Hi there;
I've followed all of your advice and posted my combofix log below. My computer seems to be running quite a bit faster now, and I can't see any suspicious processes running…….though after cleaning the computer previously with other antivirus software it would also seem to be better for awhile, and then relapse. I'm really hoping this worked! I greatly appreciate your help, I've been extremely frustrated trying to deal with this for the past few days! =P
Here is my combofix log:
ComboFix 09-06-01.03 - user 06/02/2009 23:14.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1556 [GMT -2.5:30]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: The Shield Deluxe 2009 Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\bold.log
c:\documents and settings\user\Local Settings\Temporary Internet Files\asek.sys
c:\documents and settings\user\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\user\Local Settings\Temporary Internet Files\comovi.sys
c:\documents and settings\user\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\user\Local Settings\Temporary Internet Files\Cpvff.stt
c:\documents and settings\user\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\user\Local Settings\Temporary Internet Files\qede.lib
c:\documents and settings\user\Local Settings\Temporary Internet Files\raseja._dl
C:\mimic.log
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\temp\DIV55
c:\temp\DIV55\xDb.log
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
c:\windows\system32\drivers\ovfsthoognosbuwesbiqcrrdkrjidttkbgpdqm.sys
c:\windows\system32\drivers\TDSSserv.sys
c:\windows\system32\op4
c:\windows\system32\ovfsthaqqypqffnwwegiptnqpedsslcimxegvq.dat
c:\windows\system32\ovfsthklmacqsisevvjdsmlqpmsmnrcxypxdle.dat
c:\windows\system32\ovfsthvyiekbrlvrcptryxvtpanivvoiscpfkl.dll
c:\windows\system32\ovfsthwwurwmfbewqdppcfcphyfkhogvxkrbaa.dll
c:\windows\system32\ovfsthyrgowexyuurtlirnepuwpnkiseqqoqlt.dll
c:\windows\system32\TDSSwpye.dat
c:\windows\system32\uniq.tll
c:\windows\system32\vos
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\Tasks\dymhpcub.job
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_TDSSSERV
——-\Legacy_TDSSSERV
——-\Legacy_AVAST!ANTIVIRUS
——-\Service_ovfsthchbopppwaivkdmyxyqjduovhgmkjxwak
((((((((((((((((((((((((( Files Created from 2009-05-03 to 2009-06-03 )))))))))))))))))))))))))))))))
.
2009-06-02 23:36 . 2009-06-02 23:36 ——– d—–w- c:\program files\Trend Micro
2009-06-02 21:00 . 2009-06-02 21:00 111271 —-a-w- c:\windows\system32\install.48025.exe
2009-06-01 14:57 . 2009-06-01 14:57 ——– d—–w- c:\program files\NVT Malware Remover Tool
2009-05-31 11:56 . 2009-05-31 11:56 192 —-a-w- C:\487656.bat
2009-05-31 00:22 . 2009-05-31 00:22 ——– d-s—w- c:\windows\system32\config\systemprofile\UserData
2009-05-29 01:09 . 2009-06-03 01:57 81984 —-a-w- c:\windows\system32\bdod.bin
2009-05-29 00:23 . 2009-05-29 00:23 16 —-a-w- C:\asdict.dat
2009-05-27 22:06 . 2009-05-26 06:48 105 —-a-w- C:\tj.vbs
2009-05-26 21:35 . 2009-05-26 21:35 ——– d—–w- c:\documents and settings\user\Application Data\BitDefender
2009-05-26 21:34 . 2009-05-26 21:36 ——– d—–w- c:\documents and settings\All Users\Application Data\BitDefender
2009-05-26 21:34 . 2009-05-26 21:34 ——– d—–w- c:\program files\PCSecurityShield
2009-05-26 21:32 . 2009-05-26 21:35 ——– d—–w- c:\program files\Common Files\BitDefender
2009-05-26 02:29 . 2009-05-05 18:46 2051864 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-05-26 02:29 . 2009-05-05 18:46 3288344 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-05-26 02:29 . 2009-05-05 18:46 486168 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgrsx.exe
2009-05-26 02:29 . 2009-05-05 18:46 2302232 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-05-26 02:29 . 2009-05-05 18:46 424472 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwdwsc.dll
2009-05-26 02:29 . 2009-05-05 18:46 3399960 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-05-26 02:29 . 2009-05-05 18:46 177432 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgmail.dll
2009-05-26 02:29 . 2009-05-05 18:45 312088 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avglngx.dll
2009-05-26 02:29 . 2009-05-05 18:46 755992 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll
2009-05-26 02:29 . 2009-05-05 18:46 1437464 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-05-05 18:59 . 2009-06-01 14:58 ——– d–h–w- C:\$AVG8.VAULT$
2009-05-05 18:46 . 2009-05-05 18:46 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-05 18:46 . 2009-05-05 18:46 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-05 18:46 . 2009-05-05 18:46 325896 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-05 18:46 . 2009-06-02 16:21 ——– d—–w- c:\windows\system32\drivers\Avg
2009-05-05 18:46 . 2009-05-26 21:11 ——– d—–w- c:\documents and settings\user\Application Data\AVGTOOLBAR
2009-05-05 18:45 . 2009-05-31 03:20 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-05-05 18:45 . 2009-05-05 18:45 ——– d—–w- c:\program files\AVG
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 00:54 . 2007-05-18 02:31 ——– d—–w- c:\documents and settings\user\Application Data\StumbleUpon
2009-05-27 02:01 . 2008-09-04 13:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-27 02:01 . 2008-12-08 14:37 3371383 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-27 00:13 . 2008-09-18 13:42 242184 —-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2009-05-26 15:50 . 2008-09-04 13:14 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 15:49 . 2008-09-04 13:14 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-05 18:46 . 2008-03-26 00:08 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-05 14:53 . 2008-11-07 01:43 ——– d—–w- c:\program files\Common
2009-05-04 23:21 . 2008-09-10 22:18 ——– d—–w- c:\program files\MSECache
2009-04-21 17:21 . 2007-05-18 02:31 ——– d—–w- c:\program files\StumbleUpon
2009-04-15 23:33 . 2006-11-10 18:13 ——– d—–w- c:\documents and settings\user\Application Data\BitTorrent
2008-10-26 08:00 . 2008-10-26 08:00 16208 —-a-w- c:\program files\Common Files\aduwusewod.db
2009-05-27 00:12 . 2008-10-30 20:04 61440 —-a-w- c:\program files\mozilla firefox\components\FFComm.dll
2008-12-19 14:50 . 2007-09-14 14:42 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 14:50 . 2007-09-14 14:42 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 14:50 . 2007-09-14 14:42 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 14:50 . 2007-09-14 14:42 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 14:50 . 2007-09-14 14:42 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2007-11-15 19:05 . 2008-02-29 17:32 89088 —-a-w- c:\program files\mozilla firefox\plugins\atl71.dll
2007-11-15 19:05 . 2008-02-29 17:32 53248 —-a-w- c:\program files\mozilla firefox\plugins\boost_filesystem-vc71-mt-1_33_1.dll
2007-11-15 19:05 . 2008-02-29 17:32 499712 —-a-w- c:\program files\mozilla firefox\plugins\msvcp71.dll
2007-11-15 19:05 . 2008-02-29 17:32 348160 —-a-w- c:\program files\mozilla firefox\plugins\msvcr71.dll
2007-11-15 19:05 . 2008-02-29 17:32 110592 —-a-w- c:\program files\mozilla firefox\plugins\v22_base.dll
2007-11-15 19:05 . 2008-02-29 17:32 114688 —-a-w- c:\program files\mozilla firefox\plugins\v22_compression.dll
2007-11-15 19:05 . 2008-02-29 17:32 106496 —-a-w- c:\program files\mozilla firefox\plugins\v22_connect.dll
2007-11-15 19:05 . 2008-02-29 17:32 229376 —-a-w- c:\program files\mozilla firefox\plugins\v22_update.dll
2007-11-15 19:05 . 2008-02-29 17:32 196608 —-a-w- c:\program files\mozilla firefox\plugins\v22_utility.dll
2007-11-15 19:05 . 2008-02-29 17:32 159744 —-a-w- c:\program files\mozilla firefox\plugins\v22_winapplib.dll
2005-06-23 18:00 . 2005-06-23 18:00 220 -csh–w- c:\windows\dwin.sys
2005-06-28 18:13 . 2005-06-23 19:44 56 -csh–r- c:\windows\system32\412D79B7A6.sys
2008-09-12 02:37 . 2006-03-05 18:54 1838 -csha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-03 158208]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Loadout Manager.lnk - c:\program files\Belkin\Nostromo\nost_LM.exe [2003-6-24 442368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:12 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-05 18:46 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\user\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^ChkDisk.dll]
path=c:\documents and settings\user\Start Menu\Programs\Startup\ChkDisk.dll
backup=c:\windows\pss\ChkDisk.dllStartup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^ChkDisk.lnk]
path=c:\documents and settings\user\Start Menu\Programs\Startup\ChkDisk.lnk
backup=c:\windows\pss\ChkDisk.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^Dialog Helper.lnk]
path=c:\documents and settings\user\Start Menu\Programs\Startup\Dialog Helper.lnk
backup=c:\windows\pss\Dialog Helper.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
"27532:TCP"= 27532:TCP:BitComet 27532 TCP
"27532:UDP"= 27532:UDP:BitComet 27532 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/5/2009 4:16 PM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/5/2009 4:16 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/5/2009 4:16 PM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/5/2009 4:15 PM 298776]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [9/18/2008 11:09 AM 111112]
S2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [8/7/2006 6:38 PM 3712]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [6/22/2005 12:00 PM 20160]
S3 Arrakis3;PCSecurityShield Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [7/17/2008 12:06 PM 118784]
S3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [7/23/2003 4:46 PM 22821]
S3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [6/22/2005 12:52 PM 140288]
S3 SPC610NC;Philips SPC500NC Webcam;c:\windows\system32\DRIVERS\SPC610NC.SYS –> c:\windows\system32\DRIVERS\SPC610NC.SYS [?]
S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\StumbleUpon\StumbleUponUpdateService.exe [4/12/2009 3:49 PM 120168]
S3 WLUX96;I-Hotel (v1.1.14.2) – 3Com 3CRSHEW696 Wireless LAN USB Adapter;c:\windows\system32\drivers\wlux96f.sys [8/15/2006 1:56 PM 80768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder
2009-05-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 18:57]
c:\windows\Tasks\At9.job
2009-06-02 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-06-22 15:24]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\user\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://aolsvc.aol.com/onlinegames/free-trial-mahjong-escape-ancient-japan/SpinTopGamesLauncher.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\ykquu7hi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.ca
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-02 23:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
C:\sccfg.sys 20 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(3032)
c:\program files\Belkin\Nostromo\nost_FSH.dll
c:\windows\system32\btneighborhood.dll
c:\windows\system32\wbtapi.dll
c:\windows\system32\btwpimif.dll
c:\windows\system32\btosif.dll
c:\windows\system32\btrez.dll
c:\windows\system32\CSH.dll
c:\windows\system32\browselc.dll
c:\program files\Common Files\Nero\Lib\NeroDigitalExt.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\WMASF.DLL
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
c:\program files\PCSecurityShield\BitDefender 2009\vsserv.exe
c:\windows\system32\ati2evxx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\PAStiSvc.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-03 23:39 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-03 02:09
Pre-Run: 17,790,140,416 bytes free
Post-Run: 19,499,528,192 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=10 Default=10 Failed=9 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,10,11269