This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Overrun with malware

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Was playing the game spore & was asked if i wanted to download the newest patch. I said yes & then my computer froze up. I turned it off & back on & after I when it started back up, spyware guard & avg told me I had infections & i selected to have them removed. I restarted again & then spybot s&d was giving me probs. It kept asking me if I wanted to allow changes to certain registries (some added, some deleted). I kept saying deny change & it just keeps popping up. I ctrl+alt+del & saw numerous processes running that shouldn't be (from rundll33.exe, iexplore.exe even though I never tried opening the internet, & wuauclt.exe). I ended all the processes & the spybot s&d requests keep coming. I also have spywareguard popups telling me the following BHO has been added to my system: {d5bf4552-94f1-42bd-f434-3604812c807d} I keep selecting to remove the BHO but it just pops back up I can't run Malwarebytes AntiMalware, or SuperAntiSpyware. I ran avg in safe-mode (could only run it command line scanner), and it gave me a .txt document titled avrep. Here it is: AVG 8.0 Anti-Virus command line scanner Copyright © 1992 - 2008 AVG Technologies Program version 8.0.228, engine 8.0.237 Virus Database: Version 270.10.23/1952 2009-02-13 C:\WINDOWS\system32\crypts.dll Trojan horse Downloader.Small.FFJ Object was moved to Virus Vault. C:\WINDOWS\system32\winlogon.exe (260) Trojan horse Downloader.Small.FFJ Object was moved to Virus Vault. C:\WINDOWS\system32\uisaj387dd.dll Trojan horse Agent.AYJO Object was moved to Virus Vault. C:\WINDOWS\system32\hsfd83jfdg.dll Trojan horse Agent.AXOO Object was moved to Virus Vault. C:\WINDOWS\explorer.exe (868) Trojan horse Agent.AYJO Object was moved to Virus Vault. C:\DOCUME~1\Nick\LOCALS~1\Temp\csrssc.exe Trojan horse SHeur2.OOX Object was moved to Virus Vault. HKU\S-1-5-21-267048546-3394276723-1217438979-1006\Software\Microsoft\Windows\CurrentVersion\Run\\tezrtsjhfr84iusjfo84f Found registry key with reference to infected file C:\DOCUME~1\Nick\LOCALS~1\Temp\csrssc.exe Object was moved to Virus Vault. C:\WINDOWS\system32\grcrt.exe Trojan horse SHeur2.GVC Object was moved to Virus Vault. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DeskTopSrv Found registry key with reference to infected file C:\WINDOWS\system32\grcrt.exe Object was moved to Virus Vault. ———————————————————— Objects scanned : 263018 Found infections : 7 Found PUPs : 0 Healed infections : 7 Healed PUPs : 0 Warnings : 0 ———————————————————— Also have DSS logs (both DSS.txt & Attach.txt) if you would like me to post them as well. Tried restoring the computer from a restore point, but after waiting about 2 hours & nothing happening, I'm giving up hope of that working either.
Hi ezpkns34,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please post both DDS logs for my review.
DDS.txt:

DDS (Ver_09-02-01.01) - NTFSx86
Run by [removed] at 14:15:16.73 on Sun 02/15/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.553 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Nick\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
BHO: c:\windows\system32\uisaj387dd.dll: {d5bf4552-94f1-42bd-f434-3604812c807d} - c:\windows\system32\uisaj387dd.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [BitTorrent] "c:\program files\bittorrent\bittorrent.exe" –force_start_minimized
uRun: [EA Core] c:\program files\electronic arts\eadm\Core.exe -silent
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [KADxMain] c:\windows\system32\KADxMain.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [dscactivate] "%ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mExplorerRun: [xccinit] c:\windows\system32\inf\rundll33.exe c:\windows\xccdf16_090131a.dll xccd16
StartupFolder: c:\docume~1\nick\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: Crawler Search
IE: E&xport; to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\nick\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://152.1.164.197/activex/AxisCamControl.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-yahtzee/zylomplayer.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} - hxxp://www.worldwinner.com/games/v47/familyfeud/familyfeud.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: crypt - crypts.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: c:\windows\system32\uisaj387dd.dll: {d5bf4552-94f1-42bd-f434-3604812c807d} - c:\windows\system32\uisaj387dd.dll
STS: c:\windows\system32\hsfd83jfdg.dll: {c5bf49a2-94f3-42bd-f434-3604812c8955} - c:\windows\system32\hsfd83jfdg.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\nick\applic~1\mozilla\firefox\profiles\5ei8gwd3.default\
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-11-2 325128]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-11-2 27656]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-31 298264]
R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2007-12-9 2560]
S2 MSMQSVC;Message Queuing Service;c:\windows\system32\mqsv32.exe –> c:\windows\system32\mqsv32.exe [?]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-8 24652]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S3 xbreader;MaxDrive XBox Driver (xbreader.sys);c:\windows\system32\drivers\xbreader.sys [2001-1-2 19677]

=============== Created Last 30 ================

2009-02-15 04:06 15,504 a——- c:\windows\system32\drivers\mbam.sys
2009-02-15 04:06 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-15 04:01 40,960 a——- c:\windows\system32\grcrt.dll
2009-02-15 04:01 26,624 a——- c:\windows\system32\grcrt2.exe
2009-02-15 02:51 664 a——- c:\windows\system32\d3d9caps.dat
2009-02-14 18:14 0 a——- c:\windows\system32\drivers\seneka.sys
2009-02-14 17:38 99,696 a——- c:\windows\system32\drivers\e00e1a0c.sys
2009-02-14 17:38 2,048 a——- C:\nwpy.exe
2009-02-14 17:37 40,448 a——- c:\windows\Phipuxiqivoquli.dll
2009-02-14 17:37 15,872 a——- c:\windows\system32\senekavjppasah.dll
2009-02-14 17:37 14,336 a——- c:\windows\system32\senekapqspnyxj.dll
2009-02-14 17:37 1,792 a——- c:\windows\system32\senekasdewulqe.dat
2009-02-14 17:37 67,584 a——- c:\windows\system32\drivers\senekatofxhole.sys
2009-02-14 17:37 49,152 a——- c:\windows\system32\senekaivkkyigf.dll
2009-02-14 17:08 197 a——- c:\windows\system32\xcchit32.ini
2009-02-14 17:08 –d—– c:\docume~1\alluse~1\applic~1\Electronic Arts
2009-02-04 20:24 –d—– c:\docume~1\nick\applic~1\Maple
2009-02-04 20:16 212,992 a——- c:\windows\system32\WMIMPLEX.dll
2009-02-04 20:16 40,960 a——- c:\windows\system32\maplec.dll
2009-02-04 20:16 20,480 a——- c:\windows\system32\maplecompat.dll
2009-02-04 20:16 –d—– C:\watcom-1.3
2009-02-04 20:14 –d-h— c:\program files\Zero G Registry
2009-02-04 20:14 –d—– c:\program files\Maple 12
2009-02-04 20:13 –d-h— c:\documents and settings\nick\InstallAnywhere
2009-01-31 12:16 10,520 a——- c:\windows\system32\avgrsstx.dll
2009-01-23 15:52 268,648 a——- c:\windows\system32\mucltui.dll
2009-01-23 15:52 208,744 a——- c:\windows\system32\muweb.dll
2009-01-23 15:52 27,496 a——- c:\windows\system32\mucltui.dll.mui

==================== Find3M ====================

2009-02-15 14:15 99,696 a——- c:\windows\system32\drivers\33e1b4cb.sys
2009-02-15 14:03 251,392 a——- c:\windows\xccdf32_090131a.dll
2009-02-15 14:03 3,609 a–sh— c:\windows\system32\mmf.sys
2009-02-14 17:37 216,576 a——- c:\windows\system32\mqapi.exe
2009-02-14 17:08 87,024 a——- c:\windows\system32\nvModes.dat
2009-02-14 17:03 106,496 a——- c:\windows\system32\fejokt.dll
2009-02-14 17:03 3,182 a——- c:\windows\ios.dat
2009-02-14 17:03 90,119 a——- C:\nxspv.exe
2009-02-14 17:03 82,432 a——- C:\xxmwr.exe
2009-02-14 17:03 15,000 a——- c:\windows\system32\uisaj387dd.dll
2009-02-14 17:03 36,352 a——- c:\windows\xccdf16_090131a.dll
2009-01-31 12:16 325,128 a——- c:\windows\system32\drivers\avgldx86.sys
2009-01-16 21:35 3,594,752 ——– c:\windows\system32\dllcache\mshtml.dll
2009-01-14 12:20 107,888 a——- c:\windows\system32\CmdLineExt.dll
2009-01-12 20:39 2,802,580 a——- c:\program files\PFCSetup1.0.223.exe
2009-01-12 12:13 6,274,206 a——- c:\program files\102_35143.exe
2008-12-19 04:10 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 04:10 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 00:25 634,024 ——– c:\windows\system32\dllcache\iexplore.exe
2008-12-19 00:23 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2008-12-17 19:33 77,803 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-12-11 05:57 333,952 ——– c:\windows\system32\dllcache\srv.sys
2008-11-07 17:09 536,811 a——- c:\program files\ie-spyad.exe
2008-11-07 17:08 2,062,665 a——- c:\program files\spywareguardsetup.exe
2008-11-07 17:07 2,869,536 a——- c:\program files\spywareblastersetup41.exe
2008-10-23 11:17 18,829,383 a——- c:\program files\tibia831.exe
2008-08-13 20:59 232,904,074 a——- c:\program files\ootp9setup.exe
2008-07-07 08:34 24,234,968 a——- c:\program files\setupeng.exe
2008-07-04 14:01 15,336,856 a——- c:\program files\jre-6u10-beta-windows-i586-p.exe
2008-07-04 13:50 50,688 a——- c:\program files\ATF-Cleaner.exe
2008-06-26 16:45 9,722,720 a——- c:\program files\spybotsd152.exe
2008-06-22 21:32 49,384,056 a——- c:\program files\avg_free_stf_all_8_100a1323.exe
2008-06-20 19:07 5,632 a–sh— c:\program files\Thumbs.db
2008-05-18 02:37 18,289,392 a——- c:\program files\DivXInstaller.exe
2007-11-21 17:55 6,637,432 a——- c:\program files\dMC-R12.3-Ref-Registered.exe
2007-11-13 11:01 13,871,095 a——- c:\program files\schedulemaker.zip
2007-06-15 00:35 9,690,219 a——- c:\program files\mws094f.exe
2007-06-14 11:29 380,208,128 a——- c:\program files\mtgodl2.exe
2007-03-18 18:57 26,583,420 a——- c:\program files\Geneforge4Demo.exe

============= FINISH: 14:16:07.34 ===============



Attach.txt:

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-02-01.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 12/8/2007 10:49:36 PM
System Uptime: 2/15/2009 2:02:11 PM (0 hours ago)

Motherboard: Dell Inc. | | 0KY768
Processor: Intel® Core™2 Duo CPU T7500 @ 2.20GHz | Microprocessor | 2194/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 143 GiB total, 54.095 GiB free.
D: is CDROM (UDF)

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Dell Wireless 1390 WLAN Mini-Card
Device ID: PCI\VEN_14E4&DEV;_4311&SUBSYS;_00071028&REV;_01\4&AB208E;&0&00E1
Manufacturer: Broadcom
Name: Dell Wireless 1390 WLAN Mini-Card
PNP Device ID: PCI\VEN_14E4&DEV;_4311&SUBSYS;_00071028&REV;_01\4&AB208E;&0&00E1
Service: BCM43XX

==== System Restore Points ===================

RP102: 11/28/2008 9:27:32 PM - 11-28
RP103: 11/28/2008 9:33:05 PM - Removed SUPERAntiSpyware Free Edition
RP104: 12/2/2008 6:23:07 PM - System Checkpoint
RP105: 12/4/2008 6:22:06 PM - System Checkpoint
RP106: 12/4/2008 11:01:41 PM -
RP107: 12/7/2008 4:26:10 PM - System Checkpoint
RP108: 12/8/2008 7:37:44 PM - System Checkpoint
RP109: 12/10/2008 3:00:19 AM - Software Distribution Service 3.0
RP110: 12/11/2008 1:30:10 PM - System Checkpoint
RP111: 12/17/2008 4:27:12 PM - System Checkpoint
RP112: 12/17/2008 6:09:55 PM - Software Distribution Service 3.0
RP113: 12/17/2008 6:17:56 PM - Software Distribution Service 3.0
RP114: 12/17/2008 7:19:11 PM - Software Distribution Service 3.0
RP115: 12/18/2008 3:39:39 AM - Software Distribution Service 3.0
RP116: 12/19/2008 6:32:36 PM - System Checkpoint
RP117: 12/20/2008 2:30:48 AM - Shockwave Player
RP118: 12/20/2008 2:31:35 AM - Shockwave Player
RP119: 12/21/2008 2:38:01 PM - System Checkpoint
RP120: 12/22/2008 8:45:28 PM - System Checkpoint
RP121: 12/23/2008 9:22:42 PM - System Checkpoint
RP122: 12/25/2008 8:11:07 AM - System Checkpoint
RP123: 12/26/2008 2:19:14 PM - System Checkpoint
RP124: 12/27/2008 4:38:24 PM - System Checkpoint
RP125: 12/28/2008 4:43:27 PM - System Checkpoint
RP126: 12/29/2008 11:19:24 AM - Avg8 Update
RP127: 12/31/2008 5:31:57 PM - System Checkpoint
RP128: 1/1/2009 8:22:33 PM - System Checkpoint
RP129: 1/3/2009 7:41:32 PM - System Checkpoint
RP130: 1/4/2009 9:14:13 PM - System Checkpoint
RP131: 1/5/2009 11:47:34 PM - System Checkpoint
RP132: 1/7/2009 2:32:43 AM - System Checkpoint
RP133: 1/8/2009 9:49:02 AM - Removed PurePlay Poker.
RP134: 1/13/2009 12:47:57 PM - System Checkpoint
RP135: 1/14/2009 3:00:24 AM - Software Distribution Service 3.0
RP136: 1/14/2009 12:03:23 PM - Removed SPORE™ Creature Creator Trial Edition
RP137: 1/14/2009 12:04:55 PM - Installed SPORE™
RP138: 1/14/2009 12:19:13 PM - Installed EA Download Manager
RP139: 1/14/2009 12:27:07 PM - Configured SPORE™
RP140: 1/15/2009 6:03:14 PM - Installed Java™ 6 Update 11
RP141: 1/16/2009 8:25:43 PM - System Checkpoint
RP142: 1/19/2009 7:26:24 PM - System Checkpoint
RP143: 1/21/2009 6:35:17 AM - System Checkpoint
RP144: 1/23/2009 8:00:08 PM - System Checkpoint
RP145: 1/24/2009 3:00:21 AM - Software Distribution Service 3.0
RP146: 1/25/2009 3:00:29 AM - Software Distribution Service 3.0
RP147: 1/26/2009 6:30:31 PM - System Checkpoint
RP148: 1/27/2009 8:28:08 PM - System Checkpoint
RP149: 1/28/2009 10:52:53 PM - System Checkpoint
RP150: 1/30/2009 1:18:30 PM - System Checkpoint
RP151: 1/31/2009 12:10:56 PM - Avg8 Update
RP152: 1/31/2009 12:12:07 PM - Avg8 Update
RP153: 1/31/2009 12:16:52 PM - Avg8 Update
RP154: 2/1/2009 7:13:53 PM - System Checkpoint
RP155: 2/2/2009 8:09:02 PM - System Checkpoint
RP156: 2/4/2009 10:08:16 PM - System Checkpoint
RP157: 2/6/2009 12:17:42 AM - System Checkpoint
RP158: 2/8/2009 9:29:32 PM - System Checkpoint
RP159: 2/9/2009 10:44:25 PM - System Checkpoint
RP160: 2/10/2009 11:34:30 AM - Avg8 Update
RP161: 2/11/2009 12:41:15 PM - System Checkpoint
RP162: 2/12/2009 12:06:05 PM - Software Distribution Service 3.0
RP163: 2/13/2009 11:52:38 AM - Avg8 Update
RP164: 2/14/2009 3:34:47 PM - System Checkpoint
RP165: 2/14/2009 5:30:26 PM - Configured SPORE™

==== Installed Programs ======================

µTorrent
AC3Filter (remove only)
Acrobat.com
Action Replay XBOX 1.42
Ad-Aware
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Reader 9
Adobe Shockwave Player
AIM 6
AnalogX POW!
Apple Mobile Device Support
Apple Software Update
AutoUpdate
AVG Free 8.0
Baseball Mogul 2008
Broadcom Management Programs
Browser Address Error Redirector
Compatibility Pack for the 2007 Office system
Conexant HDA D330 MDC V.92 Modem
Dell DataSafe Online
Dell Support Center (Support Software)
Dell System Restore
Dell Touchpad
Dell Wireless WLAN Card
Digital Line Detect
DivX Codec
DivX Converter
DivX Player
DivX Web Player
Documentation & Support Launcher
Draft Day Sports: College Basketball
Draft Day Sports: Pro Basketball
Full Tilt Poker.Net
Games, Music, & Photos Launcher
High Definition Audio Driver Package - KB835221
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Icy's DDSCB Real pack 1.3
IntelliSonic Speech Enhancement
Internet Service Offers Launcher
Java™ 6 Update 11
Malwarebytes' Anti-Malware
Maple 12
MediaDirect
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Application Compatibility Toolkit 5.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Modem Diagnostic Tool
Mozilla Firefox (3.0.6)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
MtG Database
Musicmatch for Windows Media Player
NetWaiting
NVIDIA Drivers
Oregon Trail II
Out of the Park Baseball 9
OutlookAddinSetup
QuickSet
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Drag-to-Disc
Roxio Express Labeler
Roxio MyDVD DE
Roxio Update Manager
SearchAssist
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB960715)
Sonic Activation Module
Spybot - Search & Destroy
SpywareBlaster 4.1
SpywareGuard v2.2
Ss Registry Fixer 2.0
The Movies™
Tibia
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Viewpoint Media Player
WebFldrs XP
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows XP Service Pack 3
WinPcap 4.0.2
WinZip
Wrestling Encore (remove only)
Yahoo! Messenger
Yahoo! Music Jukebox

==== Event Viewer Messages From Past Week ========

2/14/2009 5:08:53 PM, error: Service Control Manager [7000] - The Viewpoint Manager Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/14/2009 5:08:53 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Viewpoint Manager Service service to connect.
2/14/2009 5:08:53 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Message Queuing Service service to connect.
2/13/2009 8:50:51 PM, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.0.103 with the system having network hardware address 00:23:DF:C5:5D:EC. Network operations on this system may be disrupted as a result.
2/13/2009 2:40:39 PM, error: Dhcp [1002] - The IP address lease 192.168.2.8 for the Network Card with network address 001D60DE8E02 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
2/13/2009 12:57:38 PM, error: Dhcp [1002] - The IP address lease 192.168.2.7 for the Network Card with network address 001D60DE8E02 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
2/13/2009 11:47:30 AM, error: Dhcp [1002] - The IP address lease 192.168.2.4 for the Network Card with network address 001D60DE8E02 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
2/14/2009 5:14:11 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/14/2009 5:14:21 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
2/14/2009 5:14:58 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2/14/2009 5:14:58 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/14/2009 5:14:58 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
2/14/2009 5:14:58 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/14/2009 5:14:58 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/14/2009 5:14:58 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD APPDRV AvgLdx86 AvgMfx86 Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
2/14/2009 5:26:33 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
2/14/2009 5:37:51 PM, error: Service Control Manager [7034] - The Windows Installer service terminated unexpectedly. It has done this 1 time(s).
2/14/2009 6:13:01 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
2/14/2009 6:13:01 PM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
2/15/2009 1:57:57 AM, error: Dhcp [1002] - The IP address lease 192.168.0.100 for the Network Card with network address 001D60DE8E02 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
2/15/2009 11:10:39 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service RoxMediaDB9 with arguments "" in order to run the server: {5EFBB572-1CBD-47DA-8BBA-5BAB9CADD108}
2/14/2009 6:01:56 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\wuauclt.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 7.2.6001.788.

==== End Of File ===========================
ezpkns34,

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Same prob I have with MBAM & SAS. I try to run CF from the cd (downloaded it to a cd from this computer) & tried to run it by copying it from the cd to the desktop. Nothing happens Want me to try it in safe mode?
Good call, it worked with no probs after changing the name. Here's the requested CF log:

ComboFix 09-02-15.01 - Nick 2009-02-15 19:51:28.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.645 [GMT -5:00]
Running from: D:\Worknow.com
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bold.log
c:\windows\IE4 Error Log.txt
c:\windows\ios.dat
c:\windows\Phipuxiqivoquli.dll
c:\windows\system32\c.ico
c:\windows\system32\comsa32.sys
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekatofxhole.sys
c:\windows\system32\drivers\UACinevstil.sys
c:\windows\system32\inf\rundll33.exe
c:\windows\system32\inf\xccdfb16_090131.dll
c:\windows\system32\inf\xccefb090131.scr
c:\windows\system32\m.ico
c:\windows\system32\p.ico
c:\windows\system32\s.ico
c:\windows\system32\senekaivkkyigf.dll
c:\windows\system32\senekapqspnyxj.dll
c:\windows\system32\senekasdewulqe.dat
c:\windows\system32\senekavjppasah.dll
c:\windows\system32\tpszxyd.sys
c:\windows\system32\UACaabwwqbd.log
c:\windows\system32\UACetbojslv.dll
c:\windows\system32\UACqhcwhkyl.log
c:\windows\system32\UACqqhewfjj.dll
c:\windows\system32\UACrxroevqw.dll
c:\windows\system32\UACtardlyxs.dll
c:\windows\system32\UACtqxtewcf.dat
c:\windows\system32\UACxtafirwm.log
c:\windows\system32\uisaj387dd.dll
c:\windows\system32\xcchit32.ini
c:\windows\wiaserviv.log
c:\windows\xccdf16_090131a.dll
c:\windows\xccdf32_090131a.dll
c:\windows\xccwinsys.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-01-16 to 2009-02-16 )))))))))))))))))))))))))))))))
.

2009-02-15 04:06 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-15 04:06 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-15 04:01 . 2009-02-15 04:01 40,960 –a—— c:\windows\system32\grcrt.dll
2009-02-15 04:01 . 2009-02-15 04:01 26,624 –a—— c:\windows\system32\grcrt2.exe
2009-02-15 02:51 . 2009-02-15 02:51 664 –a—— c:\windows\system32\d3d9caps.dat
2009-02-14 17:38 . 2009-02-14 18:14 99,696 –a—— c:\windows\system32\drivers\e00e1a0c.sys
2009-02-14 17:38 . 2009-02-14 17:38 2,048 –a—— C:\nwpy.exe
2009-02-14 17:08 . 2009-02-14 17:26 d——– c:\documents and settings\All Users\Application Data\Electronic Arts
2009-02-14 17:03 . 2009-02-15 19:52 d——– c:\windows\system32\inf
2009-02-14 17:03 . 2009-02-14 17:37 216,576 –a—— c:\windows\system32\mqapi.exe
2009-02-14 17:03 . 2009-02-14 17:03 155,156 –a—— c:\windows\system\xccef090131.exe
2009-02-14 17:03 . 2009-02-14 17:03 106,496 –a—— c:\windows\system32\fejokt.dll
2009-02-14 17:03 . 2009-02-15 19:55 99,696 –a—— c:\windows\system32\drivers\33e1b4cb.sys
2009-02-14 17:03 . 2009-02-14 17:03 90,119 –a—— C:\nxspv.exe
2009-02-14 17:03 . 2009-02-14 17:03 82,432 –a—— C:\xxmwr.exe
2009-02-14 17:03 . 2009-02-14 17:03 19,214 –a—— c:\windows\system32\sf.ico
2009-02-14 17:03 . 2009-02-14 17:03 13,942 –a—— c:\windows\system32\m3.ico
2009-02-14 17:03 . 2009-02-15 11:16 5,189 –a—— c:\windows\system32\uacinit.dll
2009-02-14 17:03 . 2009-02-14 17:38 2 –a—— C:\210699162
2009-02-10 16:35 . 2009-02-10 16:35 0 –a—— c:\windows\nsreg.dat
2009-02-04 20:24 . 2009-02-04 20:24 d——– c:\documents and settings\Nick\Application Data\Maple
2009-02-04 20:16 . 2009-02-04 20:16 d——– C:\watcom-1.3
2009-02-04 20:16 . 2009-02-04 20:16 212,992 –a—— c:\windows\system32\WMIMPLEX.dll
2009-02-04 20:16 . 2009-02-04 20:16 40,960 –a—— c:\windows\system32\maplec.dll
2009-02-04 20:16 . 2009-02-04 20:16 20,480 –a—— c:\windows\system32\maplecompat.dll
2009-02-04 20:14 . 2009-02-04 20:14 d–h—– c:\program files\Zero G Registry
2009-02-04 20:14 . 2009-02-04 20:17 d——– c:\program files\Maple 12
2009-02-04 20:13 . 2009-02-04 20:13 d–h—– c:\documents and settings\Nick\InstallAnywhere
2009-01-31 12:16 . 2009-01-31 12:16 10,520 –a—— c:\windows\system32\avgrsstx.dll
2009-01-23 15:52 . 2008-10-16 14:06 268,648 –a—— c:\windows\system32\mucltui.dll
2009-01-23 15:52 . 2008-10-16 14:06 208,744 –a—— c:\windows\system32\muweb.dll
2009-01-23 15:52 . 2008-10-16 14:06 27,496 –a—— c:\windows\system32\mucltui.dll.mui
2009-01-23 02:19 . 2009-01-23 02:19 d——– c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-16 00:51 3,609 –sha-w c:\windows\system32\mmf.sys
2009-02-15 17:14 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-15 16:16 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-15 06:52 ——— d—–w c:\program files\BitTorrent
2009-02-14 22:32 ——— d—–w c:\program files\Electronic Arts
2009-02-14 19:51 ——— d—–w c:\documents and settings\Nick\Application Data\uTorrent
2009-02-03 03:58 ——— d—–w c:\program files\Wolverine Studios
2009-01-31 17:16 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-24 08:13 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-24 08:01 ——— d—–w c:\program files\Microsoft Works
2009-01-17 02:35 3,594,752 ——w c:\windows\system32\dllcache\mshtml.dll
2009-01-15 23:03 ——— d—–w c:\program files\Java
2009-01-14 17:22 ——— d—–w c:\documents and settings\Nick\Application Data\SPORE
2009-01-14 17:20 107,888 —-a-w c:\windows\system32\CmdLineExt.dll
2009-01-14 17:20 ——— d–h–r c:\documents and settings\Nick\Application Data\SecuROM
2009-01-13 01:39 2,802,580 —-a-w c:\program files\PFCSetup1.0.223.exe
2009-01-13 01:20 ——— d—–w c:\documents and settings\Nick\Application Data\BitTorrent
2009-01-12 17:13 6,274,206 —-a-w c:\program files\102_35143.exe
2009-01-09 17:26 ——— d—–w c:\program files\uTorrent
2009-01-08 14:52 ——— d—–w c:\documents and settings\Nick\Application Data\SPORE Creature Creator
2009-01-08 14:47 ——— d—–w c:\program files\DominateGame
2008-12-25 09:48 ——— d—–w c:\program files\WinPcap
2008-12-23 19:43 ——— d—–w c:\program files\music
2008-12-19 09:10 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ——w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 10:57 333,952 ——w c:\windows\system32\dllcache\srv.sys
2008-11-07 22:09 536,811 —-a-w c:\program files\ie-spyad.exe
2008-11-07 22:08 2,062,665 —-a-w c:\program files\spywareguardsetup.exe
2008-11-07 22:07 2,869,536 —-a-w c:\program files\spywareblastersetup41.exe
2008-10-23 16:17 18,829,383 —-a-w c:\program files\tibia831.exe
2008-08-14 01:59 232,904,074 —-a-w c:\program files\ootp9setup.exe
2008-07-07 13:34 24,234,968 —-a-w c:\program files\setupeng.exe
2008-07-04 19:01 15,336,856 —-a-w c:\program files\jre-6u10-beta-windows-i586-p.exe
2008-07-04 18:50 50,688 —-a-w c:\program files\ATF-Cleaner.exe
2008-06-26 21:45 9,722,720 —-a-w c:\program files\spybotsd152.exe
2008-06-23 02:32 49,384,056 —-a-w c:\program files\avg_free_stf_all_8_100a1323.exe
2008-06-21 00:07 5,632 –sha-w c:\program files\Thumbs.db
2008-05-18 07:37 18,289,392 —-a-w c:\program files\DivXInstaller.exe
2007-11-21 22:55 6,637,432 —-a-w c:\program files\dMC-R12.3-Ref-Registered.exe
2007-11-13 16:01 13,871,095 —-a-w c:\program files\schedulemaker.zip
2007-06-15 05:35 9,690,219 —-a-w c:\program files\mws094f.exe
2007-06-14 16:29 380,208,128 —-a-w c:\program files\mtgodl2.exe
2007-03-18 23:57 26,583,420 —-a-w c:\program files\Geneforge4Demo.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-09 851968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-06 81920]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-03 1228800]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"nwiz"="nwiz.exe" [2007-06-06 c:\windows\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2007-06-06 c:\windows\system32\nvhotkey.dll]
"SigmatelSysTrayApp"="stsystra.exe" [2007-07-09 c:\windows\stsystra.exe]

c:\documents and settings\Nick\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-01 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 12:16 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\a.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\matrix31290.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpa.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpb.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpc.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
–a—— 2006-08-17 10:00 1116920 c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
–a—— 2006-11-05 12:22 221184 c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\mtg\\Magic\\Manalink.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Maple 12\\jre\\bin\\maple.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-11-02 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-31 298264]
R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2007-12-09 2560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-12-08 24652]
S2 MSMQSVC;Message Queuing Service;c:\windows\system32\mqsv32.exe –> c:\windows\system32\mqsv32.exe [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
S3 xbreader;MaxDrive XBox Driver (xbreader.sys);c:\windows\system32\drivers\xbreader.sys [2001-01-02 19677]
.
Contents of the 'Scheduled Tasks' folder

2009-02-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-BitTorrent - c:\program files\BitTorrent\bittorrent.exe
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKLM-Explorer_Run-xccinit - c:\windows\system32\inf\rundll33.exe
SharedTaskScheduler-{D5BF4552-94F1-42BD-F434-3604812C807D} - c:\windows\system32\uisaj387dd.dll
SharedTaskScheduler-{C5BF49A2-94F3-42BD-F434-3604812C8955} - c:\windows\system32\hsfd83jfdg.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: Crawler Search
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Nick\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-yahtzee/zylomplayer.cab
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\5ei8gwd3.default\
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-15 19:54:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\33e1b4cb]
"ImagePath"="\SystemRoot\System32\drivers\33e1b4cb.sys"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\s-1-5-21-267048546-3394276723-1217438979-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{487E2DE6-47C1-82BA-77C5-BBCA30098FFF}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abiloomoglgjpidfgnnkhadhplebcckbfe"=hex:61,61,00,00
"bbiloomoglgjpidfgnmkkafcdennaabjgdal"=hex:61,61,00,00

[HKEY_USERS\s-1-5-21-267048546-3394276723-1217438979-1006\Software\SecuROM\License information*]
"datasecu"=hex:8c,f8,da,f0,d7,f1,ea,e5,2b,9c,4e,6b,89,01,7d,1b,6d,01,b3,64,9d,
2e,81,17,6b,c0,b5,fe,f4,97,db,ca,7a,8b,7f,c2,22,c1,ef,85,83,1b,0a,69,93,14,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847]
"1"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,86,2b,9b,9b,f3,96,a9,
e9
"2"=hex:05,83,26,a9,dc,b6,17,45,de,2e,f0,41,a5,95,91,56,fe,07,ca,23,63,6c,c8,
df,a0,cb,29,a7,07,62,23,54
"3"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,39,39,6a,6e,1d,99,29,
0e,9a,9e,61,33,16,37,68,38,ee,25,f6,f1,91,9f,21,a9,58,ec,19,f6,96,30,78,09

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\13D3AF07D4AFC792B9BD996AC108D6B5]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,15,18,bd,aa,84,24,4a,2c
"2"=hex:ed,a7,cb,4f,94,68,06,bf
"3"=hex:cf,54,22,5c,b2,32,a3,f4,13,e2,99,75,72,f5,de,7b,7f,a5,9e,59,7e,5c,50,
44,b2,68,4e,b6,6c,25,93,09,5a,dc,75,c8,13,9f,30,27,3a,76,73,04,ed,44,fc,f6,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,2f,a8,42,c9,bd,28,bd,03,a4,ed,67,8d,07,a7,03,f5,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,91,e8,a9,4b,f4,c5,51,
df,c7,9b,39,cf,09,f9,b0,9b,ad,64,39,7b,c1,66,34,b7,bd,5f,73,03,3f,65,09,a8,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:65,4e,c5,8b,92,5b,93,b4,84,b4,53,c9,0f,64,69,91,d5,cf,39,d2,75,99,08,
27,e6,19,a2,b5,8e,b8,6c,07,ee,9f,43,2e,79,b7,48,19,56,03,46,c5,47,47,5e,70,\
"13"=hex:f8,b3,e2,65,7c,0d,e7,15,ac,0e,57,02,77,42,98,d3,b2,2e,ba,2f,10,0d,5f,
a0
"14"=hex:0d,7e,11,86,a7,43,bb,80,cb,84,d6,9b,52,2b,0b,b6
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:fc,1b,0f,70,de,f5,b6,81,51,f6,6c,be,8c,f4,09,4f
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:ea,3d,b9,9a,7b,92,6d,f6,6d,47,d0,e6,0f,f6,f3,8d,61,dc,12,97,34,e6,62,
83,72,96,f8,4a,e7,dc,ff,05,8e,96,13,15,e6,04,c8,3e,b1,5b,d5,2e,13,82,02,68,\

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\CC7B909C85BC507A2CDBC39B09A1A69B]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,3c,a9,5c,7c,76,d5,a4,ad
"2"=hex:4c,00,a2,b4,d4,72,2e,96
"3"=hex:8f,79,e9,fb,03,cd,2a,03,2d,0f,cb,cd,74,1e,fc,f9,c7,60,c5,d9,0d,89,2d,
e1,ac,91,a2,29,00,7d,b8,b0,5b,db,a3,bb,64,f6,e7,69,15,09,37,66,19,58,5e,67,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,32,04,0f,a6,73,b5,06,c7,40,57,27,33,7c,b4,61,2d,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:63,5a,d7,1b,b1,d4,18,46,9d,8a,b3,da,f7,a8,9d,ab,87,a3,2a,ca,13,f6,e4,
c5,41,b1,c1,29,7c,b2,b7,13,8f,1c,0d,5f,4b,3c,0f,fb
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:28,d5,32,14,d2,aa,ea,92,15,12,99,8b,12,63,43,80,74,95,f1,5d,0b,3d,c7,
a4,18,ad,c2,8f,ac,bb,a4,80,d2,74,e3,27,c9,ce,dd,39,92,fa,e1,a3,17,5c,47,2e,\
"13"=hex:0b,d1,9c,3a,64,a8,b5,e9,8c,33,4e,cd,6a,da,75,60,fc,13,0a,57,f6,08,bb,
c3
"14"=hex:0d,f5,4e,44,fe,9e,11,67,d4,ec,25,e7,d8,da,e7,24
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:f7,77,5c,72,03,28,57,bd,09,30,5c,5d,2b,ad,12,bd
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:ec,c6,8f,95,1e,e3,3a,a1,ca,92,d1,4c,08,18,ed,8e,3d,fe,1c,4e,f7,7d,db,
77,ee,48,d8,f6,7f,4c,f8,3e,88,68,c2,6c,63,e6,3e,8a,a3,6d,7d,b9,5b,6f,f1,9a,\

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,44,f7,88,8f,b5,4c,1b,f9,3e,da,c2,d2,eb,69,77,32,91,02,8c,84,09,5e,d2,d3
"2"=hex:f1,df,16,de,80,08,0e,2a,d1,38,b5,6f,94,ca,dc,d2,b3,e8,d2,40,6c,6f,61,
5e,d2,5e,7f,21,14,b5,b2,29
"3"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,f2,55,76,c8,bc,53,92,25,3f,d1,b6,bc,00,35,73,43,96,90,79,f6,5b,97,35,47,\

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F\3323E31CCF524E1933A08EFC0405BBBB]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,ce,d6,da,a0,ab,80,e1,24
"2"=hex:cf,77,c8,3e,ea,da,16,30
"3"=hex:a8,94,fb,1d,a8,04,93,f6,27,ba,9f,0c,1e,f4,d0,fa,15,d2,13,e7,60,58,bf,
34,53,b1,e8,5a,1a,a8,42,b7,2d,fd,1c,80,83,b7,98,df,e2,e7,5e,a6,54,59,11,31,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,9f,82,d5,6a,b3,ab,12,e7,1d,59,ee,f8,65,a3,77,fa,21,98,53,17,b3,88,55,98,\
"7"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,e5,98,6b,ad,2b,ca,86,50
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,6b,8d,dd,0b,84,72,f6,
f2,3d,a6,3c,a0,07,7d,db,f3,88,a8,6c,3f,5c,60,94,94,89,77,0c,65,96,1c,ff,8e,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:1c,bd,ea,59,8e,8d,e1,5f
"11"=hex:7d,ba,74,77,fe,09,92,36
"12"=hex:a0,df,59,f4,e0,d8,0a,fb,cc,26,53,e2,71,64,8d,71,ba,4e,45,28,8c,cb,ad,
f4,ad,a6,4b,f6,0b,36,45,63,80,07,b3,29,1a,d2,24,19,0d,d9,f2,62,b0,4d,44,2b,\
"13"=hex:dc,57,f7,3b,8a,43,9d,48,6e,d4,56,e7,f9,b4,6f,02,ef,9f,db,da,f9,28,c9,
17
"14"=hex:4e,63,05,ff,92,a2,5b,c8
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:55,3b,68,6f,03,fb,52,52,1d,27,1b,a1,9b,47,55,0a
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:e8,cc,f6,66,72,7c,fe,c6,e4,b5,3c,4a,a8,61,22,91,aa,4c,e9,68,ac,5f,e5,
82,00,ba,60,5d,62,f0,d8,db,11,10,68,38,36,5d,7f,2d,b3,37,f5,6d,42,af,fb,27,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(944)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-02-15 19:57:06
ComboFix-quarantined-files.txt 2009-02-16 00:56:42

Pre-Run: 58,017,296,384 bytes free
Post-Run: 58,348,204,032 bytes free

Current=4 Default=4 Failed=1 LastKnownGood=2 Sets=1,2,3,4
364 — E O F — 2009-02-12 17:11:48
ezpkns34,

BitTorrent and uTorrent
You have BitTorrent and uTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall BitTorrent and uTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Disable your protection programs as we did before.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\windows\system32\grcrt.dll
    c:\windows\system32\grcrt2.exe
    c:\windows\system32\drivers\e00e1a0c.sys
    C:\nwpy.exe
    c:\windows\system32\mqapi.exe
    c:\windows\system\xccef090131.exe
    c:\windows\system32\fejokt.dll
    c:\windows\system32\drivers\33e1b4cb.sys
    C:\nxspv.exe
    C:\xxmwr.exe
    c:\windows\system32\sf.ico
    c:\windows\system32\m3.ico
    c:\windows\system32\uacinit.dll
    C:\210699162
    c:\program files\102_35143.exe
    c:\windows\system32\mqsv32.exe
    
    dirlook::
    c:\windows\system32\inf
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet004\Services\33e1b4cb]
    
    Driver::
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • Rooter report
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Rooter report:

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Core™2 Duo CPU T7500 @ 2.20GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A04
USER : Nick ( Administrator )
BOOT : Normal boot

Antivirus : AVG Anti-Virus Free 8.0 (Not Activated)


C:\ (Local Disk) - NTFS - Total:143 Go (Free:54 Go)
D:\ (CD or DVD)

Sun 02/15/2009|21:11

———————-\\ Search..

———————-\\ Cracks & Keygens..

C:\DOCUME~1\Nick\Desktop\torrential\Winzip 11 pro\keygen.exe
C:\DOCUME~1\Nick\My Documents\Out of the Park Developments\OOTP Baseball 9\photos\quinton_mccracken.jpg


1 - "C:\Rooter$\Rooter_1.txt" - Sun 02/15/2009|21:13



ComboFix txt:
ComboFix 09-02-15.01 - Nick 2009-02-15 21:16:21.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.511 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nick\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
C:\210699162
C:\nwpy.exe
C:\nxspv.exe
c:\program files\102_35143.exe
c:\windows\system\xccef090131.exe
c:\windows\system32\drivers\33e1b4cb.sys
c:\windows\system32\drivers\e00e1a0c.sys
c:\windows\system32\fejokt.dll
c:\windows\system32\grcrt.dll
c:\windows\system32\grcrt2.exe
c:\windows\system32\m3.ico
c:\windows\system32\mqapi.exe
c:\windows\system32\mqsv32.exe
c:\windows\system32\sf.ico
c:\windows\system32\uacinit.dll
C:\xxmwr.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\210699162
C:\nwpy.exe
C:\nxspv.exe
c:\program files\102_35143.exe
c:\windows\system\xccef090131.exe
c:\windows\system32\drivers\33e1b4cb.sys
c:\windows\system32\drivers\e00e1a0c.sys
c:\windows\system32\fejokt.dll
c:\windows\system32\grcrt.dll
c:\windows\system32\grcrt2.exe
c:\windows\system32\m3.ico
c:\windows\system32\mqapi.exe
c:\windows\system32\sf.ico
c:\windows\system32\uacinit.dll
C:\xxmwr.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_33e1b4cb


((((((((((((((((((((((((( Files Created from 2009-01-16 to 2009-02-16 )))))))))))))))))))))))))))))))
.

2009-02-15 21:11 . 2009-02-15 21:13 d——– C:\Rooter$
2009-02-15 19:45 . 2009-02-15 19:57 d——– C:\Worknow
2009-02-15 04:06 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-15 04:06 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-15 02:51 . 2009-02-15 02:51 664 –a—— c:\windows\system32\d3d9caps.dat
2009-02-14 17:08 . 2009-02-14 17:26 d——– c:\documents and settings\All Users\Application Data\Electronic Arts
2009-02-14 17:03 . 2009-02-15 19:52 d——– c:\windows\system32\inf
2009-02-10 16:35 . 2009-02-10 16:35 0 –a—— c:\windows\nsreg.dat
2009-02-04 20:24 . 2009-02-04 20:24 d——– c:\documents and settings\Nick\Application Data\Maple
2009-02-04 20:16 . 2009-02-04 20:16 d——– C:\watcom-1.3
2009-02-04 20:16 . 2009-02-04 20:16 212,992 –a—— c:\windows\system32\WMIMPLEX.dll
2009-02-04 20:16 . 2009-02-04 20:16 40,960 –a—— c:\windows\system32\maplec.dll
2009-02-04 20:16 . 2009-02-04 20:16 20,480 –a—— c:\windows\system32\maplecompat.dll
2009-02-04 20:14 . 2009-02-04 20:14 d–h—– c:\program files\Zero G Registry
2009-02-04 20:14 . 2009-02-04 20:17 d——– c:\program files\Maple 12
2009-02-04 20:13 . 2009-02-04 20:13 d–h—– c:\documents and settings\Nick\InstallAnywhere
2009-01-31 12:16 . 2009-01-31 12:16 10,520 –a—— c:\windows\system32\avgrsstx.dll
2009-01-23 15:52 . 2008-10-16 14:06 268,648 –a—— c:\windows\system32\mucltui.dll
2009-01-23 15:52 . 2008-10-16 14:06 208,744 –a—— c:\windows\system32\muweb.dll
2009-01-23 15:52 . 2008-10-16 14:06 27,496 –a—— c:\windows\system32\mucltui.dll.mui
2009-01-23 02:19 . 2009-01-23 02:19 d——– c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-15 17:14 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-15 16:16 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-15 06:52 ——— d—–w c:\program files\BitTorrent
2009-02-14 22:32 ——— d—–w c:\program files\Electronic Arts
2009-02-14 19:51 ——— d—–w c:\documents and settings\Nick\Application Data\uTorrent
2009-02-03 03:58 ——— d—–w c:\program files\Wolverine Studios
2009-01-31 17:16 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-24 08:13 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-24 08:01 ——— d—–w c:\program files\Microsoft Works
2009-01-15 23:03 ——— d—–w c:\program files\Java
2009-01-14 17:22 ——— d—–w c:\documents and settings\Nick\Application Data\SPORE
2009-01-14 17:20 ——— d–h–r c:\documents and settings\Nick\Application Data\SecuROM
2009-01-13 01:39 2,802,580 —-a-w c:\program files\PFCSetup1.0.223.exe
2009-01-13 01:20 ——— d—–w c:\documents and settings\Nick\Application Data\BitTorrent
2009-01-09 17:26 ——— d—–w c:\program files\uTorrent
2009-01-08 14:52 ——— d—–w c:\documents and settings\Nick\Application Data\SPORE Creature Creator
2009-01-08 14:47 ——— d—–w c:\program files\DominateGame
2008-12-25 09:48 ——— d—–w c:\program files\WinPcap
2008-12-23 19:43 ——— d—–w c:\program files\music
2008-11-07 22:09 536,811 —-a-w c:\program files\ie-spyad.exe
2008-11-07 22:08 2,062,665 —-a-w c:\program files\spywareguardsetup.exe
2008-11-07 22:07 2,869,536 —-a-w c:\program files\spywareblastersetup41.exe
2008-10-23 16:17 18,829,383 —-a-w c:\program files\tibia831.exe
2008-08-14 01:59 232,904,074 —-a-w c:\program files\ootp9setup.exe
2008-07-07 13:34 24,234,968 —-a-w c:\program files\setupeng.exe
2008-07-04 19:01 15,336,856 —-a-w c:\program files\jre-6u10-beta-windows-i586-p.exe
2008-07-04 18:50 50,688 —-a-w c:\program files\ATF-Cleaner.exe
2008-06-26 21:45 9,722,720 —-a-w c:\program files\spybotsd152.exe
2008-06-23 02:32 49,384,056 —-a-w c:\program files\avg_free_stf_all_8_100a1323.exe
2008-06-21 00:07 5,632 –sha-w c:\program files\Thumbs.db
2008-05-18 07:37 18,289,392 —-a-w c:\program files\DivXInstaller.exe
2007-11-21 22:55 6,637,432 —-a-w c:\program files\dMC-R12.3-Ref-Registered.exe
2007-11-13 16:01 13,871,095 —-a-w c:\program files\schedulemaker.zip
2007-06-15 05:35 9,690,219 —-a-w c:\program files\mws094f.exe
2007-06-14 16:29 380,208,128 —-a-w c:\program files\mtgodl2.exe
2007-03-18 23:57 26,583,420 —-a-w c:\program files\Geneforge4Demo.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of c:\windows\system32\inf —-



((((((((((((((((((((((((((((( SnapShot@2009-02-15_19.55.28.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2009-02-16 00:51:05 3,609 –sha-w c:\windows\system32\mmf.sys
+ 2009-02-16 02:19:53 3,609 –sha-w c:\windows\system32\mmf.sys
- 2009-02-15 20:24:37 59,652 —-a-w c:\windows\system32\perfc009.dat
+ 2009-02-16 00:58:24 59,652 —-a-w c:\windows\system32\perfc009.dat
- 2009-02-15 20:24:37 395,580 —-a-w c:\windows\system32\perfh009.dat
+ 2009-02-16 00:58:24 395,580 —-a-w c:\windows\system32\perfh009.dat
+ 2009-02-16 02:21:22 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_a6c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-09 851968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-06 81920]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-03 1228800]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"nwiz"="nwiz.exe" [2007-06-06 c:\windows\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2007-06-06 c:\windows\system32\nvhotkey.dll]
"SigmatelSysTrayApp"="stsystra.exe" [2007-07-09 c:\windows\stsystra.exe]

c:\documents and settings\Nick\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-01 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 12:16 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\a.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\matrix31290.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpa.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpb.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpc.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
–a—— 2006-08-17 10:00 1116920 c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
–a—— 2006-11-05 12:22 221184 c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\mtg\\Magic\\Manalink.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Maple 12\\jre\\bin\\maple.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-11-02 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-31 298264]
R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2007-12-09 2560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-12-08 24652]
S2 MSMQSVC;Message Queuing Service;c:\windows\system32\mqsv32.exe –> c:\windows\system32\mqsv32.exe [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
S3 xbreader;MaxDrive XBox Driver (xbreader.sys);c:\windows\system32\drivers\xbreader.sys [2001-01-02 19677]
.
Contents of the 'Scheduled Tasks' folder

2009-02-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: Crawler Search
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Nick\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-yahtzee/zylomplayer.cab
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\5ei8gwd3.default\
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-15 21:20:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-267048546-3394276723-1217438979-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{487E2DE6-47C1-82BA-77C5-BBCA30098FFF}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abiloomoglgjpidfgnnkhadhplebcckbfe"=hex:61,61,00,00
"bbiloomoglgjpidfgnmkkafcdennaabjgdal"=hex:61,61,00,00

[HKEY_USERS\S-1-5-21-267048546-3394276723-1217438979-1006\Software\SecuROM\License information*]
"datasecu"=hex:8c,f8,da,f0,d7,f1,ea,e5,2b,9c,4e,6b,89,01,7d,1b,6d,01,b3,64,9d,
2e,81,17,6b,c0,b5,fe,f4,97,db,ca,7a,8b,7f,c2,22,c1,ef,85,83,1b,0a,69,93,14,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847]
"1"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,86,2b,9b,9b,f3,96,a9,
e9
"2"=hex:05,83,26,a9,dc,b6,17,45,de,2e,f0,41,a5,95,91,56,fe,07,ca,23,63,6c,c8,
df,a0,cb,29,a7,07,62,23,54
"3"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,39,39,6a,6e,1d,99,29,
0e,9a,9e,61,33,16,37,68,38,ee,25,f6,f1,91,9f,21,a9,58,ec,19,f6,96,30,78,09

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\13D3AF07D4AFC792B9BD996AC108D6B5]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,15,18,bd,aa,84,24,4a,2c
"2"=hex:ed,a7,cb,4f,94,68,06,bf
"3"=hex:cf,54,22,5c,b2,32,a3,f4,13,e2,99,75,72,f5,de,7b,7f,a5,9e,59,7e,5c,50,
44,b2,68,4e,b6,6c,25,93,09,5a,dc,75,c8,13,9f,30,27,3a,76,73,04,ed,44,fc,f6,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,2f,a8,42,c9,bd,28,bd,03,a4,ed,67,8d,07,a7,03,f5,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,91,e8,a9,4b,f4,c5,51,
df,c7,9b,39,cf,09,f9,b0,9b,ad,64,39,7b,c1,66,34,b7,bd,5f,73,03,3f,65,09,a8,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:65,4e,c5,8b,92,5b,93,b4,84,b4,53,c9,0f,64,69,91,d5,cf,39,d2,75,99,08,
27,e6,19,a2,b5,8e,b8,6c,07,ee,9f,43,2e,79,b7,48,19,56,03,46,c5,47,47,5e,70,\
"13"=hex:f8,b3,e2,65,7c,0d,e7,15,ac,0e,57,02,77,42,98,d3,b2,2e,ba,2f,10,0d,5f,
a0
"14"=hex:0d,7e,11,86,a7,43,bb,80,cb,84,d6,9b,52,2b,0b,b6
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:fc,1b,0f,70,de,f5,b6,81,51,f6,6c,be,8c,f4,09,4f
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:ea,3d,b9,9a,7b,92,6d,f6,6d,47,d0,e6,0f,f6,f3,8d,61,dc,12,97,34,e6,62,
83,72,96,f8,4a,e7,dc,ff,05,8e,96,13,15,e6,04,c8,3e,b1,5b,d5,2e,13,82,02,68,\

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\CC7B909C85BC507A2CDBC39B09A1A69B]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,3c,a9,5c,7c,76,d5,a4,ad
"2"=hex:4c,00,a2,b4,d4,72,2e,96
"3"=hex:8f,79,e9,fb,03,cd,2a,03,2d,0f,cb,cd,74,1e,fc,f9,c7,60,c5,d9,0d,89,2d,
e1,ac,91,a2,29,00,7d,b8,b0,5b,db,a3,bb,64,f6,e7,69,15,09,37,66,19,58,5e,67,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,32,04,0f,a6,73,b5,06,c7,40,57,27,33,7c,b4,61,2d,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:63,5a,d7,1b,b1,d4,18,46,9d,8a,b3,da,f7,a8,9d,ab,87,a3,2a,ca,13,f6,e4,
c5,41,b1,c1,29,7c,b2,b7,13,8f,1c,0d,5f,4b,3c,0f,fb
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:28,d5,32,14,d2,aa,ea,92,15,12,99,8b,12,63,43,80,74,95,f1,5d,0b,3d,c7,
a4,18,ad,c2,8f,ac,bb,a4,80,d2,74,e3,27,c9,ce,dd,39,92,fa,e1,a3,17,5c,47,2e,\
"13"=hex:0b,d1,9c,3a,64,a8,b5,e9,8c,33,4e,cd,6a,da,75,60,fc,13,0a,57,f6,08,bb,
c3
"14"=hex:0d,f5,4e,44,fe,9e,11,67,d4,ec,25,e7,d8,da,e7,24
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:f7,77,5c,72,03,28,57,bd,09,30,5c,5d,2b,ad,12,bd
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:ec,c6,8f,95,1e,e3,3a,a1,ca,92,d1,4c,08,18,ed,8e,3d,fe,1c,4e,f7,7d,db,
77,ee,48,d8,f6,7f,4c,f8,3e,88,68,c2,6c,63,e6,3e,8a,a3,6d,7d,b9,5b,6f,f1,9a,\

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,44,f7,88,8f,b5,4c,1b,f9,3e,da,c2,d2,eb,69,77,32,91,02,8c,84,09,5e,d2,d3
"2"=hex:f1,df,16,de,80,08,0e,2a,d1,38,b5,6f,94,ca,dc,d2,b3,e8,d2,40,6c,6f,61,
5e,d2,5e,7f,21,14,b5,b2,29
"3"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,f2,55,76,c8,bc,53,92,25,3f,d1,b6,bc,00,35,73,43,96,90,79,f6,5b,97,35,47,\

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F\3323E31CCF524E1933A08EFC0405BBBB]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,ce,d6,da,a0,ab,80,e1,24
"2"=hex:cf,77,c8,3e,ea,da,16,30
"3"=hex:a8,94,fb,1d,a8,04,93,f6,27,ba,9f,0c,1e,f4,d0,fa,15,d2,13,e7,60,58,bf,
34,53,b1,e8,5a,1a,a8,42,b7,2d,fd,1c,80,83,b7,98,df,e2,e7,5e,a6,54,59,11,31,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,9f,82,d5,6a,b3,ab,12,e7,1d,59,ee,f8,65,a3,77,fa,21,98,53,17,b3,88,55,98,\
"7"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,e5,98,6b,ad,2b,ca,86,50
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,6b,8d,dd,0b,84,72,f6,
f2,3d,a6,3c,a0,07,7d,db,f3,88,a8,6c,3f,5c,60,94,94,89,77,0c,65,96,1c,ff,8e,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:1c,bd,ea,59,8e,8d,e1,5f
"11"=hex:7d,ba,74,77,fe,09,92,36
"12"=hex:a0,df,59,f4,e0,d8,0a,fb,cc,26,53,e2,71,64,8d,71,ba,4e,45,28,8c,cb,ad,
f4,ad,a6,4b,f6,0b,36,45,63,80,07,b3,29,1a,d2,24,19,0d,d9,f2,62,b0,4d,44,2b,\
"13"=hex:dc,57,f7,3b,8a,43,9d,48,6e,d4,56,e7,f9,b4,6f,02,ef,9f,db,da,f9,28,c9,
17
"14"=hex:4e,63,05,ff,92,a2,5b,c8
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:55,3b,68,6f,03,fb,52,52,1d,27,1b,a1,9b,47,55,0a
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:e8,cc,f6,66,72,7c,fe,c6,e4,b5,3c,4a,a8,61,22,91,aa,4c,e9,68,ac,5f,e5,
82,00,ba,60,5d,62,f0,d8,db,11,10,68,38,36,5d,7f,2d,b3,37,f5,6d,42,af,fb,27,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(928)
c:\windows\System32\BCMLogon.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\SpywareGuard\sgbhp.exe
c:\windows\system32\wscript.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-02-15 21:24:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-16 02:24:21
ComboFix2.txt 2009-02-16 00:57:07

Pre-Run: 58,325,827,584 bytes free
Post-Run: 58,209,218,560 bytes free

Current=4 Default=4 Failed=1 LastKnownGood=2 Sets=1,2,3,4
370 — E O F — 2009-02-12 17:11:48
Kaspersky log:
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, February 16, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, February 16, 2009 02:49:41
Records in database: 1801936
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 274566
Threat name: 11
Infected objects: 15
Suspicious objects: 0
Duration of the scan: 06:52:50


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\nxspv.exe.vir Infected: Trojan-Dropper.Win32.Agent.ahak 1
C:\Qoobox\Quarantine\C\WINDOWS\system\xccef090131.exe.vir Infected: Trojan.Win32.Buzus.alnb 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\senekatofxhole.sys.vir Infected: Rootkit.Win32.TDSS.phm 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_UACinevstil_.sys.zip Infected: Rootkit.Win32.TDSS.gwh 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\fejokt.dll.vir Infected: Trojan.Win32.BHO.mjs 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\grcrt.dll.vir Infected: Trojan-GameThief.Win32.OnLineGames.bktu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\grcrt2.exe.vir Infected: Trojan.Win32.Agent.bprc 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\inf\xccdfb16_090131.dll.vir Infected: Trojan-Spy.Win32.Pophot.gzv 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\inf\xccefb090131.scr.vir Infected: Trojan.Win32.Buzus.alnb 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACqqhewfjj.dll.vir Infected: Rootkit.Win32.TDSS.eyj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACrxroevqw.dll.vir Infected: Rootkit.Win32.TDSS.eyj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACtardlyxs.dll.vir Infected: Rootkit.Win32.TDSS.eyj 1
C:\Qoobox\Quarantine\C\WINDOWS\xccdf16_090131a.dll.vir Infected: Trojan-Spy.Win32.Pophot.gzv 1
C:\Qoobox\Quarantine\C\WINDOWS\xccdf32_090131a.dll.vir Infected: Trojan-Spy.Win32.Pophot.gzu 1
C:\Qoobox\Quarantine\C\xxmwr.exe.vir Infected: Trojan.Win32.Inject.oll 1

The selected area was scanned.



New HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:38:38 AM, on 2/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Nick\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5071202
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [dscactivate] "%ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Nick\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://152.1.164.197/activex/AxisCamControl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil…/familyfeud.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Message Queuing Service (MSMQSVC) - Unknown owner - C:\WINDOWS\system32\mqsv32.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 8591 bytes
ezpkns34,

You get infected because you download cracks.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
      O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
      O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\DOCUME~1\Nick\Desktop\torrential\Winzip 11 pro\keygen.exe
    
    Folder::
    
    Registry::
    
    Driver::
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


In your next reply please provide:
  • ComboFix.txt
  • New HijackThis log taken after everything else completed
ComboFix txt:
ComboFix 09-02-15.01 - Nick 2009-02-16 10:26:24.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.658 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nick\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\docume~1\Nick\Desktop\torrential\Winzip 11 pro\keygen.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Nick\Desktop\torrential\Winzip 11 pro\keygen.exe

.
((((((((((((((((((((((((( Files Created from 2009-01-16 to 2009-02-16 )))))))))))))))))))))))))))))))
.

2009-02-15 21:11 . 2009-02-15 21:13 d——– C:\Rooter$
2009-02-15 19:45 . 2009-02-15 19:57 d——– C:\Worknow
2009-02-15 04:06 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-15 04:06 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-15 02:51 . 2009-02-15 02:51 664 –a—— c:\windows\system32\d3d9caps.dat
2009-02-14 17:08 . 2009-02-14 17:26 d——– c:\documents and settings\All Users\Application Data\Electronic Arts
2009-02-14 17:03 . 2009-02-15 19:52 d——– c:\windows\system32\inf
2009-02-10 16:35 . 2009-02-10 16:35 0 –a—— c:\windows\nsreg.dat
2009-02-04 20:24 . 2009-02-04 20:24 d——– c:\documents and settings\Nick\Application Data\Maple
2009-02-04 20:16 . 2009-02-04 20:16 d——– C:\watcom-1.3
2009-02-04 20:16 . 2009-02-04 20:16 212,992 –a—— c:\windows\system32\WMIMPLEX.dll
2009-02-04 20:16 . 2009-02-04 20:16 40,960 –a—— c:\windows\system32\maplec.dll
2009-02-04 20:16 . 2009-02-04 20:16 20,480 –a—— c:\windows\system32\maplecompat.dll
2009-02-04 20:14 . 2009-02-04 20:14 d–h—– c:\program files\Zero G Registry
2009-02-04 20:14 . 2009-02-04 20:17 d——– c:\program files\Maple 12
2009-02-04 20:13 . 2009-02-04 20:13 d–h—– c:\documents and settings\Nick\InstallAnywhere
2009-01-31 12:16 . 2009-01-31 12:16 10,520 –a—— c:\windows\system32\avgrsstx.dll
2009-01-23 15:52 . 2008-10-16 14:06 268,648 –a—— c:\windows\system32\mucltui.dll
2009-01-23 15:52 . 2008-10-16 14:06 208,744 –a—— c:\windows\system32\muweb.dll
2009-01-23 15:52 . 2008-10-16 14:06 27,496 –a—— c:\windows\system32\mucltui.dll.mui
2009-01-23 02:19 . 2009-01-23 02:19 d——– c:\program files\Microsoft Silverlight

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-16 02:19 3,609 –sha-w c:\windows\system32\mmf.sys
2009-02-15 17:14 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-15 16:16 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-15 06:52 ——— d—–w c:\program files\BitTorrent
2009-02-14 22:32 ——— d—–w c:\program files\Electronic Arts
2009-02-14 19:51 ——— d—–w c:\documents and settings\Nick\Application Data\uTorrent
2009-02-03 03:58 ——— d—–w c:\program files\Wolverine Studios
2009-01-31 17:16 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-24 08:13 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-24 08:01 ——— d—–w c:\program files\Microsoft Works
2009-01-17 02:35 3,594,752 ——w c:\windows\system32\dllcache\mshtml.dll
2009-01-15 23:03 ——— d—–w c:\program files\Java
2009-01-14 17:22 ——— d—–w c:\documents and settings\Nick\Application Data\SPORE
2009-01-14 17:20 107,888 —-a-w c:\windows\system32\CmdLineExt.dll
2009-01-14 17:20 ——— d–h–r c:\documents and settings\Nick\Application Data\SecuROM
2009-01-13 01:39 2,802,580 —-a-w c:\program files\PFCSetup1.0.223.exe
2009-01-13 01:20 ——— d—–w c:\documents and settings\Nick\Application Data\BitTorrent
2009-01-09 17:26 ——— d—–w c:\program files\uTorrent
2009-01-08 14:52 ——— d—–w c:\documents and settings\Nick\Application Data\SPORE Creature Creator
2009-01-08 14:47 ——— d—–w c:\program files\DominateGame
2008-12-25 09:48 ——— d—–w c:\program files\WinPcap
2008-12-23 19:43 ——— d—–w c:\program files\music
2008-12-19 09:10 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ——w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 10:57 333,952 ——w c:\windows\system32\dllcache\srv.sys
2008-11-07 22:09 536,811 —-a-w c:\program files\ie-spyad.exe
2008-11-07 22:08 2,062,665 —-a-w c:\program files\spywareguardsetup.exe
2008-11-07 22:07 2,869,536 —-a-w c:\program files\spywareblastersetup41.exe
2008-10-23 16:17 18,829,383 —-a-w c:\program files\tibia831.exe
2008-08-14 01:59 232,904,074 —-a-w c:\program files\ootp9setup.exe
2008-07-07 13:34 24,234,968 —-a-w c:\program files\setupeng.exe
2008-07-04 19:01 15,336,856 —-a-w c:\program files\jre-6u10-beta-windows-i586-p.exe
2008-07-04 18:50 50,688 —-a-w c:\program files\ATF-Cleaner.exe
2008-06-26 21:45 9,722,720 —-a-w c:\program files\spybotsd152.exe
2008-06-23 02:32 49,384,056 —-a-w c:\program files\avg_free_stf_all_8_100a1323.exe
2008-06-21 00:07 5,632 –sha-w c:\program files\Thumbs.db
2008-05-18 07:37 18,289,392 —-a-w c:\program files\DivXInstaller.exe
2007-11-21 22:55 6,637,432 —-a-w c:\program files\dMC-R12.3-Ref-Registered.exe
2007-11-13 16:01 13,871,095 —-a-w c:\program files\schedulemaker.zip
2007-06-15 05:35 9,690,219 —-a-w c:\program files\mws094f.exe
2007-06-14 16:29 380,208,128 —-a-w c:\program files\mtgodl2.exe
2007-03-18 23:57 26,583,420 —-a-w c:\program files\Geneforge4Demo.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-02-15_19.55.28.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2009-02-15 20:24:37 59,652 —-a-w c:\windows\system32\perfc009.dat
+ 2009-02-16 02:24:22 59,652 —-a-w c:\windows\system32\perfc009.dat
- 2009-02-15 20:24:37 395,580 —-a-w c:\windows\system32\perfh009.dat
+ 2009-02-16 02:24:22 395,580 —-a-w c:\windows\system32\perfh009.dat
+ 2009-02-16 02:19:53 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_2bc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-09 851968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-06 81920]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"NVHotkey"="nvHotkey.dll" [2007-06-06 c:\windows\system32\nvhotkey.dll]

c:\documents and settings\Nick\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-01 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 12:16 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\a.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\matrix31290.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpa.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpb.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpc.exe]
"Debugger"=c:\windows\system32\alg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
–a—— 2006-08-17 10:00 1116920 c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
–a—— 2006-11-05 12:22 221184 c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\mtg\\Magic\\Manalink.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Maple 12\\jre\\bin\\maple.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-11-02 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-31 298264]
R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2007-12-09 2560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-12-08 24652]
S2 MSMQSVC;Message Queuing Service;c:\windows\system32\mqsv32.exe –> c:\windows\system32\mqsv32.exe [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
S3 xbreader;MaxDrive XBox Driver (xbreader.sys);c:\windows\system32\drivers\xbreader.sys [2001-01-02 19677]
.
Contents of the 'Scheduled Tasks' folder

2009-02-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: Crawler Search
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Nick\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-yahtzee/zylomplayer.cab
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\5ei8gwd3.default\
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-16 10:29:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-267048546-3394276723-1217438979-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{487E2DE6-47C1-82BA-77C5-BBCA30098FFF}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abiloomoglgjpidfgnnkhadhplebcckbfe"=hex:61,61,00,00
"bbiloomoglgjpidfgnmkkafcdennaabjgdal"=hex:61,61,00,00

[HKEY_USERS\S-1-5-21-267048546-3394276723-1217438979-1006\Software\SecuROM\License information*]
"datasecu"=hex:8c,f8,da,f0,d7,f1,ea,e5,2b,9c,4e,6b,89,01,7d,1b,6d,01,b3,64,9d,
2e,81,17,6b,c0,b5,fe,f4,97,db,ca,7a,8b,7f,c2,22,c1,ef,85,83,1b,0a,69,93,14,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847]
"1"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,86,2b,9b,9b,f3,96,a9,
e9
"2"=hex:05,83,26,a9,dc,b6,17,45,de,2e,f0,41,a5,95,91,56,fe,07,ca,23,63,6c,c8,
df,a0,cb,29,a7,07,62,23,54
"3"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,39,39,6a,6e,1d,99,29,
0e,9a,9e,61,33,16,37,68,38,ee,25,f6,f1,91,9f,21,a9,58,ec,19,f6,96,30,78,09

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\13D3AF07D4AFC792B9BD996AC108D6B5]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,15,18,bd,aa,84,24,4a,2c
"2"=hex:ed,a7,cb,4f,94,68,06,bf
"3"=hex:cf,54,22,5c,b2,32,a3,f4,13,e2,99,75,72,f5,de,7b,7f,a5,9e,59,7e,5c,50,
44,b2,68,4e,b6,6c,25,93,09,5a,dc,75,c8,13,9f,30,27,3a,76,73,04,ed,44,fc,f6,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,2f,a8,42,c9,bd,28,bd,03,a4,ed,67,8d,07,a7,03,f5,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,91,e8,a9,4b,f4,c5,51,
df,c7,9b,39,cf,09,f9,b0,9b,ad,64,39,7b,c1,66,34,b7,bd,5f,73,03,3f,65,09,a8,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:65,4e,c5,8b,92,5b,93,b4,84,b4,53,c9,0f,64,69,91,d5,cf,39,d2,75,99,08,
27,e6,19,a2,b5,8e,b8,6c,07,ee,9f,43,2e,79,b7,48,19,56,03,46,c5,47,47,5e,70,\
"13"=hex:f8,b3,e2,65,7c,0d,e7,15,ac,0e,57,02,77,42,98,d3,b2,2e,ba,2f,10,0d,5f,
a0
"14"=hex:0d,7e,11,86,a7,43,bb,80,cb,84,d6,9b,52,2b,0b,b6
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:fc,1b,0f,70,de,f5,b6,81,51,f6,6c,be,8c,f4,09,4f
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:ea,3d,b9,9a,7b,92,6d,f6,6d,47,d0,e6,0f,f6,f3,8d,61,dc,12,97,34,e6,62,
83,72,96,f8,4a,e7,dc,ff,05,8e,96,13,15,e6,04,c8,3e,b1,5b,d5,2e,13,82,02,68,\

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\CC7B909C85BC507A2CDBC39B09A1A69B]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,3c,a9,5c,7c,76,d5,a4,ad
"2"=hex:4c,00,a2,b4,d4,72,2e,96
"3"=hex:8f,79,e9,fb,03,cd,2a,03,2d,0f,cb,cd,74,1e,fc,f9,c7,60,c5,d9,0d,89,2d,
e1,ac,91,a2,29,00,7d,b8,b0,5b,db,a3,bb,64,f6,e7,69,15,09,37,66,19,58,5e,67,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,32,04,0f,a6,73,b5,06,c7,40,57,27,33,7c,b4,61,2d,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:63,5a,d7,1b,b1,d4,18,46,9d,8a,b3,da,f7,a8,9d,ab,87,a3,2a,ca,13,f6,e4,
c5,41,b1,c1,29,7c,b2,b7,13,8f,1c,0d,5f,4b,3c,0f,fb
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:28,d5,32,14,d2,aa,ea,92,15,12,99,8b,12,63,43,80,74,95,f1,5d,0b,3d,c7,
a4,18,ad,c2,8f,ac,bb,a4,80,d2,74,e3,27,c9,ce,dd,39,92,fa,e1,a3,17,5c,47,2e,\
"13"=hex:0b,d1,9c,3a,64,a8,b5,e9,8c,33,4e,cd,6a,da,75,60,fc,13,0a,57,f6,08,bb,
c3
"14"=hex:0d,f5,4e,44,fe,9e,11,67,d4,ec,25,e7,d8,da,e7,24
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:f7,77,5c,72,03,28,57,bd,09,30,5c,5d,2b,ad,12,bd
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:ec,c6,8f,95,1e,e3,3a,a1,ca,92,d1,4c,08,18,ed,8e,3d,fe,1c,4e,f7,7d,db,
77,ee,48,d8,f6,7f,4c,f8,3e,88,68,c2,6c,63,e6,3e,8a,a3,6d,7d,b9,5b,6f,f1,9a,\

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,44,f7,88,8f,b5,4c,1b,f9,3e,da,c2,d2,eb,69,77,32,91,02,8c,84,09,5e,d2,d3
"2"=hex:f1,df,16,de,80,08,0e,2a,d1,38,b5,6f,94,ca,dc,d2,b3,e8,d2,40,6c,6f,61,
5e,d2,5e,7f,21,14,b5,b2,29
"3"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,f2,55,76,c8,bc,53,92,25,3f,d1,b6,bc,00,35,73,43,96,90,79,f6,5b,97,35,47,\

[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F\3323E31CCF524E1933A08EFC0405BBBB]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,ce,d6,da,a0,ab,80,e1,24
"2"=hex:cf,77,c8,3e,ea,da,16,30
"3"=hex:a8,94,fb,1d,a8,04,93,f6,27,ba,9f,0c,1e,f4,d0,fa,15,d2,13,e7,60,58,bf,
34,53,b1,e8,5a,1a,a8,42,b7,2d,fd,1c,80,83,b7,98,df,e2,e7,5e,a6,54,59,11,31,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,9f,82,d5,6a,b3,ab,12,e7,1d,59,ee,f8,65,a3,77,fa,21,98,53,17,b3,88,55,98,\
"7"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,e5,98,6b,ad,2b,ca,86,50
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,6b,8d,dd,0b,84,72,f6,
f2,3d,a6,3c,a0,07,7d,db,f3,88,a8,6c,3f,5c,60,94,94,89,77,0c,65,96,1c,ff,8e,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:1c,bd,ea,59,8e,8d,e1,5f
"11"=hex:7d,ba,74,77,fe,09,92,36
"12"=hex:a0,df,59,f4,e0,d8,0a,fb,cc,26,53,e2,71,64,8d,71,ba,4e,45,28,8c,cb,ad,
f4,ad,a6,4b,f6,0b,36,45,63,80,07,b3,29,1a,d2,24,19,0d,d9,f2,62,b0,4d,44,2b,\
"13"=hex:dc,57,f7,3b,8a,43,9d,48,6e,d4,56,e7,f9,b4,6f,02,ef,9f,db,da,f9,28,c9,
17
"14"=hex:4e,63,05,ff,92,a2,5b,c8
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:55,3b,68,6f,03,fb,52,52,1d,27,1b,a1,9b,47,55,0a
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:e8,cc,f6,66,72,7c,fe,c6,e4,b5,3c,4a,a8,61,22,91,aa,4c,e9,68,ac,5f,e5,
82,00,ba,60,5d,62,f0,d8,db,11,10,68,38,36,5d,7f,2d,b3,37,f5,6d,42,af,fb,27,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(928)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-02-16 10:31:58
ComboFix-quarantined-files.txt 2009-02-16 15:31:33
ComboFix2.txt 2009-02-16 00:57:07

Pre-Run: 58,105,802,752 bytes free
Post-Run: 58,145,996,800 bytes free

Current=4 Default=4 Failed=1 LastKnownGood=2 Sets=1,2,3,4
315 — E O F — 2009-02-12 17:11:48



HiJackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:21 AM, on 2/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Nick\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5071202
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [dscactivate] "%ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Nick\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://152.1.164.197/activex/AxisCamControl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil…/familyfeud.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Message Queuing Service (MSMQSVC) - Unknown owner - C:\WINDOWS\system32\mqsv32.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 7811 bytes
ezpkns34,

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.
Please delete Rooter.

The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI