Lavasoft
    2009-06-27 04:08 . 2009-06-27 04:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-30 06:59 . 2006-11-26 23:14 -------- d-----w- c:\documents and settings\School\Application Data\U3
    2009-06-28 21:29 . 2007-04-03 22:03 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
    2009-06-24 18:23 . 2009-03-25 00:00 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-06-24 18:23 . 2009-03-25 00:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-06-24 18:23 . 2006-11-16 08:32 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-06-24 11:05 . 2006-11-16 19:15 -------- d-----w- c:\program files\Google
    2009-06-23 01:13 . 2006-09-14 05:27 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-06-16 06:41 . 2009-03-24 23:59 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
    2009-06-15 08:36 . 2006-11-23 03:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-05-07 15:44 . 2006-03-16 04:00 344064 ----a-w- c:\windows\system32\localspl.dll
    2009-05-05 04:07 . 2009-03-25 00:00 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-04-29 04:56 . 2006-03-16 04:00 827392 ----a-w- c:\windows\system32\wininet.dll
    2009-04-29 04:55 . 2006-03-16 04:00 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-04-23 03:42 . 2007-01-23 06:00 1324 ----a-w- c:\windows\system32\d3d9caps.dat
    2009-04-17 09:58 . 2006-03-16 04:00 1846656 ----a-w- c:\windows\system32\win32k.sys
    2009-04-15 15:26 . 2006-03-16 04:00 583168 ----a-w- c:\windows\system32\rpcrt4.dll
    2006-11-16 21:12 . 2006-11-16 21:12 22 --sha-w- c:\windows\SMINST\HPCD.sys
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-06-30_07.37.23 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2006-11-23 03:23 . 2006-11-23 03:23 48128 c:\windows\Installer\e6441e.msi
    + 2008-10-09 03:45 . 2008-10-09 03:45 31232 c:\windows\Installer\a0eb13.msi
    + 2008-10-09 03:45 . 2008-10-09 03:45 31232 c:\windows\Installer\a0eb0d.msi
    + 2006-09-14 07:19 . 2006-09-14 07:19 83968 c:\windows\Installer\386d0.msi
    + 2009-06-24 11:05 . 2009-06-24 11:05 24064 c:\windows\Installer\140320.msi
    + 2006-11-23 03:24 . 2006-11-23 03:24 501248 c:\windows\Installer\e64473.msi
    + 2006-11-23 03:24 . 2006-11-23 03:24 501248 c:\windows\Installer\e6445b.msi
    + 2006-11-23 03:24 . 2006-11-23 03:24 506880 c:\windows\Installer\e64455.msi
    + 2006-11-23 03:24 . 2006-11-23 03:24 516608 c:\windows\Installer\e6444d.msi
    + 2006-11-23 03:23 . 2006-11-23 03:23 513024 c:\windows\Installer\e6443c.msi
    + 2006-11-23 03:23 . 2006-11-23 03:23 501248 c:\windows\Installer\e6442a.msi
    + 2006-11-23 03:22 . 2006-11-23 03:22 501248 c:\windows\Installer\e64401.msi
    + 2006-11-16 19:14 . 2006-11-16 19:14 188416 c:\windows\Installer\d138d.msi
    + 2007-10-15 05:44 . 2007-10-15 05:44 324608 c:\windows\Installer\c8da91.msp
    + 2007-10-15 05:46 . 2007-10-15 05:46 324608 c:\windows\Installer\c8da8a.msp
    + 2008-01-02 19:06 . 2008-01-02 19:06 106496 c:\windows\Installer\b130e2.msi
    + 2008-10-09 03:43 . 2008-10-09 03:43 625664 c:\windows\Installer\a0eb07.msi
    + 2007-02-01 06:10 . 2007-02-01 06:10 697856 c:\windows\Installer\7470c3.msi
    + 2007-02-16 06:04 . 2007-02-16 06:04 189952 c:\windows\Installer\620fd.msi
    + 2007-08-18 03:07 . 2007-08-18 03:07 431104 c:\windows\Installer\5802c9c.msi
    + 2009-06-27 04:08 . 2009-06-27 04:08 236032 c:\windows\Installer\422c63.msi
    + 2006-06-29 18:23 . 2006-06-29 18:23 366592 c:\windows\Installer\3b9fe.msi
    + 2006-06-29 18:23 . 2006-06-29 18:23 363008 c:\windows\Installer\3b9f9.msi
    + 2006-09-14 07:19 . 2006-09-14 07:19 112128 c:\windows\Installer\386d5.msi
    + 2006-09-14 07:01 . 2006-09-14 07:01 335872 c:\windows\Installer\3866f.msi
    + 2006-09-14 06:56 . 2006-09-14 06:56 903168 c:\windows\Installer\38651.msi
    + 2009-05-27 00:53 . 2009-05-27 00:53 579072 c:\windows\Installer\2fb8b.msp
    + 2006-09-14 07:31 . 2006-09-14 07:31 440320 c:\windows\Installer\2cea10.msi
    + 2006-11-16 20:10 . 2006-11-16 20:10 428544 c:\windows\Installer\27a62c.msi
    + 2008-11-12 06:37 . 2008-11-12 06:37 432640 c:\windows\Installer\21769d1.msi
    + 2007-05-10 06:50 . 2007-05-10 06:50 470528 c:\windows\Installer\1fa4146.msi
    + 2007-12-20 04:44 . 2007-12-20 04:44 282624 c:\windows\Installer\1dea879.msi
    + 2007-08-21 01:41 . 2007-08-21 01:41 282624 c:\windows\Installer\1b6747.msi
    + 2006-06-29 18:49 . 2006-06-29 18:49 221184 c:\windows\Installer\1af85e.msi
    + 2006-06-29 18:49 . 2006-06-29 18:49 239104 c:\windows\Installer\1af858.msi
    + 2006-06-29 18:49 . 2006-06-29 18:49 237568 c:\windows\Installer\1af852.msi
    + 2006-06-29 18:49 . 2006-06-29 18:49 238080 c:\windows\Installer\1af84d.msi
    + 2006-06-29 18:49 . 2006-06-29 18:49 238080 c:\windows\Installer\1af848.msi
    + 2006-06-29 18:49 . 2006-06-29 18:49 238080 c:\windows\Installer\1af843.msi
    + 2006-06-29 18:49 . 2006-06-29 18:49 120832 c:\windows\Installer\1af83b.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 471552 c:\windows\Installer\1af836.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 664064 c:\windows\Installer\1af82d.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 121344 c:\windows\Installer\1af821.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 239104 c:\windows\Installer\1af81c.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 239104 c:\windows\Installer\1af816.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 542208 c:\windows\Installer\1af810.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 245248 c:\windows\Installer\1af73c.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 324096 c:\windows\Installer\1af736.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 250368 c:\windows\Installer\1af72f.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 239616 c:\windows\Installer\1af72a.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 250368 c:\windows\Installer\1af724.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 240128 c:\windows\Installer\1af71e.msi
    + 2006-06-29 18:48 . 2006-06-29 18:48 239104 c:\windows\Installer\1af719.msi
    + 2006-06-29 18:47 . 2006-06-29 18:47 260096 c:\windows\Installer\1af6f2.msi
    + 2006-06-29 18:47 . 2006-06-29 18:47 422912 c:\windows\Installer\1af6ed.msi
    + 2006-06-29 18:47 . 2006-06-29 18:47 121344 c:\windows\Installer\1af6e8.msi
    + 2006-06-29 18:46 . 2006-06-29 18:46 227840 c:\windows\Installer\154ef6.msi
    + 2006-06-29 18:46 . 2006-06-29 18:46 838144 c:\windows\Installer\154eef.msi
    + 2006-06-29 18:44 . 2006-06-29 18:44 226304 c:\windows\Installer\154e73.msi
    + 2006-06-29 18:19 . 2006-06-29 18:19 264704 c:\windows\Installer\13db4.msi
    + 2009-03-24 23:58 . 2009-03-24 23:58 337408 c:\windows\Installer\10ac441.msi
    + 2006-03-16 04:00 . 2006-03-16 04:00 1326080 c:\windows\system32\webfldrs.msi
    + 2007-05-25 18:08 . 2007-05-25 18:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp
    + 2009-02-07 05:31 . 2009-02-07 05:31 5047808 c:\windows\Installer\ef52fd.msp
    + 2006-11-23 03:25 . 2006-11-23 03:25 1640960 c:\windows\Installer\e64479.msi
    + 2006-11-23 03:24 . 2006-11-23 03:24 1652736 c:\windows\Installer\e6446d.msi
    + 2006-11-23 03:24 . 2006-11-23 03:24 1652736 c:\windows\Installer\e64467.msi
    + 2006-11-23 03:24 . 2006-11-23 03:24 1652736 c:\windows\Installer\e64461.msi
    + 2006-11-23 03:23 . 2006-11-23 03:23 2319872 c:\windows\Installer\e64430.msi
    + 2006-11-23 03:23 . 2006-11-23 03:23 1647616 c:\windows\Installer\e64424.msi
    + 2006-11-23 03:23 . 2006-11-23 03:23 1640960 c:\windows\Installer\e64414.msi
    + 2006-11-23 03:23 . 2006-11-23 03:23 2022912 c:\windows\Installer\e6440e.msi
    + 2006-11-23 03:22 . 2006-11-23 03:22 1713152 c:\windows\Installer\e64407.msi
    + 2006-11-23 03:22 . 2006-11-23 03:22 2397184 c:\windows\Installer\e643fb.msi
    + 2007-10-15 05:43 . 2007-10-15 05:43 5749760 c:\windows\Installer\c8da66.msp
    + 2007-02-27 23:13 . 2007-02-27 23:13 3358720 c:\windows\Installer\c67ae.msp
    + 2008-01-02 19:11 . 2008-01-02 19:11 4669952 c:\windows\Installer\b130ea.msi
    + 2009-01-08 03:25 . 2009-01-08 03:25 5046784 c:\windows\Installer\aabc84.msp
    + 2007-01-30 01:23 . 2007-01-30 01:23 3361280 c:\windows\Installer\a6a41d.msp
    + 2008-10-09 03:38 . 2008-10-09 03:38 2109440 c:\windows\Installer\9bd1ff.msi
    + 2008-02-15 14:54 . 2008-02-15 14:54 9736192 c:\windows\Installer\8d79f8.msp
    + 2008-03-17 23:55 . 2008-03-17 23:55 5049344 c:\windows\Installer\8d79cb.msp
    + 2008-02-25 21:08 . 2008-02-25 21:08 5050368 c:\windows\Installer\822d75.msp
    + 2007-10-28 17:53 . 2007-10-28 17:53 5047808 c:\windows\Installer\672079.msp
    + 2007-06-17 07:18 . 2007-06-17 07:18 5050368 c:\windows\Installer\5f17e4.msp
    + 2007-05-29 04:01 . 2007-05-29 04:01 4597760 c:\windows\Installer\5f17cd.msp
    + 2007-06-01 21:54 . 2007-06-01 21:54 9626624 c:\windows\Installer\5f1786.msp
    + 2007-07-26 17:27 . 2007-07-26 17:27 5053440 c:\windows\Installer\5802cb2.msp
    + 2007-07-21 19:26 . 2007-07-21 19:26 7574016 c:\windows\Installer\5802c93.msp
    + 2008-04-12 00:48 . 2008-04-12 00:48 6774272 c:\windows\Installer\506fb.msp
    + 2008-07-17 01:01 . 2008-07-17 01:01 5110272 c:\windows\Installer\506e2.msp
    + 2007-10-01 03:12 . 2007-10-01 03:12 5052416 c:\windows\Installer\500f42.msp
    + 2007-03-31 04:20 . 2007-03-31 04:20 5800960 c:\windows\Installer\4b3e9.msp
    + 2007-03-27 22:15 . 2007-03-27 22:15 8395776 c:\windows\Installer\4b3d2.msp
    + 2008-04-12 00:08 . 2008-04-12 00:08 6302720 c:\windows\Installer\47b41.msp
    + 2008-04-26 02:14 . 2008-04-26 02:14 5052928 c:\windows\Installer\47b26.msp
    + 2008-04-18 20:56 . 2008-04-18 20:56 6215680 c:\windows\Installer\47b0f.msp
    + 2008-06-16 06:37 . 2008-06-16 06:37 1440256 c:\windows\Installer\45f81a.msi
    + 2008-11-13 09:57 . 2008-11-13 09:57 5099520 c:\windows\Installer\41ead.msp
    + 2008-10-20 17:18 . 2008-10-20 17:18 6474240 c:\windows\Installer\41e96.msp
    + 2006-09-14 07:06 . 2006-09-14 07:06 1327616 c:\windows\Installer\386a8.msi
    + 2006-09-14 07:04 . 2006-09-14 07:04 3037184 c:\windows\Installer\38675.msi
    + 2006-09-14 06:59 . 2006-09-14 06:59 4806656 c:\windows\Installer\3865e.msi
    + 2007-09-01 03:58 . 2007-09-01 03:58 5054976 c:\windows\Installer\32ef6.msp
    + 2009-05-04 13:46 . 2009-05-04 13:46 8299008 c:\windows\Installer\2fbeb.msp
    + 2009-05-04 13:47 . 2009-05-04 13:47 9124864 c:\windows\Installer\2fbd3.msp
    + 2009-04-24 18:30 . 2009-04-24 18:30 2583552 c:\windows\Installer\2fbbb.msp
    + 2009-05-07 15:17 . 2009-05-07 15:17 5026816 c:\windows\Installer\2fba2.msp
    + 2009-04-24 18:29 . 2009-04-24 18:29 9013760 c:\windows\Installer\2fb74.msp
    + 2008-06-05 19:56 . 2008-06-05 19:56 5111808 c:\windows\Installer\2c71ed5.msp
    + 2009-02-26 01:08 . 2009-02-26 01:08 8311808 c:\windows\Installer\2a2ca.msp
    + 2009-03-28 15:50 . 2009-03-28 15:50 5025792 c:\windows\Installer\2a2b4.msp
    + 2008-11-20 21:48 . 2008-11-20 21:48 5097472 c:\windows\Installer\297349.msp
    + 2007-11-23 01:23 . 2007-11-23 01:23 5051904 c:\windows\Installer\283e1.msp
    + 2008-06-30 08:00 . 2008-06-30 08:00 1247744 c:\windows\Installer\26463c.msi
    + 2006-06-29 18:21 . 2006-06-29 18:21 3443712 c:\windows\Installer\22b52.msi
    + 2008-10-20 17:19 . 2008-10-20 17:19 5100032 c:\windows\Installer\21769fe.msp
    + 2007-04-09 04:32 . 2007-04-09 04:32 5131264 c:\windows\Installer\1fa4173.msp
    + 2007-03-31 04:21 . 2007-03-31 04:21 3886080 c:\windows\Installer\1fa4111.msp
    + 2007-03-31 04:17 . 2007-03-31 04:17 9589248 c:\windows\Installer\1fa40f9.msp
    + 2008-08-20 20:37 . 2008-08-20 20:37 5107712 c:\windows\Installer\1bf0756.msp
    + 2008-05-21 06:45 . 2008-05-21 06:45 5246976 c:\windows\Installer\1bf0711.msp
    + 2006-06-29 18:48 . 2006-06-29 18:48 1730048 c:\windows\Installer\1af714.msi
    + 2008-01-29 01:09 . 2008-01-29 01:09 5055488 c:\windows\Installer\175a509.msp
    + 2006-11-16 08:48 . 2006-11-16 08:48 1149952 c:\windows\Installer\15dc24.msi
    + 2007-03-24 21:57 . 2007-03-24 21:57 5135360 c:\windows\Installer\15a28ff.msp
    + 2007-03-27 22:14 . 2007-03-27 22:14 5566464 c:\windows\Installer\15a28e8.msp
    + 2006-06-29 18:44 . 2006-06-29 18:44 1143808 c:\windows\Installer\154e6d.msi
    + 2006-06-29 18:44 . 2006-06-29 18:44 1150464 c:\windows\Installer\154de4.msi
    + 2006-06-29 18:44 . 2006-06-29 18:44 1142272 c:\windows\Installer\154d5b.msi
    + 2006-06-29 18:41 . 2006-06-29 18:41 5864960 c:\windows\Installer\154d54.msp
    + 2009-04-24 18:28 . 2009-04-24 18:28 4450816 c:\windows\Installer\1155884.msp
    + 2008-12-16 05:43 . 2008-12-16 05:43 3762688 c:\windows\Installer\114c110.msi
    + 2008-12-16 05:43 . 2008-12-16 05:43 1652224 c:\windows\Installer\114c10c.msi
    + 2008-12-16 05:42 . 2008-12-16 05:42 8989696 c:\windows\Installer\114c106.msi
    + 2008-12-16 05:41 . 2008-12-16 05:41 1549312 c:\windows\Installer\114bed3.msi
    + 2008-12-16 05:41 . 2008-12-16 05:41 3152384 c:\windows\Installer\114be84.msi
    + 2008-09-02 17:42 . 2008-09-02 17:42 5104640 c:\windows\Installer\1133ca6.msp
    + 2006-11-16 18:59 . 2006-06-29 18:49 12125696 c:\windows\system32\config\systemprofile\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060}\J2SE Runtime Environment 5.0 Update 6.msi
    + 2005-09-23 13:48 . 2005-09-23 13:48 24863744 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\netfx.msi
    + 2007-02-01 06:10 . 2007-01-19 20:20 16633344 c:\windows\Installer\MSN Messenger 8.1.0178\MsnMsgs.Msi
    + 2006-11-27 02:39 . 2006-07-30 03:38 15524352 c:\windows\Installer\MSN Messenger 8.0.0812\MsnMsgs.Msi
    + 2006-11-23 03:34 . 2006-11-23 03:34 18181632 c:\windows\Installer\e65386.msi
    + 2007-10-15 05:43 . 2007-10-15 05:43 12743168 c:\windows\Installer\c8da78.msp
    + 2007-10-15 05:43 . 2007-10-15 05:43 21981184 c:\windows\Installer\c8da1e.msp
    + 2008-01-02 19:09 . 2008-01-02 19:09 13121024 c:\windows\Installer\b130e3.msi
    + 2008-01-02 19:06 . 2008-01-02 19:06 10113024 c:\windows\Installer\b130e0.msi
    + 2008-01-29 00:07 . 2008-01-29 00:07 19034624 c:\windows\Installer\8d79e2.msp
    + 2008-02-25 21:07 . 2008-02-25 21:07 11772416 c:\windows\Installer\822dcb.msp
    + 2008-01-29 00:09 . 2008-01-29 00:09 11896320 c:\windows\Installer\822db4.msp
    + 2008-01-29 00:10 . 2008-01-29 00:10 14201344 c:\windows\Installer\822d9c.msp
    + 2007-06-01 21:55 . 2007-06-01 21:55 10824704 c:\windows\Installer\5f1801.msp
    + 2007-07-11 04:04 . 2007-07-11 04:04 15256576 c:\windows\Installer\5f17b6.msp
    + 2007-06-01 21:53 . 2007-06-01 21:53 10255360 c:\windows\Installer\5f179d.msp
    + 2008-07-03 17:36 . 2008-07-03 17:36 11937792 c:\windows\Installer\50729.msp
    + 2008-07-03 17:37 . 2008-07-03 17:37 11759104 c:\windows\Installer\50712.msp
    + 2008-04-12 00:07 . 2008-04-12 00:07 13257728 c:\windows\Installer\47b5a.msp
    + 2008-10-20 17:22 . 2008-10-20 17:22 11758592 c:\windows\Installer\41ef3.msp
    + 2008-10-20 17:21 . 2008-10-20 17:21 11937280 c:\windows\Installer\41edc.msp
    + 2008-10-20 17:16 . 2008-10-20 17:16 13211648 c:\windows\Installer\41ec5.msp
    + 2006-06-29 18:21 . 2006-06-29 18:21 19210240 c:\windows\Installer\3b9f4.msp
    + 2006-09-14 07:06 . 2006-09-14 07:06 10180608 c:\windows\Installer\386be.msi
    + 2008-05-21 07:30 . 2008-05-21 07:30 14308864 c:\windows\Installer\2bc07.msp
    + 2009-02-26 01:05 . 2009-02-26 01:05 11840000 c:\windows\Installer\23c2394.msp
    + 2009-02-26 01:07 . 2009-02-26 01:07 11646464 c:\windows\Installer\23c237d.msp
    + 2008-09-24 19:05 . 2008-09-24 19:05 16381440 c:\windows\Installer\21769e7.msp
    + 2007-04-22 02:16 . 2007-04-22 02:16 12490752 c:\windows\Installer\1fa415c.msp
    + 2007-03-31 04:22 . 2007-03-31 04:22 10125824 c:\windows\Installer\1fa413f.msp
    + 2007-03-31 04:19 . 2007-03-31 04:19 10893312 c:\windows\Installer\1fa4128.msp
    + 2009-05-04 13:49 . 2009-05-04 13:49 10955776 c:\windows\Installer\1ca5c8.msp
    + 2008-08-11 17:51 . 2008-08-11 17:51 15916544 c:\windows\Installer\1bf073f.msp
    + 2008-08-11 17:49 . 2008-08-11 17:49 22457344 c:\windows\Installer\1bf0728.msp
    + 2008-07-30 05:20 . 2008-07-30 05:20 11767296 c:\windows\Installer\1133c8f.msp
    + 2008-07-30 05:18 . 2008-07-30 05:18 11933184 c:\windows\Installer\1133c78.msp
    + 2007-12-28 03:54 . 2007-12-28 03:54 14029824 c:\windows\Downloaded Installations\{CDA4B6F6-59F2-40AF-8F60-899A1E463011}\veoh.msi
    + 2008-01-22 20:46 . 2008-01-22 20:46 14030848 c:\windows\Downloaded Installations\{A89CD583-E905-4217-877A-22F69B3C7CC4}\veoh.msi
    + 2007-11-19 17:59 . 2007-12-02 17:28 13660672 c:\windows\Downloaded Installations\{34179DF9-5786-439E-BB19-5D4AC0D6EF47}\veoh.msi
    + 2007-10-15 05:43 . 2007-10-15 05:43 229852160 c:\windows\Installer\c8da16.msp
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-03-16 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-22 68856]
    "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
    "CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 700416]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
    "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
    "igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-22 94208]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-22 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-22 118784]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
    "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
    "Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
    "RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-15 208952]
    "IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2006-03-15 44032]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-15 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344]
    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-09-13 160160]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-24 1948440]
    "MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2007-07-06 177152]
    "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-06-02 61952]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]

    c:\documents and settings\School\Start Menu\Programs\Startup\
    OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
    HP Pavilion Webcam Tray Icon.lnk - c:\program files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe [2006-11-16 102400]
    HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-06-24 18:23 11952 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\system32\\mqsvc.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\MSN Messenger\\livecall.exe"=
    "c:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "8085:TCP"= 8085:TCP:podmena

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [24/03/2009 6:00 PM 327688]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [24/03/2009 6:00 PM 108552]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [24/03/2009 5:59 PM 298776]
    R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 7:19 PM 13592]
    S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [06/06/2006 2:39 PM 61952]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-06-01 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

    2009-07-11 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
    .
    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://www.ualberta.ca/
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    FF - ProfilePath - c:\documents and settings\School\Application Data\Mozilla\Firefox\Profiles\ph7vy5nn.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.ualberta.ca/
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
    FF - plugin: c:\documents and settings\School\Application Data\Mozilla\Firefox\Profiles\ph7vy5nn.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-07-11 06:41
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????L?@? ???PP??????`?@?????L?@

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2009-07-11 6:43
    ComboFix-quarantined-files.txt 2009-07-11 12:43
    ComboFix2.txt 2009-06-30 07:42

    Pre-Run: 35,083,452,416 bytes free
    Post-Run: 35,054,305,280 bytes free

    439 --- E O F --- 2009-07-11 12:05



    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0 REPORT
    Saturday, July 11, 2009
    Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Program database last update: Saturday, July 11, 2009 16:27:15
    Records in database: 2460453
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    C:\
    D:\
    E:\

    Scan statistics:
    Files scanned: 106856
    Threat name: 9
    Infected objects: 13
    Suspicious objects: 0
    Duration of the scan: 02:17:57


    File name / Threat name / Threats count
    C:\Documents and Settings\School\Desktop\requested-files[2009-06-29_19_50].cab Infected: Trojan.Win32.TDSS.aegg 3
    C:\Documents and Settings\School\Desktop\requested-files[2009-06-29_19_50].cab Infected: Packed.Win32.Tdss.m 1
    C:\Documents and Settings\School\My Documents\My Music\Sophie Ellis Bextor - Trip The Lig.wma Infected: Trojan-Downloader.WMA.GetCodec.a 1
    C:\Documents and Settings\School\Shared\janet jackson - son of a gun - greatest hits.mp3 Infected: Trojan-Downloader.WMA.GetCodec.ac 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACrqujoymxenfoewm.sys.vir Infected: Rootkit.Win32.Pakes.sx 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\UACfulckvagbsmtkfb.dll.vir Infected: Trojan.Win32.TDSS.aida 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\UACiriltiqerkwnemh.dll.vir Infected: Packed.Win32.Tdss.m 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\UACiydxetfpavbdwyb.dll.vir Infected: Trojan.Win32.TDSS.aicz 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\UACkauprqoblpdwwcj.dll.vir Infected: Trojan.Win32.TDSS.aekg 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\UACxyvolhkkvjxpwty.dll.vir Infected: Trojan.Win32.TDSS.aegg 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\UACycijubodpkkpeji.dll.vir Infected: Trojan.Win32.TDSS.adzz 1

    The selected area was scanned.



    DDS (Ver_09-06-26.01) - NTFSx86
    Run by School at 11:20:21.48 on 11/07/2009
    Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_14
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3062.2194 [GMT -6:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Zune\ZuneLauncher.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
    C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
    svchost.exe
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    c:\WINDOWS\system32\ZuneBusEnum.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\WINDOWS\system32\mqsvc.exe
    C:\WINDOWS\system32\mqtgsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Java\jre6\bin\java.exe
    C:\Documents and Settings\School\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://www.ualberta.ca/
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
    uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe"
    mRun: [ehTray] c:\windows\ehome\ehtray.exe
    mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
    mRun: [igfxtray] c:\windows\system32\igfxtray.exe
    mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
    mRun: [igfxpers] c:\windows\system32\igfxpers.exe
    mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
    mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
    mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe
    mRun: [RecGuard] c:\windows\sminst\RecGuard.exe
    mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
    mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
    mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
    mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
    mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
    mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop elements 4.0\apdproxy.exe"
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    StartupFolder: c:\docume~1\school\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppavi~1.lnk - c:\program files\hewlett-packard\hp pavilion webcam\HPWebcam.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} - hxxp://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/3/d/83d1fe15-fe0f-4bdf-b09c-4e3c49808ec7/LegitCheckControl.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171605677359
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: avgrsstarter - avgrsstx.dll
    Notify: igfxcui - igfxdev.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\school\applic~1\mozilla\firefox\profiles\ph7vy5nn.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.ualberta.ca/
    FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
    FF - plugin: c:\documents and settings\school\application data\mozilla\firefox\profiles\ph7vy5nn.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-24 327688]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-11-16 27784]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-24 108552]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-24 298776]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-6-6 61952]

    =============== Created Last 30 ================

    2009-07-11 08:02 410,984 a------- c:\windows\system32\deploytk.dll
    2009-07-11 08:02 73,728 a------- c:\windows\system32\javacpl.cpl
    2009-07-11 06:36 <DIR> --ds---- C:\Combo-Fix
    2009-06-30 01:41 <DIR> --d----- c:\windows\system32\dllcache\cache
    2009-06-30 01:22 <DIR> a-dshr-- C:\cmdcons
    2009-06-30 01:20 161,792 a------- c:\windows\SWREG.exe
    2009-06-30 01:20 155,136 a------- c:\windows\PEV.exe
    2009-06-30 01:20 98,816 a------- c:\windows\sed.exe
    2009-06-28 15:29 <DIR> --d----- c:\windows\system32\appmgmt
    2009-06-28 15:07 494 a---h--- C:\aaw7boot.cmd
    2009-06-26 23:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
    2009-06-26 22:08 <DIR> --d----- c:\program files\Lavasoft
    2009-06-12 13:02 206 a------- c:\windows\system32\MRT.INI

    ==================== Find3M ====================

    2009-06-24 12:23 327,688 a------- c:\windows\system32\drivers\avgldx86.sys
    2009-06-24 12:23 11,952 a------- c:\windows\system32\avgrsstx.dll
    2009-05-07 09:44 344,064 a------- c:\windows\system32\localspl.dll
    2009-05-07 09:44 344,064 -------- c:\windows\system32\dllcache\localspl.dll
    2009-04-28 22:56 827,392 a------- c:\windows\system32\wininet.dll
    2009-04-28 22:56 827,392 a------- c:\windows\system32\dllcache\cache\wininet.dll
    2009-04-28 22:56 827,392 -------- c:\windows\system32\dllcache\wininet.dll
    2009-04-28 22:56 233,472 -------- c:\windows\system32\dllcache\webcheck.dll
    2009-04-28 22:56 1,159,680 -------- c:\windows\system32\dllcache\urlmon.dll
    2009-04-28 22:56 671,232 -------- c:\windows\system32\dllcache\mstime.dll
    2009-04-28 22:56 105,984 -------- c:\windows\system32\dllcache\url.dll
    2009-04-28 22:56 102,912 -------- c:\windows\system32\dllcache\occache.dll
    2009-04-28 22:56 44,544 -------- c:\windows\system32\dllcache\pngfilt.dll
    2009-04-28 22:56 3,596,288 -------- c:\windows\system32\dllcache\mshtml.dll
    2009-04-28 22:56 477,696 -------- c:\windows\system32\dllcache\mshtmled.dll
    2009-04-28 22:56 193,024 -------- c:\windows\system32\dllcache\msrating.dll
    2009-04-28 03:05 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
    2009-04-28 03:05 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
    2009-04-24 23:27 636,088 -------- c:\windows\system32\dllcache\iexplore.exe
    2009-04-24 23:26 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
    2009-04-17 03:58 1,846,656 a------- c:\windows\system32\win32k.sys
    2009-04-17 03:58 1,846,656 -------- c:\windows\system32\dllcache\win32k.sys
    2009-04-15 09:26 583,168 a------- c:\windows\system32\rpcrt4.dll
    2009-04-15 09:26 583,168 -------- c:\windows\system32\dllcache\rpcrt4.dll
    2007-10-20 05:07 976 a------- c:\docume~1\school\applic~1\wklnhst.dat
    2006-11-16 15:12 22 a--sh--- c:\windows\sminst\HPCD.sys

    ============= FINISH: 11:20:46.68 ===============


    Thanks!

  10. #10
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi again,


    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    File::
    C:\Documents and Settings\School\Desktop\requested-files[2009-06-29_19_50].cab
    C:\Documents and Settings\School\Desktop\requested-files[2009-06-29_19_50].cab
    C:\Documents and Settings\School\My Documents\My Music\Sophie Ellis Bextor - Trip The Lig.wma
    C:\Documents and Settings\School\Shared\janet jackson - son of a gun - greatest hits.mp3
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "8085:TCP"=-

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log & a fresh dds.txt log. Still those symptoms described in this topic?


    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •