This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Uacinit.dll etc

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I stumbled across the website when searching for a method to delete this damned thing. MalwareBytes managed to remove all except this. I've followed the proceedings upto ComboFix but noticed that the solutions following, where you enter passages into notepad and move it to ComboFix, vary from computer to computer. Would it be possible to post my ComboFix log here and receive any suggested methods of proceeding? Thanks.


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 17:22:30.14 on 16/07/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1267 [GMT 1:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgtray.exe
E:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Adam\Desktop\dds.pif

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [Skype] "e:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Octoshape Streaming Services] "c:\documents and settings\adam\application data\octoshape\octoshape streaming services\OctoshapeClient.exe" -inv:bootrun
uRun: [Steam] "e:\program files\valve\steam\steam.exe" -silent
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SkyTel] SkyTel.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [JMB36X Configure] c:\windows\system32\JMRaidTool.exe boot
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Procaster] "c:\program files\procaster\Procaster.exe" -autorun
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
StartupFolder: c:\docume~1\adam\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\adam\startm~1\programs\startup\hamachi.lnk - c:\program files\hamachi\hamachi.exe
StartupFolder: c:\docume~1\adam\startm~1\programs\startup\magicd~1.lnk - e:\program files\magiciso\magicdisc\MagicDisc.exe
StartupFolder: c:\docume~1\adam\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {41564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-2-2 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-2-2 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-2 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-2-2 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-2-2 298776]
RUnknown cahab;cahab; [x]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\viewpoint\common\viewpointservice.exe" –> c:\program files\viewpoint\common\ViewpointService.exe [?]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-3-10 33176]

=============== Created Last 30 ================

2009-07-16 16:54 -cd—– c:\windows\system32\dllcache\cache
2009-07-16 16:23 a-dshr– C:\cmdcons
2009-07-16 16:20 219,648 a——- c:\windows\PEV.exe
2009-07-16 16:20 161,792 a——- c:\windows\SWREG.exe
2009-07-16 16:20 98,816 a——- c:\windows\sed.exe
2009-07-16 16:20 –ds—- C:\ComboFix
2009-07-16 14:51 –d—– C:\Program
2009-07-16 13:40 –d—– c:\docume~1\adam\applic~1\Malwarebytes
2009-07-16 13:39 –d—– c:\program files\AntiM
2009-07-16 13:14 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-16 13:14 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-16 10:09 –d—– c:\documents and settings\adam\DoctorWeb
2009-07-16 09:52 –d—– c:\program files\Spybot - Search & Destroy
2009-07-16 09:52 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-07-15 23:14 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-15 21:33 139,152 a——- c:\docume~1\adam\applic~1\PnkBstrK.sys
2009-07-15 21:32 794,408 a——- c:\windows\system32\pbsvc.exe
2009-07-15 21:18 –d—– c:\program files\EA Games
2009-07-15 17:19 –d—– C:\Mass Effect
2009-07-15 14:15 –d—– c:\docume~1\adam\applic~1\GetRightToGo
2009-07-15 13:20 –d—– c:\program files\EA
2009-07-02 14:19 –d—– c:\program files\common files\HP
2009-07-02 14:18 –d—– c:\program files\common files\Hewlett-Packard
2009-07-02 14:04 15,104 ac—— c:\windows\system32\dllcache\usbscan.sys
2009-07-02 14:04 15,104 a——- c:\windows\system32\drivers\usbscan.sys
2009-07-02 14:04 204,800 a——- c:\windows\system32\HPZipr12.dll
2009-07-02 14:04 94,208 a——- c:\windows\system32\HPZipt12.dll
2009-07-02 14:04 69,632 a——- c:\windows\system32\HPZipm12.exe
2009-07-02 14:04 61,440 a——- c:\windows\system32\HPZinw12.exe
2009-07-02 14:04 57,344 a——- c:\windows\system32\HPZisn12.dll
2009-07-02 14:04 278,584 a——- c:\windows\system32\HPZidr12.dll
2009-07-02 13:59 –d—– c:\program files\HP
2009-07-02 13:56 69,443 a——- c:\windows\hpoins05.dat
2009-07-02 13:56 19,696 ——– c:\windows\hpomdl05.dat
2009-07-02 13:54 –d—– c:\temp\HP_WebRelease
2009-07-02 13:54 –d—– C:\temp
2009-07-02 13:19 25,856 ac—— c:\windows\system32\dllcache\usbprint.sys
2009-07-02 13:19 25,856 a——- c:\windows\system32\drivers\usbprint.sys
2009-06-30 23:37 668 a——- c:\windows\entpack.ini
2009-06-30 14:38 221,184 a——- c:\windows\system32\wmpns.dll
2009-06-30 14:28 107,864 a——- c:\windows\system32\tsccvid.dll
2009-06-30 14:28 –d—– c:\windows\system32\QuickTime
2009-06-30 13:50 –d—– c:\program files\Procaster
2009-06-30 09:51 –d—– C:\Spelunky
2009-06-29 11:35 –d—– c:\program files\Bethesda Softworks
2009-06-26 21:41 a-d—– c:\documents and settings\adam\stunnel
2009-06-26 21:41 –d—– c:\documents and settings\adam\DCPlusPlus
2009-06-24 04:28 –d—– c:\docume~1\alluse~1\applic~1\Viewpoint
2009-06-24 04:28 –d—– c:\docume~1\alluse~1\applic~1\acccore
2009-06-24 04:28 –d—– c:\program files\common files\AOL
2009-06-24 04:27 –d—– c:\program files\AIM6
2009-06-24 04:27 466 a—h— C:\IPH.PH
2009-06-23 19:31 –d—– c:\documents and settings\adam\Tracing
2009-06-23 18:03 –d—– c:\program files\Educational Simulations
2009-06-23 18:02 –d—– C:\real-lives
2009-06-21 12:01 –d—– c:\docume~1\adam\applic~1\Gizmostripe_Software

==================== Find3M ====================

2009-07-15 21:59 139,016 a——- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-15 21:59 189,488 a——- c:\windows\system32\PnkBstrB.exe
2009-07-06 09:52 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-05-05 10:50 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-04-22 00:20 14,311,680 a——- c:\windows\system32\xlive.dll
2009-04-22 00:20 13,642,496 a——- c:\windows\system32\xlivefnt.dll
2009-04-15 20:38 47,360 a——- c:\docume~1\adam\applic~1\pcouffin.sys

============= FINISH: 17:22:44.32 ===============

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 02/02/2009 13:38:13
System Uptime: 16/07/2009 16:45:18 (1 hours ago)

Motherboard: http://www.abit.com.tw/ | | AB9/AB9RPO(Intel965+ICH8)
Processor: Intel® Core™2 CPU 6400 @ 2.13GHz | Socket 775 | 2176/272mhz
Processor: Intel® Core™2 CPU 6400 @ 2.13GHz | Socket 775 | 2176/272mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 233 GiB total, 114.115 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 128 GiB total, 21.901 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Multimedia Audio Controller
Device ID: PCI\VEN_13F6&DEV_0111&SUBSYS_1144153B&REV_10\4&11B6166B&0&28F0
Manufacturer:
Name: Multimedia Audio Controller
PNP Device ID: PCI\VEN_13F6&DEV_0111&SUBSYS_1144153B&REV_10\4&11B6166B&0&28F0
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ABT2005\3&2411E6FE&0
Manufacturer:
Name:
PNP Device ID: ACPI\ABT2005\3&2411E6FE&0
Service:

