This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware Issues

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was traveling and thus unable to respond to the instructions in the original thread I started:
http://forums.whatthetech.com/malware_issues_t99953.html

I did follow the last instructions and below is the JavaRa log:

JavaRa 1.12 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Mon Feb 16 18:58:12 2009

Found and removed: C:\Windows\System32\jpicpl32.cpl

Found and removed: C:\Windows\System32\jupdate-1.5.0_01-b08.log

Found and removed: Software\JavaSoft\Java2D\1.5.0_01

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510001

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510001

Found and removed: SOFTWARE\Classes\JavaPlugin.150_01

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_01

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_01

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150010}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_01

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510001

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_01\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip

————————————

Finished reporting.



JavaRa 1.12 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Thu Feb 26 17:33:52 2009

Found and removed: C:\Program Files\Java\jre1.5.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

————————————

Finished reporting.
Below is the ComboFix Log:

ComboFix 09-02-26.01 - Owner 2009-02-26 17:56:44.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1024.549 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point

FILE ::
c:\windows\Tasks\Symantec NetDetect.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\Symantec NetDetect.job

.
((((((((((((((((((((((((( Files Created from 2009-01-26 to 2009-02-26 )))))))))))))))))))))))))))))))
.

2009-02-17 21:14 . 2008-06-10 15:04 31,048 –a—— c:\windows\system32\drivers\point32.sys
2009-02-17 21:13 . 2009-02-17 21:14 d——– c:\program files\Microsoft IntelliPoint
2009-02-17 21:12 . 2009-02-17 21:12 d——– c:\program files\MSXML 6.0
2009-02-17 21:10 . 2004-08-04 02:56 21,504 –a—— c:\windows\system32\hidserv.dll
2009-02-17 21:10 . 2004-08-04 02:56 21,504 –a–c— c:\windows\system32\dllcache\hidserv.dll
2009-02-16 19:04 . 2009-02-16 19:04 410,984 –a—— c:\windows\system32\deploytk.dll
2009-02-16 19:04 . 2009-02-16 19:04 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-02-12 19:47 . 2009-02-12 19:47 d——– c:\windows\ERUNT
2009-02-12 19:47 . 2001-08-18 12:00 1,688 –a—— c:\windows\system32\AUTOEXEC.NT
2009-02-12 19:43 . 2009-02-12 20:21 d—-c— C:\SDFix
2009-02-12 19:41 . 2009-02-12 19:41 d——– c:\documents and settings\Owner\Application Data\ATI
2009-02-12 19:41 . 2009-02-12 19:41 d——– c:\documents and settings\All Users\Application Data\ATI
2009-02-12 19:35 . 2009-02-12 19:35 d——– c:\program files\Common Files\ATI Technologies
2009-02-12 19:34 . 2008-12-01 14:35 593,920 ——— c:\windows\system32\ati2sgag.exe
2009-02-12 19:33 . 2009-02-12 19:36 d——– c:\program files\ATI Technologies
2009-02-10 19:39 . 2009-02-10 19:39 d——– c:\program files\ERUNT
2009-02-04 20:21 . 2009-02-04 20:21 7,900 –a—— c:\windows\system32\d3d9caps.dat
2009-02-04 20:20 . 2009-01-05 09:17 425,984 -ra—— c:\windows\system32\ATIDEMGX.dll
2009-02-04 20:20 . 2009-01-05 09:17 307,200 -ra—— c:\windows\system32\atiiiexx.dll
2009-02-04 20:20 . 2009-01-05 09:17 15,079 -ra—— c:\windows\atiogl.xml
2009-02-04 20:20 . 2009-01-05 09:17 529 -ra—— c:\windows\system32\ATIODCLI.exe.manifest
2009-02-04 20:20 . 2009-01-05 09:17 527 -ra—— c:\windows\system32\ATIODE.exe.manifest
2009-02-04 20:20 . 2009-02-04 20:20 0 –a—— c:\windows\ativpsrm.bin
2009-02-04 20:19 . 2009-01-05 09:19 3,107,788 -ra—— c:\windows\system32\ativvaxx.dat
2009-02-04 20:19 . 2009-01-05 09:18 3,107,788 -ra—— c:\windows\system32\ativva5x.dat
2009-02-04 20:19 . 2009-01-05 09:18 887,724 -ra—— c:\windows\system32\ativva6x.dat
2009-02-04 20:19 . 2009-01-05 09:17 180,720 -ra—— c:\windows\system32\atiicdxx.dat
2009-02-04 20:19 . 2009-01-05 09:17 7,167 -ra—— c:\windows\system32\atifglpf.xml

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-26 22:39 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-26 22:33 ——— d—–w c:\program files\Java
2009-02-16 23:54 ——— d—–w c:\program files\Viewpoint
2009-02-16 23:54 ——— d—–w c:\documents and settings\Owner\Application Data\Viewpoint
2009-02-16 23:54 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-02-13 01:33 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-13 00:35 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-11 15:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-02-06 19:57 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-06 19:57 10,520 —-a-w c:\windows\system32\avgrsstx.dll
2009-02-06 19:57 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-06 19:56 107,272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-05 14:19 2,495,360 —-a-w c:\windows\system32\ativvaxx.dll
2009-01-05 14:19 147,456 —-a-w c:\windows\system32\Oemdspif.dll
2009-01-05 14:18 286,720 —-a-w c:\windows\system32\atiok3x2.dll
2009-01-05 14:18 24,064 —-a-w c:\windows\system32\ativcoxx.dll
2009-01-05 14:18 188,416 —-a-w c:\windows\system32\atipdlxx.dll
2009-01-05 14:18 17,408 —-a-w c:\windows\system32\atitvo32.dll
2009-01-05 14:18 11,304,960 —-a-w c:\windows\system32\atioglxx.dll
2009-01-05 14:17 81,920 —-a-w c:\windows\system32\ATIODE.exe
2009-01-05 14:17 45,056 —-a-w c:\windows\system32\ATIODCLI.exe
2009-01-05 14:17 401,408 —-a-w c:\windows\system32\atikvmag.dll
2009-01-05 14:16 86,016 —-a-w c:\windows\system32\atiadlxx.dll
2009-01-05 14:16 598,016 —-a-w c:\windows\system32\ati2evxx.exe
2009-01-05 14:16 53,248 —-a-w c:\windows\system32\ATIDDC.DLL
2009-01-05 14:16 4,120,384 —-a-w c:\windows\system32\ati3duag.dll
2009-01-05 14:16 3,452,928 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-01-05 14:16 26,112 —-a-w c:\windows\system32\Ati2mdxx.exe
2009-01-05 14:16 118,784 —-a-w c:\windows\system32\atibrtmon.exe
2009-01-05 14:15 577,536 —-a-w c:\windows\system32\ati2cqag.dll
2009-01-05 14:15 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2009-01-05 14:15 48,640 —-a-w c:\windows\system32\amdpcom32.dll
2009-01-05 14:15 45,056 —-a-w c:\windows\system32\amdcalrt.dll
2009-01-05 14:15 45,056 —-a-w c:\windows\system32\amdcalcl.dll
2009-01-05 14:15 43,520 —-a-w c:\windows\system32\ati2edxx.dll
2009-01-05 14:15 318,464 —-a-w c:\windows\system32\ati2dvag.dll
2009-01-05 14:15 3,252,224 —-a-w c:\windows\system32\Amdcaldd.dll
2009-01-05 14:15 143,360 —-a-w c:\windows\system32\ati2evxx.dll
2009-01-02 06:21 ——— d—–w c:\program files\AVG
2009-01-02 05:43 ——— d—–w c:\documents and settings\Owner\Application Data\BPFTP
2009-01-02 05:33 ——— d—–w c:\program files\BulletProof FTP Client v2.6
2009-01-02 03:14 ——— d—–w c:\documents and settings\Owner\Application Data\Malwarebytes
2009-01-02 03:14 ——— d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-02 02:30 ——— d—–w c:\program files\World of Warcraft
2009-01-02 01:41 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-02 01:41 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-01-02 01:33 ——— d—–w c:\program files\Alwil Software
2009-01-02 00:18 ——— d—–w c:\program files\Trend Micro
2009-01-01 21:39 ——— d—–w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-01-01 21:39 ——— d—–w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-12-09 21:44 97,280 —-a-w c:\windows\scan.dll
2008-01-14 18:07 792,624 -c–a-w c:\program files\LOTRO-US-Book11-Downloader-FreeTrial-StandardRes.exe
2003-09-16 23:56 3,584 —-a-w c:\documents and settings\Owner\netcache.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-02-15_12.45.30.79 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-03 13:03:29 8,460,800 —-a-w c:\windows\$hf_mig$\KB967715\SP2QFE\shell32.dll
+ 2008-02-15 09:06:21 351,744 —-a-w c:\windows\$hf_mig$\KB967715\SP2QFE\xpsp3res.dll
+ 2008-06-17 19:02:19 8,461,312 —-a-w c:\windows\$hf_mig$\KB967715\SP3GDR\shell32.dll
+ 2008-06-17 19:04:34 8,461,824 —-a-w c:\windows\$hf_mig$\KB967715\SP3QFE\shell32.dll
+ 2008-07-09 07:38:24 17,272 —-a-w c:\windows\$hf_mig$\KB967715\spmsg.dll
+ 2008-07-09 07:38:25 231,288 —-a-w c:\windows\$hf_mig$\KB967715\spuninst.exe
+ 2008-07-09 07:38:24 26,488 —-a-w c:\windows\$hf_mig$\KB967715\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 —-a-w c:\windows\$hf_mig$\KB967715\update\update.exe
+ 2008-07-09 07:38:37 382,840 —-a-w c:\windows\$hf_mig$\KB967715\update\updspapi.dll
+ 2009-02-18 02:14:06 25,214 —-a-r c:\windows\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\ARPPRODUCTICON.exe
+ 2009-02-18 02:14:06 25,214 —-a-r c:\windows\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\CPL_DTSC.exe
+ 2009-02-18 02:14:06 25,214 —-a-r c:\windows\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\CPL_SC.exe
+ 2009-02-18 02:14:06 25,214 —-a-r c:\windows\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\HCG_SC.exe
+ 2009-02-18 02:14:06 4,846 —-a-r c:\windows\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\MouseUG.exe
+ 2009-02-18 02:14:06 29,926 —-a-r c:\windows\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\NewShortcut1_6463554370E7436D8D6D4A721595029E.exe
+ 2009-02-18 02:14:06 29,926 —-a-r c:\windows\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\NewShortcut2_6463554370E7436D8D6D4A721595029E.exe
+ 2009-02-18 02:14:06 65,536 —-a-r c:\windows\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\NewShortcut3_4748AC220AD3439FA5EECE4BB6C12AAC.exe
+ 2009-02-18 02:14:06 65,536 —-a-r c:\windows\Installer\{66A9D30D-1464-4C7F-B2F3-507DADAF2595}\NewShortcut4_66A9D30D14644C7FB2F3507DADAF2595.exe
- 2007-10-26 03:36:51 8,454,656 -c–a-w c:\windows\system32\dllcache\shell32.dll
+ 2008-07-03 13:16:57 8,454,656 -c–a-w c:\windows\system32\dllcache\shell32.dll
+ 2008-06-09 20:12:04 18,504 -c–a-w c:\windows\system32\DRVSTORE\nuidfltr_E8F8C714821A786671DE95508EA821EFC993B9E1\NuidFltr.sys
+ 2008-06-09 20:12:56 1,421,384 -c–a-w c:\windows\system32\DRVSTORE\nuidfltr_E8F8C714821A786671DE95508EA821EFC993B9E1\wdfcoinstaller01005.dll
+ 2008-06-10 20:04:26 33,352 -c–a-w c:\windows\system32\DRVSTORE\pnt32pk_10A740FB87D0ACA33593A12D9BBD5CBB5DED03D4\point32k.sys
+ 2008-06-10 20:04:26 31,048 -c–a-w c:\windows\system32\DRVSTORE\pnt32pw_81F87EB3DFFD672CD4DE30C5341B8C7F08DA9486\point32.sys
+ 2008-06-10 20:04:26 33,352 -c–a-w c:\windows\system32\DRVSTORE\pnt32uk_8477F1120BF994C8009DDB48E4DD8FA85A9039FC\point32k.sys
+ 2008-06-10 20:04:26 31,048 -c–a-w c:\windows\system32\DRVSTORE\pnt32uw_667890F3485BB5D1C47F7877D51185D7490A7A6A\point32.sys
- 2008-10-15 18:35:14 285,312 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-02-18 19:29:47 286,904 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2004-12-07 00:04:12 49,248 —-a-w c:\windows\system32\java.exe
+ 2009-02-17 00:04:28 144,792 —-a-w c:\windows\system32\java.exe
- 2004-12-07 00:04:20 49,250 —-a-w c:\windows\system32\javaw.exe
+ 2009-02-17 00:04:28 144,792 —-a-w c:\windows\system32\javaw.exe
+ 2009-02-17 00:04:28 148,888 —-a-w c:\windows\system32\javaws.exe
+ 2008-08-30 01:06:44 1,350,664 —-a-w c:\windows\system32\msxml6.dll
+ 2006-10-05 09:31:10 79,872 —-a-w c:\windows\system32\msxml6r.dll
+ 2004-08-04 05:58:32 23,040 —-a-w c:\windows\system32\ReinstallBackups\0010\DriverFiles\i386\mouclass.sys
+ 2001-08-17 18:48:00 12,160 —-a-w c:\windows\system32\ReinstallBackups\0010\DriverFiles\i386\mouhid.sys
- 2007-10-26 03:36:51 8,454,656 —-a-w c:\windows\system32\shell32.dll
+ 2008-07-03 13:16:57 8,454,656 —-a-w c:\windows\system32\shell32.dll
+ 2009-02-26 19:40:44 16,384 —-atw c:\windows\temp\Perflib_Perfdata_1a0.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"washindex"="c:\program files\Washer\washidx.exe" [2002-09-19 33792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"IntelliType"="c:\program files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-21 94208]
"Windows Media Connect 2"="c:\program files\Windows Media Connect 2\WMCCFG.exe" [2006-10-18 8704]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-16 148888]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 158208]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-12-09 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2005-12-26 1073152]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\6]
Source= c:\documents and settings\Owner\My Documents\gamercard.txt
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-06 14:57 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
–a—— 2009-02-06 14:56 1601304 c:\progra~1\AVG\AVG8\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
–a–c— 2005-05-19 08:47 57344 c:\program files\SlySoft\CloneCD\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 11:24 1694208 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter]
–a—— 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Washer]
–a—— 2003-01-10 15:28 798208 c:\program files\Washer\washer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Valve\\Steam\\Steam.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\thrones.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"= c:\\program files\\mozilla firefox\\firefox.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\DOSBox-0.61\\dosbox.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\whiteknight117\\half-life 2\\hl2.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\whiteknight117\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\Age3.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.4.6314-to-2.0.5.6320-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.6.6337-to-2.0.7.6383-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\whiteknight117\\source sdk base\\hl2.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5160:TCP"= 5160:TCP:BND
"14879:TCP"= 14879:TCP:BND
"7606:TCP"= 7606:TCP:BND
"19631:TCP"= 19631:TCP:BND
"33706:TCP"= 33706:TCP:BND
"30050:TCP"= 30050:TCP:BND
"11884:TCP"= 11884:TCP:BND
"24118:TCP"= 24118:TCP:BND
"20758:TCP"= 20758:TCP:BND
"23359:TCP"= 23359:TCP:BND
"14172:TCP"= 14172:TCP:BND
"32325:TCP"= 32325:TCP:BND
"31836:TCP"= 31836:TCP:BND
"27111:TCP"= 27111:TCP:BND
"17930:TCP"= 17930:TCP:BND
"8837:TCP"= 8837:TCP:BND
"5640:TCP"= 5640:TCP:BND
"32923:TCP"= 32923:TCP:BND
"17412:TCP"= 17412:TCP:BND
"15082:TCP"= 15082:TCP:BND
"5208:TCP"= 5208:TCP:BND
"25116:TCP"= 25116:TCP:BND
"27846:TCP"= 27846:TCP:BND
"28338:TCP"= 28338:TCP:BND
"22099:TCP"= 22099:TCP:BND
"31740:TCP"= 31740:TCP:BND
"30262:TCP"= 30262:TCP:BND
"27331:TCP"= 27331:TCP:BND
"17625:TCP"= 17625:TCP:BND
"31084:TCP"= 31084:TCP:BND
"11300:TCP"= 11300:TCP:BND
"30069:TCP"= 30069:TCP:BND
"20066:TCP"= 20066:TCP:BND
"22883:TCP"= 22883:TCP:BND
"7771:TCP"= 7771:TCP:BND
"21801:TCP"= 21801:TCP:BND
"7429:TCP"= 7429:TCP:BND
"25936:TCP"= 25936:TCP:BND
"25513:TCP"= 25513:TCP:BND
"25593:TCP"= 25593:TCP:BND
"15716:TCP"= 15716:TCP:BND
"21940:TCP"= 21940:TCP:BND
"17067:TCP"= 17067:TCP:BND
"5666:TCP"= 5666:TCP:BND
"18889:TCP"= 18889:TCP:BND
"28250:TCP"= 28250:TCP:BND
"6308:TCP"= 6308:TCP:BND

R0 SSI;SSI;c:\windows\system32\drivers\ssi.sys [2005-10-15 79872]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-02 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-02 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-02 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-02 298264]
S2 gupdate1c8cb1f344263d0;Google Update Service (gupdate1c8cb1f344263d0);c:\program files\Google\Update\GoogleUpdate.exe [2008-07-18 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Legacy VGA Drivers V1.0]
c:\windows\certproc32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Sony DVDRam Version 1.8B]
c:\windows\uiengine32.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-02-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-14 16:42]

2009-02-26 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-08-29 19:18]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.5.0_01\bin\jusched.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
Trusted Zone: aol.com\free
Trusted Zone: tgnfiles.com\www
TCP: {F4865033-B1DC-46EA-9959-A57BA1CE8CF4} = 68.9.16.25,68.9.16.30
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\28axsn38.John\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\28axsn38.John\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\GameTap\bin\Release\npgametaptool.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.20926.0.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npff_gdm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-26 18:01:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1606980848-1123561945-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)

[HKEY_USERS\S-1-5-21-1606980848-1123561945-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:4c,24,7f,a4,62,4e,cb,ea,c3,ea,3f,6a,14,c2,b8,75,71,b8,1d,7c,fe,cd,b6,
dd,2a,45,37,b0,5a,d6,88,a9,67,fb,11,70,a3,4b,1a,5e,d4,2f,08,44,bb,24,7b,49,\
"??"=hex:f4,c1,39,27,8e,33,69,46,5e,79,b1,61,79,2a,dd,61

[HKEY_USERS\S-1-5-21-1606980848-1123561945-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:74,bd,b8,56,34,77,24,52,f7,f4,d2,66,73,38,f2,19,c6,54,05,01,33,
b0,00,2c,c5,3b,7f,11,e5,73,68,dc,a9,af,e6,36,bd,77,05,ad,03,9f,2f,58,e3,ef,\
"rkeysecu"=hex:75,45,1f,9e,2c,ce,b3,94,73,c2,bb,12,7d,57,26,95
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\WRLogonNTF.dll
.
Completion time: 2009-02-26 18:07:01
ComboFix-quarantined-files.txt 2009-02-26 23:05:44
ComboFix2.txt 2009-02-17 02:09:19
ComboFix3.txt 2009-02-15 17:48:09

Pre-Run: 32,383,504,384 bytes free
Post-Run: 32,438,476,800 bytes free

355 — E O F — 2009-02-25 06:30:31
And lastly, the new Hijack This Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:16:05 PM, on 2/26/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe
O4 - Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GameSpotDownloadManager_Win32.exe
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155673643515
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion….ebio5_2_3_0.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4865033-B1DC-46EA-9959-A57BA1CE8CF4}: NameServer = 68.9.16.25,68.9.16.30
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c8cb1f344263d0) (gupdate1c8cb1f344263d0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: WPS Scanner Service (WPSScannerSvc) - Skyhook Wireless - C:\Program Files\Skyhook Wireless\Wi-Fi Service\WPSScannerSvc.exe
O24 - Desktop Component 0: (no name) - http://010612779305286.football.nfl.com/im…raond-72x72.jpg
O24 - Desktop Component 1: (no name) - http://home.comcast.net/~nutrino/newTSlogo.gif
O24 - Desktop Component 2: (no name) - http://www.neo-buzz.com/images/1/background.gif
O24 - Desktop Component 3: (no name) - http://image.com.com/gamespot/shared/pc_bg.gif
O24 - Desktop Component 4: (no name) - http://i.i.com.com/cnet.g2/shared/page_bg.jpg
O24 - Desktop Component 6: (no name) - C:\Documents and Settings\Owner\My Documents\gamercard.txt

–
End of file - 8500 bytes
Other than the fact that I can't enable 'Show Hidden Files and Folders,' it seems to fine. I don't haven't noticed any other issues.
Paul Varjak,

Well then. Let's see if we can find the cause of that.

Please Click on Start in the lower left of your screen.

Click on Run.

In the window that opens, please paste the following:
regedit.exe /e "%userprofile%\Desktop\myfile.txt" "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Advanced\Folder\Hidden\SHOWALL"


Click on OK

A file will appear on your desktop called myfile.txt

Please attach that file to your next reply.
Paul Varjak,

Well, everything looks in order there. At this point I suggest that you let the Tech Team have a go. You can post the question in the Windows Forum here. Please provide a link there back to this thread. That will allow them to see your logs.

Meanwhile, Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Thanks for your help, Tom. I will try posting in the Windows Forum. At least it appears the system is clean now.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI