Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Operating Systems » Windows XP/2000 » I'm in computer hell....HELP!!

Windows XP/2000 - I'm in computer hell....HELP!! posted in the Operating Systems forums; Ok.Thats as helped to remove some more... Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #29  
Old 08-01-2008
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 4,065
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: I'm in computer hell....HELP!!

Ok.Thats as helped to remove some more...



Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

It's IMPORTANT to carry out the instructions in the sequence listed below.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open *notepad* and copy/paste the text in the quotebox below into it:


File::
C:\WINDOWS\system32\bcMlmnnn.ini
C:\WINDOWS\system32\YFijQqru.ini
C:\WINDOWS\system32\peejkdvu.tmp
Folder::
C:\Temp\epr1
C:\Temp\btxv15
C:\WINDOWS\system32\carH18
C:\Temp\zpv201
C:\WINDOWS\system32\aumsDK18
Registry::
Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.




Refering to the picture above, drag CFScript.txt into ComboFix.exe


When finished, it shall produce a log for you at C:\ComboFix.txt

Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.


*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #30  
Old 08-01-2008
Bronze Member
 
Join Date: Jul 2008
Location: British Columbia
Posts: 42
PC Experience: Beginner
daysofoz - See this Members User comments on their Profile page
Default Re: I'm in computer hell....HELP!!

I was trying to run the combofix but I kept getting the message that the "combo-Fix" wouldn't work, anyway, I downloaded the version again from
your recommended website this time without a hyphen,(I think it was computergeeks.com) and I pasted the stuff from notepad into the icon, and here is the resulting report. I'm nervous that I've stuffed something up by downloading the combofix again..

ComboFix 08-07-31.01 - angela 2008-07-31 19:23:39.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.179 [GMT -7:00]
Running from: C:\Documents and Settings\angela\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\angela\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\bcMlmnnn.ini
C:\WINDOWS\system32\peejkdvu.tmp
C:\WINDOWS\system32\YFijQqru.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\btxv15
C:\Temp\epr1
C:\Temp\epr1\K19i.log
C:\Temp\zpv201
C:\Temp\zpv201\chckNB2.log
C:\WINDOWS\system32\aumsDK18
C:\WINDOWS\system32\bcMlmnnn.ini
C:\WINDOWS\system32\carH18
C:\WINDOWS\system32\peejkdvu.tmp
C:\WINDOWS\system32\YFijQqru.ini
.
((((((((((((((((((((((((( Files Created from 2008-07-01 to 2008-08-01 )))))))))))))))))))))))))))))))
.
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Malwarebytes
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-28 09:15 . 2008-07-28 09:15 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-07-28 03:05 . 2008-07-28 03:05 <DIR> d-------- C:\Deckard
2008-07-21 12:57 . 2008-07-21 12:56 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-21 12:56 . 2008-07-21 13:34 <DIR> d-------- C:\Documents and Settings\angela\.housecall6.6
2008-07-21 12:49 . 2008-07-22 15:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-20 15:41 . 2008-07-20 15:41 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Ahead
2008-07-20 15:41 . 2008-07-20 15:41 0 --a------ C:\WINDOWS\Irremote.ini
2008-07-20 15:01 . 2008-07-20 15:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Program Files\Nero
2008-07-20 14:34 . 2008-07-21 09:51 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-07-19 11:08 . 2008-07-20 09:29 <DIR> d-------- C:\Documents and Settings\angela\Application Data\muvee Technologies
2008-07-18 10:14 . 2008-07-31 07:03 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-18 10:00 . 2008-07-18 10:00 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-18 08:12 . 2008-07-31 08:23 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-18 08:12 . 2008-07-18 10:00 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-18 08:12 . 2008-07-18 10:01 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Program Files\AVG
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-17 21:05 . 2008-07-18 07:52 <DIR> d--hs---- C:\WINDOWS\ZGF5
2008-07-17 10:48 . 2008-07-17 10:48 149 --a------ C:\WINDOWS\wininit.ini
2008-07-17 09:56 . 2008-07-18 14:59 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-17 09:56 . 2008-07-18 15:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-17 08:45 . 2008-07-17 09:24 <DIR> d---s---- C:\Documents and Settings\Administrator
2008-07-16 08:48 . 2008-07-16 08:40 109,568 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-07-16 08:48 . 2008-07-16 08:40 108,544 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-07-15 05:32 . 2008-07-15 05:42 537 --ahs---- C:\WINDOWS\system32\kjkUvGgh.ini
2008-07-14 17:24 . 2008-07-14 17:25 <DIR> d-------- C:\Documents and Settings\angela\Application Data\gtk-2.0
2008-07-14 17:23 . 2008-07-14 17:26 <DIR> d-------- C:\Documents and Settings\angela\.gimp-2.4
2008-07-14 14:36 . 2008-07-14 14:36 <DIR> d-------- C:\Program Files\Aurora Digital Imaging
2008-07-14 14:34 . 2008-07-14 14:34 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-07-14 09:10 . 2008-07-14 09:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-14 07:32 . 2008-07-14 07:32 <DIR> d-------- C:\Program Files\Windows Defender
2008-07-14 06:27 . 2008-07-14 06:27 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-07-14 06:18 . 2008-07-14 13:54 2,582 --ahs---- C:\WINDOWS\system32\cffMVvut.ini
2008-07-14 06:13 . 2008-07-15 05:28 <DIR> d-------- C:\WINDOWS\system32\olixds18
2008-07-14 06:13 . 2008-07-31 19:24 <DIR> d-------- C:\Temp
2008-07-13 14:18 . 2008-07-13 14:18 <DIR> d-------- C:\Documents and Settings\angela\Application Data\FastStone
2008-07-10 22:12 . 2008-07-10 22:12 <DIR> d-------- C:\Program Files\iPod
2008-07-10 21:54 . 2008-07-10 21:54 <DIR> d-------- C:\Program Files\Safari
2008-07-02 12:28 . 2008-07-02 12:28 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-14 10:42 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-02 16:14 <DIR> d-------- C:\DVDVideoSoft
2008-07-02 12:28 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-07-01 17:39 . 2008-07-01 17:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
2008-07-01 17:31 . 2008-07-02 16:16 <DIR> d-------- C:\Program Files\Flypaper Beta
2008-07-01 17:24 . 2008-07-01 17:24 <DIR> d-------- C:\Program Files\MSBuild
2008-07-01 17:23 . 2008-07-01 17:23 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-07-01 17:23 . 2008-07-01 17:23 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-07-01 17:22 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-07-01 17:17 . 2008-07-01 17:17 <DIR> d-------- C:\Program Files\MSXML 6.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-08-01 02:28 --------- d-----w C:\Documents and Settings\angela\Application Data\Skype
2008-07-22 16:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-21 23:45 --------- d-----w C:\Program Files\Picasa2
2008-07-20 20:50 --------- d-----w C:\Program Files\Ahead
2008-07-20 13:33 --------- d-----w C:\Program Files\Incomplete
2008-07-17 01:27 --------- d-----w C:\Documents and Settings\Jen\Application Data\LimeWire
2008-07-16 16:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-14 22:18 129 ----a-w C:\WINDOWS\Fonts\1001freefonts.txt
2008-07-14 20:36 --------- d-----w C:\Program Files\Java
2008-07-13 14:03 --------- d-----w C:\Documents and Settings\angela\Application Data\Apple Computer
2008-07-11 05:12 --------- d-----w C:\Program Files\iTunes
2008-07-11 05:08 --------- d-----w C:\Program Files\QuickTime
2008-07-10 16:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-06-29 04:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 23:02 --------- d-----w C:\Documents and Settings\Jen\Application Data\Apple Computer
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 10:04 --------- d-----w C:\Program Files\Microsoft Works
2008-06-08 17:38 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-13 16:12 33,280 ----a-w C:\WINDOWS\system32\HUFFYUV.DLL
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-07 20:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-04-07 00:38 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-09-29 17:25 21871656]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-25 18:23 443968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-18 10:01 1232152]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\M SCONFIG.EXE" [2004-08-04 05:00 158208]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\Alcxmntr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-03-22 19:29 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--------- 2008-07-07 09:42 2156368 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\ \SAGENT4.EXE"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-18 10:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-18 10:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-18 10:00]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-18 10:01]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{9ef3de30-ff49-11dc-9a4a-806d6172696f}]
\Shell\AutoRun\command - E:\Info.exe folder.htt 480 480
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-07-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2008-08-01 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-31 19:29:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-07-31 19:53:08
ComboFix-quarantined-files.txt 2008-08-01 02:53:02
ComboFix2.txt 2008-07-31 06:35:11
Pre-Run: 10,041,335,808 bytes free
Post-Run: 10,036,129,792 bytes free
183 --- E O F --- 2008-08-01 01:31:52

and the HijackThis report

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:44 PM, on 7/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - Add to Windows Live Favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype add-on - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://paris.ville.orange.fr/CO/acti...CamControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 6496 bytes


  #31  
Old 08-01-2008
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 4,065
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: I'm in computer hell....HELP!!

No problem..all is fine.This will be the last of the cleanup.


Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

It's IMPORTANT to carry out the instructions in the sequence listed below.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open *notepad* and copy/paste the text in the quotebox below into it:




File::
C:\WINDOWS\system32\kjkUvGgh.ini

Folder::
C:\Documents and Settings\Jen\Application Data\LimeWire

Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.




Refering to the picture above, drag CFScript.txt into ComboFix.exe


When finished, it shall produce a log for you at C:\ComboFix.txt

Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.


*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*


===================================


We need to install your Recovery Console.
Go to Microsoft's website => How to obtain Windows XP Setup disks for a floppy boot installation
Select the download that's appropriate for your Operating System




Download the file & save it as it's originally named, next to ComboFix.exe.






Now close all open windows and programs, including all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Drag the setup package onto ComboFix.exe and drop it.
  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.
  • At the next prompt, click 'Yes' to run the full ComboFix scan.


  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt along with a new HijackThis log for further review.


__________________
  • An Australian Member of
  • and
My real name is Eddy

Last edited by Pancake; 08-02-2008 at 04:00 AM.
  #32  
Old 08-02-2008
Bronze Member
 
Join Date: Jul 2008
Location: British Columbia
Posts: 42
PC Experience: Beginner
daysofoz - See this Members User comments on their Profile page
Default Re: I'm in computer hell....HELP!!

Here is the Combofix txt. I notice there is heaps of Limewire stuff on there, what's that all about? We've never had trouble before with this site.

ComboFix 08-07-31.01 - angela 2008-07-31 21:46:19.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.166 [GMT -7:00]
Running from: C:\Documents and Settings\angela\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\angela\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\kjkUvGgh.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Jen\Application Data\LimeWire
C:\Documents and Settings\Jen\Application Data\LimeWire\active.mojito
C:\Documents and Settings\Jen\Application Data\LimeWire\createtimes.cache
C:\Documents and Settings\Jen\Application Data\LimeWire\fileurns.bak
C:\Documents and Settings\Jen\Application Data\LimeWire\fileurns.cache
C:\Documents and Settings\Jen\Application Data\LimeWire\filters.props
C:\Documents and Settings\Jen\Application Data\LimeWire\installation.props
C:\Documents and Settings\Jen\Application Data\LimeWire\library.dat
C:\Documents and Settings\Jen\Application Data\LimeWire\limewire.props
C:\Documents and Settings\Jen\Application Data\LimeWire\mojito.props
C:\Documents and Settings\Jen\Application Data\LimeWire\questions.props
C:\Documents and Settings\Jen\Application Data\LimeWire\simpp.xml
C:\Documents and Settings\Jen\Application Data\LimeWire\tables.props
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme.lwtp
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\01_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\02_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\03_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\04_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\05_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button1.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button1_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button2.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button2_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button3.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button3_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button4.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button4_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button5.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\button5_press.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\chat.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\connections.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\dir_closed.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\dir_open.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\forward_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\forward_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\kill.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\kill_on.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\library.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\logo.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\monitor.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\notsearching.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\pause_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\pause_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\play_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\play_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\plug.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\question.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\rewind_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\rewind_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\search.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\searching.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\shopping.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\splash.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\stop_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\stop_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\theme.txt
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\party_theme\warning.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme.lwtp
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\01_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\02_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\03_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\04_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\05_star.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\chat.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\forward_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\kill.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\kill_on.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\logo.png
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\notsearching.pn g
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\pause_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\play_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\play_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\question.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\searching.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\stop_up.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\theme.txt
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\version.txt
C:\Documents and Settings\Jen\Application Data\LimeWire\themes\windows_theme\warning.gif
C:\Documents and Settings\Jen\Application Data\LimeWire\version.xml
C:\WINDOWS\system32\kjkUvGgh.ini
.
((((((((((((((((((((((((( Files Created from 2008-07-01 to 2008-08-01 )))))))))))))))))))))))))))))))
.
2008-07-31 20:30 . 2008-07-31 20:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Gogii
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Malwarebytes
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-28 09:15 . 2008-07-28 09:15 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-07-28 03:05 . 2008-07-28 03:05 <DIR> d-------- C:\Deckard
2008-07-21 12:57 . 2008-07-21 12:56 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-21 12:56 . 2008-07-21 13:34 <DIR> d-------- C:\Documents and Settings\angela\.housecall6.6
2008-07-21 12:49 . 2008-07-22 15:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-20 15:41 . 2008-07-20 15:41 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Ahead
2008-07-20 15:41 . 2008-07-20 15:41 0 --a------ C:\WINDOWS\Irremote.ini
2008-07-20 15:01 . 2008-07-20 15:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Program Files\Nero
2008-07-20 14:34 . 2008-07-21 09:51 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-07-19 11:08 . 2008-07-20 09:29 <DIR> d-------- C:\Documents and Settings\angela\Application Data\muvee Technologies
2008-07-18 10:14 . 2008-07-31 07:03 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-18 10:00 . 2008-07-18 10:00 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-18 08:12 . 2008-07-31 08:23 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-18 08:12 . 2008-07-18 10:00 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-18 08:12 . 2008-07-18 10:01 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Program Files\AVG
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-17 21:05 . 2008-07-18 07:52 <DIR> d--hs---- C:\WINDOWS\ZGF5
2008-07-17 10:48 . 2008-07-17 10:48 149 --a------ C:\WINDOWS\wininit.ini
2008-07-17 09:56 . 2008-07-18 14:59 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-17 09:56 . 2008-07-18 15:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-17 08:45 . 2008-07-17 09:24 <DIR> d---s---- C:\Documents and Settings\Administrator
2008-07-16 08:48 . 2008-07-16 08:40 109,568 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-07-16 08:48 . 2008-07-16 08:40 108,544 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-07-14 17:24 . 2008-07-14 17:25 <DIR> d-------- C:\Documents and Settings\angela\Application Data\gtk-2.0
2008-07-14 17:23 . 2008-07-14 17:26 <DIR> d-------- C:\Documents and Settings\angela\.gimp-2.4
2008-07-14 14:36 . 2008-07-14 14:36 <DIR> d-------- C:\Program Files\Aurora Digital Imaging
2008-07-14 14:34 . 2008-07-14 14:34 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-07-14 09:10 . 2008-07-14 09:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-14 07:32 . 2008-07-14 07:32 <DIR> d-------- C:\Program Files\Windows Defender
2008-07-14 06:27 . 2008-07-14 06:27 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-07-14 06:18 . 2008-07-14 13:54 2,582 --ahs---- C:\WINDOWS\system32\cffMVvut.ini
2008-07-14 06:13 . 2008-07-15 05:28 <DIR> d-------- C:\WINDOWS\system32\olixds18
2008-07-14 06:13 . 2008-07-31 19:24 <DIR> d-------- C:\Temp
2008-07-13 14:18 . 2008-07-13 14:18 <DIR> d-------- C:\Documents and Settings\angela\Application Data\FastStone
2008-07-10 22:12 . 2008-07-10 22:12 <DIR> d-------- C:\Program Files\iPod
2008-07-10 21:54 . 2008-07-10 21:54 <DIR> d-------- C:\Program Files\Safari
2008-07-02 12:28 . 2008-07-02 12:28 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-14 10:42 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-02 16:14 <DIR> d-------- C:\DVDVideoSoft
2008-07-02 12:28 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-07-01 17:39 . 2008-07-01 17:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
2008-07-01 17:31 . 2008-07-02 16:16 <DIR> d-------- C:\Program Files\Flypaper Beta
2008-07-01 17:24 . 2008-07-01 17:24 <DIR> d-------- C:\Program Files\MSBuild
2008-07-01 17:23 . 2008-07-01 17:23 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-07-01 17:23 . 2008-07-01 17:23 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-07-01 17:22 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-07-01 17:17 . 2008-07-01 17:17 <DIR> d-------- C:\Program Files\MSXML 6.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-08-01 04:50 --------- d-----w C:\Documents and Settings\angela\Application Data\Skype
2008-07-22 16:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-21 23:45 --------- d-----w C:\Program Files\Picasa2
2008-07-20 20:50 --------- d-----w C:\Program Files\Ahead
2008-07-20 13:33 --------- d-----w C:\Program Files\Incomplete
2008-07-16 16:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-14 22:18 129 ----a-w C:\WINDOWS\Fonts\1001freefonts.txt
2008-07-14 20:36 --------- d-----w C:\Program Files\Java
2008-07-13 14:03 --------- d-----w C:\Documents and Settings\angela\Application Data\Apple Computer
2008-07-11 05:12 --------- d-----w C:\Program Files\iTunes
2008-07-11 05:08 --------- d-----w C:\Program Files\QuickTime
2008-07-10 16:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-06-29 04:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 23:02 --------- d-----w C:\Documents and Settings\Jen\Application Data\Apple Computer
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 10:04 --------- d-----w C:\Program Files\Microsoft Works
2008-06-08 17:38 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-07 20:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-04-07 00:38 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-07-30_23.34.31.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-01 10:04:53 2,216 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{2069A2 92-9FED-4ED5-BE82-53C8AD47C81E}.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-09-29 17:25 21871656]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-25 18:23 443968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-18 10:01 1232152]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\M SCONFIG.EXE" [2004-08-04 05:00 158208]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\Alcxmntr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-03-22 19:29 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--------- 2008-07-07 09:42 2156368 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\ \SAGENT4.EXE"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-18 10:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-18 10:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-18 10:00]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-18 10:01]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{9ef3de30-ff49-11dc-9a4a-806d6172696f}]
\Shell\AutoRun\command - E:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2008-07-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2008-08-01 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-01 08:00:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\iPod\bin\iPodService.exe
.
************************************************** ************************
.
Completion time: 2008-08-01 8:13:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-01 15:13:05
ComboFix2.txt 2008-08-01 02:53:10
ComboFix3.txt 2008-07-31 06:35:11
Pre-Run: 9,798,717,440 bytes free
Post-Run: 9,766,653,952 bytes free
267 --- E O F --- 2008-08-01 10:03:02

HIJACK THIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:55:30 PM, on 8/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - Add to Windows Live Favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype add-on - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://paris.ville.orange.fr/CO/acti...CamControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobi