This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Win32/Heur.dropper virus

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ive been searching high and low on google + asked alot of my "computer techy" friends for solutions, but we cant seem to find anything about it (even after searching here and i really dont want to format my computer).

Anyhow the problem occured today after opening a suspicious file (stupid of me, i got careless).

After that my AVG have been prompting me about "Win32/Heur.dropper" virus and it cant seem to remove it, i cant find much info about this virus either on google etc. So im hoping you can help me out :)
I cant access my "Task manager" either. The ".exe"(proccess) that AVG tells me has this virus is "vha.exe". And i cant try to close it seeing i cant access my process tree or anything :/

Hijackthis log;

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:23:25, on 19.07.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Programfiler\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Programfiler\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Programfiler\Sygate\SON\sgserv.exe
C:\Programfiler\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\DeathSoul\vha.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Programfiler\Winamp\winampa.exe
C:\Programfiler\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Sygate\SON\Sygate.exe
C:\WINDOWS\system32\mspgw.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Windows Live\Messenger\msnmsgr.exe
C:\Programfiler\DAEMON Tools Lite\daemon.exe
C:\Programfiler\Messenger\msmsgs.exe
C:\Programfiler\RALINK\Common\RaUI.exe
C:\Programfiler\Windows Desktop Search\WindowsSearch.exe
C:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Programfiler\Windows Live\Contacts\wlcomm.exe
C:\Programfiler\mIRC\mirc.exe
C:\Programfiler\Mozilla Firefox\firefox.exe
c:\programfiler\aim toolbar\aimtbServer.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\Programfiler\Java\jre6\bin\java.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Programfiler\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
R3 - URLSearchHook: (no name) - *{0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\DeathSoul\vha.exe \s
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Programfiler\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Programfiler\AVG\AVG8\avgssie.dll
O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Programfiler\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Programfiler\AIM Toolbar\aimtb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programfiler\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programfiler\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programfiler\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Programfiler\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Programfiler\AIM Toolbar\aimtb.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Programfiler\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [GEST] m‘|\ü
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\winampa.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programfiler\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SyGateManager] C:\Programfiler\Sygate\SON\Sygate.exe
O4 - HKLM\..\Run: [udkydc] C:\WINDOWS\system32\udkydc.exe \u
O4 - HKLM\..\Run: [Manage Program Gateway] C:\WINDOWS\system32\mspgw.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programfiler\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Programfiler\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Aim6] "C:\Programfiler\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Programfiler\RALINK\Common\RaUI.exe
O4 - Global Startup: Windows Search.lnk = C:\Programfiler\Windows Desktop Search\WindowsSearch.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Programdata\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Programfiler\AIM Toolbar\aimtb.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programfiler\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programfiler\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1234912479235
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Programfiler\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FELLES~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programfiler\Java\jre6\bin\jqs.exe
O23 - Service: SyGateService (SaService) - Sygate technologies Inc. - C:\Programfiler\Sygate\SON\sgserv.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Programfiler\TVersity\Media Server\MediaServer.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Programfiler\Viewpoint\Common\ViewpointService.exe

–
End of file - 9280 bytes

———-

While speaking im doing a kapersky online scan (which takes a while i guess). Will update with a log of that if you dont know any solutions for this (though im hoping for one).
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hello again and thanks for the fast replay :) (thanks for the welcome too). Here are the files requested (also attached them) DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 11:16:01,51 on 19.07.2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.47.1044.18.3326.2551 [GMT 2:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Programfiler\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Programfiler\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\system32\SearchIndexer.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Programfiler\AVG\AVG8\avgcsrvx.exe C:\Programfiler\Sygate\SON\sgserv.exe C:\WINDOWS\Explorer.EXE C:\Documents and Settings\DeathSoul\vha.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe svchost.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Programfiler\Winamp\winampa.exe C:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Programfiler\Java\jre6\bin\jusched.exe C:\Programfiler\Sygate\SON\Sygate.exe C:\WINDOWS\system32\mspgw.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Windows Live\Messenger\msnmsgr.exe C:\Programfiler\DAEMON Tools Lite\daemon.exe C:\Programfiler\Messenger\msmsgs.exe C:\Programfiler\RALINK\Common\RaUI.exe C:\Programfiler\Windows Desktop Search\WindowsSearch.exe C:\Programfiler\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\system32\wuauclt.exe C:\Programfiler\Mozilla Firefox\firefox.exe C:\Programfiler\Internet Explorer\iexplore.exe C:\Programfiler\Internet Explorer\iexplore.exe c:\programfiler\aim toolbar\aimtbServer.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Programfiler\Internet Explorer\iexplore.exe C:\Programfiler\Internet Explorer\iexplore.exe C:\Programfiler\Internet Explorer\iexplore.exe C:\Documents and Settings\DeathSoul\Skrivebord\dds.pif ============== Pseudo HJT Report =============== uStart Page = about:blank uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\programfiler\avg\avg8\toolbar\IEToolbar.dll uURLSearchHooks: H - No File uURLSearchHooks: H - No File uURLSearchHooks: H - No File mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\programfiler\aim toolbar\aimtb.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\programfiler\avg\avg8\toolbar\IEToolbar.dll mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\documents and settings\deathsoul\vha.exe \s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programfiler\fellesfiler\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\programfiler\askbardis\bar\bin\askBar.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\programfiler\avg\avg8\avgssie.dll BHO: Påloggingshjelp for Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\programfiler\fellesfiler\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\programfiler\avg\avg8\toolbar\IEToolbar.dll BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\programfiler\aim toolbar\aimtb.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programfiler\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programfiler\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\programfiler\daemon tools toolbar\DTToolbar.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\programfiler\askbardis\bar\bin\askBar.dll TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\programfiler\aim toolbar\aimtb.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\programfiler\avg\avg8\toolbar\IEToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [msnmsgr] "c:\programfiler\windows live\messenger\msnmsgr.exe" /background uRun: [DAEMON Tools Lite] "c:\programfiler\daemon tools lite\daemon.exe" -autorun uRun: [MSMSGS] "c:\programfiler\messenger\msmsgs.exe" /background uRun: [Aim6] "c:\programfiler\aim6\aim6.exe" /d locale=en-US ee://aol/imApp mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [GEST] m‘|\ü mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [StartCCC] "c:\programfiler\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [WinampAgent] c:\programfiler\winamp\winampa.exe mRun: [Adobe Reader Speed Launcher] "c:\programfiler\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\programfiler\java\jre6\bin\jusched.exe" mRun: [SyGateManager] c:\programfiler\sygate\son\Sygate.exe mRun: [udkydc] c:\windows\system32\udkydc.exe \u mRun: [Manage Program Gateway] c:\windows\system32\mspgw.exe dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\start-~1\progra~1\oppstart\ralink wireless utility.lnk - c:\programfiler\ralink\common\RaUI.exe StartupFolder: c:\docume~1\alluse~1\start-~1\progra~1\oppstart\window~1.lnk - c:\programfiler\windows desktop search\WindowsSearch.exe IE: &AIM; Toolbar Search - c:\documents and settings\all users\programdata\aim toolbar\ietoolbar\resources\en-us\local\search.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\programfiler\icq6.5\ICQ.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programfiler\messenger\msmsgs.exe IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\programfiler\aim toolbar\aimtb.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1234912479235 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\programfiler\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\felles~1\skype\SKYPE4~1.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\programfiler\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\deaths~1\progra~1\mozilla\firefox\profiles\4y19whb4.default\ FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;= FF - prefs.js: browser.search.selectedEngine - AIM Search FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;= FF - component: c:\programfiler\avg\avg8\firefox\components\avgssff.dll FF - component: c:\programfiler\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\programfiler\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\programfiler\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\programfiler\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - component: c:\programfiler\daemon tools toolbar\firefoxdtt\components\DTToolbarFF.dll FF - plugin: c:\progra~1\sony online entertainment\npsoe.dll FF - plugin: c:\programfiler\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\programfiler\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\programfiler\viewpoint\viewpoint media player\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\programfiler\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\programfiler\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\programfiler\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); ============= SERVICES / DRIVERS =============== R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2009-2-24 39472] R0 Wsdrv;SyGate for NT, Wsdrv;\SystemRoot\\SystemRoot\SYSTEM32\Drivers\Wsdrv.sys –> \SystemRoot\\SystemRoot\SYSTEM32\Drivers\Wsdrv.sys [?] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-2-18 335752] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-2-18 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-18 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-2-18 907032] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-2-18 298776] R2 SaService;SyGateService;c:\programfiler\sygate\son\Sgserv.exe [2009-7-12 176128] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\programfiler\viewpoint\common\ViewpointService.exe [2009-5-28 24652] R2 Wg1n;SyGate for NT, Wg1n;c:\windows\system32\drivers\Wg1n.sys [2009-7-12 8023] R2 Wg2n;SyGate for NT, Wg2n;c:\windows\system32\drivers\Wg2n.sys [2009-7-12 8023] R2 wg8n;SyGate for NT, wg8n;c:\windows\system32\drivers\wg8n.sys [2009-7-12 7309] R2 wg9n;SyGate for NT, wg9n;c:\windows\system32\drivers\wg9n.sys [2009-7-12 7309] R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-2-17 93184] R3 P1130VID;Creative WebCam NX Pro;c:\windows\system32\drivers\P1130Vid.sys [2009-6-28 90229] R3 portio32;portio32;c:\windows\system32\drivers\portio32.sys [2009-5-28 2048] S3 ZD1211BU(3COM Corporation);3Com OfficeConnect Wireless 54Mbps 11g Compact USB Adapter(3COM Corporation);c:\windows\system32\drivers\ZD1211BU.sys [2009-2-17 402944] =============== Created Last 30 ================ 2009-07-19 11:14 58,368 a——- c:\windows\system32\86483.exe 2009-07-19 11:13 58,368 a——- c:\windows\system32\578110.exe 2009-07-19 11:11 58,368 a——- c:\windows\system32\18195.exe 2009-07-19 08:25 58,368 a——- c:\windows\system32\51399.exe 2009-07-19 08:22 58,368 a——- c:\windows\system32\82332.exe 2009-07-19 08:19 58,368 a——- c:\windows\system32\988516.exe 2009-07-19 08:18 58,368 a——- c:\windows\system32\651420.exe 2009-07-19 08:15 58,368 a——- c:\windows\system32\621713.exe 2009-07-19 08:12 58,368 a——- c:\windows\system32\494157.exe 2009-07-19 08:10 58,368 a——- c:\windows\system32\56928.exe 2009-07-19 08:05 58,368 a——- c:\windows\system32\43947.exe 2009-07-19 08:04 58,368 a——- c:\windows\system32\803445.exe 2009-07-19 08:01 58,368 a——- c:\windows\system32\77746.exe 2009-07-19 07:59 58,368 a——- c:\windows\system32\496828.exe 2009-07-19 07:58 58,368 a——- c:\windows\system32\479683.exe 2009-07-19 07:57 58,368 a——- c:\windows\system32\52305.exe 2009-07-19 07:56 58,368 a——- c:\windows\system32\889876.exe 2009-07-19 07:54 58,368 a——- c:\windows\system32\63553.exe 2009-07-19 07:53 58,368 a——- c:\windows\system32\626377.exe 2009-07-19 07:52 58,368 a——- c:\windows\system32\969629.exe 2009-07-19 07:47 58,368 a——- c:\windows\system32\962495.exe 2009-07-19 07:45 58,368 a——- c:\windows\system32\965221.exe 2009-07-19 07:45 58,368 a——- c:\windows\system32\632328.exe 2009-07-19 07:44 58,368 a——- c:\windows\system32\787165.exe 2009-07-19 07:42 58,368 a——- c:\windows\system32\661711.exe 2009-07-19 07:41 58,368 a——- c:\windows\system32\78563.exe 2009-07-19 07:40 58,368 a——- c:\windows\system32\751243.exe 2009-07-19 07:38 58,368 a——- c:\windows\system32\652933.exe 2009-07-19 07:37 58,368 a——- c:\windows\system32\794141.exe 2009-07-19 07:35 58,368 a——- c:\windows\system32\807171.exe 2009-07-19 07:35 58,368 a——- c:\windows\system32\535290.exe 2009-07-19 07:30 58,368 a——- c:\windows\system32\892048.exe 2009-07-19 07:28 58,368 a——- c:\windows\system32\723727.exe 2009-07-19 07:27 58,368 a——- c:\windows\system32\913923.exe 2009-07-19 07:24 58,368 a——- c:\windows\system32\548727.exe 2009-07-19 07:23 58,368 a——- c:\windows\system32\998883.exe 2009-07-19 07:20 58,368 a——- c:\windows\system32\68267.exe 2009-07-19 07:17 58,368 a——- c:\windows\system32\413248.exe 2009-07-19 07:15 58,368 a——- c:\windows\system32\53895.exe 2009-07-19 07:14 58,368 a——- c:\windows\system32\789929.exe 2009-07-19 07:11 58,368 a——- c:\windows\system32\877838.exe 2009-07-19 07:10 58,368 a——- c:\windows\system32\739260.exe 2009-07-19 07:08 58,368 a——- c:\windows\system32\992194.exe 2009-07-19 07:07 58,368 a——- c:\windows\system32\691078.exe 2009-07-19 07:05 58,368 a——- c:\windows\system32\895686.exe 2009-07-19 07:04 58,368 a——- c:\windows\system32\892880.exe 2009-07-19 07:02 58,368 a——- c:\windows\system32\961243.exe 2009-07-19 07:01 58,368 a——- c:\windows\system32\938495.exe 2009-07-19 06:58 58,368 a——- c:\windows\system32\65926.exe 2009-07-19 06:57 58,368 a——- c:\windows\system32\879324.exe 2009-07-19 06:56 58,368 a——- c:\windows\system32\938518.exe 2009-07-19 06:54 58,368 a——- c:\windows\system32\783820.exe 2009-07-19 06:53 58,368 a——- c:\windows\system32\936614.exe 2009-07-19 06:51 58,368 a——- c:\windows\system32\56960.exe 2009-07-19 06:48 58,368 a——- c:\windows\system32\787942.exe 2009-07-19 06:47 58,368 a——- c:\windows\system32\822052.exe 2009-07-19 06:45 58,368 a——- c:\windows\system32\998775.exe 2009-07-19 06:44 58,368 a——- c:\windows\system32\717444.exe 2009-07-19 06:43 58,368 a——- c:\windows\system32\465758.exe 2009-07-19 06:41 58,368 a——- c:\windows\system32\456053.exe 2009-07-19 06:39 58,368 a——- c:\windows\system32\6421.exe 2009-07-19 06:36 58,368 a——- c:\windows\system32\826120.exe 2009-07-19 06:33 58,368 a——- c:\windows\system32\822615.exe 2009-07-19 06:32 58,368 a——- c:\windows\system32\695523.exe 2009-07-19 06:31 58,368 a——- c:\windows\system32\648068.exe 2009-07-19 06:29 58,368 a——- c:\windows\system32\501377.exe 2009-07-19 06:26 58,368 a——- c:\windows\system32\678063.exe 2009-07-19 06:24 58,368 a——- c:\windows\system32\50316.exe 2009-07-19 06:21 58,368 a——- c:\windows\system32\723563.exe 2009-07-19 06:20 58,368 a——- c:\windows\system32\987784.exe 2009-07-19 06:19 58,368 a——- c:\windows\system32\547451.exe 2009-07-19 06:18 58,368 a——- c:\windows\system32\865521.exe 2009-07-19 06:17 58,368 a——- c:\windows\system32\978626.exe 2009-07-19 06:16 58,368 a——- c:\windows\system32\537885.exe 2009-07-19 06:12 58,368 a——- c:\windows\system32\42799.exe 2009-07-19 06:11 58,368 a——- c:\windows\system32\582838.exe 2009-07-19 06:10 58,368 a——- c:\windows\system32\682792.exe 2009-07-19 06:09 58,368 a——- c:\windows\system32\83025.exe 2009-07-19 06:01 58,368 a——- c:\windows\system32\983520.exe 2009-07-19 06:00 58,368 a——- c:\windows\system32\604358.exe 2009-07-19 05:57 58,368 a——- c:\windows\system32\641422.exe 2009-07-19 05:56 58,368 a——- c:\windows\system32\908344.exe 2009-07-19 05:55 58,368 a——- c:\windows\system32\76490.exe 2009-07-19 05:54 58,368 a——- c:\windows\system32\732999.exe 2009-07-19 05:53 58,368 a——- c:\windows\system32\54322.exe 2009-07-19 05:51 58,368 a——- c:\windows\system32\532745.exe 2009-07-19 05:47 58,368 a——- c:\windows\system32\549750.exe 2009-07-19 05:46 58,368 a——- c:\windows\system32\5271.exe 2009-07-19 05:45 58,368 a——- c:\windows\system32\576493.exe 2009-07-19 05:44 58,368 a——- c:\windows\system32\94538.exe 2009-07-19 05:42 58,368 a——- c:\windows\system32\755675.exe 2009-07-19 05:39 58,368 a——- c:\windows\system32\803079.exe 2009-07-19 05:36 58,368 a——- c:\windows\system32\6599.exe 2009-07-19 05:35 58,368 a——- c:\windows\system32\879025.exe 2009-07-19 05:33 58,368 a——- c:\windows\system32\477051.exe 2009-07-19 05:28 58,368 a——- c:\windows\system32\68227.exe 2009-07-19 05:26 58,368 a——- c:\windows\system32\76916.exe 2009-07-19 05:25 58,368 a——- c:\windows\system32\908669.exe 2009-07-19 05:24 58,368 a——- c:\windows\system32\442513.exe 2009-07-19 05:23 58,368 a——- c:\windows\system32\753442.exe 2009-07-19 05:22 58,368 a——- c:\windows\system32\908530.exe 2009-07-19 05:21 58,368 a——- c:\windows\system32\577374.exe 2009-07-19 05:20 58,368 a——- c:\windows\system32\886962.exe 2009-07-19 05:19 58,368 a——- c:\windows\system32\418383.exe 2009-07-19 05:17 58,368 a——- c:\windows\system32\727858.exe 2009-07-19 05:15 58,368 a——- c:\windows\system32\668960.exe 2009-07-19 05:13 58,368 a——- c:\windows\system32\605373.exe 2009-07-19 05:11 58,368 a——- c:\windows\system32\457092.exe 2009-07-19 05:09 58,368 a——- c:\windows\system32\783141.exe 2009-07-19 05:06 58,368 a——- c:\windows\system32\555286.exe 2009-07-19 05:05 58,368 a——- c:\windows\system32\857654.exe 2009-07-19 04:59 58,368 a——- c:\windows\system32\566531.exe 2009-07-19 04:57 58,368 a——- c:\windows\system32\53827.exe 2009-07-19 04:56 58,368 a——- c:\windows\system32\732545.exe 2009-07-19 04:55 58,368 a——- c:\windows\system32\474053.exe 2009-07-19 04:54 58,368 a——- c:\windows\system32\98846.exe 2009-07-19 04:53 58,368 a——- c:\windows\system32\584632.exe 2009-07-19 04:51 58,368 a——- c:\windows\system32\702238.exe 2009-07-19 04:50 58,368 a——- c:\windows\system32\979078.exe 2009-07-19 04:49 58,368 a——- c:\windows\system32\52020.exe 2009-07-19 04:48 58,368 a——- c:\windows\system32\6628.exe 2009-07-19 04:47 58,368 a——- c:\windows\system32\836740.exe 2009-07-19 04:46 58,368 a——- c:\windows\system32\466477.exe 2009-07-19 04:40 58,368 a——- c:\windows\system32\708676.exe 2009-07-19 04:38 58,368 a——- c:\windows\system32\479072.exe 2009-07-19 04:36 58,368 a——- c:\windows\system32\64623.exe 2009-07-19 04:34 58,368 a——- c:\windows\system32\55548.exe 2009-07-19 04:32 58,368 a——- c:\windows\system32\768641.exe 2009-07-19 04:32 58,368 a——- c:\windows\system32\889955.exe 2009-07-19 04:29 58,368 a——- c:\windows\system32\652372.exe 2009-07-19 04:27 58,368 a——- c:\windows\system32\499739.exe 2009-07-19 04:26 58,368 a——- c:\windows\system32\765416.exe 2009-07-19 04:25 58,368 a——- c:\windows\system32\79259.exe 2009-07-19 04:24 58,368 a——- c:\windows\system32\883527.exe 2009-07-19 04:23 58,368 a——- c:\windows\system32\904920.exe 2009-07-19 04:22 58,368 a——- c:\windows\system32\415651.exe 2009-07-19 04:21 58,368 a——- c:\windows\system32\499070.exe 2009-07-19 04:20 58,368 a——- c:\windows\system32\44687.exe 2009-07-19 04:19 58,368 a——- c:\windows\system32\75826.exe 2009-07-19 04:14 58,368 a——- c:\windows\system32\48240.exe 2009-07-19 04:10 58,368 a——- c:\windows\system32\923268.exe 2009-07-19 04:09 58,368 a——- c:\windows\system32\826897.exe 2009-07-19 04:08 58,368 a——- c:\windows\system32\72422.exe 2009-07-19 04:07 58,368 a——- c:\windows\system32\734410.exe 2009-07-19 04:06 58,368 a——- c:\windows\system32\611424.exe 2009-07-19 04:04 58,368 a——- c:\windows\system32\933962.exe 2009-07-19 04:03 58,368 a——- c:\windows\system32\863239.exe 2009-07-19 04:02 58,368 a——- c:\windows\system32\59358.exe 2009-07-19 04:01 58,368 a——- c:\windows\system32\631689.exe 2009-07-19 03:55 58,368 a——- c:\windows\system32\897353.exe 2009-07-19 03:53 58,368 a——- c:\windows\system32\453872.exe 2009-07-19 03:52 58,368 a——- c:\windows\system32\95058.exe 2009-07-19 03:50 58,368 a——- c:\windows\system32\7674.exe 2009-07-19 03:49 58,368 a——- c:\windows\system32\976824.exe 2009-07-19 03:41 58,368 a——- c:\windows\system32\922018.exe 2009-07-19 03:40 58,368 a——- c:\windows\system32\6770.exe 2009-07-19 03:38 58,368 a——- c:\windows\system32\68869.exe 2009-07-19 03:28 58,368 a——- c:\windows\system32\759792.exe 2009-07-19 03:27 58,368 a——- c:\windows\system32\849673.exe 2009-07-19 03:26 58,368 a——- c:\windows\system32\765867.exe 2009-07-19 03:23 –d—– c:\programfiler\Trend Micro 2009-07-19 02:16 32,913,408 a——- c:\windows\system32\mspgw.exe 2009-07-18 12:20 30,208 a——- c:\windows\system32\udkydc.exe 2009-07-18 12:20 30,208 —-h— c:\documents and settings\deathsoul\vha.exe 2009-07-18 12:20 10 a——- c:\windows\system32\kr_done1 2009-07-13 00:14 –d—– c:\programfiler\TVersity Codec Pack 2009-07-13 00:14 –d—– c:\programfiler\TVersity 2009-07-12 21:15 13,224 a——- c:\windows\DhcpClient.dat 2009-07-12 21:06 529,394 a——- c:\windows\system32\drivers\Wsdrv.sys 2009-07-12 21:06 150 a——- c:\windows\ODBC.INI 2009-07-12 21:06 8,023 a——- c:\windows\system32\drivers\wg6n.sys 2009-07-12 21:06 7,309 a——- c:\windows\system32\drivers\wg9n.sys 2009-07-12 21:06 7,309 a——- c:\windows\system32\drivers\wg8n.sys 2009-07-12 21:06 8,023 a——- c:\windows\system32\drivers\wg5n.sys 2009-07-12 21:06 8,023 a——- c:\windows\system32\drivers\wg4n.sys 2009-07-12 21:06 8,023 a——- c:\windows\system32\drivers\Wg2n.sys 2009-07-12 21:06 8,023 a——- c:\windows\system32\drivers\Wg1n.sys 2009-07-12 21:06 –d—– c:\programfiler\Sygate 2009-07-11 13:03 –d—– c:\programfiler\Thoosje Vista Sidebar 2009-07-08 01:55 41,808 a——- c:\windows\system32\xfcodec.dll 2009-06-29 18:28 –d—– C:\Program Files 2009-06-28 15:55 5,504 ac—— c:\windows\system32\dllcache\mstee.sys 2009-06-28 15:55 5,504 a——- c:\windows\system32\drivers\MSTEE.sys 2009-06-28 15:55 10,880 ac—— c:\windows\system32\dllcache\ndisip.sys 2009-06-28 15:55 10,880 a——- c:\windows\system32\drivers\NdisIP.sys 2009-06-28 15:55 16,384 ac—— c:\windows\system32\dllcache\ipsink.ax 2009-06-28 15:55 15,232 ac—— c:\windows\system32\dllcache\streamip.sys 2009-06-28 15:55 16,384 a——- c:\windows\system32\ipsink.ax 2009-06-28 15:55 15,232 a——- c:\windows\system32\drivers\StreamIP.sys 2009-06-28 15:55 11,136 ac—— c:\windows\system32\dllcache\slip.sys 2009-06-28 15:55 11,136 a——- c:\windows\system32\drivers\SLIP.sys 2009-06-28 15:55 19,200 ac—— c:\windows\system32\dllcache\wstcodec.sys 2009-06-28 15:55 19,200 a——- c:\windows\system32\drivers\WSTCODEC.SYS ==================== Find3M ==================== 2009-07-07 08:36 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-16 16:43 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 16:43 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 21:11 1,294,336 a——- c:\windows\system32\quartz.dll 2009-05-25 00:24 350,208 a——- c:\windows\system32\mssph.dll 2009-05-19 08:49 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-05-13 07:06 915,456 a——- c:\windows\system32\wininet.dll 2009-05-12 15:12 26,144 a——- c:\windows\system32\spupdsvc.exe 2009-05-07 17:34 346,112 a——- c:\windows\system32\localspl.dll 2009-02-25 03:31 32,768 a–sh— c:\windows\system32\config\systemprofile\lokale innstillinger\logg\history.ie5\mshist012009021620090223\index.dat 2009-02-25 03:31 32,768 a–sh— c:\windows\system32\config\systemprofile\lokale innstillinger\logg\history.ie5\mshist012009022520090226\index.dat ============= FINISH: 11:16:19,17 =============== —– UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 07.05.2005 17:24:05 System Uptime: 19.07.2009 11:09:44 (0 hours ago) Motherboard: Gigabyte Technology Co., Ltd. | | GA-MA790X-DS4 Processor: AMD Phenom™ 9950 Quad-Core Processor | Socket M2 | 2611/200mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 29 GiB total, 15,181 GiB free. D: is FIXED (NTFS) - 298 GiB total, 33,36 GiB free. E: is FIXED (NTFS) - 298 GiB total, 8,135 GiB free. F: is FIXED (NTFS) - 157 GiB total, 11,052 GiB free. G: is CDROM () H: is FIXED (NTFS) - 466 GiB total, 402,439 GiB free. I: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: MAC Bridge Miniport Device ID: ROOT\MS_BRIDGEMP\0000 Manufacturer: Microsoft Name: MAC Bridge Miniport PNP Device ID: ROOT\MS_BRIDGEMP\0000 Service: BridgeMP ==== System Restore Points =================== RP108: 13.05.2009 05:51:02 - Kontrollpunkt for system RP109: 14.05.2009 06:51:03 - Kontrollpunkt for system RP110: 14.05.2009 15:17:04 - Software Distribution Service 3.0 RP111: 18.05.2009 08:11:18 - Kontrollpunkt for system RP112: 19.05.2009 08:35:31 - Kontrollpunkt for system RP113: 19.05.2009 08:47:22 - Avg8 Update RP114: 19.05.2009 08:49:12 - Avg8 Update RP115: 20.05.2009 09:41:25 - Kontrollpunkt for system RP116: 21.05.2009 10:40:20 - Kontrollpunkt for system RP117: 22.05.2009 11:40:20 - Kontrollpunkt for system RP118: 23.05.2009 12:15:33 - Kontrollpunkt for system RP119: 24.05.2009 14:27:33 - Kontrollpunkt for system RP120: 25.05.2009 15:15:32 - Kontrollpunkt for system RP121: 26.05.2009 15:53:07 - Kontrollpunkt for system RP122: 28.05.2009 03:47:22 - Installering av usignert driver RP123: 29.05.2009 01:17:44 - Software Distribution Service 3.0 RP124: 30.05.2009 16:48:01 - Kontrollpunkt for system RP125: 31.05.2009 22:40:30 - Kontrollpunkt for system RP126: 02.06.2009 00:47:00 - Kontrollpunkt for system RP127: 03.06.2009 03:31:23 - Kontrollpunkt for system RP128: 04.06.2009 04:00:46 - Kontrollpunkt for system RP129: 05.06.2009 05:00:46 - Kontrollpunkt for system RP130: 06.06.2009 14:24:09 - Kontrollpunkt for system RP131: 07.06.2009 14:55:17 - Kontrollpunkt for system RP132: 08.06.2009 15:02:02 - Kontrollpunkt for system RP133: 09.06.2009 17:46:10 - Kontrollpunkt for system RP134: 11.06.2009 03:45:51 - Kontrollpunkt for system RP135: 11.06.2009 21:31:24 - Software Distribution Service 3.0 RP136: 12.06.2009 09:47:18 - Avg8 Update RP137: 12.06.2009 09:48:00 - Avg8 Update RP138: 13.06.2009 21:03:56 - Kontrollpunkt for system RP139: 14.06.2009 21:41:38 - Kontrollpunkt for system RP140: 16.06.2009 01:37:57 - Kontrollpunkt for system RP141: 17.06.2009 02:26:45 - Kontrollpunkt for system RP142: 17.06.2009 08:12:12 - Avg8 Update RP143: 17.06.2009 08:12:47 - Avg8 Update RP144: 18.06.2009 08:42:27 - Kontrollpunkt for system RP145: 19.06.2009 11:09:08 - Kontrollpunkt for system RP146: 22.06.2009 02:51:49 - Kontrollpunkt for system RP147: 23.06.2009 03:51:08 - Kontrollpunkt for system RP148: 24.06.2009 21:01:23 - Kontrollpunkt for system RP149: 26.06.2009 01:36:31 - Kontrollpunkt for system RP150: 27.06.2009 09:02:35 - Avg8 Update RP151: 28.06.2009 18:27:56 - Kontrollpunkt for system RP152: 29.06.2009 20:12:32 - Kontrollpunkt for system RP153: 30.06.2009 21:51:02 - Kontrollpunkt for system RP154: 30.06.2009 22:31:12 - Software Distribution Service 3.0 RP155: 01.07.2009 22:59:05 - Kontrollpunkt for system RP156: 02.07.2009 23:59:05 - Kontrollpunkt for system RP157: 04.07.2009 01:46:39 - Kontrollpunkt for system RP158: 05.07.2009 02:12:16 - Kontrollpunkt for system RP159: 07.07.2009 08:36:15 - Avg8 Update RP160: 07.07.2009 08:37:07 - Avg8 Update RP161: 08.07.2009 08:31:41 - Avg8 Update RP162: 09.07.2009 08:45:19 - Kontrollpunkt for system RP163: 11.07.2009 01:16:46 - Kontrollpunkt for system RP164: 12.07.2009 01:49:28 - Kontrollpunkt for system RP165: 13.07.2009 02:21:56 - Kontrollpunkt for system RP166: 14.07.2009 03:03:33 - Kontrollpunkt for system RP167: 15.07.2009 04:03:33 - Kontrollpunkt for system RP168: 16.07.2009 05:03:33 - Kontrollpunkt for system RP169: 17.07.2009 06:03:33 - Kontrollpunkt for system RP170: 18.07.2009 06:49:56 - Kontrollpunkt for system RP171: 18.07.2009 12:54:54 - Software Distribution Service 3.0 ==== Installed Programs ====================== abgx360 v1.0.1 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.1.2 - Norsk AIM 6 AIM Toolbar AMD Processor Driver Ask Toolbar ATI - Software Uninstall Utility ATI AVIVO Codecs ATI Catalyst Control Center ATI Display Driver ATI HYDRAVISION ATI Parental Control & Encoder ATI Problem Report Wizard µTorrent Audacity 1.2.6 AVG Free 8.5 Browser Configuration Utility Burnout™ Paradise The Ultimate Box Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center HydraVision Full ccc-core-preinstall ccc-core-static ccc-utility CCC Help English Choice Guard Creative WebCam NX Pro Driver (1.03.03.0326) Curse Client CuteFTP 8 Professional DAEMON Tools Toolbar Download Updater (AOL LLC) Fraps (remove only) Free Realms Installer High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB915800-v4) Hotfix for Windows XP (KB954550-v5) Hurtigreparasjon for Windows Media Player 11 (KB939683) Hurtigreparasjon for Windows XP (KB952287) Hurtigreparasjon for Windows XP (KB961118) ICQ6.5 ImgBurn Java™ 6 Update 13 Kritisk oppdatering for Windows Media Player 11 (KB959772) Left 4 Dead Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 1.1 Norwegian Language Pack Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - NOR Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - NOR Microsoft .NET Framework 3.5 Language Pack SP1 - nor Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Base Smart Card Cryptographic Service Provider-pakke Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 Redistributable mIRC Mozilla Firefox (3.0.11) MSVCRT Nero 6 Enterprise Edition NNScript Oppdatering for Windows Internet Explorer 8 (KB971180) Oppdatering for Windows XP (KB943729) Oppdatering for Windows XP (KB951978) Oppdatering for Windows XP (KB955839) Oppdatering for Windows XP (KB961503) Oppdatering for Windows XP (KB967715) Opplastingsverktøy for Windows Live Paragon Drive Backup 8.51 Professional Trial Paragon Partition Manager 9.0 Professional Påloggingsassistent for Windows Live Ralink Wireless LAN Card RapidShare Manager REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver Security Update for Windows Search 4 - KB963093 Segoe UI Sikkerhetsoppdatering for Windows Internet Explorer 7 (KB938127-v2) Sikkerhetsoppdatering for Windows Internet Explorer 7 (KB956390) Sikkerhetsoppdatering for Windows Internet Explorer 7 (KB961260) Sikkerhetsoppdatering for Windows Internet Explorer 7 (KB963027) Sikkerhetsoppdatering for Windows Internet Explorer 8 (KB969897) Sikkerhetsoppdatering for Windows Media Player (KB952069) Sikkerhetsoppdatering for Windows Media Player 11 (KB936782) Sikkerhetsoppdatering for Windows Media Player 11 (KB954154) Sikkerhetsoppdatering for Windows XP (KB923561) Sikkerhetsoppdatering for Windows XP (KB923789) Sikkerhetsoppdatering for Windows XP (KB938464-v2) Sikkerhetsoppdatering for Windows XP (KB938464) Sikkerhetsoppdatering for Windows XP (KB941569) Sikkerhetsoppdatering for Windows XP (KB946648) Sikkerhetsoppdatering for Windows XP (KB950760) Sikkerhetsoppdatering for Windows XP (KB950762) Sikkerhetsoppdatering for Windows XP (KB950974) Sikkerhetsoppdatering for Windows XP (KB951066) Sikkerhetsoppdatering for Windows XP (KB951376-v2) Sikkerhetsoppdatering for Windows XP (KB951698) Sikkerhetsoppdatering for Windows XP (KB951748) Sikkerhetsoppdatering for Windows XP (KB952004) Sikkerhetsoppdatering for Windows XP (KB952954) Sikkerhetsoppdatering for Windows XP (KB954211) Sikkerhetsoppdatering for Windows XP (KB954459) Sikkerhetsoppdatering for Windows XP (KB954600) Sikkerhetsoppdatering for Windows XP (KB955069) Sikkerhetsoppdatering for Windows XP (KB956572) Sikkerhetsoppdatering for Windows XP (KB956802) Sikkerhetsoppdatering for Windows XP (KB956803) Sikkerhetsoppdatering for Windows XP (KB956841) Sikkerhetsoppdatering for Windows XP (KB957097) Sikkerhetsoppdatering for Windows XP (KB958215) Sikkerhetsoppdatering for Windows XP (KB958644) Sikkerhetsoppdatering for Windows XP (KB958687) Sikkerhetsoppdatering for Windows XP (KB958690) Sikkerhetsoppdatering for Windows XP (KB959426) Sikkerhetsoppdatering for Windows XP (KB960225) Sikkerhetsoppdatering for Windows XP (KB960714) Sikkerhetsoppdatering for Windows XP (KB960715) Sikkerhetsoppdatering for Windows XP (KB960803) Sikkerhetsoppdatering for Windows XP (KB961371) Sikkerhetsoppdatering for Windows XP (KB961373) Sikkerhetsoppdatering for Windows XP (KB961501) Sikkerhetsoppdatering for Windows XP (KB968537) Sikkerhetsoppdatering for Windows XP (KB969898) Sikkerhetsoppdatering for Windows XP (KB970238) Sikkerhetsoppdatering for Windows XP (KB971633) Sikkerhetsoppdatering for Windows XP (KB973346) Skins Skype™ 4.0 Spotify Språkpakke for Microsoft .NET Framework 3.5 SP1 - NOR Sygate Office Network (Host) TVersity Codec Pack 1.2 TVersity Media Server Pro 1.6 Beta Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Ventrilo Client VentriloMIX Viewpoint Media Player VLC media player 0.9.8a WebFldrs XP Winamp (remove only) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows Search 4.0 Windows XP Service Pack 3 WinRAR archiver Xfire (remove only) XML Paper Specification Shared Components Language Pack 1.0 XP Codec Pack ==== End Of File ===========================
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Here you go :)

ComboFix 09-07-19.01 - DeathSoul 19.07.2009 15:41.1.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.47.1044.18.3326.2452 [GMT 2:00]
Kjører fra: c:\documents and settings\DeathSoul\Skrivebord\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\08845.exe
c:\windows\system32\109624.exe
c:\windows\system32\111321.exe
c:\windows\system32\113995.exe
c:\windows\system32\126783.exe
c:\windows\system32\146347.exe
c:\windows\system32\164911.exe
c:\windows\system32\21724.exe
c:\windows\system32\218986.exe
c:\windows\system32\225210.exe
c:\windows\system32\23051.exe
c:\windows\system32\244728.exe
c:\windows\system32\251613.exe
c:\windows\system32\257465.exe
c:\windows\system32\258829.exe
c:\windows\system32\275233.exe
c:\windows\system32\279723.exe
c:\windows\system32\285454.exe
c:\windows\system32\3079.exe
c:\windows\system32\33622.exe
c:\windows\system32\35074.exe
c:\windows\system32\352221.exe
c:\windows\system32\367646.exe
c:\windows\system32\3980.exe
c:\windows\system32\417447.exe
c:\windows\system32\446714.exe
c:\windows\system32\454248.exe
c:\windows\system32\48512.exe
c:\windows\system32\491388.exe
c:\windows\system32\508468.exe
c:\windows\system32\509461.exe
c:\windows\system32\52275.exe
c:\windows\system32\528317.exe
c:\windows\system32\53256.exe
c:\windows\system32\535689.exe
c:\windows\system32\575750.exe
c:\windows\system32\63517.exe
c:\windows\system32\646296.exe
c:\windows\system32\646946.exe
c:\windows\system32\656152.exe
c:\windows\system32\666835.exe
c:\windows\system32\67382.exe
c:\windows\system32\681525.exe
c:\windows\system32\71399.exe
c:\windows\system32\747625.exe
c:\windows\system32\766028.exe
c:\windows\system32\769377.exe
c:\windows\system32\778820.exe
c:\windows\system32\797021.exe
c:\windows\system32\803112.exe
c:\windows\system32\851293.exe
c:\windows\system32\891518.exe
c:\windows\system32\908396.exe
c:\windows\system32\923158.exe
c:\windows\system32\936836.exe
c:\windows\system32\958035.exe
c:\windows\system32\984039.exe
c:\windows\system32\99631.exe
c:\windows\system32\ATIODCLI.exe
c:\windows\system32\ATIODE.exe
c:\windows\system32\kr_done1
c:\windows\system32\WgaLogon.dll

.
((((((((((((((((((((((((((( Filer Opprettet Fra 2009-06-19 til 2009-07-19 )))))))))))))))))))))))))))))))))
.

2009-07-19 01:23 . 2009-07-19 01:23 ——– d—–w- c:\programfiler\Trend Micro
2009-07-19 00:16 . 2009-07-19 00:16 32913408 —-a-w- c:\windows\system32\mspgw.exe
2009-07-12 22:14 . 2009-07-12 22:15 ——– d—–w- c:\programfiler\TVersity Codec Pack
2009-07-12 22:14 . 2009-07-12 22:14 ——– d—–w- c:\programfiler\TVersity
2009-07-12 21:09 . 2009-07-12 21:09 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-07-12 20:02 . 2008-04-14 16:22 26624 —-a-w- c:\documents and settings\LocalService\Programdata\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-07-12 19:15 . 2009-07-19 13:45 13224 —-a-w- c:\windows\DhcpClient.dat
2009-07-12 19:06 . 2002-07-24 19:02 529394 —-a-w- c:\windows\system32\drivers\Wsdrv.sys
2009-07-12 19:06 . 2002-11-15 11:31 7309 —-a-w- c:\windows\system32\drivers\wg9n.sys
2009-07-12 19:06 . 2002-11-15 11:30 7309 —-a-w- c:\windows\system32\drivers\wg8n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\wg6n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\wg5n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\wg4n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\Wg2n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\Wg1n.sys
2009-07-12 19:06 . 2009-07-12 19:06 ——– d—–w- c:\programfiler\Sygate
2009-07-11 11:03 . 2009-07-11 11:03 ——– d—–w- c:\documents and settings\DeathSoul\Lokale innstillinger\Programdata\Stardock
2009-07-11 11:03 . 2009-07-11 11:15 ——– d—–w- c:\programfiler\Thoosje Vista Sidebar
2009-07-08 06:31 . 2009-07-07 06:36 2167576 —-a-w- c:\documents and settings\All Users\Programdata\avg8\update\backup\avgresf.dll
2009-07-07 23:55 . 2009-07-07 23:55 41808 —-a-w- c:\windows\system32\xfcodec.dll
2009-06-29 16:28 . 2009-06-29 16:28 ——– d—–w- C:\Program Files
2009-06-28 13:55 . 2008-04-13 17:39 5504 -c–a-w- c:\windows\system32\dllcache\mstee.sys
2009-06-28 13:55 . 2008-04-13 17:39 5504 —-a-w- c:\windows\system32\drivers\MSTEE.sys
2009-06-28 13:55 . 2008-04-13 17:46 10880 -c–a-w- c:\windows\system32\dllcache\ndisip.sys
2009-06-28 13:55 . 2008-04-13 17:46 10880 —-a-w- c:\windows\system32\drivers\NdisIP.sys
2009-06-28 13:55 . 2008-04-13 17:46 15232 -c–a-w- c:\windows\system32\dllcache\streamip.sys
2009-06-28 13:55 . 2008-04-13 17:46 15232 —-a-w- c:\windows\system32\drivers\StreamIP.sys
2009-06-28 13:55 . 2008-04-13 17:46 11136 -c–a-w- c:\windows\system32\dllcache\slip.sys
2009-06-28 13:55 . 2008-04-13 17:46 11136 —-a-w- c:\windows\system32\drivers\SLIP.sys
2009-06-28 13:55 . 2008-04-13 17:46 19200 -c–a-w- c:\windows\system32\dllcache\wstcodec.sys
2009-06-28 13:55 . 2008-04-13 17:46 19200 —-a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2009-06-28 07:51 . 2009-06-28 07:51 ——– d—–w- c:\documents and settings\DeathSoul\Lokale innstillinger\Programdata\AVG Security Toolbar
2009-06-27 07:02 . 2009-07-07 06:36 2054424 —-a-w- c:\documents and settings\All Users\Programdata\avg8\update\backup\avgcorex.dll
2009-06-22 00:29 . 2009-06-02 11:37 1004800 —-a-w- c:\documents and settings\All Users\Programdata\AVG Security Toolbar\IEToolbar.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 12:26 . 2009-02-17 23:25 ——– d—–w- c:\documents and settings\All Users\Programdata\avg8
2009-07-19 12:21 . 2009-02-17 23:15 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\uTorrent
2009-07-19 00:53 . 2009-03-28 00:20 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\NoNameScript
2009-07-19 00:53 . 2009-03-28 00:19 ——– d—–w- c:\programfiler\mIRC
2009-07-19 00:42 . 2009-02-19 13:37 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\Skype
2009-07-18 16:45 . 2009-02-19 13:40 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\skypePM
2009-07-18 10:59 . 2009-02-18 16:50 ——– d—–w- c:\programfiler\Xfire
2009-07-18 08:47 . 2009-02-18 16:50 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\Xfire
2009-07-12 19:06 . 2009-02-17 19:34 ——– d–h–w- c:\programfiler\InstallShield Installation Information
2009-07-10 09:13 . 2009-03-28 00:19 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\mIRC
2009-07-07 06:36 . 2009-02-17 23:25 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 00:29 . 2009-06-12 07:48 ——– d—–w- c:\documents and settings\All Users\Programdata\AVG Security Toolbar
2009-06-17 06:12 . 2009-02-17 23:25 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:43 . 2004-08-03 23:03 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:43 . 2001-10-09 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-13 23:38 . 2009-06-11 18:34 ——– d—–w- c:\programfiler\PopCap Games
2009-06-12 07:48 . 2009-06-12 07:48 ——– d—–w- c:\documents and settings\LocalService\Programdata\AVGTOOLBAR
2009-06-11 21:01 . 2009-02-25 02:56 ——– d—–w- c:\programfiler\Windows Desktop Search
2009-06-04 23:14 . 2009-03-30 14:24 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\Spotify
2009-06-03 19:11 . 2004-08-03 23:03 1294336 —-a-w- c:\windows\system32\quartz.dll
2009-05-31 17:57 . 2009-02-17 23:25 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\AVGTOOLBAR
2009-05-29 15:26 . 2009-05-29 15:26 ——– d—–w- c:\programfiler\abgx360
2009-05-28 02:17 . 2009-04-07 20:19 ——– d—–w- c:\documents and settings\All Users\Programdata\DriverScanner
2009-05-28 02:17 . 2009-04-07 19:59 ——– d—–w- c:\programfiler\Uniblue
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\acccore
2009-05-28 01:57 . 2009-05-28 01:56 ——– d—–w- c:\programfiler\AIM6
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\programfiler\Fellesfiler\Software Update Utility
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\programfiler\AIM Toolbar
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\AIM Toolbar
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\programfiler\Viewpoint
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\Viewpoint
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\acccore
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\AOL OCP
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\AOL
2009-05-28 01:56 . 2009-05-28 01:56 ——– d—–w- c:\programfiler\Fellesfiler\AOL
2009-05-24 22:24 . 2008-05-26 21:18 350208 —-a-w- c:\windows\system32\mssph.dll
2009-05-20 15:11 . 2009-02-17 22:26 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\Ventrilo
2009-05-19 06:49 . 2009-02-17 23:25 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-19 06:48 . 2009-02-17 23:25 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-13 05:06 . 2004-08-03 23:03 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-12 13:12 . 2009-02-17 19:34 26144 —-a-w- c:\windows\system32\spupdsvc.exe
2009-05-07 15:34 . 2004-08-03 23:03 346112 —-a-w- c:\windows\system32\localspl.dll
2009-05-06 18:11 . 2009-05-06 18:11 69120 —-a-w- c:\documents and settings\All Users\Programdata\AIM Toolbar\ieToolbar\resources\en-US\aimtbres.dll
2009-06-13 23:02 . 2009-02-17 21:25 134648 —-a-w- c:\programfiler\mozilla firefox\components\brwsrcmp.dll
.

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\programfiler\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 15:20 279944 —-a-w- c:\programfiler\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 07:29 1004800 —-a-w- c:\programfiler\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\programfiler\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programfiler\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\programfiler\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programfiler\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\programfiler\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885400]
"DAEMON Tools Lite"="c:\programfiler\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"MSMSGS"="c:\programfiler\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\programfiler\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"StartCCC"="c:\programfiler\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"WinampAgent"="c:\programfiler\Winamp\winampa.exe" [2006-02-23 35328]
"Adobe Reader Speed Launcher"="c:\programfiler\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\programfiler\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"SyGateManager"="c:\programfiler\Sygate\SON\Sygate.exe" [2003-02-08 802816]
"Manage Program Gateway"="c:\windows\system32\mspgw.exe" [2009-07-19 32913408]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-08-26 16851456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\
Ralink Wireless Utility.lnk - c:\programfiler\RALINK\Common\RaUI.exe [2009-4-14 630784]
Windows Search.lnk - c:\programfiler\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programfiler\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-19 06:49 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\regedit.exe]
"Debugger"=0

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe]
"Debugger"=0

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programfiler\\Ventrilo\\Ventrilo.exe"=
"c:\\Programfiler\\uTorrent\\uTorrent.exe"=
"c:\\Programfiler\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programfiler\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programfiler\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programfiler\\Xfire\\Xfire.exe"=
"c:\\Programfiler\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\World of Warcraft\\Wow.exe"=
"f:\\Installed games\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutLauncher.exe"=
"f:\\Installed games\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutConfigTool.exe"=
"f:\\Installed games\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutParadise.exe"=
"f:\\Installed games\\Steam\\steamapps\\deathsoul234\\counter-strike source\\hl2.exe"=
"c:\\Programfiler\\mIRC\\mirc.exe"=
"c:\\Programfiler\\Spotify\\spotify.exe"=
"c:\\Programfiler\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programfiler\\ICQ6.5\\ICQ.exe"=
"e:\\World of Warcraft\\Launcher.exe"=
"c:\\Programfiler\\Curse\\CurseClient.exe"=
"f:\\Installed games\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Programfiler\\Fellesfiler\\AOL\\Loader\\aolload.exe"=
"c:\\Programfiler\\AIM6\\aim6.exe"=
"c:\\Programfiler\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Programfiler\\Skype\\Phone\\Skype.exe"=

R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [24.02.2009 00:48 39472]
R0 Wsdrv;SyGate for NT, Wsdrv;\SystemRoot\\SystemRoot\SYSTEM32\Drivers\Wsdrv.sys –> \SystemRoot\\SystemRoot\SYSTEM32\Drivers\Wsdrv.sys [?]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18.02.2009 01:25 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18.02.2009 01:25 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [18.02.2009 01:25 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [18.02.2009 01:25 298776]
R2 SaService;SyGateService;c:\programfiler\Sygate\SON\Sgserv.exe [12.07.2009 21:06 176128]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\programfiler\Viewpoint\Common\ViewpointService.exe [28.05.2009 03:57 24652]
R2 Wg1n;SyGate for NT, Wg1n;c:\windows\system32\drivers\Wg1n.sys [12.07.2009 21:06 8023]
R2 Wg2n;SyGate for NT, Wg2n;c:\windows\system32\drivers\Wg2n.sys [12.07.2009 21:06 8023]
R2 wg8n;SyGate for NT, wg8n;c:\windows\system32\drivers\wg8n.sys [12.07.2009 21:06 7309]
R2 wg9n;SyGate for NT, wg9n;c:\windows\system32\drivers\wg9n.sys [12.07.2009 21:06 7309]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [17.02.2009 21:46 93184]
R3 P1130VID;Creative WebCam NX Pro;c:\windows\system32\drivers\P1130Vid.sys [28.06.2009 15:54 90229]
R3 portio32;portio32;c:\windows\system32\drivers\portio32.sys [28.05.2009 01:35 2048]
S3 ZD1211BU(3COM Corporation);3Com OfficeConnect Wireless 54Mbps 11g Compact USB Adapter(3COM Corporation);c:\windows\system32\drivers\ZD1211BU.sys [17.02.2009 22:51 402944]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Tilleggsskanning ——-
.
uStart Page = about:blank
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Programdata\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
FF - ProfilePath - c:\documents and settings\DeathSoul\Programdata\Mozilla\Firefox\Profiles\4y19whb4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\programfiler\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\programfiler\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\programfiler\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\programfiler\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\programfiler\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\programfiler\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - component: c:\programfiler\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\progra~1\Sony Online Entertainment\npsoe.dll
FF - plugin: c:\programfiler\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\programfiler\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\programfiler\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\programfiler\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-19 15:45
Windows 5.1.2600 Service Pack 3 NTFS

skanner skjulte prosesser …

skanner skjulte autostart-oppføringer …

skanner skjulte filer …

skanning vellykket
skjulte filer: 0

**************************************************************************
.
——————— DLL'er Lastet Av Kjørende Prosesser ———————

- - - - - - - > 'winlogon.exe'(996)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(4072)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Andre Kjørende Prosesser ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\programfiler\Java\jre6\bin\jqs.exe
c:\windows\system32\searchindexer.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\programfiler\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\programfiler\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\programfiler\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\programfiler\Internet Explorer\iexplore.exe
c:\programfiler\Internet Explorer\iexplore.exe
c:\programfiler\AIM Toolbar\aimtbServer.exe
.
**************************************************************************
.
Tidspunkt ferdig: 2009-07-19 15:48 - maskinen ble startet på nytt
ComboFix-quarantined-files.txt 2009-07-19 13:48

Pre-Run: 16 114 327 552 byte ledig
Post-Run: 16 840 822 784 byte ledig

WindowsXP-KB310994-SP2-Pro-BootDisk-NOR.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

332 — E O F — 2009-07-18 10:57

Attachments:

Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Win32_Heur_dropper_virus_t105319.html&view=findpost&p=579656#entry579656

Collect::
c:\windows\system32\mspgw.exe

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
Hi,


I would like you to upload a couple of the deleted files for me for analysis:

Please do the following:

Open notepad and copy/paste the text inside the codebox below into it:

@echo off
for %%g in (
C:\Qoobox\Quarantine\c\windows\system32\ATIODCLI.exe.vir
C:\Qoobox\Quarantine\c\windows\system32\ATIODE.exe.vir
) do zip Files_for_submission %%g
del %0

Save this as zip.bat
Choose to "Save type as - All Files"
Save it on your desktop.

It should look like this: [external image: Posted Image]

A file, Files_for_submission.zip will be created on your desktop.

Please upload that file here –> http://www.bleepingcomputer.com/submit-malware.php?channel=4

Please let me know that it was successfully uploaded

Thank-you

~CB
Kapersky online scan is still ongoing (15hours now) will post that one when it get's done sometime :)
I also tried making that bat file you requested, but there's no " Files_for_submission.zip" after running the bat file sadly.



ComboFix 09-07-19.01 - DeathSoul 19.07.2009 16:13.2.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.47.1044.18.3326.2660 [GMT 2:00]
Kjører fra: c:\documents and settings\DeathSoul\Skrivebord\ComboFix.exe
Command switches brukt :: c:\documents and settings\DeathSoul\Skrivebord\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\windows\system32\mspgw.exe
.

((((((((((((((((((((((((((((((((((((((( Andre slettinger )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\mspgw.exe

.
((((((((((((((((((((((((((( Filer Opprettet Fra 2009-06-19 til 2009-07-19 )))))))))))))))))))))))))))))))))
.

2009-07-19 01:23 . 2009-07-19 01:23 ——– d—–w- c:\programfiler\Trend Micro
2009-07-12 22:14 . 2009-07-12 22:15 ——– d—–w- c:\programfiler\TVersity Codec Pack
2009-07-12 22:14 . 2009-07-12 22:14 ——– d—–w- c:\programfiler\TVersity
2009-07-12 21:09 . 2009-07-12 21:09 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-07-12 20:02 . 2008-04-14 16:22 26624 —-a-w- c:\documents and settings\LocalService\Programdata\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-07-12 19:15 . 2009-07-19 13:45 13224 —-a-w- c:\windows\DhcpClient.dat
2009-07-12 19:06 . 2002-07-24 19:02 529394 —-a-w- c:\windows\system32\drivers\Wsdrv.sys
2009-07-12 19:06 . 2002-11-15 11:31 7309 —-a-w- c:\windows\system32\drivers\wg9n.sys
2009-07-12 19:06 . 2002-11-15 11:30 7309 —-a-w- c:\windows\system32\drivers\wg8n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\wg6n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\wg5n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\wg4n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\Wg2n.sys
2009-07-12 19:06 . 2002-01-07 11:29 8023 —-a-w- c:\windows\system32\drivers\Wg1n.sys
2009-07-12 19:06 . 2009-07-12 19:06 ——– d—–w- c:\programfiler\Sygate
2009-07-11 11:03 . 2009-07-11 11:03 ——– d—–w- c:\documents and settings\DeathSoul\Lokale innstillinger\Programdata\Stardock
2009-07-11 11:03 . 2009-07-11 11:15 ——– d—–w- c:\programfiler\Thoosje Vista Sidebar
2009-07-08 06:31 . 2009-07-07 06:36 2167576 —-a-w- c:\documents and settings\All Users\Programdata\avg8\update\backup\avgresf.dll
2009-07-07 23:55 . 2009-07-07 23:55 41808 —-a-w- c:\windows\system32\xfcodec.dll
2009-06-29 16:28 . 2009-06-29 16:28 ——– d—–w- C:\Program Files
2009-06-28 13:55 . 2008-04-13 17:39 5504 -c–a-w- c:\windows\system32\dllcache\mstee.sys
2009-06-28 13:55 . 2008-04-13 17:39 5504 —-a-w- c:\windows\system32\drivers\MSTEE.sys
2009-06-28 13:55 . 2008-04-13 17:46 10880 -c–a-w- c:\windows\system32\dllcache\ndisip.sys
2009-06-28 13:55 . 2008-04-13 17:46 10880 —-a-w- c:\windows\system32\drivers\NdisIP.sys
2009-06-28 13:55 . 2008-04-13 17:46 15232 -c–a-w- c:\windows\system32\dllcache\streamip.sys
2009-06-28 13:55 . 2008-04-13 17:46 15232 —-a-w- c:\windows\system32\drivers\StreamIP.sys
2009-06-28 13:55 . 2008-04-13 17:46 11136 -c–a-w- c:\windows\system32\dllcache\slip.sys
2009-06-28 13:55 . 2008-04-13 17:46 11136 —-a-w- c:\windows\system32\drivers\SLIP.sys
2009-06-28 13:55 . 2008-04-13 17:46 19200 -c–a-w- c:\windows\system32\dllcache\wstcodec.sys
2009-06-28 13:55 . 2008-04-13 17:46 19200 —-a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2009-06-28 07:51 . 2009-06-28 07:51 ——– d—–w- c:\documents and settings\DeathSoul\Lokale innstillinger\Programdata\AVG Security Toolbar
2009-06-27 07:02 . 2009-07-07 06:36 2054424 —-a-w- c:\documents and settings\All Users\Programdata\avg8\update\backup\avgcorex.dll
2009-06-22 00:29 . 2009-06-02 11:37 1004800 —-a-w- c:\documents and settings\All Users\Programdata\AVG Security Toolbar\IEToolbar.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 12:26 . 2009-02-17 23:25 ——– d—–w- c:\documents and settings\All Users\Programdata\avg8
2009-07-19 12:21 . 2009-02-17 23:15 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\uTorrent
2009-07-19 00:53 . 2009-03-28 00:20 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\NoNameScript
2009-07-19 00:53 . 2009-03-28 00:19 ——– d—–w- c:\programfiler\mIRC
2009-07-19 00:42 . 2009-02-19 13:37 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\Skype
2009-07-18 16:45 . 2009-02-19 13:40 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\skypePM
2009-07-18 10:59 . 2009-02-18 16:50 ——– d—–w- c:\programfiler\Xfire
2009-07-18 08:47 . 2009-02-18 16:50 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\Xfire
2009-07-12 19:06 . 2009-02-17 19:34 ——– d–h–w- c:\programfiler\InstallShield Installation Information
2009-07-10 09:13 . 2009-03-28 00:19 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\mIRC
2009-07-07 06:36 . 2009-02-17 23:25 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 00:29 . 2009-06-12 07:48 ——– d—–w- c:\documents and settings\All Users\Programdata\AVG Security Toolbar
2009-06-17 06:12 . 2009-02-17 23:25 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:43 . 2004-08-03 23:03 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:43 . 2001-10-09 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-13 23:38 . 2009-06-11 18:34 ——– d—–w- c:\programfiler\PopCap Games
2009-06-12 07:48 . 2009-06-12 07:48 ——– d—–w- c:\documents and settings\LocalService\Programdata\AVGTOOLBAR
2009-06-11 21:01 . 2009-02-25 02:56 ——– d—–w- c:\programfiler\Windows Desktop Search
2009-06-04 23:14 . 2009-03-30 14:24 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\Spotify
2009-06-03 19:11 . 2004-08-03 23:03 1294336 —-a-w- c:\windows\system32\quartz.dll
2009-05-31 17:57 . 2009-02-17 23:25 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\AVGTOOLBAR
2009-05-29 15:26 . 2009-05-29 15:26 ——– d—–w- c:\programfiler\abgx360
2009-05-28 02:17 . 2009-04-07 20:19 ——– d—–w- c:\documents and settings\All Users\Programdata\DriverScanner
2009-05-28 02:17 . 2009-04-07 19:59 ——– d—–w- c:\programfiler\Uniblue
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\acccore
2009-05-28 01:57 . 2009-05-28 01:56 ——– d—–w- c:\programfiler\AIM6
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\programfiler\Fellesfiler\Software Update Utility
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\programfiler\AIM Toolbar
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\AIM Toolbar
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\programfiler\Viewpoint
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\Viewpoint
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\acccore
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\AOL OCP
2009-05-28 01:57 . 2009-05-28 01:57 ——– d—–w- c:\documents and settings\All Users\Programdata\AOL
2009-05-28 01:56 . 2009-05-28 01:56 ——– d—–w- c:\programfiler\Fellesfiler\AOL
2009-05-24 22:24 . 2008-05-26 21:18 350208 —-a-w- c:\windows\system32\mssph.dll
2009-05-20 15:11 . 2009-02-17 22:26 ——– d—–w- c:\documents and settings\DeathSoul\Programdata\Ventrilo
2009-05-19 06:49 . 2009-02-17 23:25 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-19 06:48 . 2009-02-17 23:25 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-13 05:06 . 2004-08-03 23:03 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-12 13:12 . 2009-02-17 19:34 26144 —-a-w- c:\windows\system32\spupdsvc.exe
2009-05-07 15:34 . 2004-08-03 23:03 346112 —-a-w- c:\windows\system32\localspl.dll
2009-05-06 18:11 . 2009-05-06 18:11 69120 —-a-w- c:\documents and settings\All Users\Programdata\AIM Toolbar\ieToolbar\resources\en-US\aimtbres.dll
2009-06-13 23:02 . 2009-02-17 21:25 134648 —-a-w- c:\programfiler\mozilla firefox\components\brwsrcmp.dll
.

(((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Merk* tomme oppføringer & gyldige standardoppføringer vises ikke
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\programfiler\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 15:20 279944 —-a-w- c:\programfiler\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 07:29 1004800 —-a-w- c:\programfiler\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\programfiler\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programfiler\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\programfiler\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\programfiler\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\programfiler\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885400]
"DAEMON Tools Lite"="c:\programfiler\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"MSMSGS"="c:\programfiler\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Aim6"="c:\programfiler\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"StartCCC"="c:\programfiler\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"WinampAgent"="c:\programfiler\Winamp\winampa.exe" [2006-02-23 35328]
"Adobe Reader Speed Launcher"="c:\programfiler\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\programfiler\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"SyGateManager"="c:\programfiler\Sygate\SON\Sygate.exe" [2003-02-08 802816]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-08-26 16851456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start-meny\Programmer\Oppstart\
Ralink Wireless Utility.lnk - c:\programfiler\RALINK\Common\RaUI.exe [2009-4-14 630784]
Windows Search.lnk - c:\programfiler\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\programfiler\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-19 06:49 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programfiler\\Ventrilo\\Ventrilo.exe"=
"c:\\Programfiler\\uTorrent\\uTorrent.exe"=
"c:\\Programfiler\\AVG\\AVG8\\avgemc.exe"=
"c:\\Programfiler\\AVG\\AVG8\\avgupd.exe"=
"c:\\Programfiler\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Programfiler\\Xfire\\Xfire.exe"=
"c:\\Programfiler\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programfiler\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\World of Warcraft\\Wow.exe"=
"f:\\Installed games\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutLauncher.exe"=
"f:\\Installed games\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutConfigTool.exe"=
"f:\\Installed games\\Electronic Arts\\Burnout™ Paradise The Ultimate Box\\BurnoutParadise.exe"=
"f:\\Installed games\\Steam\\steamapps\\deathsoul234\\counter-strike source\\hl2.exe"=
"c:\\Programfiler\\mIRC\\mirc.exe"=
"c:\\Programfiler\\Spotify\\spotify.exe"=
"c:\\Programfiler\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Programfiler\\ICQ6.5\\ICQ.exe"=
"e:\\World of Warcraft\\Launcher.exe"=
"c:\\Programfiler\\Curse\\CurseClient.exe"=
"f:\\Installed games\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Programfiler\\Fellesfiler\\AOL\\Loader\\aolload.exe"=
"c:\\Programfiler\\AIM6\\aim6.exe"=
"c:\\Programfiler\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Programfiler\\Skype\\Phone\\Skype.exe"=

R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [24.02.2009 00:48 39472]
R0 Wsdrv;SyGate for NT, Wsdrv;\SystemRoot\\SystemRoot\SYSTEM32\Drivers\Wsdrv.sys –> \SystemRoot\\SystemRoot\SYSTEM32\Drivers\Wsdrv.sys [?]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18.02.2009 01:25 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18.02.2009 01:25 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [18.02.2009 01:25 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [18.02.2009 01:25 298776]
R2 SaService;SyGateService;c:\programfiler\Sygate\SON\Sgserv.exe [12.07.2009 21:06 176128]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\programfiler\Viewpoint\Common\ViewpointService.exe [28.05.2009 03:57 24652]
R2 Wg1n;SyGate for NT, Wg1n;c:\windows\system32\drivers\Wg1n.sys [12.07.2009 21:06 8023]
R2 Wg2n;SyGate for NT, Wg2n;c:\windows\system32\drivers\Wg2n.sys [12.07.2009 21:06 8023]
R2 wg8n;SyGate for NT, wg8n;c:\windows\system32\drivers\wg8n.sys [12.07.2009 21:06 7309]
R2 wg9n;SyGate for NT, wg9n;c:\windows\system32\drivers\wg9n.sys [12.07.2009 21:06 7309]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [17.02.2009 21:46 93184]
R3 P1130VID;Creative WebCam NX Pro;c:\windows\system32\drivers\P1130Vid.sys [28.06.2009 15:54 90229]
R3 portio32;portio32;c:\windows\system32\drivers\portio32.sys [28.05.2009 01:35 2048]
S3 ZD1211BU(3COM Corporation);3Com OfficeConnect Wireless 54Mbps 11g Compact USB Adapter(3COM Corporation);c:\windows\system32\drivers\ZD1211BU.sys [17.02.2009 22:51 402944]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - TOMME PEKERE FJERNET - - - -

HKLM-Run-Manage Program Gateway - c:\windows\system32\mspgw.exe


.
——- Tilleggsskanning ——-
.
uStart Page = about:blank
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Programdata\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
FF - ProfilePath - c:\documents and settings\DeathSoul\Programdata\Mozilla\Firefox\Profiles\4y19whb4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\programfiler\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\programfiler\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\programfiler\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\programfiler\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\programfiler\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\programfiler\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll
FF - component: c:\programfiler\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\progra~1\Sony Online Entertainment\npsoe.dll
FF - plugin: c:\programfiler\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\programfiler\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\programfiler\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\programfiler\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-19 16:15
Windows 5.1.2600 Service Pack 3 NTFS

skanner skjulte prosesser …

skanner skjulte autostart-oppføringer …

skanner skjulte filer …

skanning vellykket
skjulte filer: 0

**************************************************************************
.
——————— DLL'er Lastet Av Kjørende Prosesser ———————

- - - - - - - > 'winlogon.exe'(996)
c:\windows\system32\Ati2evxx.dll
.
Tidspunkt ferdig: 2009-07-19 16:16
ComboFix-quarantined-files.txt 2009-07-19 14:16
ComboFix2.txt 2009-07-19 13:48

Pre-Run: 16 905 216 000 byte ledig
Post-Run: 16 855 130 112 byte ledig

239 — E O F — 2009-07-18 10:57
Opplasting vellykket


——-

Malwarebytes' Anti-Malware 1.39
Database version: 2462
Windows 5.1.2600 Service Pack 3

19.07.2009 16:23:50
mbam-log-2009-07-19 (16-23-50).txt

Scan type: Quick Scan
Objects scanned: 76473
Time elapsed: 1 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

———
are you able to navigate to those files via windows explorer (windows key + E) and upload them one at a time
while waiting for the kapersky onlien scan to be finished (it's on the last harddrive now 92% atm). I can now access my task manager again and look at my proccess tree, also AVG (+ the files that was running the Heur.dropper virus) is gone now. What antivirus program / firewall and such do you recommend i use in the future? Seeing AVG Free does not seem like the "best" solution for me.
I usually recommend either Avira or Avast as antivirus programs


Avira AntiVir
Avast
NOTE: DO NOT install more than one antivirus.

and for firewalls:

Three excellent free firewalls are:

Comodo
Sunbelt Kerio
Sygate
NOTE: DO NOT install more than one firewall.

Note: If you choose Comodo - Please be careful with the installation of the Comodo program, it comes bundled with an adware toolbar which you need to de-select when you are going through the installation process. It's not a malicious program, but it may be a privacy risk and I don't think you want it on your system.



(I like Comode - but all three are good)

If all is good with Kaspersky, we have a little more work to do to clean up the tools used, so stay with me.

You might also want to consider removing utorrent - peer2peer programs are the usual source of infection we see these days - you cannot trust the source of the download.
finally kaspersky finished :) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Monday, July 20, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Monday, July 20, 2009 00:26:59 Records in database: 2497181 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan statistics: Files scanned: 225869 Threat name: 3 Infected objects: 5 Suspicious objects: 1 Duration of the scan: 17:00:55 File name / Threat name / Threats count C:\Programfiler\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\Programfiler\mIRC\mirc.exe.BAK Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\System Volume Information\_restore{7B1923EF-77D5-475A-98D0-6BDDCE7C08DD}\RP170\A0039354.exe Infected: Trojan.Win32.Agent.cqig 1 C:\System Volume Information\_restore{7B1923EF-77D5-475A-98D0-6BDDCE7C08DD}\RP170\A0039368.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 C:\System Volume Information\_restore{7B1923EF-77D5-475A-98D0-6BDDCE7C08DD}\RP171\A0039510.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1 F:\torrent downloads\Xbox.360.Hack.Pack.RC1\Xbox 360 Hack Pack RC1\Xbox 360 Hack Pack RC1 Installer.exe Suspicious: Packed.Win32.Black.d 1 The selected area was scanned.
Hi,

I'd get rid of the XBox360 hack installer…it's infected.


the rest is in old system restore points which we will clean up now.

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI