This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijack This Logfile

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I use Google search and click on a result I get a random page of anything but what I want. I then click the back arrow and my correct page shows. My Windows XP is up to date. I have ran Spyware Doctor, Malwarebytes Anti-Malware, Ad-Aware and AVG Internet Security. Could you help me? Thanks Here is my log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:51:48 AM, on 4/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
G:\Dad\PrfldSvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dad\My Documents\Password Agent\PwAgent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1454471165-1563985344-725345543-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Mom')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1229815666593
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…=javadl.sun.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - G:\Dad\PrfldSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 8472 bytes
Hi,

Did MalwareBytes' find anything?

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
Thanks for your response. Malwarebytes didn't find anything, I can't open your link to DDS, don't know why. MY Internet Explorer doesn't seem to open it. How do I disable script blocking?
Hi,

I don't think script blocking is the issue here.

Please download OTViewIt and save it to your Desktop.
  • Double-click OTViewIt to run it.
  • Click Run Scan to beginning scanning.
  • OTViewIt will now scan your system. When it finishes, two logs will open in notepad windows.
  • Please post the contents of OTViewIt.txt in your next reply.
  • Please attach the Extras.txt report to your next reply.
Thanks.
OTViewIt logfile created on: 4/16/2009 12:12:31 AM - Run 2
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Dad\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.77 Gb Available Physical Memory | 61.97% Memory free
2.98 Gb Paging File | 2.33 Gb Available in Paging File | 78.28% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 113.17 Gb Free Space | 75.93% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465.76 Gb Total Space | 390.74 Gb Free Space | 83.89% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAIN
Current User Name: Dad
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2009/03/25 23:18:53 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
[2009/03/25 23:18:56 | 01,356,616 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgfws8.exe
[1999/12/13 02:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTSVCCDA.EXE
[2009/01/17 15:10:29 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
[2004/02/04 11:37:00 | 00,077,824 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
[2004/09/29 13:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
[2009/03/19 23:35:15 | 00,066,872 | —- | M] () – C:\WINDOWS\system32\PnkBstrA.exe
[2006/04/21 22:06:14 | 00,069,632 | —- | M] () – G:\Dad\PrfldSvc.exe
[2009/03/25 23:19:10 | 00,832,792 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgam.exe
[2009/03/25 23:19:16 | 00,485,144 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
[2009/01/07 13:40:56 | 00,348,752 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe
[2009/03/25 23:18:58 | 00,593,176 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
[2009/01/21 14:08:06 | 01,095,560 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe
[2009/03/25 23:18:59 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
[2009/03/25 23:19:16 | 00,691,992 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
[2009/03/25 23:19:06 | 01,932,568 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
[2008/12/08 14:33:48 | 01,173,384 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsTray.exe
[2008/12/19 01:25:25 | 00,634,024 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
[2009/04/16 00:10:18 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2008/12/27 01:29:04 | 00,072,704 | —- | M] (Adobe Systems) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe – (Adobe LM Service [On_Demand | Stopped])
[2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
[2009/03/25 23:18:59 | 00,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
[2009/03/25 23:18:53 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
[2009/03/25 23:18:56 | 01,356,616 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgfws8.exe – (avgfws8 [Auto | Running])
[2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[1999/12/13 02:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTSVCCDA.EXE – (Creative Service for CDROM Access [Auto | Running])
[2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
[2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
[2009/01/17 15:10:29 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
[2003/03/03 14:33:40 | 00,143,360 | —- | M] (Intel® Corporation) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc [On_Demand | Stopped])
[2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
[2004/02/04 11:37:00 | 00,077,824 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc [Auto | Running])
[2004/09/29 13:14:36 | 00,069,632 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12 [Auto | Running])
[2009/03/19 23:35:15 | 00,066,872 | —- | M] () – C:\WINDOWS\system32\PnkBstrA.exe – (PnkBstrA [Auto | Running])
[2006/04/21 22:06:14 | 00,069,632 | —- | M] () – G:\Dad\PrfldSvc.exe – (prfldsvc [Auto | Running])
[2009/01/07 13:40:56 | 00,348,752 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsAuxs.exe – (sdAuxService [Auto | Running])
[2009/01/21 14:08:06 | 01,095,560 | —- | M] (PC Tools) – C:\Program Files\Spyware Doctor\pctsSvc.exe – (sdCoreService [Auto | Running])
[2006/10/18 21:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services ==========

[2008/12/26 22:29:51 | 00,029,208 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgfwdx.sys – (Avgfwdx [On_Demand | Running])
[2008/12/26 22:29:51 | 00,029,208 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgfwdx.sys – (Avgfwfd [On_Demand | Stopped])
[2009/03/25 23:19:16 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgldx86.sys – (AvgLdx86 [System | Running])
[2009/01/08 15:17:04 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
[2009/01/08 15:17:01 | 00,012,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgrkx86.sys – (AvgRkx86 [Boot | Running])
[2009/03/25 23:19:04 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgtdix.sys – (AvgTdiX [System | Running])
[2003/02/20 18:22:38 | 00,135,040 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctac32k.sys – (ctac32k [On_Demand | Running])
[2003/03/26 17:33:58 | 00,498,688 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctaud2k.sys – (ctaud2k [On_Demand | Running])
[2003/03/27 12:58:56 | 00,287,920 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctdvda2k.sys – (ctdvda2k [On_Demand | Stopped])
[2003/02/20 18:24:18 | 00,006,144 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctprxy2k.sys – (ctprxy2k [On_Demand | Running])
[2003/02/20 18:24:34 | 00,135,248 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k [On_Demand | Running])
[2003/03/04 12:56:26 | 00,145,408 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\drivers\e100b325.sys – (E100B [On_Demand | Running])
[2003/02/20 18:24:46 | 00,116,000 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\emupia2k.sys – (emupia [On_Demand | Running])
[2003/03/26 17:31:40 | 00,823,616 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\ha10kx2k.sys – (ha10kx2k [On_Demand | Running])
[2003/03/26 17:32:02 | 00,141,536 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\drivers\hap16v2k.sys – (hap16v2k [On_Demand | Running])
[2005/03/08 00:52:26 | 00,051,120 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZid412.sys – (HPZid412 [On_Demand | Stopped])
[2005/03/08 00:52:27 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZipr12.sys – (HPZipr12 [On_Demand | Stopped])
[2005/03/08 00:52:28 | 00,021,744 | R— | M] (HP) – C:\WINDOWS\system32\drivers\HPZius12.sys – (HPZius12 [On_Demand | Stopped])
[2004/02/04 11:37:00 | 01,878,432 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv [On_Demand | Running])
[2001/08/22 09:42:58 | 00,013,632 | —- | M] (Dell Computer Corporation) – C:\WINDOWS\system32\drivers\omci.sys – (OMCI [System | Running])
[2003/03/26 17:32:32 | 00,189,504 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv [On_Demand | Running])
[2009/03/06 16:45:06 | 00,130,424 | —- | M] (PC Tools) – C:\WINDOWS\system32\drivers\PCTCore.sys – (PCTCore [Boot | Running])
[2003/03/06 11:10:34 | 00,015,840 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\system32\drivers\pfmodnt.sys – (PfModNT [Auto | Running])
[2006/04/21 09:22:24 | 00,070,912 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\drivers\prvflder.sys – (Prvflder [Auto | Running])
[2003/07/16 16:42:18 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink [On_Demand | Running])
[2008/11/06 12:37:28 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\drivers\pxhelp20.sys – (PxHelp20 [Boot | Running])
[2008/04/13 12:39:15 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv [On_Demand | Stopped])
[2008/04/13 14:45:12 | 00,060,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio [On_Demand | Running])
[2008/04/13 14:46:20 | 00,121,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\usbvideo.sys – (usbvideo [On_Demand | Stopped])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.com/

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries…
127.0.0.1 localhost

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) – C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} (HKLM) – C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (HKLM) – C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) – C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{AE7CD045-E861-484f-8273-0445EE161910} (HKLM) – C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} (HKLM) – C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) – C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (HKLM) – C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

========== (O3) Toolbars ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414}" (HKLM) – C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) – C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) – C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" (HKLM) – Reg Error: Key does not exist or could not be opened. File not found

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsioReg"=REGSVR32.EXE /S CTASIO.DLL (Microsoft Corporation)
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" (PC Tools)
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"UpdReg"=C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
"UserFaultCheck"=%systemroot%\system32\dumprep 0 -u File not found

========== (O4) Startup Folders ==========


========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
&D&ownload &with BitComet: C:\Program Files\BitComet\BitComet.exe [2008/12/03 06:11:42 | 02,514,744 | —- | M] (www.BitComet.com)
&D&ownload all video with BitComet: C:\Program Files\BitComet\BitComet.exe [2008/12/03 06:11:42 | 02,514,744 | —- | M] (www.BitComet.com)
&D&ownload all with BitComet: C:\Program Files\BitComet\BitComet.exe [2008/12/03 06:11:42 | 02,514,744 | —- | M] (www.BitComet.com)
Convert link target to Adobe PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert link target to existing PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert selected links to Adobe PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert selected links to existing PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert selection to Adobe PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert selection to existing PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert to Adobe PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
Convert to existing PDF: C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006/12/18 05:18:14 | 00,231,160 | —- | M] (Adobe Systems Incorporated)
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [2001/02/16 02:05:38 | 09,164,192 | R— | M] (Microsoft Corporation)

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A}: Button: BitComet – %ProgramFiles%\BitComet\tools\BitCometBHO_1.2.8.7.dll [2008/08/11 04:12:14 | 00,656,696 | —- | M] (BitComet)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 – %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 14:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger – %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger – %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | —- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find…=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
: msn in My Computer

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{6414512B-B978-451D-A0D8-FCFDF33E833C}: http://www.update.microsoft.com/windowsupd…b?1229815666593 – WUWebControl Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…=javadl.sun.com – Java Plug-in 1.6.0_11
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab – Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab – Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab – Shockwave Flash Object

========== (O17) DNS Name Servers ==========

{5F626E98-A6DD-4AD8-A787-5EC00921F05D} (Servers: | Description: Intel® PRO/100 VE Network Connection)
{D40E7502-BF13-485A-A048-A9B562C71BA4} (Servers: | Description: )
{E11F8FCE-2960-4377-9ABA-69323650A802} (Servers: | Description: 1394 Net Adapter)

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
avgrsstarter: "DllName" = avgrsstx.dll – C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2008/12/20 18:12:44 | 00,000,000 | —- | M] () – C:\AUTOEXEC.BAT – [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/16 00:10:14 | 00,422,912 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTViewIt.exe
[2009/04/14 22:44:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\My Albums
[2009/04/14 00:16:48 | 00,007,168 | -HS- | C] () – C:\WINDOWS\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
[2009/04/13 02:03:17 | 00,000,317 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Correct Webpages Not Opening.url
@Alternate Data Stream - 3638 bytes -> C:\Documents and Settings\Dad\Desktop\Correct Webpages Not Opening.url:favicon
[2009/04/13 01:51:34 | 00,001,740 | —- | C] () – C:\Documents and Settings\Dad\Desktop\HijackThis.lnk
[2009/04/13 01:51:33 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/11 23:24:01 | 00,000,166 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Auto-mo-brella by GTM Products, LLC,.url
[2009/04/11 23:17:19 | 00,000,322 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Trailer Hitch Umbrella.url
@Alternate Data Stream - 6598 bytes -> C:\Documents and Settings\Dad\Desktop\Trailer Hitch Umbrella.url:favicon
[2009/04/08 18:36:53 | 00,024,576 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Tail light.doc
[2009/04/07 19:33:27 | 00,000,358 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Xshade hitchmount canopy. - Toyota FJ Cruiser Forum.url
@Alternate Data Stream - 4286 bytes -> C:\Documents and Settings\Dad\Desktop\Xshade hitchmount canopy. - Toyota FJ Cruiser Forum.url:favicon
[2009/04/06 20:21:21 | 00,048,064 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Email-Sms.mp3
[2009/04/03 18:58:04 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/04/02 23:15:25 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
[2009/04/02 23:13:27 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/04/02 23:13:23 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/04/02 23:13:15 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/04/02 23:12:13 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/04/02 23:12:13 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/04/02 23:12:13 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/04/02 23:12:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/04/02 23:12:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/04/02 23:12:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/04/02 23:12:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/04/02 23:05:53 | 00,000,000 | RH-D | C] – C:\AHCache
[2009/04/02 22:59:59 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
[2009/04/02 22:55:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\Uniblue 2009 (SpeedUpMyPC + RegistryBooster + DriverScanner){H33T}{JOHNCANADUDE}
[2009/04/02 22:48:53 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\Uniblue
[2009/03/31 23:45:13 | 00,332,276 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Nitro_Circus.mp3
[2009/03/31 23:40:53 | 00,104,906 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Cool_One.mp3
[2009/03/31 23:39:15 | 00,046,854 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Soft_Alert.mp3
[2009/03/31 23:38:20 | 00,034,316 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Nova.mp3
[2009/03/31 22:31:36 | 00,159,600 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2009/03/31 22:31:20 | 00,130,424 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2009/03/31 22:31:20 | 00,073,840 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2009/03/31 22:31:09 | 00,001,637 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/03/31 22:31:07 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2009/03/31 22:31:06 | 00,064,392 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2009/03/31 22:31:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2009/03/29 17:02:12 | 00,395,264 | —- | C] () – C:\Documents and Settings\All Users\Documents\Wenonah 1.doc
[2009/03/29 14:28:18 | 00,395,264 | —- | C] () – C:\Documents and Settings\All Users\Documents\Wenonah.doc
[2009/03/29 14:28:04 | 00,395,264 | —- | C] () – C:\Documents and Settings\All Users\Documents\Wenonah 2.doc
[2009/03/28 15:00:03 | 00,024,064 | —- | C] () – C:\Documents and Settings\All Users\Documents\Canoe For Sale.doc
[2009/03/28 12:51:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\iWin
[2009/03/28 00:24:20 | 00,022,952 | —- | C] () – C:\Documents and Settings\Dad\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/27 23:46:41 | 00,352,256 | —- | C] () – C:\Documents and Settings\Dad\My Documents\SWINGARM Parts.doc
[2009/03/27 22:33:35 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/03/27 22:33:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Mozilla
[2009/03/27 22:33:29 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\Mozilla
[2009/03/27 22:33:12 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/03/26 13:03:16 | 00,278,528 | —- | C] (Real Networks, Inc) – C:\WINDOWS\System32\pncrt.dll
[2009/03/26 13:03:14 | 00,000,000 | —D | C] – C:\Program Files\Real Alternative
[2009/03/26 13:03:14 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Real
[2009/03/26 13:03:14 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\Real
[2009/03/26 13:03:14 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Real
[2009/03/25 23:16:45 | 00,000,000 | —D | C] – C:\WINDOWS\Minidump
[2009/03/19 23:37:12 | 00,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/19 23:37:06 | 00,103,736 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/03/19 23:35:15 | 00,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/16 00:10:18 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTViewIt.exe
[2009/04/16 00:05:39 | 00,003,733 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/04/15 19:33:44 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/15 19:33:42 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/15 00:02:34 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/15 00:02:34 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/15 00:02:34 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/15 00:02:34 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2009/04/15 00:02:34 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/04/15 00:02:34 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/04/15 00:02:34 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2009/04/15 00:02:33 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2009/04/14 23:39:02 | 00,028,160 | —- | M] () – C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/14 00:21:04 | 00,000,322 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Trailer Hitch Umbrella.url
@Alternate Data Stream - 6598 bytes -> C:\Documents and Settings\Dad\Desktop\Trailer Hitch Umbrella.url:favicon
[2009/04/14 00:16:48 | 00,007,168 | -HS- | M] () – C:\WINDOWS\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\WINDOWS\Thumbs.db:encryptable
[2009/04/14 00:15:56 | 00,013,312 | -HS- | M] () – C:\Documents and Settings\Dad\Desktop\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Dad\Desktop\Thumbs.db:encryptable
[2009/04/14 00:15:02 | 00,000,474 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Shared Documents.lnk
[2009/04/14 00:13:22 | 00,000,358 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Xshade hitchmount canopy. - Toyota FJ Cruiser Forum.url
@Alternate Data Stream - 4286 bytes -> C:\Documents and Settings\Dad\Desktop\Xshade hitchmount canopy. - Toyota FJ Cruiser Forum.url:favicon
[2009/04/14 00:10:18 | 00,000,166 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Auto-mo-brella by GTM Products, LLC,.url
[2009/04/13 23:27:45 | 00,000,317 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Correct Webpages Not Opening.url
@Alternate Data Stream - 3638 bytes -> C:\Documents and Settings\Dad\Desktop\Correct Webpages Not Opening.url:favicon
[2009/04/13 16:52:33 | 00,521,942 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/13 16:52:33 | 00,441,124 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/13 16:52:33 | 00,071,060 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/13 01:51:34 | 00,001,740 | —- | M] () – C:\Documents and Settings\Dad\Desktop\HijackThis.lnk
[2009/04/12 06:52:55 | 00,000,010 | —- | M] () – C:\WINDOWS\popcinfo.dat
[2009/04/11 09:40:24 | 35,043,589 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/04/11 09:40:24 | 00,093,132 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/04/08 20:30:00 | 00,000,601 | —- | M] () – C:\WINDOWS\win.ini
[2009/04/08 20:30:00 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/08 20:30:00 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/04/08 18:36:54 | 00,024,576 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Tail light.doc
[2009/04/07 18:23:54 | 00,024,576 | —- | M] () – C:\Documents and Settings\Dad\My Documents\You are bidding on a like new 2006 Bob Long Alias.doc
[2009/04/06 20:21:22 | 00,048,064 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Email-Sms.mp3
[2009/04/02 23:18:50 | 00,022,952 | —- | M] () – C:\Documents and Settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/02 23:16:52 | 00,126,112 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/01 00:39:50 | 00,046,854 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Soft_Alert.mp3
[2009/04/01 00:13:24 | 00,034,316 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Nova.mp3
[2009/03/31 23:45:13 | 00,332,276 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Nitro_Circus.mp3
[2009/03/31 23:40:53 | 00,104,906 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Cool_One.mp3
[2009/03/31 22:35:16 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/31 22:31:09 | 00,001,637 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/03/29 17:02:12 | 00,395,264 | —- | M] () – C:\Documents and Settings\All Users\Documents\Wenonah 1.doc
[2009/03/29 14:28:19 | 00,395,264 | —- | M] () – C:\Documents and Settings\All Users\Documents\Wenonah.doc
[2009/03/29 14:28:04 | 00,395,264 | —- | M] () – C:\Documents and Settings\All Users\Documents\Wenonah 2.doc
[2009/03/28 15:00:04 | 00,024,064 | —- | M] () – C:\Documents and Settings\All Users\Documents\Canoe For Sale.doc
[2009/03/28 00:24:20 | 00,022,952 | —- | M] () – C:\Documents and Settings\Dad\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/27 23:46:41 | 00,352,256 | —- | M] () – C:\Documents and Settings\Dad\My Documents\SWINGARM Parts.doc
[2009/03/27 22:33:35 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/03/25 23:19:17 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/03/25 23:19:16 | 00,325,640 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/03/25 23:19:04 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/03/22 11:28:42 | 00,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2009/03/20 22:15:58 | 00,022,328 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/20 22:15:51 | 00,103,736 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/03/19 23:35:15 | 00,066,872 | —- | M] () – C:\WINDOWS\System32\PnkBstrA.exe
< End of report >

Attachments:

Hi,

Please download DaonolFix from the link below and save it to your Desktop
Download Mirror #1
  • Double-click DaonolFix.exe to run it.
  • Select 1. Find Daonol (no fix) by typing 1 and pressing Enter.
  • You will see a lot of files being listed - don't worry, they are just being scanned.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called DaonolFix.txt).

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

Thanks.
DaonolFix (15.04.09) by jpshortstuff
Log created at 20:32 on 16/04/2009 by Dad
Running from C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\7W4VB4I2\DaonolFix[1].exe

=====Find Daonol=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"aux"="wdmaud.drv"
"aux2"="C:\WINDOWS\system32\..\oxqh.gfx"
"midi"="wdmaud.drv"
"midi1"="wdmaud.drv"
"midimapper"="midimap.dll"
"mixer"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"msacm.iac2"="iac25_32.ax"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.l3acm"="C:\WINDOWS\System32\l3codeca.acm"
"msacm.msadpcm"="msadp32.acm"
"msacm.msaudio1"="msaud32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msg723"="msg723.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.sl_anet"="sl_anet.acm"
"msacm.trspch"="tssoft32.acm"
"MSVideo8"="VfWWDM32.dll"
"vidc.cvid"="iccvid.dll"
"vidc.DIVX"="DivX.dll"
"VIDC.DVSD"="pdvcodec.dll"
"VIDC.I420"="msh263.drv"
"vidc.iv31"="ir32_32.dll"
"vidc.iv32"="ir32_32.dll"
"vidc.iv41"="ir41_32.ax"
"vidc.iv50"="ir50_32.dll"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.LEAD"="LCODCCMP.DLL"
"vidc.M261"="msh261.drv"
"vidc.M263"="msh263.drv"
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"vidc.yv12"="DivX.dll"
"VIDC.YVU9"="tsbyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"wave"="wdmaud.drv"
"wave1"="wdmaud.drv"
"wavemapper"="msacm32.drv"

-=Daonol Files=-
(none found)

-=End Of File
GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-04-18 09:48:29
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF7483506]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF7472240]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF7472432]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF7483CC8]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF7483F88]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF74823EC]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF74843EC]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF74837B8]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF7471EF0]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu@ CmdLineContextMenu Class
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu\CLSID
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu\CLSID@ {9869EFB4-18E9-11D3-A837-00104B9E30B5}
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu\CurVer
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu\CurVer@ CmdLineExt.CmdLineContextMenu.1
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu.1@ CmdLineContextMenu Class
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu.1\CLSID
Reg HKLM\SOFTWARE\Classes\CmdLineExt.CmdLineContextMenu.1\CLSID@ {9869EFB4-18E9-11D3-A837-00104B9E30B5}
Reg HKLM\SOFTWARE\Classes\steam@ URL:steam protocol
Reg HKLM\SOFTWARE\Classes\steam@URL Protocol
Reg HKLM\SOFTWARE\Classes\steam\DefaultIcon
Reg HKLM\SOFTWARE\Classes\steam\DefaultIcon@ steam.exe
Reg HKLM\SOFTWARE\Classes\steam\Shell
Reg HKLM\SOFTWARE\Classes\steam\Shell\Open
Reg HKLM\SOFTWARE\Classes\steam\Shell\Open\Command
Reg HKLM\SOFTWARE\Classes\steam\Shell\Open\Command@ "G:\Program Files\Valve\Steam\steam.exe" "%1"
Reg HKLM\SOFTWARE\Classes\Valve.SteamP2P\shell
Reg HKLM\SOFTWARE\Classes\Valve.SteamP2P\shell\open
Reg HKLM\SOFTWARE\Classes\Valve.SteamP2P\shell\open\command
Reg HKLM\SOFTWARE\Classes\Valve.SteamP2P\shell\open\command@ "g:\program files\valve\steam\steam.exe" "%1"

—- EOF - GMER 1.0.15 —-
Bingo, found the problem.

Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Please open the AVG Control Center program, by right clicking on the AVG 8 icon on task bar.
  • Click on Tools.
  • Select Advanced.
  • In the left hand pane, scroll down to "Resident Shield".
  • In the main pane, deselect the option to "Enable Resident Shield".
    To re-enable AVG 8, select "Enable Resident Shield" again.
Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 09-04-20.02 - Dad 04/20/2009 1:26.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.775 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Internet Security 3-pack *On-access scanning disabled* (Updated)
FW: AVG Firewall *enabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-03-20 to 2009-04-20 )))))))))))))))))))))))))))))))
.

2009-04-19 02:36 . 2009-04-19 02:36 140 —-a-w c:\windows\RealFlight.INI
2009-04-16 22:07 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-16 22:07 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 22:07 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-16 22:07 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 22:07 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 22:07 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 22:07 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 22:07 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 22:07 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 22:07 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 22:07 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 22:07 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 21:15 . 2009-04-14 21:15 ——– d—–w c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
2009-04-14 04:16 . 2009-04-14 04:16 7168 –sha-w c:\windows\Thumbs.db
2009-04-12 04:48 . 2009-04-12 04:48 ——– d—–w c:\documents and settings\Buddy\Application Data\uniblue
2009-04-12 04:45 . 2009-04-12 04:45 ——– d—–w c:\documents and settings\Mom\Application Data\uniblue
2009-04-03 22:58 . 2009-01-09 19:19 1089593 -c—-w c:\windows\system32\dllcache\ntprint.cat
2009-04-03 03:15 . 2009-04-03 03:19 ——– dc-h–w c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2009-04-03 03:14 . 2009-04-03 04:26 77872 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-03 03:13 . 2009-04-03 03:13 ——– d—–w c:\windows\system32\XPSViewer
2009-04-03 03:12 . 2008-07-06 12:06 89088 -c—-w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-03 03:12 . 2008-07-06 12:06 117760 ——w c:\windows\system32\prntvpt.dll
2009-04-03 03:12 . 2008-07-06 10:50 597504 -c—-w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-03 03:12 . 2008-07-06 12:06 575488 -c—-w c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-03 03:12 . 2008-07-06 12:06 575488 ——w c:\windows\system32\xpsshhdr.dll
2009-04-03 03:12 . 2008-07-06 12:06 1676288 -c—-w c:\windows\system32\dllcache\xpssvcs.dll
2009-04-03 03:12 . 2008-07-06 12:06 1676288 ——w c:\windows\system32\xpssvcs.dll
2009-04-03 03:05 . 2009-04-03 03:05 ——– d–h–r C:\AHCache
2009-04-03 02:59 . 2009-04-03 03:00 ——– dc-h–w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-04-03 02:48 . 2009-04-03 03:23 ——– d—–w c:\documents and settings\Dad\Application Data\Uniblue
2009-04-01 02:31 . 2008-12-11 12:38 159600 —-a-w c:\windows\system32\drivers\pctgntdi.sys
2009-04-01 02:31 . 2009-03-06 20:45 130424 —-a-w c:\windows\system32\drivers\PCTCore.sys
2009-04-01 02:31 . 2008-12-18 16:16 73840 —-a-w c:\windows\system32\drivers\PCTAppEvent.sys
2009-04-01 02:31 . 2008-12-10 16:36 64392 —-a-w c:\windows\system32\drivers\pctplsg.sys
2009-04-01 02:31 . 2009-04-01 02:31 ——– d—–w c:\documents and settings\All Users\Application Data\PC Tools
2009-03-28 16:51 . 2009-03-28 16:51 ——– d—–w c:\documents and settings\Dad\Application Data\iWin
2009-03-28 04:24 . 2009-03-28 04:24 22952 —-a-w c:\documents and settings\Dad\Application Data\GDIPFONTCACHEV1.DAT
2009-03-28 02:33 . 2009-03-28 02:33 0 —-a-w c:\windows\nsreg.dat
2009-03-28 02:33 . 2009-03-28 02:33 ——– d—–w c:\documents and settings\Dad\Local Settings\Application Data\Mozilla
2009-03-27 12:23 . 2009-03-27 12:23 ——– d—–w c:\documents and settings\LocalService\Application Data\Intuit
2009-03-26 17:03 . 2009-03-26 17:03 ——– d—–w c:\documents and settings\Dad\Local Settings\Application Data\Real
2009-03-21 14:06 . 2009-03-21 14:06 989696 -c—-w c:\windows\system32\dllcache\kernel32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-20 05:11 . 2009-04-19 02:20 ——– d—–w c:\program files\RealFlightG3
2009-04-20 04:11 . 2009-04-19 02:20 ——– d—–w c:\program files\Common Files\KnifeEdge
2009-04-19 02:19 . 2009-04-19 02:19 434 —-a-w C:\KEError log 04-18-2009 (22h19m31s).txt
2009-04-17 00:37 . 2009-01-05 21:35 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-17 00:36 . 2009-01-05 21:34 ——– d—–w c:\program files\Spyware Doctor
2009-04-14 04:14 . 2009-01-04 22:02 ——– d—–w c:\program files\BitComet
2009-04-13 05:51 . 2009-04-13 05:51 ——– d—–w c:\program files\Trend Micro
2009-04-12 21:18 . 2008-12-21 00:54 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-04 13:40 . 2009-01-03 13:26 ——– d—–w c:\program files\Quicken
2009-04-03 09:43 . 2008-12-25 11:35 22952 —-a-w c:\documents and settings\Mom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-03 03:26 . 2009-02-04 05:06 ——– d—–w c:\documents and settings\Dad\Application Data\Simple Sudoku
2009-04-03 03:18 . 2008-12-21 00:15 22952 —-a-w c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-03 03:13 . 2009-04-03 03:13 ——– d—–w c:\program files\MSBuild
2009-04-03 03:13 . 2009-04-03 03:13 ——– d—–w c:\program files\Reference Assemblies
2009-04-01 02:33 . 2009-04-01 02:31 ——– d—–w c:\program files\Common Files\PC Tools
2009-03-28 19:19 . 2009-01-12 16:49 ——– d—–w c:\documents and settings\Dad\Application Data\Move Networks
2009-03-26 17:03 . 2009-03-26 17:03 ——– d—–w c:\program files\Real Alternative
2009-03-26 03:19 . 2008-12-21 00:54 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-03-26 03:19 . 2008-12-21 00:54 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-26 03:19 . 2008-12-21 00:54 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-03-22 15:28 . 2009-03-11 23:21 43520 —-a-w c:\windows\system32\CmdLineExt03.dll
2009-03-21 02:15 . 2009-03-20 03:37 22328 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-03-21 02:15 . 2009-03-20 03:37 103736 —-a-w c:\windows\system32\PnkBstrB.exe
2009-03-20 03:35 . 2009-03-20 03:35 66872 —-a-w c:\windows\system32\PnkBstrA.exe
2009-03-17 13:05 . 2009-01-02 21:39 7880 —-a-w C:\DSpoof.txt
2009-03-15 15:57 . 2009-03-15 15:57 ——– d—–w c:\documents and settings\Buddy\Application Data\GRETECH
2009-03-14 00:04 . 2009-03-14 00:04 ——– d—–w c:\documents and settings\Mom\Application Data\HP
2009-03-13 15:08 . 2009-03-13 15:08 ——– d—–w c:\documents and settings\All Users\Application Data\Panasonic
2009-03-13 15:06 . 2009-03-13 15:06 ——– d—–w c:\program files\Common Files\Panasonic
2009-03-13 15:06 . 2009-03-13 15:06 ——– d—–w c:\program files\Panasonic
2009-03-13 15:06 . 2008-12-20 22:34 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-13 14:31 . 2009-03-13 14:31 ——– d—–w c:\documents and settings\Dad\Application Data\GRETECH
2009-03-13 14:31 . 2009-03-13 14:31 ——– d—–w c:\program files\GRETECH
2009-03-11 23:22 . 2009-03-11 23:22 ——– d—–w c:\documents and settings\Buddy\Application Data\Atari
2009-03-06 14:22 . 2003-07-16 20:41 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 21:10 . 2009-03-03 21:10 ——– d—–w c:\documents and settings\Buddy\Application Data\AdobeUM
2009-03-03 00:18 . 2006-06-23 16:33 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-26 17:01 . 2009-02-26 17:01 ——– d—–w c:\documents and settings\Buddy\Application Data\DivX
2009-02-26 17:00 . 2009-02-26 17:00 ——– d—–w c:\documents and settings\Mom\Application Data\DivX
2009-02-24 04:07 . 2009-01-20 04:49 ——– d—–w c:\documents and settings\Dad\Application Data\AdobeUM
2009-02-24 04:02 . 2008-12-27 05:27 ——– d—–w c:\program files\Common Files\Adobe
2009-02-22 18:13 . 2009-01-31 16:06 ——– d—–w c:\program files\TaxCut08
2009-02-21 21:52 . 2009-02-21 21:52 ——– d—–w c:\documents and settings\All Users\Application Data\PlayPond
2009-02-20 18:09 . 2004-08-04 07:56 78336 ——w c:\windows\system32\ieencode.dll
2009-02-19 20:50 . 2009-01-05 19:44 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-14 16:07 . 2008-12-27 02:27 22952 —-a-w c:\documents and settings\Buddy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-09 12:10 . 2003-07-16 20:32 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2005-07-26 04:31 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2003-07-16 20:39 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2003-07-16 20:23 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2003-07-16 20:51 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2003-07-16 20:44 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2003-07-16 20:39 2145280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2003-07-16 20:43 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2002-08-29 01:04 2023936 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2003-07-16 20:44 56832 —-a-w c:\windows\system32\secur32.dll
2009-02-02 15:19 . 2009-02-02 15:19 128 —-a-w c:\documents and settings\Buddy\Local Settings\Application Data\fusioncache.dat
2009-01-31 17:52 . 2009-01-31 17:52 51716 —-a-w c:\windows\system32\pdf995mon.dll
2009-01-31 17:52 . 2009-01-31 17:52 249856 —-a-w c:\windows\system32\pdfmona.dll
2009-01-22 01:47 . 2009-01-22 01:47 22560 —-a-w c:\documents and settings\Mom\Application Data\GDIPFONTCACHEV1.DAT
2008-12-31 15:35 . 2008-12-31 15:35 126 —-a-w c:\documents and settings\Dad\Local Settings\Application Data\fusioncache.dat
2008-12-27 11:57 . 2008-12-27 11:57 126 —-a-w c:\documents and settings\Mom\Local Settings\Application Data\fusioncache.dat
2008-11-30 23:06 . 2009-01-02 16:13 26163360 —-a-w c:\documents and settings\All Users\BoggleSetup.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-26 1932568]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-02-04 2899968]
"AsioReg"="CTASIO.DLL" - c:\windows\system32\CTASIO.DLL [2003-02-20 110592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-26 03:19 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\RealFlightG3\\RealFlight.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25422:TCP"= 25422:TCP:BitComet 25422 TCP
"25422:UDP"= 25422:UDP:BitComet 25422 UDP

R3 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwdx.sys [2008-12-27 29208]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-07 348752]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2009-01-08 12552]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-06 130424]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-26 325640]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-03-26 108552]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-26 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-26 298264]
S2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [2009-03-26 1356616]
S2 Prvflder;Prvflder;c:\windows\system32\DRIVERS\prvflder.sys [2006-04-21 70912]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\DRIVERS\avgfwdx.sys [2008-12-27 29208]


— Other Services/Drivers In Memory —

*Deregistered* - aujasnkj
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-20 01:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1176)
g:\dad\ShellExt.dll
c:\windows\system32\PFLib.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-04-20 1:31
ComboFix-quarantined-files.txt 2009-04-20 05:31

Pre-Run: 135,642,046,464 bytes free
Post-Run: 135,765,278,720 bytes free

229 — E O F — 2009-04-16 22:56



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:34:56 AM, on 4/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
G:\Dad\PrfldSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1454471165-1563985344-725345543-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Mom')
O4 - HKUS\S-1-5-21-1454471165-1563985344-725345543-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Buddy')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1229815666593
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…=javadl.sun.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - G:\Dad\PrfldSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 8114 bytes
Hi,

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\oxqh.gfx

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"aux2"=-

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Let me know how things are running. Still getting redirects?
Thank-You you guys are the best, that seems to have done the trick. What was the problem so as I know not to do it again. Once again, Thanks—Buddy

ComboFix 09-04-20.02 - Dad 04/20/2009 11:16.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.826 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dad\Desktop\CFScript.txt
AV: AVG Internet Security 3-pack *On-access scanning disabled* (Updated)
FW: AVG Firewall *enabled*
* Created a new restore point

FILE ::
c:\windows\oxqh.gfx
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\oxqh.gfx

.
((((((((((((((((((((((((( Files Created from 2009-03-20 to 2009-04-20 )))))))))))))))))))))))))))))))
.

2009-04-19 02:36 . 2009-04-19 02:36 140 —-a-w c:\windows\RealFlight.INI
2009-04-16 22:07 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-16 22:07 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 22:07 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-16 22:07 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 22:07 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 22:07 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 22:07 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 22:07 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 22:07 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 22:07 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 22:07 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 22:07 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 21:15 . 2009-04-14 21:15 ——– d—–w c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
2009-04-14 04:16 . 2009-04-14 04:16 7168 –sha-w c:\windows\Thumbs.db
2009-04-12 04:48 . 2009-04-12 04:48 ——– d—–w c:\documents and settings\Buddy\Application Data\uniblue
2009-04-12 04:45 . 2009-04-12 04:45 ——– d—–w c:\documents and settings\Mom\Application Data\uniblue
2009-04-03 22:58 . 2009-01-09 19:19 1089593 -c—-w c:\windows\system32\dllcache\ntprint.cat
2009-04-03 03:15 . 2009-04-03 03:19 ——– dc-h–w c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2009-04-03 03:14 . 2009-04-03 04:26 77872 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-03 03:13 . 2009-04-03 03:13 ——– d—–w c:\windows\system32\XPSViewer
2009-04-03 03:12 . 2008-07-06 12:06 89088 -c—-w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-03 03:12 . 2008-07-06 12:06 117760 ——w c:\windows\system32\prntvpt.dll
2009-04-03 03:12 . 2008-07-06 10:50 597504 -c—-w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-03 03:12 . 2008-07-06 12:06 575488 -c—-w c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-03 03:12 . 2008-07-06 12:06 575488 ——w c:\windows\system32\xpsshhdr.dll
2009-04-03 03:12 . 2008-07-06 12:06 1676288 -c—-w c:\windows\system32\dllcache\xpssvcs.dll
2009-04-03 03:12 . 2008-07-06 12:06 1676288 ——w c:\windows\system32\xpssvcs.dll
2009-04-03 03:05 . 2009-04-03 03:05 ——– d–h–r C:\AHCache
2009-04-03 02:59 . 2009-04-03 03:00 ——– dc-h–w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-04-03 02:48 . 2009-04-03 03:23 ——– d—–w c:\documents and settings\Dad\Application Data\Uniblue
2009-04-01 02:31 . 2008-12-11 12:38 159600 —-a-w c:\windows\system32\drivers\pctgntdi.sys
2009-04-01 02:31 . 2009-03-06 20:45 130424 —-a-w c:\windows\system32\drivers\PCTCore.sys
2009-04-01 02:31 . 2008-12-18 16:16 73840 —-a-w c:\windows\system32\drivers\PCTAppEvent.sys
2009-04-01 02:31 . 2008-12-10 16:36 64392 —-a-w c:\windows\system32\drivers\pctplsg.sys
2009-04-01 02:31 . 2009-04-01 02:31 ——– d—–w c:\documents and settings\All Users\Application Data\PC Tools
2009-03-28 16:51 . 2009-03-28 16:51 ——– d—–w c:\documents and settings\Dad\Application Data\iWin
2009-03-28 04:24 . 2009-03-28 04:24 22952 —-a-w c:\documents and settings\Dad\Application Data\GDIPFONTCACHEV1.DAT
2009-03-28 02:33 . 2009-03-28 02:33 0 —-a-w c:\windows\nsreg.dat
2009-03-28 02:33 . 2009-03-28 02:33 ——– d—–w c:\documents and settings\Dad\Local Settings\Application Data\Mozilla
2009-03-27 12:23 . 2009-03-27 12:23 ——– d—–w c:\documents and settings\LocalService\Application Data\Intuit
2009-03-26 17:03 . 2009-03-26 17:03 ——– d—–w c:\documents and settings\Dad\Local Settings\Application Data\Real

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-20 05:11 . 2009-04-19 02:20 ——– d—–w c:\program files\RealFlightG3
2009-04-20 04:11 . 2009-04-19 02:20 ——– d—–w c:\program files\Common Files\KnifeEdge
2009-04-19 02:19 . 2009-04-19 02:19 434 —-a-w C:\KEError log 04-18-2009 (22h19m31s).txt
2009-04-17 00:37 . 2009-01-05 21:35 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-17 00:36 . 2009-01-05 21:34 ——– d—–w c:\program files\Spyware Doctor
2009-04-14 04:14 . 2009-01-04 22:02 ——– d—–w c:\program files\BitComet
2009-04-13 05:51 . 2009-04-13 05:51 ——– d—–w c:\program files\Trend Micro
2009-04-12 21:18 . 2008-12-21 00:54 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-04 13:40 . 2009-01-03 13:26 ——– d—–w c:\program files\Quicken
2009-04-03 09:43 . 2008-12-25 11:35 22952 —-a-w c:\documents and settings\Mom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-03 03:26 . 2009-02-04 05:06 ——– d—–w c:\documents and settings\Dad\Application Data\Simple Sudoku
2009-04-03 03:18 . 2008-12-21 00:15 22952 —-a-w c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-03 03:13 . 2009-04-03 03:13 ——– d—–w c:\program files\MSBuild
2009-04-03 03:13 . 2009-04-03 03:13 ——– d—–w c:\program files\Reference Assemblies
2009-04-01 02:33 . 2009-04-01 02:31 ——– d—–w c:\program files\Common Files\PC Tools
2009-03-28 19:19 . 2009-01-12 16:49 ——– d—–w c:\documents and settings\Dad\Application Data\Move Networks
2009-03-26 17:03 . 2009-03-26 17:03 ——– d—–w c:\program files\Real Alternative
2009-03-26 03:19 . 2008-12-21 00:54 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-03-26 03:19 . 2008-12-21 00:54 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-26 03:19 . 2008-12-21 00:54 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-03-22 15:28 . 2009-03-11 23:21 43520 —-a-w c:\windows\system32\CmdLineExt03.dll
2009-03-21 02:15 . 2009-03-20 03:37 22328 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-03-21 02:15 . 2009-03-20 03:37 103736 —-a-w c:\windows\system32\PnkBstrB.exe
2009-03-20 03:35 . 2009-03-20 03:35 66872 —-a-w c:\windows\system32\PnkBstrA.exe
2009-03-17 13:05 . 2009-01-02 21:39 7880 —-a-w C:\DSpoof.txt
2009-03-15 15:57 . 2009-03-15 15:57 ——– d—–w c:\documents and settings\Buddy\Application Data\GRETECH
2009-03-14 00:04 . 2009-03-14 00:04 ——– d—–w c:\documents and settings\Mom\Application Data\HP
2009-03-13 15:08 . 2009-03-13 15:08 ——– d—–w c:\documents and settings\All Users\Application Data\Panasonic
2009-03-13 15:06 . 2009-03-13 15:06 ——– d—–w c:\program files\Common Files\Panasonic
2009-03-13 15:06 . 2009-03-13 15:06 ——– d—–w c:\program files\Panasonic
2009-03-13 15:06 . 2008-12-20 22:34 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-13 14:31 . 2009-03-13 14:31 ——– d—–w c:\documents and settings\Dad\Application Data\GRETECH
2009-03-13 14:31 . 2009-03-13 14:31 ——– d—–w c:\program files\GRETECH
2009-03-11 23:22 . 2009-03-11 23:22 ——– d—–w c:\documents and settings\Buddy\Application Data\Atari
2009-03-06 14:22 . 2003-07-16 20:41 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 21:10 . 2009-03-03 21:10 ——– d—–w c:\documents and settings\Buddy\Application Data\AdobeUM
2009-03-03 00:18 . 2006-06-23 16:33 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-26 17:01 . 2009-02-26 17:01 ——– d—–w c:\documents and settings\Buddy\Application Data\DivX
2009-02-26 17:00 . 2009-02-26 17:00 ——– d—–w c:\documents and settings\Mom\Application Data\DivX
2009-02-24 04:07 . 2009-01-20 04:49 ——– d—–w c:\documents and settings\Dad\Application Data\AdobeUM
2009-02-24 04:02 . 2008-12-27 05:27 ——– d—–w c:\program files\Common Files\Adobe
2009-02-22 18:13 . 2009-01-31 16:06 ——– d—–w c:\program files\TaxCut08
2009-02-21 21:52 . 2009-02-21 21:52 ——– d—–w c:\documents and settings\All Users\Application Data\PlayPond
2009-02-20 18:09 . 2004-08-04 07:56 78336 ——w c:\windows\system32\ieencode.dll
2009-02-19 20:50 . 2009-01-05 19:44 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-14 16:07 . 2008-12-27 02:27 22952 —-a-w c:\documents and settings\Buddy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-09 12:10 . 2003-07-16 20:32 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2005-07-26 04:31 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2003-07-16 20:39 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2003-07-16 20:23 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2003-07-16 20:51 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2003-07-16 20:44 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2003-07-16 20:39 2145280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2003-07-16 20:43 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2002-08-29 01:04 2023936 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2003-07-16 20:44 56832 —-a-w c:\windows\system32\secur32.dll
2009-02-02 15:19 . 2009-02-02 15:19 128 —-a-w c:\documents and settings\Buddy\Local Settings\Application Data\fusioncache.dat
2009-01-31 17:52 . 2009-01-31 17:52 51716 —-a-w c:\windows\system32\pdf995mon.dll
2009-01-31 17:52 . 2009-01-31 17:52 249856 —-a-w c:\windows\system32\pdfmona.dll
2009-01-22 01:47 . 2009-01-22 01:47 22560 —-a-w c:\documents and settings\Mom\Application Data\GDIPFONTCACHEV1.DAT
2008-12-31 15:35 . 2008-12-31 15:35 126 —-a-w c:\documents and settings\Dad\Local Settings\Application Data\fusioncache.dat
2008-12-27 11:57 . 2008-12-27 11:57 126 —-a-w c:\documents and settings\Mom\Local Settings\Application Data\fusioncache.dat
2008-11-30 23:06 . 2009-01-02 16:13 26163360 —-a-w c:\documents and settings\All Users\BoggleSetup.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-04-20_05.30.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-20 15:08 . 2009-04-20 15:08 16384 c:\windows\Temp\Perflib_Perfdata_dc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-26 1932568]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-02-04 2899968]
"AsioReg"="CTASIO.DLL" - c:\windows\system32\CTASIO.DLL [2003-02-20 110592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-26 03:19 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\RealFlightG3\\RealFlight.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25422:TCP"= 25422:TCP:BitComet 25422 TCP
"25422:UDP"= 25422:UDP:BitComet 25422 UDP

R3 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwdx.sys [2008-12-27 29208]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-07 348752]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2009-01-08 12552]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-06 130424]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-26 325640]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-03-26 108552]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-03-26 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-26 298264]
S2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [2009-03-26 1356616]
S2 Prvflder;Prvflder;c:\windows\system32\DRIVERS\prvflder.sys [2006-04-21 70912]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\DRIVERS\avgfwdx.sys [2008-12-27 29208]

.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000004.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-20 11:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-04-20 11:22
ComboFix-quarantined-files.txt 2009-04-20 15:21
ComboFix2.txt 2009-04-20 05:31

Pre-Run: 135,708,000,256 bytes free
Post-Run: 135,682,281,472 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

234 — E O F — 2009-04-16 22:56

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:24:06 AM, on 4/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
G:\Dad\PrfldSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1229815666593
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…=javadl.sun.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - G:\Dad\PrfldSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 7854 bytes
Well, you had a particular virus known as the Daonol trojan. Its fairly new, so not all AntiVirus scanners are getting. I would be grateful if I could grab a quick sample.

Please go to this site:
Bleeping Computer Submission

Please paste a link to this topic in the first field. Browse to the following file:
C:\QooBox\Quarantine\c\windows\oxqh.gfx

Click Send File.

Are you having any other problems with the computer or is it all running smoothly now?
Hi Budz

Thanks for the upload. Glad to hear everything is running better :thumbup:


Click Start >> Run, and then type ComboFix /u and hit enter.

Clean up with OTMoveIt3
  • Double-click OTViewIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
You can now delete any other tools I had you download and use, unless you wish to keep them.


Now that your system appears to be clean, there's just a few steps I'd like you to take to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI