Calibrator
Hi CatByte,
Scan completed 8 hours……
To answer your initial questions:
I am afraid I didn't save the log from the original Dr Web scan and I am not entirely sure where I got the idea of Virut from, I do remember AVG reported SHeur but I am unsure about virut. I seem to recall something like xxxxxx.Win32.i56 but cannot be sure if this was what came up in a search when I Googled SHeur.
Sorry for not being more specific but I was panicking at the time.
Anyway here are the logs:
ComboFix
ComboFix 09-04-01.01 - Administrator 2009-04-03 4:54:31.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1118 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\system32\30.tmp
c:\windows\system32\31.tmp
c:\windows\system32\32.tmp
c:\windows\system32\3B.tmp
c:\windows\system32\pqicgjmb.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\30.tmp
c:\windows\system32\31.tmp
c:\windows\system32\32.tmp
c:\windows\system32\3B.tmp
c:\windows\explorer.exe . . . is infected!!
.
————— FCopy —————
c:\windows\ServicePackFiles\i386\explorer.exe –> c:\windows\explorer.exe
c:\windows\ServicePackFiles\i386\ctfmon.exe –> c:\windows\system32\ctfmon.exe
c:\windows\ServicePackFiles\i386\userinit.exe –> c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-03 to 2009-04-03 )))))))))))))))))))))))))))))))
.
2009-04-02 17:23 . 2009-04-02 17:23 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-04-02 17:20 . 2009-04-02 17:21 d——– c:\windows\ERUNT
2009-04-02 17:15 . 2009-04-02 17:49 d——– C:\SDFix
2009-04-02 09:40 . 2009-04-02 09:40 d——– c:\program files\Trend Micro
2009-04-02 08:49 . 2009-04-02 08:49 d——– c:\program files\ERUNT
2009-04-02 08:30 . 2009-04-02 08:30 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-02 08:30 . 2009-04-02 08:30 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-02 08:30 . 2009-04-02 08:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-04-02 08:30 . 2009-03-26 16:49 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-02 08:30 . 2009-03-26 16:49 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-04-02 07:42 . 2008-07-12 08:18 3,851,784 –a—— c:\windows\system32\D3DX9_39.dll
2009-04-02 07:42 . 2008-07-12 08:18 1,493,528 –a—— c:\windows\system32\D3DCompiler_39.dll
2009-04-02 07:42 . 2008-07-12 08:18 467,984 –a—— c:\windows\system32\d3dx10_39.dll
2009-04-02 07:41 . 2009-04-02 07:41 d——– c:\program files\PerformanceTest
2009-04-02 07:41 . 2009-04-02 07:41 d——– c:\documents and settings\All Users\Application Data\PassMark
2009-04-01 12:05 . 2009-04-01 12:05 d——– C:\Oscar
2009-03-30 11:46 . 2009-03-30 11:57 d——– c:\windows\SxsCaPendDel
2009-03-30 11:46 . 2009-03-30 11:46 d——– C:\45bb6b287e696ff21d8f8dae445d
2009-03-30 11:41 . 2008-06-17 20:02 8,461,312 —–c— c:\windows\system32\dllcache\shell32.dll
2009-03-30 11:41 . 2008-12-05 07:54 144,896 —–c— c:\windows\system32\dllcache\schannel.dll
2009-03-30 11:35 . 2008-06-20 12:51 361,600 —–c— c:\windows\system32\dllcache\tcpip.sys
2009-03-30 11:35 . 2008-06-20 18:46 245,248 —–c— c:\windows\system32\dllcache\mswsock.dll
2009-03-30 11:35 . 2008-06-20 12:08 225,856 —–c— c:\windows\system32\dllcache\tcpip6.sys
2009-03-30 11:35 . 2008-06-20 18:46 147,968 —–c— c:\windows\system32\dllcache\dnsapi.dll
2009-03-30 11:28 . 2009-03-30 11:28 d——– c:\program files\Sun
2009-03-30 11:28 . 2009-03-30 11:27 410,984 –a—— c:\windows\system32\deploytk.dll
2009-03-30 11:22 . 2009-03-30 11:25 d——– c:\documents and settings\Administrator\.SunDownloadManager
2009-03-28 12:04 . 2009-02-25 16:15 593,920 ——— c:\windows\system32\ati2sgag.exe
2009-03-26 20:40 . 2009-03-28 08:05 d——– c:\documents and settings\Administrator\DoctorWeb
2009-03-24 21:55 . 2009-03-24 21:57 d——– c:\program files\Nexus Radio
2009-03-24 20:15 . 2009-03-24 20:15 d——– c:\windows\Replay Media Catcher
2009-03-24 20:15 . 2009-03-30 09:23 d——– c:\program files\Replay Media Catcher
2009-03-24 20:15 . 2009-03-30 08:58 323,584 –a—— c:\windows\system32\AUDIOGENIE2.DLL
2009-03-24 20:15 . 2009-03-30 08:58 237,568 –a—— c:\windows\system32\rmc_rtspdl.dll
2009-03-24 20:15 . 2009-03-30 08:58 156,672 –a—— c:\windows\system32\rmc_fixasf.exe
2009-03-24 19:44 . 2009-03-24 19:44 d——– c:\program files\Philips
2009-03-06 21:49 . 2009-03-06 21:49 d——– c:\documents and settings\Administrator\Application Data\Stellarium
2009-03-06 21:48 . 2009-03-06 21:49 d——– c:\program files\Stellarium
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 19:18 ——— d—–w c:\documents and settings\All Users\Application Data\TrackMania
2009-04-02 19:12 ——— d—–w c:\program files\Steam
2009-03-30 10:51 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-30 10:27 ——— d—–w c:\program files\Java
2009-03-30 08:53 ——— d—–w c:\documents and settings\Administrator\Application Data\Spotify
2009-03-30 08:49 ——— d—–w c:\program files\Spotify
2009-03-28 08:50 ——— d—–w c:\program files\mIRC
2009-03-28 08:00 966,656 —-a-w c:\windows\UNRecode.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroVision.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroShowTime.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroMediaHome.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroBackItUp.exe
2009-03-28 08:00 283,648 —-a-w c:\windows\winhlp32.exe
2009-03-26 19:43 1,052,672 —-a-w c:\windows\explorer.exe
2009-03-26 18:07 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-03-26 18:06 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-24 20:49 ——— d—–w c:\documents and settings\Administrator\Application Data\NCH Swift Sound
2009-03-24 20:48 ——— d—–w c:\program files\NCH Software
2009-03-24 18:44 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-25 22:58 3,565,568 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-25 20:37 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-22 09:50 ——— d—–w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-02-22 09:43 27,136 —-a-w c:\windows\system32\drivers\nchssvad.sys
2009-02-22 09:43 ——— d—–w c:\documents and settings\All Users\Application Data\NCH Software
2009-02-14 13:19 ——— d—–w c:\program files\AMD
2009-02-14 12:27 ——— d—–w c:\program files\TRUST 640U SILVERLINE HEADSET USB
2009-02-06 17:09 ——— d—–w c:\program files\Audio Recorder
2008-04-27 09:41 774,144 —-a-w c:\program files\RngInterstitial.dll
.
——- Sigcheck ——-
2009-03-26 20:43 1052672 c0e3ad1446ee377b603a767a551af1bf c:\windows\explorer.exe
2009-03-28 09:03 1033216 1dd6b3b2ac20843fa043009969ad62d3 c:\windows\$NtServicePackUninstall$\explorer.exe
2009-03-28 09:11 1033728 76afe06854aad9fb48834da6cdc44b42 c:\windows\$NtUninstallKB938828$\explorer.exe
2009-03-28 09:27 1033728 799770b46fa0a806a7a0f52e1a85e887 c:\windows\ServicePackFiles\i386\explorer.exe
2009-03-28 09:03 15360 edf00d5b9133d927adf802b1f7d7c259 c:\windows\$NtServicePackUninstall$\ctfmon.exe
2009-03-28 09:27 15360 6d550f617e0ab3629734c7363dcae628 c:\windows\ServicePackFiles\i386\ctfmon.exe
2009-03-28 09:27 15360 6d550f617e0ab3629734c7363dcae628 c:\windows\system32\ctfmon.exe
2009-03-28 09:09 25088 3ee9d7262239565fea14558f2cf81d68 c:\windows\$NtServicePackUninstall$\userinit.exe
2009-03-28 09:35 26624 1ff2ee91dd1b1bda034e56a03e633cef c:\windows\ServicePackFiles\i386\userinit.exe
2009-03-28 09:35 26624 1ff2ee91dd1b1bda034e56a03e633cef c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-04-02_17.57.52.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-03 03:58:34 16,384 —-atw c:\windows\temp\Perflib_Perfdata_270.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2009-03-28 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-26 1601304]
"TI WLAN"="c:\program files\Wireless LAN Utility\TIWLANCu.exe" [2009-03-26 1171456]
"WheelMouse"="c:\advanced wheel mouse\wh_exec.exe" [2009-03-26 98304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2009-03-26 77824]
"VTTimer"="VTTimer.exe" [2009-03-26 c:\windows\system32\VTTimer.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-26 19:06 10520 c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Steam\\steamapps\\calibrator67\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\calibrator67\\counter-strike\\hl.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-19 325128]
R1 eusk2par;EUTRON SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [2008-03-21 24786]
R2 avg8wd;avg8wd;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-19 298264]
R3 TNET1130;802.11 WLAN;c:\windows\system32\drivers\TNET1130.sys [2008-08-17 438912]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-07-20 84992]
S3 eusk3usb;SmartKey 3 USB;c:\windows\system32\drivers\eusk3usb.sys [2008-03-21 45534]
.
Contents of the 'Scheduled Tasks' folder
2009-03-30 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2007-07-09 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride =
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cgr16zu7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-03 04:58:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-343818398-484763869-725345543-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Wireless LAN Utility\tiwlnsvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-03 5:02:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-03 04:02:03
ComboFix2.txt 2009-04-02 16:59:05
ComboFix3.txt 2009-03-30 09:34:12
Pre-Run: 277,698,134,016 bytes free
Post-Run: 277,702,606,848 bytes free
199
Kaspersky
Scanned: 837161
Detected: 19
Untreated: 0
Start time: 03/04/2009 05:23:16
Duration: 07:54:29
Finish time: 03/04/2009 13:17:45
Detected
——–
Status Object
—— ——
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\30.tmp.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\31.tmp.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\3B.tmp.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\7.tmp.vir
deleted: Trojan program Trojan.Win32.VB.mnr File: C:\Qoobox\Quarantine\C\WINDOWS\system32\dxonool32.sys.vir
deleted: Trojan program Trojan-Downloader.Win32.Agent.bpew File: C:\Qoobox\Quarantine\C\WINDOWS\system32\tpszxyd.sys.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/10.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/11.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/12.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/15.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/16.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/17.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/18.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/1A.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/1B.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/24.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/25.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/2C.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/2D.tmp
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:26:45, on 03/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Wireless LAN Utility\TIWLANCu.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wireless LAN Utility\tiwlnsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TI WLAN] C:\Program Files\Wireless LAN Utility\TIWLANCu.exe
O4 - HKLM\..\Run: [WheelMouse] C:\Advanced Wheel Mouse\wh_exec.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1229158219187
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229160138828
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avg8wd - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: TI Wlan Service (tiwlnsvc) - Unknown owner - C:\Program Files\Wireless LAN Utility\tiwlnsvc.exe
–
End of file - 6349 bytes
Shaun
Scan completed 8 hours……
To answer your initial questions:
I am afraid I didn't save the log from the original Dr Web scan and I am not entirely sure where I got the idea of Virut from, I do remember AVG reported SHeur but I am unsure about virut. I seem to recall something like xxxxxx.Win32.i56 but cannot be sure if this was what came up in a search when I Googled SHeur.
Sorry for not being more specific but I was panicking at the time.
Anyway here are the logs:
ComboFix
ComboFix 09-04-01.01 - Administrator 2009-04-03 4:54:31.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1118 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\system32\30.tmp
c:\windows\system32\31.tmp
c:\windows\system32\32.tmp
c:\windows\system32\3B.tmp
c:\windows\system32\pqicgjmb.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\30.tmp
c:\windows\system32\31.tmp
c:\windows\system32\32.tmp
c:\windows\system32\3B.tmp
c:\windows\explorer.exe . . . is infected!!
.
————— FCopy —————
c:\windows\ServicePackFiles\i386\explorer.exe –> c:\windows\explorer.exe
c:\windows\ServicePackFiles\i386\ctfmon.exe –> c:\windows\system32\ctfmon.exe
c:\windows\ServicePackFiles\i386\userinit.exe –> c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-03 to 2009-04-03 )))))))))))))))))))))))))))))))
.
2009-04-02 17:23 . 2009-04-02 17:23 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-04-02 17:20 . 2009-04-02 17:21 d——– c:\windows\ERUNT
2009-04-02 17:15 . 2009-04-02 17:49 d——– C:\SDFix
2009-04-02 09:40 . 2009-04-02 09:40 d——– c:\program files\Trend Micro
2009-04-02 08:49 . 2009-04-02 08:49 d——– c:\program files\ERUNT
2009-04-02 08:30 . 2009-04-02 08:30 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-02 08:30 . 2009-04-02 08:30 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-02 08:30 . 2009-04-02 08:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-04-02 08:30 . 2009-03-26 16:49 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-02 08:30 . 2009-03-26 16:49 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-04-02 07:42 . 2008-07-12 08:18 3,851,784 –a—— c:\windows\system32\D3DX9_39.dll
2009-04-02 07:42 . 2008-07-12 08:18 1,493,528 –a—— c:\windows\system32\D3DCompiler_39.dll
2009-04-02 07:42 . 2008-07-12 08:18 467,984 –a—— c:\windows\system32\d3dx10_39.dll
2009-04-02 07:41 . 2009-04-02 07:41 d——– c:\program files\PerformanceTest
2009-04-02 07:41 . 2009-04-02 07:41 d——– c:\documents and settings\All Users\Application Data\PassMark
2009-04-01 12:05 . 2009-04-01 12:05 d——– C:\Oscar
2009-03-30 11:46 . 2009-03-30 11:57 d——– c:\windows\SxsCaPendDel
2009-03-30 11:46 . 2009-03-30 11:46 d——– C:\45bb6b287e696ff21d8f8dae445d
2009-03-30 11:41 . 2008-06-17 20:02 8,461,312 —–c— c:\windows\system32\dllcache\shell32.dll
2009-03-30 11:41 . 2008-12-05 07:54 144,896 —–c— c:\windows\system32\dllcache\schannel.dll
2009-03-30 11:35 . 2008-06-20 12:51 361,600 —–c— c:\windows\system32\dllcache\tcpip.sys
2009-03-30 11:35 . 2008-06-20 18:46 245,248 —–c— c:\windows\system32\dllcache\mswsock.dll
2009-03-30 11:35 . 2008-06-20 12:08 225,856 —–c— c:\windows\system32\dllcache\tcpip6.sys
2009-03-30 11:35 . 2008-06-20 18:46 147,968 —–c— c:\windows\system32\dllcache\dnsapi.dll
2009-03-30 11:28 . 2009-03-30 11:28 d——– c:\program files\Sun
2009-03-30 11:28 . 2009-03-30 11:27 410,984 –a—— c:\windows\system32\deploytk.dll
2009-03-30 11:22 . 2009-03-30 11:25 d——– c:\documents and settings\Administrator\.SunDownloadManager
2009-03-28 12:04 . 2009-02-25 16:15 593,920 ——— c:\windows\system32\ati2sgag.exe
2009-03-26 20:40 . 2009-03-28 08:05 d——– c:\documents and settings\Administrator\DoctorWeb
2009-03-24 21:55 . 2009-03-24 21:57 d——– c:\program files\Nexus Radio
2009-03-24 20:15 . 2009-03-24 20:15 d——– c:\windows\Replay Media Catcher
2009-03-24 20:15 . 2009-03-30 09:23 d——– c:\program files\Replay Media Catcher
2009-03-24 20:15 . 2009-03-30 08:58 323,584 –a—— c:\windows\system32\AUDIOGENIE2.DLL
2009-03-24 20:15 . 2009-03-30 08:58 237,568 –a—— c:\windows\system32\rmc_rtspdl.dll
2009-03-24 20:15 . 2009-03-30 08:58 156,672 –a—— c:\windows\system32\rmc_fixasf.exe
2009-03-24 19:44 . 2009-03-24 19:44 d——– c:\program files\Philips
2009-03-06 21:49 . 2009-03-06 21:49 d——– c:\documents and settings\Administrator\Application Data\Stellarium
2009-03-06 21:48 . 2009-03-06 21:49 d——– c:\program files\Stellarium
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 19:18 ——— d—–w c:\documents and settings\All Users\Application Data\TrackMania
2009-04-02 19:12 ——— d—–w c:\program files\Steam
2009-03-30 10:51 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-30 10:27 ——— d—–w c:\program files\Java
2009-03-30 08:53 ——— d—–w c:\documents and settings\Administrator\Application Data\Spotify
2009-03-30 08:49 ——— d—–w c:\program files\Spotify
2009-03-28 08:50 ——— d—–w c:\program files\mIRC
2009-03-28 08:00 966,656 —-a-w c:\windows\UNRecode.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroVision.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroShowTime.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroMediaHome.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroBackItUp.exe
2009-03-28 08:00 283,648 —-a-w c:\windows\winhlp32.exe
2009-03-26 19:43 1,052,672 —-a-w c:\windows\explorer.exe
2009-03-26 18:07 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-03-26 18:06 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-24 20:49 ——— d—–w c:\documents and settings\Administrator\Application Data\NCH Swift Sound
2009-03-24 20:48 ——— d—–w c:\program files\NCH Software
2009-03-24 18:44 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-25 22:58 3,565,568 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-25 20:37 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-22 09:50 ——— d—–w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-02-22 09:43 27,136 —-a-w c:\windows\system32\drivers\nchssvad.sys
2009-02-22 09:43 ——— d—–w c:\documents and settings\All Users\Application Data\NCH Software
2009-02-14 13:19 ——— d—–w c:\program files\AMD
2009-02-14 12:27 ——— d—–w c:\program files\TRUST 640U SILVERLINE HEADSET USB
2009-02-06 17:09 ——— d—–w c:\program files\Audio Recorder
2008-04-27 09:41 774,144 —-a-w c:\program files\RngInterstitial.dll
.
——- Sigcheck ——-
2009-03-26 20:43 1052672 c0e3ad1446ee377b603a767a551af1bf c:\windows\explorer.exe
2009-03-28 09:03 1033216 1dd6b3b2ac20843fa043009969ad62d3 c:\windows\$NtServicePackUninstall$\explorer.exe
2009-03-28 09:11 1033728 76afe06854aad9fb48834da6cdc44b42 c:\windows\$NtUninstallKB938828$\explorer.exe
2009-03-28 09:27 1033728 799770b46fa0a806a7a0f52e1a85e887 c:\windows\ServicePackFiles\i386\explorer.exe
2009-03-28 09:03 15360 edf00d5b9133d927adf802b1f7d7c259 c:\windows\$NtServicePackUninstall$\ctfmon.exe
2009-03-28 09:27 15360 6d550f617e0ab3629734c7363dcae628 c:\windows\ServicePackFiles\i386\ctfmon.exe
2009-03-28 09:27 15360 6d550f617e0ab3629734c7363dcae628 c:\windows\system32\ctfmon.exe
2009-03-28 09:09 25088 3ee9d7262239565fea14558f2cf81d68 c:\windows\$NtServicePackUninstall$\userinit.exe
2009-03-28 09:35 26624 1ff2ee91dd1b1bda034e56a03e633cef c:\windows\ServicePackFiles\i386\userinit.exe
2009-03-28 09:35 26624 1ff2ee91dd1b1bda034e56a03e633cef c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-04-02_17.57.52.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-03 03:58:34 16,384 —-atw c:\windows\temp\Perflib_Perfdata_270.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2009-03-28 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-26 1601304]
"TI WLAN"="c:\program files\Wireless LAN Utility\TIWLANCu.exe" [2009-03-26 1171456]
"WheelMouse"="c:\advanced wheel mouse\wh_exec.exe" [2009-03-26 98304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2009-03-26 77824]
"VTTimer"="VTTimer.exe" [2009-03-26 c:\windows\system32\VTTimer.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-26 19:06 10520 c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Steam\\steamapps\\calibrator67\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\calibrator67\\counter-strike\\hl.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-19 325128]
R1 eusk2par;EUTRON SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [2008-03-21 24786]
R2 avg8wd;avg8wd;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-19 298264]
R3 TNET1130;802.11 WLAN;c:\windows\system32\drivers\TNET1130.sys [2008-08-17 438912]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-07-20 84992]
S3 eusk3usb;SmartKey 3 USB;c:\windows\system32\drivers\eusk3usb.sys [2008-03-21 45534]
.
Contents of the 'Scheduled Tasks' folder
2009-03-30 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2007-07-09 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride =
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cgr16zu7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-03 04:58:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-343818398-484763869-725345543-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Wireless LAN Utility\tiwlnsvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-03 5:02:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-03 04:02:03
ComboFix2.txt 2009-04-02 16:59:05
ComboFix3.txt 2009-03-30 09:34:12
Pre-Run: 277,698,134,016 bytes free
Post-Run: 277,702,606,848 bytes free
199
Kaspersky
Scanned: 837161
Detected: 19
Untreated: 0
Start time: 03/04/2009 05:23:16
Duration: 07:54:29
Finish time: 03/04/2009 13:17:45
Detected
——–
Status Object
—— ——
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\30.tmp.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\31.tmp.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\3B.tmp.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\7.tmp.vir
deleted: Trojan program Trojan.Win32.VB.mnr File: C:\Qoobox\Quarantine\C\WINDOWS\system32\dxonool32.sys.vir
deleted: Trojan program Trojan-Downloader.Win32.Agent.bpew File: C:\Qoobox\Quarantine\C\WINDOWS\system32\tpszxyd.sys.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/10.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/11.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/12.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/15.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/16.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/17.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/18.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/1A.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/1B.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/24.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/25.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/2C.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/2D.tmp
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:26:45, on 03/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Wireless LAN Utility\TIWLANCu.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wireless LAN Utility\tiwlnsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TI WLAN] C:\Program Files\Wireless LAN Utility\TIWLANCu.exe
O4 - HKLM\..\Run: [WheelMouse] C:\Advanced Wheel Mouse\wh_exec.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1229158219187
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229160138828
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avg8wd - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: TI Wlan Service (tiwlnsvc) - Unknown owner - C:\Program Files\Wireless LAN Utility\tiwlnsvc.exe
–
End of file - 6349 bytes
Shaun