Virtumonde and IS 2010 Infection

Mystery

New member
I'm sorry for posting a (somewhat) duplicate thread. I had a major update to make on my current status and nobody has yet responded, so I figured it was a good idea to re-post, rather than reply to my current topic and potentially be passed over for help due to the non-zero replies.

The old topic:
http://forums.spybot.info/showthread.php?t=55193
Feel free to close this. I've quoted my original post from there, as it is now only a part of my problem.

"Virtumonde Infection"

Looks like quite a bit of it going around lately, eh? :/

Symptoms started showing up Thursday with unusual pop-up windows while I'm browsing. I decided to run an immediate scan with Spybot to see what was going on and, lo and behold, it detects a bunch of Virtumonde variants. It says to visit this forum for help... so here I am. :P

I reviewed the TeaTimer log and noted this...

1/27/2010 11:36:56 PM Allowed (based on user decision) value "{06498afd-da80-48d6-9811-8a7d67d46f48}" (new data: "") added in Browser Helper Object!
1/27/2010 11:37:32 PM Allowed (based on user decision) value "lepekusiju" (new data: "Rundll32.exe "jivukubu.dll",s") added in System Startup global entry!

...looking back at my browsing history seems to confirm that I probably picked up the virus exactly where I suspected. I don't visit the website in question often but it's always been clean to my knowledge. Bad luck this time, perhaps? :( (Yes, that's late-night Wednesday. Why I would've seen symptoms starting Thursday evening is because that's when I next used the computer!)

Anyway, I allowed Spybot to finish the scan. It said to restart and perform a scan on startup to remove what it couldn't at the time, so I obliged. I ran an AVG Free 9.0 complete scan immediately after the Spybot scan (before reboot) and it detected nothing. I shut down my computer and rebooted in Safe Mode to run Spybot again. It again detected the Virtumonde viruses and claimed to fix them. I shut down, rebooted normally and Spybot started its on-startup scan... again detecting Virtumonde and "fixing" them. I was out of town Saturday, so I ran Spybot once more... same thing. I started another AVG complete scan before leaving but I'm not sure of the results. (My mother used my computer while I was gone and presumably closed it without my permission.) I can only assume it found nothing, though.

At any rate, Spybot seems to continually re-find the infection every time I run it and I'm still getting the pop-ups. Currently, that seems to be the only obvious symptom. The pop-ups open through Internet Explorer but come up with a faux-Firefox icon, presumably because I'm browsing with Firefox.

Backup stored by ERUNT.

Here in my HJT log. Version 2.0.2 would not download, so I used Version 2.0.3 (Beta):


[snip]

The Update:

I was tinkering with TeaTimer and temporarily turned it off (in anticipation for receiving help and fixing this problem, I suppose). Just a moment ago, Internet Security 2010 appeared on my computer, an extremely pervasive rogue antivirus of which I've seen a few other topics in this forum about. My desktop image was hijacked and I am unable to open the Task Manager. I am very worried about it now. :(

I immediately turned TeaTimer back on, which informed me of some malicious "smss" software present and prompted me to kill the process (which I did). I did another Spybot scan, which got rid of some things and got my desktop wallpaper back, but my Task Manager still cannot be opened.

Perhaps I could revert to the ERUNT backup just before IS-2010 took over?

And here is a new HJT logfile:


Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 1:06:55 PM, on 1/31/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\Trend Micro\HijackThis\TrendMicro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5061206
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
F2 - REG:system.ini: Shell=Explorer.exe logon.exe
O2 - BHO: (no name) - {06498afd-da80-48d6-9811-8a7d67d46f48} - yejukuya.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [zuyivudeg] Rundll32.exe "c:\windows\system32\rumepopo.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
O15 - Trusted Zone: http://*.buy-internet-security10.com
O15 - Trusted Zone: http://*.is-soft-download.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.is-software-download25.com
O15 - Trusted Zone: http://*.buy-internet-security10.com (HKLM)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) - http://www.kungfuchess.com/activex/web665.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165960990742
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{651F9C10-8AD0-4011-A45A-299F4FFAEB1D}: NameServer = 83.149.115.157,4.2.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3}: NameServer = 83.149.115.157,4.2.2.1,192.168.0.1
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: c:\windows\system32\luhawimu.dll titubeve.dll c:\windows\system32\nosogumi.dll c:\windows\system32\rumepopo.dll c:\windows\system32\hemokelu.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O21 - SSODL: zabazejiz - {c1f3a6ba-6587-42d1-84a2-7d77b3550a67} - c:\windows\system32\luhawimu.dll (file missing)
O21 - SSODL: wuhagaloy - {c9a37c57-c898-4369-9c55-0e10a7672415} - c:\windows\system32\nosogumi.dll (file missing)
O21 - SSODL: zivedepok - {34ee8cd0-0645-45a6-b85d-6a603fe1e46b} - c:\windows\system32\rumepopo.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: tokatiluy - {c1f3a6ba-6587-42d1-84a2-7d77b3550a67} - c:\windows\system32\luhawimu.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {c9a37c57-c898-4369-9c55-0e10a7672415} - c:\windows\system32\nosogumi.dll (file missing)
O22 - SharedTaskScheduler: gahurihor - {34ee8cd0-0645-45a6-b85d-6a603fe1e46b} - c:\windows\system32\rumepopo.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 12139 bytes
 
Hi,

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop. Post them back to your topic.
 
Looks like I was able to get to the computer lab at school today after all. Thank you for replying, I'll be home around 5:30pm EST (~4.5 hours) to follow your instructions, from my infected home computer.
 
Alrighty, here I am and here are the logs generated by DDS.

DDS.txt:

DDS (Ver_09-12-01.01) - NTFSx86
Run by Mr.E at 17:29:35.10 on Thu 02/04/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.494 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mr.E\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
mWinlogon: Shell=Explorer.exe logon.exe
BHO: {06498afd-da80-48d6-9811-8a7d67d46f48} - yejukuya.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [zuyivudeg] Rundll32.exe "c:\windows\system32\habemoya.dll",a
mRunOnce: [Spybot - Search & Destroy] "c:\program files\spybot - search & destroy\SpybotSD.exe" /autocheck
mRunOnce: [SpybotDeletingA1980] command.com /c del "c:\windows\system32\titubeve.dll_old"
mRunOnce: [SpybotDeletingC6638] cmd.exe /c del "c:\windows\system32\titubeve.dll_old"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: buy-internet-security10.com
Trusted Zone: gelbooru.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is-software-download25.com
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165960990742
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: c:\windows\system32\ titubeve.dll c:\windows\system32\nosogumi.dll c:\windows\system32\rumepopo.dll c:\windows\system32\bujumuto.dll c:\windows\system32\habemoya.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: nuwegukat - {6c60a125-7af9-40ee-adb7-f2602e6c30e2} - c:\windows\system32\bujumuto.dll
SSODL: zufunizov - {c6885b7d-dd0b-4b99-9eeb-c6c2da5a3ff9} - c:\windows\system32\habemoya.dll
STS: kupuhivus: {6c60a125-7af9-40ee-adb7-f2602e6c30e2} - c:\windows\system32\bujumuto.dll
STS: kupuhivus: {c6885b7d-dd0b-4b99-9eeb-c6c2da5a3ff9} - c:\windows\system32\habemoya.dll
LSA: Notification Packages = kubu.dll rojerobe.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\mr.e\applic~1\mozilla\firefox\profiles\vy89qukg.mr.e\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-5 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-12-12 28424]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-28 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-12 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-12-22 93320]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [2006-5-3 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2006-5-3 8960]

=============== Created Last 30 ================

2010-02-02 06:02:03 1530 ----a-w- C:\Your PC Protector.lnk
2010-02-02 06:02:03 0 d-----w- C:\Your PC Protector
2010-02-02 05:01:27 0 d-----w- c:\program files\schtml
2010-02-02 04:57:05 958464 ----a-w- c:\program files\adc32.dll
2010-02-02 04:57:05 43520 ----a-w- c:\program files\alggui.exe
2010-02-02 04:56:57 56 ----a-w- c:\program files\wp4.dat
2010-02-02 04:56:57 37376 ----a-w- c:\program files\svchost.exe
2010-02-02 04:56:57 36 ----a-w- c:\program files\skynet.dat
2010-02-02 04:56:57 2 ----a-w- c:\program files\wp3.dat
2010-02-02 04:56:49 0 d-----w- c:\program files\Your PC Protector
2010-02-01 04:36:09 0 d-----w- c:\program files\Magic Workstation
2010-01-31 16:24:37 0 d-----w- c:\program files\InternetSecurity2010
2010-01-31 16:24:23 0 ----a-w- c:\windows\system32\41.exe
2010-01-31 14:32:57 0 d-----w- c:\program files\Trend Micro
2010-01-30 09:14:23 39424 --sh--w- c:\windows\system32\yaromido.dll
2010-01-25 23:54:56 0 d-----w- c:\program files\MSECache
2010-01-13 04:21:32 0 d--h--w- C:\$AVG
2010-01-13 04:20:43 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-01-13 02:31:03 471552 ------w- c:\windows\system32\dllcache\aclayers.dll

==================== Find3M ====================

2010-02-02 04:57:01 9 ----a-w- c:\program files\nuar.old
2010-01-13 04:21:25 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21:25 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21:08 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-31 15:33:06 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-12-17 22:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\dikuyeji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\dulosopi.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\fapumoke.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\fedotaba.dll
1601-01-01 00:03:28 53760 --sha-w- c:\windows\system32\ganazohe.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\habemoya.dll
1601-01-01 00:03:28 21504 --sha-w- c:\windows\system32\halihupe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\hatasefa.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\kuveyuke.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\lakezado.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\lotikiwi.dll
1601-01-01 00:03:52 53760 --sha-w- c:\windows\system32\luduvibu.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\mihapulo.dll
1601-01-01 00:03:52 53760 --sha-w- c:\windows\system32\rojerobe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\sekihoki.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\selutanu.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\susalade.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\vaditujo.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\varapaji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\wukojohe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\zisapese.dll
2008-08-05 01:03:12 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008080420080805\index.dat

============= FINISH: 17:30:30.57 ===============


Attach.txt:

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 12/11/2006 6:45:50 PM
System Uptime: 2/4/2010 3:56:52 AM (14 hours ago)

Motherboard: Dell Inc | | 0UW457
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ | Socket M2 | 2004/1000mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 144 GiB total, 57.837 GiB free.
D: is CDROM (CDFS)
E: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP298: 11/4/2009 12:50:08 AM - Installed Futuremark SystemInfo
RP299: 11/4/2009 2:27:34 PM - Software Distribution Service 3.0
RP300: 11/5/2009 2:33:16 PM - System Checkpoint
RP301: 11/6/2009 11:41:17 AM - Avg8 Update
RP302: 11/7/2009 12:33:12 PM - System Checkpoint
RP303: 11/8/2009 4:36:20 PM - System Checkpoint
RP304: 11/9/2009 7:29:49 PM - System Checkpoint
RP305: 11/11/2009 2:35:18 AM - System Checkpoint
RP306: 11/11/2009 5:04:05 PM - Software Distribution Service 3.0
RP307: 11/12/2009 8:37:03 PM - System Checkpoint
RP308: 11/13/2009 9:26:03 PM - System Checkpoint
RP309: 11/15/2009 6:42:10 AM - System Checkpoint
RP310: 11/16/2009 7:25:59 AM - System Checkpoint
RP311: 11/17/2009 8:25:58 AM - System Checkpoint
RP312: 11/18/2009 9:25:57 AM - System Checkpoint
RP313: 11/19/2009 10:25:57 AM - System Checkpoint
RP314: 11/20/2009 11:25:56 AM - System Checkpoint
RP315: 11/21/2009 12:33:11 PM - System Checkpoint
RP316: 11/22/2009 1:01:37 PM - System Checkpoint
RP317: 11/23/2009 1:25:52 PM - System Checkpoint
RP318: 11/24/2009 2:25:51 PM - System Checkpoint
RP319: 11/25/2009 10:58:24 AM - Avg8 Update
RP320: 11/25/2009 4:00:17 PM - Software Distribution Service 3.0
RP321: 11/26/2009 4:34:38 PM - System Checkpoint
RP322: 11/27/2009 4:39:45 PM - System Checkpoint
RP323: 11/28/2009 4:42:31 PM - System Checkpoint
RP324: 11/29/2009 5:28:01 PM - System Checkpoint
RP325: 11/30/2009 6:05:42 PM - System Checkpoint
RP326: 12/1/2009 9:23:48 PM - System Checkpoint
RP327: 12/2/2009 10:20:42 PM - System Checkpoint
RP328: 12/3/2009 11:24:25 PM - System Checkpoint
RP329: 12/5/2009 12:20:43 AM - System Checkpoint
RP330: 12/6/2009 5:10:15 AM - System Checkpoint
RP331: 12/7/2009 5:20:40 AM - System Checkpoint
RP332: 12/8/2009 6:20:43 AM - System Checkpoint
RP333: 12/9/2009 12:58:57 AM - Software Distribution Service 3.0
RP334: 12/9/2009 5:18:20 PM - Avg8 Update
RP335: 12/11/2009 3:42:38 AM - System Checkpoint
RP336: 12/11/2009 11:39:17 AM - Avg8 Update
RP337: 12/11/2009 11:40:02 AM - Avg8 Update
RP338: 12/12/2009 7:40:24 PM - System Checkpoint
RP339: 12/14/2009 2:02:26 AM - System Checkpoint
RP340: 12/15/2009 4:27:00 AM - System Checkpoint
RP341: 12/16/2009 5:19:15 AM - System Checkpoint
RP342: 12/17/2009 6:19:14 AM - System Checkpoint
RP343: 12/18/2009 7:19:12 AM - System Checkpoint
RP344: 12/19/2009 8:19:12 AM - System Checkpoint
RP345: 12/19/2009 4:00:19 PM - Software Distribution Service 3.0
RP346: 12/20/2009 10:15:20 PM - System Checkpoint
RP347: 12/22/2009 4:46:06 AM - Avg8 Update
RP348: 12/23/2009 5:06:50 AM - System Checkpoint
RP349: 12/24/2009 5:43:25 AM - System Checkpoint
RP350: 12/25/2009 9:37:25 PM - System Checkpoint
RP351: 12/27/2009 6:49:52 AM - System Checkpoint
RP352: 12/28/2009 7:18:27 AM - System Checkpoint
RP353: 12/28/2009 10:43:18 AM - Avg8 Update
RP354: 12/29/2009 11:18:23 AM - System Checkpoint
RP355: 12/30/2009 12:18:21 PM - System Checkpoint
RP356: 12/31/2009 1:18:21 PM - System Checkpoint
RP357: 1/1/2010 10:42:03 PM - System Checkpoint
RP358: 1/3/2010 7:30:17 AM - System Checkpoint
RP359: 1/4/2010 8:18:20 AM - System Checkpoint
RP360: 1/4/2010 10:52:20 AM - Avg8 Update
RP361: 1/5/2010 11:18:19 AM - System Checkpoint
RP362: 1/6/2010 12:18:15 PM - System Checkpoint
RP363: 1/7/2010 1:18:16 PM - System Checkpoint
RP364: 1/8/2010 2:18:17 PM - System Checkpoint
RP365: 1/10/2010 4:40:34 AM - System Checkpoint
RP366: 1/11/2010 5:18:14 AM - System Checkpoint
RP367: 1/12/2010 6:18:11 AM - System Checkpoint
RP368: 1/12/2010 9:38:02 PM - Software Distribution Service 3.0
RP369: 1/12/2010 11:20:28 PM - Installed AVG Free 9.0
RP370: 1/12/2010 11:35:30 PM - Avg8 Update
RP371: 1/14/2010 2:45:09 AM - System Checkpoint
RP372: 1/15/2010 3:25:50 AM - System Checkpoint
RP373: 1/16/2010 5:41:26 AM - System Checkpoint
RP374: 1/17/2010 6:52:26 AM - System Checkpoint
RP375: 1/18/2010 7:32:29 AM - System Checkpoint
RP376: 1/18/2010 9:58:24 AM - Avg8 Update
RP377: 1/21/2010 10:15:15 PM - Software Distribution Service 3.0
RP378: 1/23/2010 6:05:21 AM - System Checkpoint
RP379: 1/24/2010 7:36:08 AM - System Checkpoint
RP380: 1/25/2010 7:56:03 AM - System Checkpoint
RP381: 1/25/2010 6:55:17 PM - Installed Compatibility Pack for the 2007 Office system
RP382: 1/26/2010 11:21:37 PM - System Checkpoint
RP383: 1/27/2010 3:31:43 AM - Installed Java(TM) 6 Update 18
RP384: 1/27/2010 9:51:17 AM - Avg8 Update
RP385: 1/28/2010 11:01:01 AM - System Checkpoint
RP386: 1/29/2010 11:45:28 AM - System Checkpoint
RP387: 1/30/2010 11:54:48 AM - System Checkpoint
RP388: 1/31/2010 9:32:54 AM - Installed HiJackThis
RP389: 2/1/2010 10:34:29 AM - System Checkpoint

==== Installed Programs ======================

7-Zip 4.62
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 7.0.7
Adobe Reader 7.0.8
AIM 6
AiO_Scan_CDA
AiOSoftwareNPI
AOL Instant Messenger
AOL Uninstaller (Choose which Products to Remove)
AOLIcon
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Control Center
ATI Display Driver
AVG Free 9.0
Bioshock
Bonjour
Broadcom Management Programs
BufferChm
C4100
c4100_Help
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Continuum 0.40
Critical Update for Windows Media Player 11 (KB959772)
Dell CinePlayer
Dell Support 3.2.1
Dell System Restore
Destinations
DeviceManagementQFolder
Diablo II
Digital Content Portal
Digital Line Detect
DivX Content Uploader
DivX Web Player
DocProc
DocProcQFolder
Documentation & Support Launcher
DocumentViewer
DocumentViewerQFolder
Dofus-Arena
ERUNT 1.1j
eSupportQFolder
Fax_CDA
Games, Music, & Photos Launcher
GemMaster Mystic
Google Toolbar for Internet Explorer
Gunbound Revolution
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart, Officejet and Deskjet 7.0.A
HP Solution Center 7.0
HPPhotoSmartExpress
HPProductAssistant
ijji
ijji Auto Installer
ijji FireFox Launcher 1.0
InstantShareDevicesMFC
IrfanView (remove only)
iTunes
Java Auto Updater
Java(TM) 6 Update 18
Learn2 Player (Uninstall Only)
Logitech Print Service
Logitech QuickCam
Logitech® Camera Driver
Macromedia Shockwave Player
MapleStory
McAfee SiteAdvisor
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Small Business Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
mIRC
Modem Diagnostic Tool
Mozilla Firefox (3.5.7)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MultiRes (remove only)
NetBattle
NetWaiting
NewCopy_CDA
Nintendo Wi-Fi USB Connector Registration Tool
OCR Software by I.R.I.S 7.0
Otto
PanoStandAlone
PCmover
ProductContextNPI
PSP Video 9 2.25
QuickTime
Readme
RealPlayer
Road Runner Medic 5.4
RON Tool Adsoftinc
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
RPG Maker 2000 - #fftchallenge RPG
RTP for RM2K (Png, Wav, Midi, Fonts)
Scan
ScannerCopy
SearchAssist
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Shizmoo Web Games
Shoddy Battle
SolutionCenter
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SpywareBlaster 4.2
Starcraft
Status
Steam
System Requirements Lab
Team Fortress 2
Toolbox
TrayApp
Trillian
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
Ventrilo Client
WebFldrs XP
WebReg
WinAce Archiver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
World of Warcraft
World of Warcraft Public Test
XP Codec Pack
XviD MPEG-4 Video Codec
Yahoo! Messenger Explorer Bar

==== Event Viewer Messages From Past Week ========

2/2/2010 2:40:37 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McAfee SiteAdvisor Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
2/2/2010 2:39:46 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT nvatabus nvraid RasAcd Rdbss Tcpip WS2IFSL
1/31/2010 11:56:06 AM, error: ipnathlp [30013] - The DHCP allocator has disabled itself on IP address 192.168.1.1, since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, please change the scope to include the IP address, or change the IP address to fall within the scope.
1/31/2010 11:56:01 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: nvatabus nvraid
1/31/2010 11:55:32 AM, error: Print [23] - Printer hp deskjet 920c failed to initialize because a suitable hp deskjet 920c driver could not be found.
1/31/2010 11:55:32 AM, error: Print [23] - Printer hp deskjet 920c (Copy 1) failed to initialize because a suitable hp deskjet 920c driver could not be found.
1/31/2010 11:55:32 AM, error: Print [23] - Printer HP DeskJet 720C failed to initialize because a suitable HP DeskJet 720C driver could not be found.
1/31/2010 10:59:11 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
1/28/2010 12:26:04 AM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
1/28/2010 1:40:19 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
1/28/2010 1:09:28 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT nvatabus nvraid RasAcd Rdbss Tcpip
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:28 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
1/28/2010 1:09:23 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

==== End Of File ===========================
 
I noticed...

Trusted Zone: buy-internet-security10.com
Trusted Zone: gelbooru.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is-software-download25.com

...and manually deleted them from the Trusted Sites of my Internet Explorer settings. I'm not sure why gelbooru is listed since, even though it's legit, I don't use IE for browsing of any sort.
 
Hi,

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.


Please continue as follows:

  1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  2. Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
 
ComboFix ComboFix Log:

ComboFix 10-02-05.01 - Mr.E 02/05/2010 15:47:51.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.562 [GMT -5:00]
Running from: c:\documents and settings\Mr.E\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Mr.E\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\program files\adc32.dll
c:\program files\alggui.exe
c:\program files\InternetSecurity2010
c:\program files\nuar.old
c:\program files\svchost.exe
c:\program files\wp3.dat
c:\program files\wp4.dat
c:\program files\Your PC Protector
c:\windows\kb913800.exe
c:\windows\system32\41.exe
c:\windows\system32\bebaroki.dll
c:\windows\system32\halihupe.dll
c:\windows\system32\rojerobe.dll
c:\windows\system32\yaromido.dll
c:\windows\Sysvxd.exe
c:\windows\unins000.dat
c:\windows\unins000.exe

----- BITS: Possible infected sites -----

hxxp://77.74.48.111
.
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.

2010-02-02 06:02 . 2010-02-02 06:02 -------- d-----w- C:\Your PC Protector
2010-02-02 05:01 . 2010-02-02 07:31 -------- d-----w- c:\program files\schtml
2010-02-02 04:56 . 2010-02-02 04:57 36 ----a-w- c:\program files\skynet.dat
2010-02-01 04:36 . 2010-02-05 07:03 -------- d-----w- c:\program files\Magic Workstation
2010-01-31 14:32 . 2010-01-31 14:32 -------- d-----w- c:\program files\Trend Micro
2010-01-31 14:24 . 2010-01-31 14:25 -------- d-----w- c:\program files\ERUNT
2010-01-27 08:32 . 2010-01-27 08:32 -------- d-----w- c:\program files\Common Files\Java
2010-01-25 23:54 . 2010-01-25 23:54 -------- d-----w- c:\program files\MSECache
2010-01-13 04:21 . 2010-01-13 04:28 -------- d-----w- C:\$AVG
2010-01-13 04:20 . 2010-02-04 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-13 02:31 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 21:00 . 2008-07-27 19:22 -------- d-----w- c:\program files\Steam
2010-02-05 20:34 . 2006-12-12 11:34 -------- d-----w- c:\program files\mIRC
2010-02-05 06:42 . 2009-06-11 09:42 -------- d-----w- c:\program files\Wesnoth
2010-02-04 10:14 . 2006-12-07 00:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-04 10:11 . 2008-12-14 09:28 -------- d-----w- c:\program files\SpywareBlaster
2010-02-01 05:16 . 2006-12-07 00:29 78976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 16:52 . 2008-01-08 12:07 -------- d-----w- c:\program files\Trillian
2010-01-31 15:20 . 2006-12-12 11:57 -------- d-----w- c:\program files\NetBattle
2010-01-31 14:32 . 2010-01-31 14:32 388096 ----a-r- c:\documents and settings\Mr.E\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-27 08:32 . 2010-01-27 08:32 348160 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcr71.dll
2010-01-27 08:32 . 2010-01-27 08:32 61440 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-sse.dll
2010-01-27 08:32 . 2010-01-27 08:32 503808 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcp71.dll
2010-01-27 08:32 . 2010-01-27 08:32 499712 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\jmc.dll
2010-01-27 08:32 . 2010-01-27 08:32 12800 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-d3d.dll
2010-01-27 08:32 . 2009-03-11 20:44 -------- d-----w- c:\program files\Java
2010-01-18 14:58 . 2010-01-18 14:58 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-18 14:58 . 2010-01-13 04:35 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-13 04:35 . 2010-01-13 04:35 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-13 04:28 . 2008-12-23 04:20 -------- d-----w- c:\program files\McAfee
2010-01-13 04:21 . 2009-04-28 18:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21 . 2008-06-05 19:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21 . 2006-12-12 21:50 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-13 04:21 . 2008-06-05 19:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-13 04:21 . 2010-01-13 04:35 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-13 04:20 . 2010-01-13 04:35 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-13 04:20 . 2010-01-13 04:35 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-13 04:20 . 2010-01-13 04:35 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-13 04:20 . 2008-06-05 19:35 -------- d-----w- c:\program files\AVG
2010-01-05 10:00 . 2005-08-16 09:18 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-08-16 09:18 17408 ------w- c:\windows\system32\corpol.dll
2009-12-17 22:14 . 2008-12-14 08:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-21 15:51 . 2005-08-16 09:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\dikuyeji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\dulosopi.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\fapumoke.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\fedotaba.dll
1601-01-01 00:03 . 1601-01-01 00:03 53760 --sha-w- c:\windows\system32\ganazohe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\hatasefa.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\kuveyuke.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\lakezado.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\lotikiwi.dll
1601-01-01 00:03 . 1601-01-01 00:03 53760 --sha-w- c:\windows\system32\luduvibu.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\mihapulo.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\sekihoki.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\selutanu.dll
1601-01-01 00:03 . 1601-01-01 00:03 92672 --sha-w- c:\windows\system32\susalade.dll
1601-01-01 00:03 . 1601-01-01 00:03 92672 --sha-w- c:\windows\system32\vaditujo.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\varapaji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\vesujuji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\wukojohe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\zisapese.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1a45aee5-c4d2-407f-9a8c-5defddda9c1e}]
1601-01-01 00:03 53760 --sha-w- c:\windows\system32\luduvibu.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-12-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-5-9 1073152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-13 04:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aim6.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/5/2008 2:35 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/28/2009 1:39 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/12/2010 11:20 PM 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/22/2008 11:21 PM 93320]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [5/3/2006 9:19 AM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [5/3/2006 9:19 AM 8960]
.
Contents of the 'Scheduled Tasks' folder

2010-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-06-02 20:31]

2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-02-11 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
FF - ProfilePath - c:\documents and settings\Mr.E\Application Data\Mozilla\Firefox\Profiles\vy89qukg.Mr.E\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\Mr.E\Local Settings\Application Data\{319C574E-35A9-4388-832A-88C8995655F5}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

BHO-{06498afd-da80-48d6-9811-8a7d67d46f48} - yejukuya.dll
HKLM-Run-zuyivudeg - c:\windows\system32\bebaroki.dll
HKLM-Run-lepekusiju - rojerobe.dll
SharedTaskScheduler-{6c60a125-7af9-40ee-adb7-f2602e6c30e2} - c:\windows\system32\bujumuto.dll
SharedTaskScheduler-{31573857-ef41-4bb4-9719-0d57114051d3} - c:\windows\system32\bebaroki.dll
SSODL-nuwegukat-{6c60a125-7af9-40ee-adb7-f2602e6c30e2} - c:\windows\system32\bujumuto.dll
SSODL-gapefifes-{31573857-ef41-4bb4-9719-0d57114051d3} - c:\windows\system32\bebaroki.dll
AddRemove-gkctpvrqly - c:\windows\system32\gkctpvrqly.exe
AddRemove-NetBattle_is1 - c:\program files\NetBattle\unins001.exe
AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe
AddRemove-ijji.com - c:\ijji\ENGLISH\ijjiUninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-05 16:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3364)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\stsystra.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\HPZipm12.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\eHome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-02-05 16:12:39 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-05 21:12
ComboFix2.txt 2008-12-17 20:16

Pre-Run: 61,955,387,392 bytes free
Post-Run: 61,655,736,320 bytes free

- - End Of File - - B90EEE6110388B7B55671282C35049EE


New DDS DDS.txt:

DDS (Ver_09-12-01.01) - NTFSx86
Run by Mr.E at 16:15:43.35 on Fri 02/05/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.344 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\HPZipm12.exe
svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mr.E\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: {1a45aee5-c4d2-407f-9a8c-5defddda9c1e} - luduvibu.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165960990742
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\mr.e\applic~1\mozilla\firefox\profiles\vy89qukg.mr.e\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-5 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-12-12 28424]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-28 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-12 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-12-22 93320]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [2006-5-3 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2006-5-3 8960]

=============== Created Last 30 ================

2010-02-05 20:46:56 98816 ----a-w- c:\windows\sed.exe
2010-02-05 20:46:56 77312 ----a-w- c:\windows\MBR.exe
2010-02-05 20:46:56 261632 ----a-w- c:\windows\PEV.exe
2010-02-05 20:46:56 161792 ----a-w- c:\windows\SWREG.exe
2010-02-02 06:02:03 1530 ----a-w- C:\Your PC Protector.lnk
2010-02-02 06:02:03 0 d-----w- C:\Your PC Protector
2010-02-02 05:01:27 0 d-----w- c:\program files\schtml
2010-02-02 04:56:57 36 ----a-w- c:\program files\skynet.dat
2010-02-01 04:36:09 0 d-----w- c:\program files\Magic Workstation
2010-01-31 14:32:57 0 d-----w- c:\program files\Trend Micro
2010-01-25 23:54:56 0 d-----w- c:\program files\MSECache
2010-01-13 04:21:32 0 d-----w- C:\$AVG
2010-01-13 04:20:43 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-01-13 02:31:03 471552 ------w- c:\windows\system32\dllcache\aclayers.dll

==================== Find3M ====================

2010-01-13 04:21:25 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21:25 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21:08 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-31 15:33:06 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-12-17 22:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\dikuyeji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\dulosopi.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\fapumoke.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\fedotaba.dll
1601-01-01 00:03:28 53760 --sha-w- c:\windows\system32\ganazohe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\hatasefa.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\kuveyuke.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\lakezado.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\lotikiwi.dll
1601-01-01 00:03:52 53760 --sha-w- c:\windows\system32\luduvibu.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\mihapulo.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\sekihoki.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\selutanu.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\susalade.dll
1601-01-01 00:03:28 92672 --sha-w- c:\windows\system32\vaditujo.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\varapaji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\vesujuji.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\wukojohe.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\zisapese.dll
2008-08-05 01:03:12 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008080420080805\index.dat

============= FINISH: 16:16:16.13 ===============


New DDS Attach.txt:

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 12/11/2006 6:45:50 PM
System Uptime: 2/5/2010 3:59:17 PM (1 hours ago)

Motherboard: Dell Inc | | 0UW457
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ | Socket M2 | 2004/1000mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 144 GiB total, 57.449 GiB free.
D: is CDROM (CDFS)
E: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP298: 11/4/2009 12:50:08 AM - Installed Futuremark SystemInfo
RP299: 11/4/2009 2:27:34 PM - Software Distribution Service 3.0
RP300: 11/5/2009 2:33:16 PM - System Checkpoint
RP301: 11/6/2009 11:41:17 AM - Avg8 Update
RP302: 11/7/2009 12:33:12 PM - System Checkpoint
RP303: 11/8/2009 4:36:20 PM - System Checkpoint
RP304: 11/9/2009 7:29:49 PM - System Checkpoint
RP305: 11/11/2009 2:35:18 AM - System Checkpoint
RP306: 11/11/2009 5:04:05 PM - Software Distribution Service 3.0
RP307: 11/12/2009 8:37:03 PM - System Checkpoint
RP308: 11/13/2009 9:26:03 PM - System Checkpoint
RP309: 11/15/2009 6:42:10 AM - System Checkpoint
RP310: 11/16/2009 7:25:59 AM - System Checkpoint
RP311: 11/17/2009 8:25:58 AM - System Checkpoint
RP312: 11/18/2009 9:25:57 AM - System Checkpoint
RP313: 11/19/2009 10:25:57 AM - System Checkpoint
RP314: 11/20/2009 11:25:56 AM - System Checkpoint
RP315: 11/21/2009 12:33:11 PM - System Checkpoint
RP316: 11/22/2009 1:01:37 PM - System Checkpoint
RP317: 11/23/2009 1:25:52 PM - System Checkpoint
RP318: 11/24/2009 2:25:51 PM - System Checkpoint
RP319: 11/25/2009 10:58:24 AM - Avg8 Update
RP320: 11/25/2009 4:00:17 PM - Software Distribution Service 3.0
RP321: 11/26/2009 4:34:38 PM - System Checkpoint
RP322: 11/27/2009 4:39:45 PM - System Checkpoint
RP323: 11/28/2009 4:42:31 PM - System Checkpoint
RP324: 11/29/2009 5:28:01 PM - System Checkpoint
RP325: 11/30/2009 6:05:42 PM - System Checkpoint
RP326: 12/1/2009 9:23:48 PM - System Checkpoint
RP327: 12/2/2009 10:20:42 PM - System Checkpoint
RP328: 12/3/2009 11:24:25 PM - System Checkpoint
RP329: 12/5/2009 12:20:43 AM - System Checkpoint
RP330: 12/6/2009 5:10:15 AM - System Checkpoint
RP331: 12/7/2009 5:20:40 AM - System Checkpoint
RP332: 12/8/2009 6:20:43 AM - System Checkpoint
RP333: 12/9/2009 12:58:57 AM - Software Distribution Service 3.0
RP334: 12/9/2009 5:18:20 PM - Avg8 Update
RP335: 12/11/2009 3:42:38 AM - System Checkpoint
RP336: 12/11/2009 11:39:17 AM - Avg8 Update
RP337: 12/11/2009 11:40:02 AM - Avg8 Update
RP338: 12/12/2009 7:40:24 PM - System Checkpoint
RP339: 12/14/2009 2:02:26 AM - System Checkpoint
RP340: 12/15/2009 4:27:00 AM - System Checkpoint
RP341: 12/16/2009 5:19:15 AM - System Checkpoint
RP342: 12/17/2009 6:19:14 AM - System Checkpoint
RP343: 12/18/2009 7:19:12 AM - System Checkpoint
RP344: 12/19/2009 8:19:12 AM - System Checkpoint
RP345: 12/19/2009 4:00:19 PM - Software Distribution Service 3.0
RP346: 12/20/2009 10:15:20 PM - System Checkpoint
RP347: 12/22/2009 4:46:06 AM - Avg8 Update
RP348: 12/23/2009 5:06:50 AM - System Checkpoint
RP349: 12/24/2009 5:43:25 AM - System Checkpoint
RP350: 12/25/2009 9:37:25 PM - System Checkpoint
RP351: 12/27/2009 6:49:52 AM - System Checkpoint
RP352: 12/28/2009 7:18:27 AM - System Checkpoint
RP353: 12/28/2009 10:43:18 AM - Avg8 Update
RP354: 12/29/2009 11:18:23 AM - System Checkpoint
RP355: 12/30/2009 12:18:21 PM - System Checkpoint
RP356: 12/31/2009 1:18:21 PM - System Checkpoint
RP357: 1/1/2010 10:42:03 PM - System Checkpoint
RP358: 1/3/2010 7:30:17 AM - System Checkpoint
RP359: 1/4/2010 8:18:20 AM - System Checkpoint
RP360: 1/4/2010 10:52:20 AM - Avg8 Update
RP361: 1/5/2010 11:18:19 AM - System Checkpoint
RP362: 1/6/2010 12:18:15 PM - System Checkpoint
RP363: 1/7/2010 1:18:16 PM - System Checkpoint
RP364: 1/8/2010 2:18:17 PM - System Checkpoint
RP365: 1/10/2010 4:40:34 AM - System Checkpoint
RP366: 1/11/2010 5:18:14 AM - System Checkpoint
RP367: 1/12/2010 6:18:11 AM - System Checkpoint
RP368: 1/12/2010 9:38:02 PM - Software Distribution Service 3.0
RP369: 1/12/2010 11:20:28 PM - Installed AVG Free 9.0
RP370: 1/12/2010 11:35:30 PM - Avg8 Update
RP371: 1/14/2010 2:45:09 AM - System Checkpoint
RP372: 1/15/2010 3:25:50 AM - System Checkpoint
RP373: 1/16/2010 5:41:26 AM - System Checkpoint
RP374: 1/17/2010 6:52:26 AM - System Checkpoint
RP375: 1/18/2010 7:32:29 AM - System Checkpoint
RP376: 1/18/2010 9:58:24 AM - Avg8 Update
RP377: 1/21/2010 10:15:15 PM - Software Distribution Service 3.0
RP378: 1/23/2010 6:05:21 AM - System Checkpoint
RP379: 1/24/2010 7:36:08 AM - System Checkpoint
RP380: 1/25/2010 7:56:03 AM - System Checkpoint
RP381: 1/25/2010 6:55:17 PM - Installed Compatibility Pack for the 2007 Office system
RP382: 1/26/2010 11:21:37 PM - System Checkpoint
RP383: 1/27/2010 3:31:43 AM - Installed Java(TM) 6 Update 18
RP384: 1/27/2010 9:51:17 AM - Avg8 Update
RP385: 1/28/2010 11:01:01 AM - System Checkpoint
RP386: 1/29/2010 11:45:28 AM - System Checkpoint
RP387: 1/30/2010 11:54:48 AM - System Checkpoint
RP388: 1/31/2010 9:32:54 AM - Installed HiJackThis
RP389: 2/1/2010 10:34:29 AM - System Checkpoint

==== Installed Programs ======================

7-Zip 4.62
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 7.0.7
Adobe Reader 7.0.8
AIM 6
AiO_Scan_CDA
AiOSoftwareNPI
AOL Instant Messenger
AOL Uninstaller (Choose which Products to Remove)
AOLIcon
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Catalyst Control Center
ATI Display Driver
AVG Free 9.0
Bioshock
Bonjour
Broadcom Management Programs
BufferChm
C4100
c4100_Help
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Continuum 0.40
Critical Update for Windows Media Player 11 (KB959772)
Dell CinePlayer
Dell Support 3.2.1
Dell System Restore
Destinations
DeviceManagementQFolder
Diablo II
Digital Content Portal
Digital Line Detect
DivX Content Uploader
DivX Web Player
DocProc
DocProcQFolder
Documentation & Support Launcher
DocumentViewer
DocumentViewerQFolder
Dofus-Arena
ERUNT 1.1j
eSupportQFolder
Fax_CDA
Games, Music, & Photos Launcher
GemMaster Mystic
Google Toolbar for Internet Explorer
Gunbound Revolution
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart, Officejet and Deskjet 7.0.A
HP Solution Center 7.0
HPPhotoSmartExpress
HPProductAssistant
ijji Auto Installer
ijji FireFox Launcher 1.0
InstantShareDevicesMFC
IrfanView (remove only)
iTunes
Java Auto Updater
Java(TM) 6 Update 18
Learn2 Player (Uninstall Only)
Logitech Print Service
Logitech QuickCam
Logitech® Camera Driver
Macromedia Shockwave Player
MapleStory
McAfee SiteAdvisor
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Small Business Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
mIRC
Modem Diagnostic Tool
Mozilla Firefox (3.5.7)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MultiRes (remove only)
NetWaiting
NewCopy_CDA
Nintendo Wi-Fi USB Connector Registration Tool
OCR Software by I.R.I.S 7.0
Otto
PanoStandAlone
PCmover
ProductContextNPI
PSP Video 9 2.25
QuickTime
Readme
RealPlayer
Road Runner Medic 5.4
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
RPG Maker 2000 - #fftchallenge RPG
RTP for RM2K (Png, Wav, Midi, Fonts)
Scan
ScannerCopy
SearchAssist
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Shizmoo Web Games
Shoddy Battle
SolutionCenter
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
Spybot - Search & Destroy
SpywareBlaster 4.2
Starcraft
Status
Steam
System Requirements Lab
Team Fortress 2
Toolbox
TrayApp
Trillian
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
Ventrilo Client
WebFldrs XP
WebReg
WinAce Archiver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
World of Warcraft
World of Warcraft Public Test
XP Codec Pack
XviD MPEG-4 Video Codec
Yahoo! Messenger Explorer Bar

==== Event Viewer Messages From Past Week ========

2/5/2010 3:54:35 PM, error: PlugPlayManager [11] - The device Root\LEGACY_GMER\0000 disappeared from the system without first being prepared for removal.
2/5/2010 3:45:44 PM, error: Service Control Manager [7031] - The AVG Free WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
2/2/2010 2:40:37 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McAfee SiteAdvisor Service with arguments "" in order to run the server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}
2/2/2010 2:39:46 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT nvatabus nvraid RasAcd Rdbss Tcpip WS2IFSL
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/2/2010 2:39:46 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/2/2010 2:39:43 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
2/2/2010 1:30:16 AM, error: ipnathlp [30013] - The DHCP allocator has disabled itself on IP address 192.168.1.1, since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, please change the scope to include the IP address, or change the IP address to fall within the scope.
2/2/2010 1:30:14 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: nvatabus nvraid
2/2/2010 1:29:44 AM, error: Print [23] - Printer hp deskjet 920c failed to initialize because a suitable hp deskjet 920c driver could not be found.
2/2/2010 1:29:44 AM, error: Print [23] - Printer hp deskjet 920c (Copy 1) failed to initialize because a suitable hp deskjet 920c driver could not be found.
2/2/2010 1:29:44 AM, error: Print [23] - Printer HP DeskJet 720C failed to initialize because a suitable HP DeskJet 720C driver could not be found.
1/31/2010 10:59:11 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

==== End Of File ===========================
 
Hi,

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Please post contents of that file in your next reply.
 
I downloaded MBAM, updated, and was in the middle of the Quick Scan when it suddenly stop running and closed itself.

I tried to restart it but Windows said mbam.exe doesn't exist. I went to Control Panel and uninstalled it using Add/Remove Programs. I was prompted to restart the computer to complete uninstallation, so I rebooted.

I downloaded MBAM again, started installing it, and while it was downloading the update it closed. An error window popped up:

[Setup]
Unable to execute file:
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

CreateProcess failed; code 2.
The system cannot find the file specified.


The error window popped up twice and, again, the MBAM program has completely disappeared from the computer.
 
Got snowed in out of town last night and just got home, heh. ;o

I started up ComboFix and, as it started to run, it said there was a new update available and asked if I wanted to update. Afraid it was some sort of trick by the virus to make it disable it, I closed out of ComboFix and redownloaded it from bleepingcomputer.com myself just in case.

The new install of ComboFix would not run. I restarted in Safe Mode and ran the old install of ComboFix. When it was finished, it rebooted my computer in normal operation and TeaTimer came back on by itself too.

So here is the new [ComboFix log:

ComboFix 10-02-05.01 - Mr.E 02/06/2010 15:10:58.5.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.769 [GMT -5:00]
Running from: c:\documents and settings\Mr.E\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\napuruya.dll

.
((((((((((((((((((((((((( Files Created from 2010-01-06 to 2010-02-06 )))))))))))))))))))))))))))))))
.

2010-02-05 23:21 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-05 23:21 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\Mr.E\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-02 06:02 . 2010-02-02 06:02 -------- d-----w- C:\Your PC Protector
2010-02-02 05:01 . 2010-02-02 07:31 -------- d-----w- c:\program files\schtml
2010-02-02 04:56 . 2010-02-02 04:57 36 ----a-w- c:\program files\skynet.dat
2010-02-01 04:36 . 2010-02-05 07:03 -------- d-----w- c:\program files\Magic Workstation
2010-01-31 14:32 . 2010-01-31 14:32 388096 ----a-r- c:\documents and settings\Mr.E\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-31 14:32 . 2010-01-31 14:32 -------- d-----w- c:\program files\Trend Micro
2010-01-31 14:24 . 2010-01-31 14:25 -------- d-----w- c:\program files\ERUNT
2010-01-27 08:32 . 2010-01-27 08:32 -------- d-----w- c:\program files\Common Files\Java
2010-01-27 08:32 . 2010-01-27 08:32 348160 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcr71.dll
2010-01-27 08:32 . 2010-01-27 08:32 61440 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-sse.dll
2010-01-27 08:32 . 2010-01-27 08:32 503808 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcp71.dll
2010-01-27 08:32 . 2010-01-27 08:32 499712 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\jmc.dll
2010-01-27 08:32 . 2010-01-27 08:32 12800 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-d3d.dll
2010-01-25 23:54 . 2010-01-25 23:54 -------- d-----w- c:\program files\MSECache
2010-01-18 14:58 . 2010-01-18 14:58 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-13 04:35 . 2010-01-18 14:58 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-13 04:35 . 2010-01-13 04:20 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-13 04:35 . 2010-01-13 04:20 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-13 04:35 . 2010-01-13 04:21 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-13 04:35 . 2010-01-13 04:20 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-13 04:35 . 2010-01-13 04:35 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-13 04:21 . 2010-01-13 04:28 -------- d-----w- C:\$AVG
2010-01-13 04:20 . 2010-02-04 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-13 02:31 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-06 20:21 . 2008-07-27 19:22 -------- d-----w- c:\program files\Steam
2010-02-06 16:36 . 2009-05-02 20:49 124 ----a-w- c:\documents and settings\Mr.E\Application Data\wklnhst.dat
2010-02-05 23:12 . 2008-01-08 12:07 -------- d-----w- c:\program files\Trillian
2010-02-05 23:11 . 2006-12-12 11:34 -------- d-----w- c:\program files\mIRC
2010-02-05 06:42 . 2009-06-11 09:42 -------- d-----w- c:\program files\Wesnoth
2010-02-04 10:14 . 2006-12-07 00:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-04 10:11 . 2008-12-14 09:28 -------- d-----w- c:\program files\SpywareBlaster
2010-02-01 05:16 . 2006-12-07 00:29 78976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 15:20 . 2006-12-12 11:57 -------- d-----w- c:\program files\NetBattle
2010-01-27 08:32 . 2009-03-11 20:44 -------- d-----w- c:\program files\Java
2010-01-13 04:28 . 2008-12-23 04:20 -------- d-----w- c:\program files\McAfee
2010-01-13 04:21 . 2009-04-28 18:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21 . 2008-06-05 19:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21 . 2006-12-12 21:50 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-13 04:21 . 2008-06-05 19:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-13 04:20 . 2008-06-05 19:35 -------- d-----w- c:\program files\AVG
2010-01-05 10:00 . 2005-08-16 09:18 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-08-16 09:18 17408 ------w- c:\windows\system32\corpol.dll
2009-12-17 22:14 . 2008-12-14 08:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-21 15:51 . 2005-08-16 09:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\dikuyeji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\dulosopi.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\fapumoke.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\fedotaba.dll
1601-01-01 00:03 . 1601-01-01 00:03 53760 --sha-w- c:\windows\system32\ganazohe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\hatasefa.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\kuveyuke.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\lakezado.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\lotikiwi.dll
1601-01-01 00:03 . 1601-01-01 00:03 53760 --sha-w- c:\windows\system32\luduvibu.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\mihapulo.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\parahuri.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\sekihoki.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\sekikawe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\selutanu.dll
1601-01-01 00:03 . 1601-01-01 00:03 92672 --sha-w- c:\windows\system32\susalade.dll
1601-01-01 00:03 . 1601-01-01 00:03 92672 --sha-w- c:\windows\system32\vaditujo.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\varapaji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\vesujuji.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\wukojohe.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\zisapese.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1a45aee5-c4d2-407f-9a8c-5defddda9c1e}]
1601-01-01 00:03 53760 --sha-w- c:\windows\system32\luduvibu.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"zuyivudeg"="c:\windows\system32\napuruya.dll" [BU]
"lepekusiju"="rojerobe.dll" [BU]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-12-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-5-9 1073152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-13 04:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aim6.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/5/2008 2:35 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/28/2009 1:39 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/12/2010 11:20 PM 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/22/2008 11:21 PM 93320]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [5/3/2006 9:19 AM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [5/3/2006 9:19 AM 8960]
.
Contents of the 'Scheduled Tasks' folder

2010-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-06-02 20:31]

2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-02-11 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
FF - ProfilePath - c:\documents and settings\Mr.E\Application Data\Mozilla\Firefox\Profiles\vy89qukg.Mr.E\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\Mr.E\Local Settings\Application Data\{319C574E-35A9-4388-832A-88C8995655F5}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

BHO-{06498afd-da80-48d6-9811-8a7d67d46f48} - (no file)
SharedTaskScheduler-{eaf453f0-faa5-4afd-8ff2-55ba42304270} - c:\windows\system32\napuruya.dll
SSODL-negaminiv-{eaf453f0-faa5-4afd-8ff2-55ba42304270} - c:\windows\system32\napuruya.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-06 15:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(964)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\stsystra.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\HPZipm12.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\eHome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-02-06 15:29:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-06 20:29
ComboFix2.txt 2010-02-05 21:12
ComboFix3.txt 2008-12-17 20:16

Pre-Run: 62,620,733,440 bytes free
Post-Run: 61,530,468,352 bytes free

- - End Of File - - E6BE3F0B5E1F01FE0FFD6340CCB16B65
 
Hi again,

Got snowed in out of town last night and just got home, heh. ;o
Doesn't sound nice. Anyway, glad you got back :)

Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
  • Run Spybot-S&D in Advanced Mode
  • If it is not already set to do this, go to the Mode menu
    select
    Advanced Mode
  • On the left hand side, click on Tools
  • Then click on the Resident icon in the list
  • Uncheck
    Resident TeaTimer
    and OK any prompts.
  • Restart your computer


Open notepad and copy/paste the text in the quotebox below into it:

Code:
DDS::
BHO: {1a45aee5-c4d2-407f-9a8c-5defddda9c1e} - luduvibu.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TCP: {651F9C10-8AD0-4011-A45A-299F4FFAEB1D} = 83.149.115.157,4.2.2.1
TCP: {D9F149B7-EA29-4B2A-8A1F-BAB8AA73B5A3} = 83.149.115.157,4.2.2.1,192.168.0.1
Firefox::
FF - HiddenExtension: XUL Cache: {319C574E-35A9-4388-832A-88C8995655F5} - c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}
File::
C:\Your PC Protector.lnk
c:\program files\skynet.dat
c:\windows\system32\dikuyeji.dll
c:\windows\system32\dulosopi.dll
c:\windows\system32\fapumoke.dll
c:\windows\system32\fedotaba.dll
c:\windows\system32\ganazohe.dll
c:\windows\system32\hatasefa.dll
c:\windows\system32\kuveyuke.dll
c:\windows\system32\lakezado.dll
c:\windows\system32\lotikiwi.dll
c:\windows\system32\luduvibu.dll
c:\windows\system32\mihapulo.dll
c:\windows\system32\sekihoki.dll
c:\windows\system32\selutanu.dll
c:\windows\system32\susalade.dll
c:\windows\system32\vaditujo.dll
c:\windows\system32\varapaji.dll
c:\windows\system32\vesujuji.dll
c:\windows\system32\wukojohe.dll
c:\windows\system32\zisapese.dll
Folder::
C:\Your PC Protector
c:\program files\schtml
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"zuyivudeg"=-
"lepekusiju"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"KernelFaultCheck"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000


Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

CFScriptB-4.gif


Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Uninstall old Adobe Reader versions and get the latest one (9.3) here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.

Uninstall your current Macromedia Shockwave Player and get the fresh one here if needed.

Uninstall vulnerable Flash versions by following instructions here. Fresh version can be obtained here.


Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
 
1) TeaTimer disabled. Don't worry, I remembered to do that previously too!
2) Restarted computer.
3) CFScript copied into Notepad and ComboFix ran with the given script. LOG BELOW. After ComboFix rebooted the computer, a Windows Security Alert showed up in the taskbar. It popped up a couple warnings at me because the firewall and my antivirus (AVG) was turned off.
4) Turned TeaTimer back on.

5) Adobe 7.0.7 and Adobe 7.0.8 removed. Downloaded the latest version (9.3).
6) Macromedia Shockwave Player could not be removed via Add or Remove Programs, kept getting an error message about WISE UNINSTALLER. I was able to remove it using the Uninstaller from the Adobe site. Downloaded the latest version (11.5.6.606).
7) Downloaded the Flash Player uninstaller and ran it... then I remembered to close Firefox and ran it again, just in case. It said two of the elements would be deleted on computer restart. I did not reboot yet. Downloaded the latest version (10.0.42.34).

8) Downloaded ATF Cleaner and ran it. Empty Selected from Main and freed up 26.xxx MB. Empty Selected from Firefox (Select All, clicked NO to keep saved passwords) and freed up 62.xxx MB.
9) Kaspersky Online Scanner ran as instructed by the picture. Wow, that took a long time. :( LOG BELOW.
10) Ran DDS and saved both DDS.txt and Attach.txt. LOG BELOW.

...And that's it I think! Here you go.

Going in chronological order, ComboFix Log first:

ComboFix 10-02-05.01 - Mr.E 02/06/2010 19:00:25.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.401 [GMT -5:00]
Running from: c:\documents and settings\Mr.E\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mr.E\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\program files\skynet.dat"
"c:\windows\system32\dikuyeji.dll"
"c:\windows\system32\dulosopi.dll"
"c:\windows\system32\fapumoke.dll"
"c:\windows\system32\fedotaba.dll"
"c:\windows\system32\ganazohe.dll"
"c:\windows\system32\hatasefa.dll"
"c:\windows\system32\kuveyuke.dll"
"c:\windows\system32\lakezado.dll"
"c:\windows\system32\lotikiwi.dll"
"c:\windows\system32\luduvibu.dll"
"c:\windows\system32\mihapulo.dll"
"c:\windows\system32\sekihoki.dll"
"c:\windows\system32\selutanu.dll"
"c:\windows\system32\susalade.dll"
"c:\windows\system32\vaditujo.dll"
"c:\windows\system32\varapaji.dll"
"c:\windows\system32\vesujuji.dll"
"c:\windows\system32\wukojohe.dll"
"c:\windows\system32\zisapese.dll"
"C:\Your PC Protector.lnk"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\chrome.manifest
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\chrome\content\_cfg.js
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\chrome\content\c.js
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\chrome\content\overlay.xul
c:\documents and settings\mr.e\local settings\application data\{319C574E-35A9-4388-832A-88C8995655F5}\install.rdf
c:\program files\schtml
c:\program files\schtml\dbsinit.exe
c:\program files\schtml\images\i1.gif
c:\program files\schtml\images\i2.gif
c:\program files\schtml\images\i3.gif
c:\program files\schtml\images\j1.gif
c:\program files\schtml\images\j2.gif
c:\program files\schtml\images\j3.gif
c:\program files\schtml\images\jj1.gif
c:\program files\schtml\images\jj2.gif
c:\program files\schtml\images\jj3.gif
c:\program files\schtml\images\l1.gif
c:\program files\schtml\images\l2.gif
c:\program files\schtml\images\l3.gif
c:\program files\schtml\images\pix.gif
c:\program files\schtml\images\t1.gif
c:\program files\schtml\images\t2.gif
c:\program files\schtml\images\Thumbs.db
c:\program files\schtml\images\up1.gif
c:\program files\schtml\images\up2.gif
c:\program files\schtml\images\w1.gif
c:\program files\schtml\images\w11.gif
c:\program files\schtml\images\w2.gif
c:\program files\schtml\images\w3.gif
c:\program files\schtml\images\w3.jpg
c:\program files\schtml\images\word.doc
c:\program files\schtml\images\wt1.gif
c:\program files\schtml\images\wt2.gif
c:\program files\schtml\images\wt3.gif
c:\program files\schtml\wispex.html
c:\program files\skynet.dat
c:\windows\system32\dikuyeji.dll
c:\windows\system32\dulosopi.dll
c:\windows\system32\fapumoke.dll
c:\windows\system32\fedotaba.dll
c:\windows\system32\ganazohe.dll
c:\windows\system32\hatasefa.dll
c:\windows\system32\kuveyuke.dll
c:\windows\system32\lakezado.dll
c:\windows\system32\lotikiwi.dll
c:\windows\system32\luduvibu.dll
c:\windows\system32\mihapulo.dll
c:\windows\system32\sekihoki.dll
c:\windows\system32\selutanu.dll
c:\windows\system32\susalade.dll
c:\windows\system32\vaditujo.dll
c:\windows\system32\varapaji.dll
c:\windows\system32\vesujuji.dll
c:\windows\system32\wukojohe.dll
c:\windows\system32\zisapese.dll
C:\Your PC Protector
C:\Your PC Protector.lnk
c:\your pc protector\Your PC Protector.lnk

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_W32TIME
-------\Service_w32time


((((((((((((((((((((((((( Files Created from 2010-01-07 to 2010-02-07 )))))))))))))))))))))))))))))))
.

2010-02-05 23:21 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-05 23:21 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\Mr.E\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 04:36 . 2010-02-05 07:03 -------- d-----w- c:\program files\Magic Workstation
2010-01-31 14:32 . 2010-01-31 14:32 388096 ----a-r- c:\documents and settings\Mr.E\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-31 14:32 . 2010-01-31 14:32 -------- d-----w- c:\program files\Trend Micro
2010-01-31 14:24 . 2010-01-31 14:25 -------- d-----w- c:\program files\ERUNT
2010-01-27 08:32 . 2010-01-27 08:32 -------- d-----w- c:\program files\Common Files\Java
2010-01-27 08:32 . 2010-01-27 08:32 348160 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcr71.dll
2010-01-27 08:32 . 2010-01-27 08:32 61440 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-sse.dll
2010-01-27 08:32 . 2010-01-27 08:32 503808 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcp71.dll
2010-01-27 08:32 . 2010-01-27 08:32 499712 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\jmc.dll
2010-01-27 08:32 . 2010-01-27 08:32 12800 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-d3d.dll
2010-01-25 23:54 . 2010-01-25 23:54 -------- d-----w- c:\program files\MSECache
2010-01-18 14:58 . 2010-01-18 14:58 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-13 04:35 . 2010-01-18 14:58 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-13 04:35 . 2010-01-13 04:20 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-13 04:35 . 2010-01-13 04:20 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-13 04:35 . 2010-01-13 04:21 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-13 04:35 . 2010-01-13 04:20 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-13 04:35 . 2010-01-13 04:35 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-13 04:21 . 2010-01-13 04:28 -------- d-----w- C:\$AVG
2010-01-13 04:20 . 2010-02-04 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-13 02:31 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 00:12 . 2008-07-27 19:22 -------- d-----w- c:\program files\Steam
2010-02-06 23:53 . 2008-01-08 12:07 -------- d-----w- c:\program files\Trillian
2010-02-06 23:50 . 2006-12-12 11:34 -------- d-----w- c:\program files\mIRC
2010-02-06 20:37 . 2006-12-07 00:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-06 20:37 . 2008-12-14 09:28 -------- d-----w- c:\program files\SpywareBlaster
2010-02-06 16:36 . 2009-05-02 20:49 124 ----a-w- c:\documents and settings\Mr.E\Application Data\wklnhst.dat
2010-02-05 06:42 . 2009-06-11 09:42 -------- d-----w- c:\program files\Wesnoth
2010-02-01 05:16 . 2006-12-07 00:29 78976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 15:20 . 2006-12-12 11:57 -------- d-----w- c:\program files\NetBattle
2010-01-27 08:32 . 2009-03-11 20:44 -------- d-----w- c:\program files\Java
2010-01-13 04:28 . 2008-12-23 04:20 -------- d-----w- c:\program files\McAfee
2010-01-13 04:21 . 2009-04-28 18:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21 . 2008-06-05 19:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21 . 2006-12-12 21:50 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-13 04:21 . 2008-06-05 19:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-13 04:20 . 2008-06-05 19:35 -------- d-----w- c:\program files\AVG
2010-01-05 10:00 . 2005-08-16 09:18 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-08-16 09:18 17408 ------w- c:\windows\system32\corpol.dll
2009-12-17 22:14 . 2008-12-14 08:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-21 15:51 . 2005-08-16 09:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\parahuri.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 --sha-w- c:\windows\system32\sekikawe.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-12-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-5-9 1073152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-13 04:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
"lepekusiju"=Rundll32.exe "rojerobe.dll",s
"zuyivudeg"=Rundll32.exe "c:\windows\system32\napuruya.dll",a

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/5/2008 2:35 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/28/2009 1:39 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/12/2010 11:20 PM 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/22/2008 11:21 PM 93320]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [5/3/2006 9:19 AM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [5/3/2006 9:19 AM 8960]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
FastUserSwitchingCompatibility
HidServ
LanmanServer
LanmanWorkstation
Messenger
Nla
NWCWorkstation
Schedule
Seclogon
SRService
Themes
TrkWks
Wmi
WmdmPmSp
winmgmt
wscsvc
xmlprov
MHN
BITS
wuauserv
ShellHWDetection
helpsvc
napagent
hkmsvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-06-02 20:31]

2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-02-11 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
FF - ProfilePath - c:\documents and settings\Mr.E\Application Data\Mozilla\Firefox\Profiles\vy89qukg.Mr.E\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

BHO-{06498afd-da80-48d6-9811-8a7d67d46f48} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-06 19:12
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2572)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\stsystra.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\HPZipm12.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-02-06 19:18:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-07 00:18
ComboFix2.txt 2010-02-06 20:29
ComboFix3.txt 2010-02-05 21:12
ComboFix4.txt 2008-12-17 20:16

Pre-Run: 61,772,849,152 bytes free
Post-Run: 61,738,446,848 bytes free

- - End Of File - - 1C7904DEF87C6BFFBCFB0EF86619A6D8


Kaspersky Report:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, February 6, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, February 07, 2010 01:19:21
Records in database: 3442979
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Objects scanned: 144351
Threats found: 2
Infected objects found: 19
Suspicious objects found: 0
Scan duration: 03:07:25


File name / Threat / Threats count
C:\Documents and Settings\Mr.E\My Documents\My Received Files\Backup.ace Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\rojerobe.dll.vir Infected: Packed.Win32.TDSS.aa 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\yaromido.dll.vir Infected: Packed.Win32.TDSS.aa 1
C:\Qoobox\Quarantine\[4]-Submit_2010-02-06_18.59.59.zip Infected: Packed.Win32.TDSS.aa 10
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP389\A0052404.dll Infected: Packed.Win32.TDSS.aa 1
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP389\A0052537.dll Infected: Packed.Win32.TDSS.aa 1
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP389\A0052538.dll Infected: Packed.Win32.TDSS.aa 1
C:\WINDOWS\system32\sekikawe.dll Infected: Packed.Win32.TDSS.aa 1
C:\WINDOWS\system32\titubeve.dll_old Infected: Packed.Win32.TDSS.aa 1

Selected area has been scanned.


After everything else, DDS.txt:

DDS (Ver_09-12-01.01) - NTFSx86
Run by Mr.E at 23:41:38.09 on Sat 02/06/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.489 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Magic Workstation\MagicWorkstation.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Mr.E\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: {06498afd-da80-48d6-9811-8a7d67d46f48} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {1a45aee5-c4d2-407f-9a8c-5defddda9c1e} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director/cabs/sw.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165960990742
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\mr.e\applic~1\mozilla\firefox\profiles\vy89qukg.mr.e\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\mr.e\application data\mozilla\firefox\profiles\vy89qukg.mr.e\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-5 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-12-12 28424]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-28 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-12 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-12-22 93320]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [2006-5-3 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2006-5-3 8960]

=============== Created Last 30 ================

2010-02-07 00:40:02 0 d-----w- c:\windows\system32\Adobe
2010-02-05 23:21:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-05 23:21:21 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-05 23:02:46 0 d-----w- c:\docume~1\mr.e\applic~1\Malwarebytes
2010-02-05 23:02:41 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-05 23:02:40 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-05 20:46:56 98816 ----a-w- c:\windows\sed.exe
2010-02-05 20:46:56 77312 ----a-w- c:\windows\MBR.exe
2010-02-05 20:46:56 261632 ----a-w- c:\windows\PEV.exe
2010-02-05 20:46:56 161792 ----a-w- c:\windows\SWREG.exe
2010-02-01 04:36:09 0 d-----w- c:\program files\Magic Workstation
2010-01-31 14:32:57 0 d-----w- c:\program files\Trend Micro
2010-01-25 23:54:56 0 d-----w- c:\program files\MSECache
2010-01-13 04:21:32 0 d-----w- C:\$AVG
2010-01-13 04:20:43 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-01-13 02:31:03 471552 ------w- c:\windows\system32\dllcache\aclayers.dll

==================== Find3M ====================

2010-02-06 16:36:18 124 ----a-w- c:\docume~1\mr.e\applic~1\wklnhst.dat
2010-01-13 04:21:25 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21:25 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21:08 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-31 15:33:06 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ----a-w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-12-17 22:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\parahuri.dll
1601-01-01 00:03:28 39424 --sha-w- c:\windows\system32\sekikawe.dll
2008-08-05 01:03:12 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008080420080805\index.dat

============= FINISH: 23:42:28.18 ===============

I did not post Attach.txt because you did not ask for it. Let me know if you wanted that too.
 
Thanks for the logs :)

Open notepad and copy/paste the text in the quotebox below into it:

Code:
File::
c:\windows\system32\parahuri.dll
c:\windows\system32\sekikawe.dll
C:\WINDOWS\system32\titubeve.dll_old
DDS::
BHO: {06498afd-da80-48d6-9811-8a7d67d46f48} - No File
BHO: {1a45aee5-c4d2-407f-9a8c-5defddda9c1e} - No File
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"lepekusiju"=-
"zuyivudeg"=-


Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

CFScriptB-4.gif


Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.

See if you're able to run updated MBAM now.
 
ComboFix did not appear to reboot my computer this time. Only the desktop shut off as ComboFix reported the log file. Two unusual error lines showed up in ComboFix and it said I should submit the malware files for further analysis. I let it do that and my desktop was restored after it finished. Not sure what's up with all that...

I will try to download/run updated MBAM momentarily. Here is ComboFix Log #4:

ComboFix 10-02-05.01 - Mr.E 02/07/2010 6:26.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.622 [GMT -5:00]
Running from: c:\documents and settings\Mr.E\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mr.E\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\windows\system32\parahuri.dll"
"c:\windows\system32\sekikawe.dll"
"c:\windows\system32\titubeve.dll_old"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\parahuri.dll
c:\windows\system32\sekikawe.dll
c:\windows\system32\titubeve.dll_old

.
((((((((((((((((((((((((( Files Created from 2010-01-07 to 2010-02-07 )))))))))))))))))))))))))))))))
.

2010-02-07 00:46 . 2010-02-07 00:46 1924200 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2010-02-07 00:40 . 2010-02-07 00:40 -------- d-----w- c:\windows\system32\Adobe
2010-02-07 00:38 . 2010-02-07 00:38 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-02-07 00:37 . 2010-02-07 00:37 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-07 00:36 . 2009-11-20 11:08 38784 ----a-w- c:\documents and settings\Mr.E\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-07 00:36 . 2009-11-20 11:08 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-07 00:36 . 2010-02-07 00:36 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-07 00:34 . 2010-02-07 00:34 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-02-07 00:34 . 2010-02-07 11:25 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-02-05 23:21 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-05 23:21 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\Mr.E\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-05 23:02 . 2010-02-05 23:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 04:36 . 2010-02-07 11:07 -------- d-----w- c:\program files\Magic Workstation
2010-01-31 14:32 . 2010-01-31 14:32 388096 ----a-r- c:\documents and settings\Mr.E\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-31 14:32 . 2010-01-31 14:32 -------- d-----w- c:\program files\Trend Micro
2010-01-31 14:24 . 2010-01-31 14:25 -------- d-----w- c:\program files\ERUNT
2010-01-27 08:32 . 2010-01-27 08:32 -------- d-----w- c:\program files\Common Files\Java
2010-01-27 08:32 . 2010-01-27 08:32 348160 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcr71.dll
2010-01-27 08:32 . 2010-01-27 08:32 61440 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-sse.dll
2010-01-27 08:32 . 2010-01-27 08:32 503808 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\msvcp71.dll
2010-01-27 08:32 . 2010-01-27 08:32 499712 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-62174b27-n\jmc.dll
2010-01-27 08:32 . 2010-01-27 08:32 12800 ----a-w- c:\documents and settings\Mr.E\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-51ceeb47-n\decora-d3d.dll
2010-01-25 23:54 . 2010-01-25 23:54 -------- d-----w- c:\program files\MSECache
2010-01-18 14:58 . 2010-01-18 14:58 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-13 04:35 . 2010-01-18 14:58 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-13 04:35 . 2010-01-13 04:20 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-13 04:35 . 2010-01-13 04:20 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-13 04:35 . 2010-01-13 04:21 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-13 04:35 . 2010-01-13 04:20 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-13 04:35 . 2010-01-13 04:35 3966744 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-13 04:21 . 2010-01-13 04:28 -------- d-----w- C:\$AVG
2010-01-13 04:20 . 2010-02-04 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-13 02:31 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 11:20 . 2006-12-12 11:34 -------- d-----w- c:\program files\mIRC
2010-02-07 00:12 . 2008-07-27 19:22 -------- d-----w- c:\program files\Steam
2010-02-06 23:53 . 2008-01-08 12:07 -------- d-----w- c:\program files\Trillian
2010-02-06 20:37 . 2006-12-07 00:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-06 20:37 . 2008-12-14 09:28 -------- d-----w- c:\program files\SpywareBlaster
2010-02-06 16:36 . 2009-05-02 20:49 124 ----a-w- c:\documents and settings\Mr.E\Application Data\wklnhst.dat
2010-02-05 06:42 . 2009-06-11 09:42 -------- d-----w- c:\program files\Wesnoth
2010-02-01 05:16 . 2006-12-07 00:29 78976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 15:20 . 2006-12-12 11:57 -------- d-----w- c:\program files\NetBattle
2010-01-27 08:32 . 2009-03-11 20:44 -------- d-----w- c:\program files\Java
2010-01-13 04:28 . 2008-12-23 04:20 -------- d-----w- c:\program files\McAfee
2010-01-13 04:21 . 2009-04-28 18:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-13 04:21 . 2008-06-05 19:35 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-13 04:21 . 2006-12-12 21:50 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-13 04:21 . 2008-06-05 19:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-13 04:20 . 2008-06-05 19:35 -------- d-----w- c:\program files\AVG
2010-01-05 10:00 . 2005-08-16 09:18 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-08-16 09:18 17408 ------w- c:\windows\system32\corpol.dll
2009-12-17 22:14 . 2008-12-14 08:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-21 15:51 . 2005-08-16 09:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-12-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2007-5-9 1073152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-13 04:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Laplink\\PCmover\\PCmover.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149546169\\ee\\aim6.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/5/2008 2:35 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/28/2009 1:39 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/12/2010 11:20 PM 285392]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/22/2008 11:21 PM 93320]
S3 LLUSBFLT;LLUSBFLT;c:\windows\system32\drivers\llusbflt.sys [5/3/2006 9:19 AM 4736]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [5/3/2006 9:19 AM 8960]
.
Contents of the 'Scheduled Tasks' folder

2010-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-06-02 20:31]

2010-02-03 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-02-11 20:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/&s=aIMmDxEf9PSLpGTjtfWhmLUBH9M
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {58172624-85DD-4482-9E64-02ADCA637E96} - hxxp://www.kungfuchess.com/activex/web665.cab
FF - ProfilePath - c:\documents and settings\Mr.E\Application Data\Mozilla\Firefox\Profiles\vy89qukg.Mr.E\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A04E0F8-DC88-B943-2C7B-226A2C7B226A}]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-02-07 06:34:16
ComboFix-quarantined-files.txt 2010-02-07 11:34
ComboFix2.txt 2010-02-07 00:18
ComboFix3.txt 2010-02-06 20:29
ComboFix4.txt 2010-02-05 21:12
ComboFix5.txt 2010-02-07 11:25

Pre-Run: 67,710,521,344 bytes free
Post-Run: 67,857,899,520 bytes free

- - End Of File - - A4231D765D3233453AAA25DC60F6A326
 
Running MBAM... was a success! I followed the instructions given to me the first time you wanted me to run it. It found six infected files. Here is the MBAM log:

Malwarebytes' Anti-Malware 1.44
Database version: 3700
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

2/7/2010 6:56:39 AM
mbam-log-2010-02-07 (06-56-39).txt

Scan type: Quick Scan
Objects scanned: 128733
Time elapsed: 4 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77dc0baa-3235-4ba9-8be8-aa9eb678fa02} (Rogue.ASCAntispyware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
 
Great. Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions :)


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis



Now lets uninstall ComboFix:
  • Click START then RUN
  • Now copy-paste Combofix /uninstall in the runbox and click OK


Please download OTC and save it to desktop.
  • Double-click OTC.exe.
  • Click the CleanUp! button.
  • Select Yes when the
    Begin cleanup Process?
    prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.

Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.



UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

  • hosts file:
    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
    • This is why using a hosts file is optional!!
    Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
    If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    1. [*]Click the start button (at the lower left hand corner of your screen) [*]Click run [*]In the dialog box, type services.msc [*]hit enter, then locate dns client [*]Highlight it, then double-click it. [*]On the dropdown box, change the setting from automatic to manual. [*]Click ok
  • Run Secunia vulnerability check here and fix its findings.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free or Comodo Firewall Pro (If you choose Comodo: Uncheck during installation Install Comodo HopSurf.., Make Comodo my default search provider and Make Comodo Search my homepage and install firewall ONLY!). Both providers have support forums that help with configuration related questions.


Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:
 
I believe I stopped having symptoms after the third ComboFix run or so but that doesn't mean something malicious isn't still lurking. :fear: I assume this Windows Security Alert in my taskbar is legit and I can tinker to make it go away again, then?

1) Reset System Restore.
2) Uninstalled ComboFix. The second install, of the updated version, did not go away, so I deleted it manually if that's ok.
3) Used OTC cleaner.

4) Downloaded IE8. I never bothered before, as I use Firefox for browsing, but I suppose it is still important to keep up-to-date because of Explorer's general integration with the OS.
5) My IE already had those things set under Security, except "Navigate sub-frames across different domains" had been set to Disable.
6) Downloaded the only security update available, something related to Javascript.

Lastly, I did the Secunia scan. My computer froze up about 10 minutes into a thorough scan but the three things it listed up to that point as vulnerable:

**Heavily outdated version of AIM, as I no longer use it. I suppose I'll update it anyway, I access my AIM account through Trillian.

**Slightly out-of-date RealPlayer. I'll take care of that for the rare occasion a website still actually uses RealPlayer to display video...

**Macromedia Flash Player (version 8.x). Looks like this might've been missed by the uninstaller I ran before? There's no uninstaller in Add/Remove Programs and I generally can find no trace of it, short of searching for individual files on the C:\ drive. What should I do here?

And that's about it. That whole "logon.exe" error message when booting up is also gone and my computer shuts down much, much faster, so woohoo!
 
Hi,

2) Uninstalled ComboFix. The second install, of the updated version, did not go away, so I deleted it manually if that's ok.
ComboFix should be properly uninstalled. Please download a fresh copy to your desktop and then do the following:
1. Click start->run->copy-paste following bolded command in it and press ok (ComboFix will run):
Code:
"%userprofile\desktop\ComboFix.exe" /skipfix
2. When finished, click start->run->copy-paste the following bolded command and press ok (that should uninstall ComboFix properly):
Code:
"%userprofile\desktop\ComboFix.exe" /uninstall
**Macromedia Flash Player (version 8.x). Looks like this might've been missed by the uninstaller I ran before? There's no uninstaller in Add/Remove Programs and I generally can find no trace of it, short of searching for individual files on the C:\ drive. What should I do here?
See if C:\WINDOWS\system32\Macromed\Flash folder holds any 8.x version Flash components (Flash8X.ocx files where X is some alphabet)
 
The ComboFix thing worked. I had to use "%userprofile%" instead of "%userprofile" as given, however.

The C:\WINDOWS\system32\Macromed\Flash folder does contain Flash8b.ocx. It also has an uninstall_plugin file, if that's what I need to run to get rid of it.
 
Back
Top