==== System Restore Points ===================

RP137: 15/07/2009 22:57:14 - System Checkpoint
RP138: 15/07/2009 22:57:15 - System Checkpoint
RP139: 15/07/2009 22:57:16 - System Checkpoint
RP140: 15/07/2009 22:57:17 - System Checkpoint
RP141: 15/07/2009 22:57:18 - System Checkpoint
RP142: 15/07/2009 22:57:19 - System Checkpoint
RP143: 15/07/2009 22:57:20 - System Checkpoint
RP144: 15/07/2009 22:57:21 - System Checkpoint
RP145: 15/07/2009 22:57:22 - System Checkpoint
RP146: 15/07/2009 22:57:23 - System Checkpoint
RP147: 15/07/2009 22:57:24 - Installed Icewind Dale II - Patch 2.01
RP148: 15/07/2009 22:57:25 - Installed DirectX
RP149: 15/07/2009 22:57:27 - System Checkpoint
RP150: 15/07/2009 22:57:29 - System Checkpoint
RP151: 15/07/2009 22:57:30 - Installed Smart Mod Manager
RP152: 15/07/2009 22:57:31 - System Checkpoint
RP153: 15/07/2009 22:57:33 - Avg8 Update
RP154: 15/07/2009 22:57:34 - Avg8 Update
RP155: 15/07/2009 22:57:36 - System Checkpoint
RP156: 15/07/2009 22:57:36 - System Checkpoint
RP157: 15/07/2009 22:57:37 - System Checkpoint
RP158: 15/07/2009 22:57:38 - System Checkpoint
RP159: 15/07/2009 22:57:39 - System Checkpoint
RP160: 15/07/2009 22:57:40 - System Checkpoint
RP161: 15/07/2009 22:57:41 - System Checkpoint
RP162: 15/07/2009 22:57:42 - Installed DirectX
RP163: 15/07/2009 22:57:43 - Avg8 Update
RP164: 15/07/2009 22:57:44 - Avg8 Update
RP165: 15/07/2009 22:57:45 - System Checkpoint
RP166: 15/07/2009 22:57:47 - System Checkpoint
RP167: 15/07/2009 22:57:48 - System Checkpoint
RP168: 15/07/2009 22:57:49 - System Checkpoint
RP169: 15/07/2009 22:57:50 - Avg8 Update
RP170: 15/07/2009 22:57:52 - System Checkpoint
RP171: 15/07/2009 22:57:52 - Installed Call Of Cthulhu DCoTE
RP172: 15/07/2009 22:57:53 - Installed Windows Media Codec Setup
RP173: 15/07/2009 22:57:53 - Installed Procaster
RP174: 15/07/2009 22:57:54 - Removed Procaster
RP175: 15/07/2009 22:57:55 - Installed Procaster
RP176: 15/07/2009 22:57:55 - Installed Camtasia Studio 4
RP177: 15/07/2009 22:57:56 - Installed Adobe Flash Media Live Encoder 3.
RP178: 15/07/2009 22:57:57 - System Checkpoint
RP179: 15/07/2009 22:57:57 - System Checkpoint
RP180: 15/07/2009 22:57:58 - System Checkpoint
RP181: 15/07/2009 22:57:59 - Avg8 Update
RP182: 15/07/2009 22:57:59 - Avg8 Update
RP183: 15/07/2009 22:58:00 - Avg8 Update
RP184: 15/07/2009 22:58:02 - System Checkpoint
RP185: 15/07/2009 22:58:03 - System Checkpoint
RP186: 15/07/2009 22:58:04 - System Checkpoint
RP187: 15/07/2009 22:58:04 - System Checkpoint
RP188: 16/07/2009 15:51:48 - System Checkpoint

==== Installed Programs ======================

µTorrent
1600
1600_Help
1600Trb
3D Custom Girl
7-Zip 4.65
Acrobat.com
Adobe AIR
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Media Live Encoder 3
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 9.1
Adobe Shockwave Player 11.5
Adobe Stock Photos 1.0
AGEIA PhysX v7.11.13
AIM 6
AiO_Scan
AiOSoftware
And Yet It Moves
Any Audio Converter 1.1.0
Apple Mobile Device Support
Apple Software Update
Arcanum
Army Men
AVG Free 8.5
Baldur's Gate™ II - Shadows of Amn™
Battlefield Heroes
Bonjour
Braid Demo
Brain Workshop 4.4
BufferChm
Call Of Cthulhu DCoTE
Call of Duty® 4 - Modern Warfare™
Call of Duty® 4 - Modern Warfare™ 1.6 Patch
Call of Duty® 4 - Modern Warfare™ 1.7 Patch
Camtasia Studio 4
Choice Guard
Company of Heroes
Company of Heroes - FAKEMSI
ConvertXtoDVD [removed]
Crazy Machines II Demo
Darkest Hour
Defcon
Destinations
Deus Ex
Diablo II
Director
DivX Web Player
Doomsday
Empire: Total War
Fax
Flash Movie Player 1.5
Free Mp3 Wma Converter V 1.8.0
Free PDF to Word Doc Converter v1.1
Freedom Force
Freedom Force vs. the 3rd Reich
GameTap
Garry's Mod
GCFScape 1.7.2
Geneforge
getPlus® for Adobe
GIMP 2.6.4
Guild Wars
Hamachi 1.0.3.0
Hearts of Iron 2
Hearts of Iron 2 Doomsday Armageddon
High Definition Audio Driver Package - KB888111
HOI2 Doomsday Armageddon 1.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
HP Extended Capabilities 4.7
HP Image Zone 4.7
HP Image Zone Express
HP Product Assistant
HP PSC & OfficeJet 4.7
HP Software Update
HPSystemDiagnostics
Icewind Dale II
iTunes
Java™ 6 Update 11
Java™ 6 Update 7
JRAID
King's Quest I
LucasArts' Outlaws
MagicDisc 2.7.106
Malwarebytes' Anti-Malware
Mare Nostrum
MarketResearch
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mozilla Firefox (3.0.11)
MSVCRT
MSXML 6.0 Parser (KB925673)
NVIDIA Drivers
Octoshape Streaming Services
OpenAL
OpenOffice.org 3.0
Planescape - Torment
Populous: The Beginning
Procaster
ProductContext
PunkBuster Services
QFolder
QuickTime
Readme
Real Lives 2007
RealPlayer
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Red Orchestra
S.T.A.L.K.E.R. - Shadow of Chernobyl [v1.0005]
Scan
ScannerCopy
Security Update for Windows Media Player (KB952069)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB960714)
Segoe UI
Smart Mod Manager
SpeedFan (remove only)
Spybot - Search & Destroy
Stardock Central
System Requirements Lab
The Graveyard Demo
TrayApp
Unload
Update for Windows XP (KB898461)
Update for Windows XP (KB955839)
Vampire: The Masquerade - Bloodlines
VC80CRTRedist - 8.0.50727.762
VTFEdit 1.2.5
Warhammer 40,000: Dawn of War II
WebFldrs XP
WebReg
Windows Genuine Advantage Notifications (KB905474)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Presentation Foundation
World of Goo
XML Paper Specification Shared Components Pack 1.0

==== Event Viewer Messages From Past Week ========

16/07/2009 17:15:49, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
16/07/2009 16:47:21, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
16/07/2009 16:24:30, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
16/07/2009 16:12:53, error: Service Control Manager [7031] - The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
16/07/2009 16:12:46, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 4 time(s).
16/07/2009 16:10:54, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 3 time(s).
16/07/2009 16:10:48, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 2 time(s).
16/07/2009 16:10:39, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 1 time(s).
16/07/2009 14:08:27, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 Fips intelppm
16/07/2009 13:30:42, error: Service Control Manager [7000] - The Viewpoint Manager Service service failed to start due to the following error: The system cannot find the path specified.
16/07/2009 12:21:14, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
16/07/2009 11:14:25, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
16/07/2009 10:53:10, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume E:.
16/07/2009 10:42:52, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
16/07/2009 10:42:34, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
16/07/2009 10:42:34, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
16/07/2009 10:42:34, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
16/07/2009 10:42:34, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
16/07/2009 10:42:34, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
16/07/2009 10:42:34, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
16/07/2009 10:42:34, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
16/07/2009 10:41:59, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
16/07/2009 10:41:58, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
16/07/2009 00:22:51, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
16/07/2009 00:22:51, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
16/07/2009 00:22:49, error: Service Control Manager [7034] - The WebClient service terminated unexpectedly. It has done this 1 time(s).
16/07/2009 00:22:49, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s).
16/07/2009 00:22:49, error: Service Control Manager [7034] - The SSDP Discovery Service service terminated unexpectedly. It has done this 1 time(s).
16/07/2009 00:22:49, error: Service Control Manager [7031] - The Remote Registry service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
16/07/2009 00:22:47, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
16/07/2009 00:22:31, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
16/07/2009 00:22:20, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
16/07/2009 00:22:15, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
16/07/2009 00:21:41, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
16/07/2009 00:21:39, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
16/07/2009 00:16:39, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Viewpoint Manager Service service to connect.
16/07/2009 00:16:39, error: Service Control Manager [7000] - The Viewpoint Manager Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
15/07/2009 23:03:51, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
15/07/2009 23:02:48, error: Service Control Manager [7034] - The Viewpoint Manager Service service terminated unexpectedly. It has done this 1 time(s).
15/07/2009 22:59:35, error: Service Control Manager [7034] - The PnkBstrB service terminated unexpectedly. It has done this 1 time(s).
15/07/2009 22:59:32, error: Service Control Manager [7034] - The PnkBstrA service terminated unexpectedly. It has done this 1 time(s).
12/07/2009 12:42:24, error: Dhcp [1002] - The IP address lease 10.1.1.5 for the Network Card with network address 00508D9530BD has been denied by the DHCP server 10.1.1.1 (The DHCP Server sent a DHCPNACK message).
12/07/2009 12:12:33, error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{75CF1591-9974-46B4-96C1-A1C0E4892B3C} because another computer on the network has the same name. The server could not start.

==== End Of File ===========================

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ComboFix 09-07-14.08 - Adam 16/07/2009 16:46.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1631 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Adam\Application Data\inst.exe
c:\windows\system32\drivers\UACvoupuvqyeqqvknofo.sys
c:\windows\system32\New Text Document.txt
c:\windows\system32\UACdarcjsxrieeiwqgho.dll
c:\windows\system32\UAChlkiexltouwlxkjta.dll
c:\windows\system32\UACkrjaytgqlsrhnasca.db
c:\windows\system32\UACmmnawgswplcyclynk.dll
c:\windows\system32\UACptmxydtcqlcfafrhk.dat
c:\windows\system32\UACqihtlaqnxgukafcxt.dll
c:\windows\system32\UACrvpyudfoswgkbcbpp.dll
c:\windows\system32\WgaLogon.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.

2009-07-16 13:51 . 2009-07-16 13:51 ——– d—–w- C:\Program
2009-07-16 12:40 . 2009-07-16 12:40 ——– d—–w- c:\documents and settings\Adam\Application Data\Malwarebytes
2009-07-16 12:39 . 2009-07-16 12:40 ——– d—–w- c:\program files\AntiM
2009-07-16 12:14 . 2009-07-13 12:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-16 12:14 . 2009-07-13 12:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-16 09:09 . 2009-07-16 09:09 ——– d—–w- c:\documents and settings\Adam\DoctorWeb
2009-07-16 08:52 . 2009-07-16 13:52 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-07-16 08:52 . 2009-07-16 09:28 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-15 22:14 . 2009-07-15 22:14 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-07-15 20:32 . 2009-07-15 20:32 794408 —-a-w- c:\windows\system32\pbsvc.exe
2009-07-15 20:18 . 2009-07-15 20:18 ——– d—–w- c:\program files\EA Games
2009-07-15 16:19 . 2009-07-15 16:20 ——– d—–w- C:\Mass Effect
2009-07-15 13:15 . 2009-07-15 14:58 ——– d—–w- c:\documents and settings\Adam\Application Data\GetRightToGo
2009-07-15 12:20 . 2009-07-15 12:20 ——– d—–w- c:\program files\EA
2009-07-02 13:20 . 2009-07-02 13:20 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\HP
2009-07-02 13:19 . 2009-07-02 13:19 ——– d—–w- c:\program files\Common Files\HP
2009-07-02 13:19 . 2009-07-02 13:19 ——– d—–w- c:\program files\Hewlett-Packard
2009-07-02 13:18 . 2009-07-02 13:18 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2009-07-02 13:04 . 2004-08-03 21:58 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2009-07-02 13:04 . 2004-08-03 21:58 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-07-02 13:04 . 2004-09-29 11:15 204800 —-a-w- c:\windows\system32\HPZipr12.dll
2009-07-02 13:04 . 2004-09-29 11:14 69632 —-a-w- c:\windows\system32\HPZipm12.exe
2009-07-02 13:04 . 2004-09-29 11:09 57344 —-a-w- c:\windows\system32\HPZisn12.dll
2009-07-02 13:04 . 2004-09-29 11:09 94208 —-a-w- c:\windows\system32\HPZipt12.dll
2009-07-02 13:04 . 2004-09-29 11:08 61440 —-a-w- c:\windows\system32\HPZinw12.exe
2009-07-02 13:04 . 2004-09-29 11:12 278584 —-a-w- c:\windows\system32\HPZidr12.dll
2009-07-02 12:59 . 2009-07-02 13:19 ——– d—–w- c:\program files\HP
2009-07-02 12:56 . 2009-07-02 13:22 69443 —-a-w- c:\windows\hpoins05.dat
2009-07-02 12:56 . 2004-12-14 23:07 19696 ——w- c:\windows\hpomdl05.dat
2009-07-02 12:54 . 2009-07-02 12:56 ——– d—–w- c:\temp\HP_WebRelease
2009-07-02 12:54 . 2009-07-02 12:54 ——– d—–w- C:\temp
2009-07-02 12:19 . 2004-08-03 22:01 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2009-07-02 12:19 . 2004-08-03 22:01 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2009-06-30 13:38 . 2004-08-04 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-06-30 13:29 . 2009-06-30 13:29 ——– d—–w- c:\documents and settings\Adam\Local Settings\Application Data\TechSmith
2009-06-30 13:28 . 2007-07-12 03:54 107864 —-a-w- c:\windows\system32\tsccvid.dll
2009-06-30 13:28 . 2009-06-30 13:28 ——– d—–w- c:\windows\system32\QuickTime
2009-06-30 13:28 . 2009-06-30 13:28 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\TechSmith
2009-06-30 13:28 . 2009-06-30 13:28 ——– d—–w- c:\program files\TechSmith
2009-06-30 12:50 . 2009-07-16 14:36 ——– d—–w- c:\documents and settings\Adam\Local Settings\Application Data\procaster
2009-06-30 12:50 . 2009-06-30 12:50 ——– d—–w- c:\program files\Procaster
2009-06-30 08:51 . 2009-06-30 08:51 ——– d—–w- C:\Spelunky
2009-06-29 16:32 . 2009-06-30 12:34 ——– d—–w- c:\documents and settings\Adam\Local Settings\Application Data\poocaster
2009-06-29 10:35 . 2009-06-29 10:35 ——– d—–w- c:\program files\Bethesda Softworks
2009-06-26 20:41 . 2009-03-01 23:10 ——– d—a-w- c:\documents and settings\Adam\stunnel
2009-06-26 20:41 . 2009-03-22 03:03 ——– d—–w- c:\documents and settings\Adam\DCPlusPlus
2009-06-24 03:29 . 2009-06-24 03:29 ——– d—–w- c:\documents and settings\Adam\Application Data\acccore
2009-06-24 03:29 . 2009-06-24 03:29 ——– d—–w- c:\documents and settings\Adam\Local Settings\Application Data\AOL OCP
2009-06-24 03:29 . 2009-06-24 03:29 ——– d—–w- c:\documents and settings\Adam\Local Settings\Application Data\AOL
2009-06-24 03:28 . 2009-07-16 09:35 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Viewpoint
2009-06-24 03:28 . 2009-06-24 03:28 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\acccore
2009-06-24 03:28 . 2009-06-24 03:28 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\AOL OCP
2009-06-24 03:28 . 2009-06-24 03:28 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\AOL
2009-06-24 03:28 . 2009-06-24 03:28 ——– d—–w- c:\program files\Common Files\AOL
2009-06-24 03:27 . 2009-06-24 03:29 ——– d—–w- c:\program files\AIM6
2009-06-23 18:31 . 2009-06-23 18:31 ——– d—–w- c:\documents and settings\Adam\Tracing
2009-06-23 17:03 . 2009-06-23 17:03 ——– d—–w- c:\program files\Educational Simulations
2009-06-23 17:02 . 2007-09-23 19:10 ——– d—–w- C:\real-lives
2009-06-21 11:01 . 2009-06-21 11:01 ——– d—–w- c:\documents and settings\Adam\Application Data\Gizmostripe_Software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-16 15:18 . 2009-03-25 17:54 ——– d—–w- c:\documents and settings\Adam\Application Data\Hamachi
2009-07-16 15:15 . 2009-02-02 21:00 ——– d—–w- c:\documents and settings\Adam\Application Data\Skype
2009-07-15 20:59 . 2009-03-16 23:08 139016 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-15 20:59 . 2009-03-16 23:07 189488 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-07-15 20:33 . 2009-07-15 20:33 139152 —-a-w- c:\documents and settings\Adam\Application Data\PnkBstrK.sys
2009-07-15 19:58 . 2009-03-14 14:39 ——– d—–w- c:\documents and settings\Adam\Application Data\uTorrent
2009-07-15 11:14 . 2009-02-03 12:38 ——– d—–w- c:\documents and settings\Adam\Application Data\foobar2000
2009-07-06 08:52 . 2009-02-02 16:37 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-29 10:35 . 2009-02-02 13:42 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-27 16:03 . 2009-04-26 10:32 ——– d—–w- c:\program files\DC++
2009-06-23 18:27 . 2009-04-07 20:31 ——– d—–w- c:\program files\Windows Live
2009-06-21 11:00 . 2009-06-09 20:19 ——– d—–w- c:\documents and settings\Adam\Application Data\Smart Mod Manager
2009-06-20 11:41 . 2009-02-02 16:37 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-10 00:09 . 2009-06-09 23:41 ——– d—–w- c:\program files\3D Custom Girl
2009-06-09 23:43 . 2009-06-09 23:43 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\{F3D79B30-A394-4389-B080-D198DF1E6244}
2009-06-09 22:07 . 2009-06-09 22:06 ——– d—–w- c:\documents and settings\Adam\Application Data\The Longest Journey
2009-06-09 20:19 . 2009-02-28 19:18 ——– d—–w- c:\program files\THQ
2009-06-01 13:13 . 2009-06-01 12:51 ——– d—–w- c:\program files\JFK Reloaded
2009-05-30 16:19 . 2009-05-30 16:19 ——– d—–w- c:\program files\BlackIsle
2009-05-29 01:12 . 2009-02-04 17:26 ——– d—–w- c:\documents and settings\Adam\Application Data\dvdcss
2009-05-27 19:43 . 2009-05-27 19:43 ——– d—–w- c:\program files\Any Audio Converter
2009-05-27 19:36 . 2009-05-27 19:36 ——– d—–w- c:\program files\Free Audio Pack
2009-05-21 22:32 . 2009-05-21 22:27 ——– d—–w- c:\program files\VTFEdit
2009-05-19 15:02 . 2009-05-19 14:48 ——– d—–w- c:\program files\GCFScape
2009-05-05 09:50 . 2009-02-02 16:37 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-05 09:50 . 2009-02-02 16:37 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-21 23:20 . 2009-04-21 23:20 14311680 —-a-w- c:\windows\system32\xlive.dll
2009-04-21 23:20 . 2009-04-21 23:20 13642496 —-a-w- c:\windows\system32\xlivefnt.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="e:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"Octoshape Streaming Services"="c:\documents and settings\Adam\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]
"Steam"="e:\program files\valve\steam\steam.exe" [2009-06-10 1217784]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-04-25 385024]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-06 136600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-14 185872]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Procaster"="c:\program files\Procaster\Procaster.exe" [2009-05-27 6006024]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-04-24 1448960]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-05-04 16206848]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-10-07 1630208]

c:\documents and settings\Adam\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2009-3-25 625952]
MagicDisc.lnk - e:\program files\MagicISO\MagicDisc\MagicDisc.exe [2009-4-15 576000]
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-05 09:50 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"e:\\Program Files\\Valve\\Steam\\steam.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\xcom ufo defense\\dosbox.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\oddworld abes oddysee demo\\AbeDemo.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\the longest journey\\game.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\commander keen\\testapp3.bat"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\commander keen\\testapp4.bat"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\commander keen\\testapp5.bat"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\thecookster\\team fortress 2\\hl2.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\thecookster\\garrysmod\\hl2.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"e:\\Program Files\\mIRC\\mirc.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\thecookster\\counter-strike source\\hl2.exe"=
"e:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Stardock\\SDCentral\\loader.exe"=
"e:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization 4 Complete\\Beyond the Sword\\Civ4BeyondSword.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\vampire the masquerade - bloodlines\\vampire.exe"=
"c:\\Program Files\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"c:\\Program Files\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\world of goo\\WorldOfGoo.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\the graveyard demo\\TheGraveyard.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\defcon\\defcon.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\thecookster\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\The 3DO Company\\Army Men\\Armymen.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicDownloader\\RelicDownloader.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\thecookster\\source sdk base\\hl2.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\dawn of war 2\\DOW2.exe"=
"c:\\Program Files\\Paradox Interactive\\Doomsday\\HoI2.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Paradox Interactive\\Hearts of Iron 2\\HoI2.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus\\DCPlusPlus.exe"=
"c:\\Program Files\\Gang Garrison\\Gang Garrison 2.exe"=
"c:\\Documents and Settings\\Adam\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\Documents and Settings\\Adam\\Desktop\\Steam Idler\\SteamStats.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\freedom force\\fforce.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\freedom force vs. the 3rd reich\\ffvt3r.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\red orchestra\\System\\RedOrchestra.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"e:\\Program Files\\DC++\\DCPlusPlus.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\left 4 dead\\left4dead.exe"=
"e:\\Program Files\\Valve\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"411:TCP"= 411:TCP:411

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [02/02/2009 17:37 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [02/02/2009 17:37 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [02/02/2009 17:37 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [02/02/2009 17:37 298776]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" –> c:\program files\Viewpoint\Common\ViewpointService.exe [?]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [10/03/2009 18:31 33176]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)


.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-16 16:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1708537768-436374069-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:dd,21,d9,f4,c5,38,e2,54,76,87,b3,f4,77,23,c5,34,b2,8e,da,fd,b8,
d4,f8,76,b6,72,1d,de,64,91,8e,62,45,da,5c,53,96,80,f5,40,65,a4,96,1c,0d,e2,\
"rkeysecu"=hex:9f,ca,16,75,83,0a,d6,fd,d2,a5,ab,cb,c1,0d,12,f7
.
Completion time: 2009-07-16 16:55
ComboFix-quarantined-files.txt 2009-07-16 15:55

Pre-Run: 115,716,349,952 bytes free
Post-Run: 122,495,987,712 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

254 — E O F — 2009-02-03 07:44
Hi Cookery,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Let's get a different scan.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI