This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware Trojan Virus

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, Thank you for taking the time to read this and I'm hopeful that I'll be able to get some assistance and get this problem fixed. I've seen this problem around, so I'm sure some of you are aware of it. My windows defender prompts with the: TrojanDownloader:Win32/Renos.IO I've searched on the forums and tried some things from other threads, the only problem I'm not able to run some programs due to this virus. Hijackthis doesn't work, nor does malwarebytes which seems to be a popular program. I click run, and it does absolutely nothing. Some programs like Adaware & ATF-Cleaner have worked, so I guess it's hit or miss. (I tried running the programs in safe mode, same issue) Everything seems to boot up fine. I get internet explorer ad popups now, and a net.net file that wants me to find an appropriate program to run it when I get my computer booted up. Weird things like a.exe, b.exe and other werid names have now taken over my processes in task manager. With that being said, I'm willing to do whatever it takes to get this removed barring that I'm able to run the program. I work and live on my computer, so I'll be around all the time trying to get this fixed ASAP. If anybody can lend a hand I would much appreciate it. Thanks.
Friend told me to run a virus scan on http://www.eset.com/onlinescan/

C:\Users\Travis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4C8JFIQC\count[1].htm JS/TrojanDownloader.Agent.NHJ trojan
C:\Users\Travis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NXNF4Z8M\count[1].htm JS/TrojanDownloader.Agent.NHJ trojan
C:\Users\Travis\AppData\Local\msf3-dev\lib\rex\exploitation\heaplib.js.b64 JS/TrojanDownloader.Agent.GJ trojan
C:\Users\Travis\AppData\Local\msf3-dev\lib\rex\exploitation\.svn\text-base\heaplib.js.b64.svn-base JS/TrojanDownloader.Agent.GJ trojan
C:\Users\Travis\AppData\Local\msf3-dev\modules\exploits\windows\browser\ie_createobject.rb JS/TrojanDownloader.Psyme.NCX trojan
C:\Users\Travis\AppData\Local\msf3-dev\modules\exploits\windows\browser\ie_xml_corruption.rb JS/Exploit.CVE-2008-4844.A trojan
C:\Users\Travis\AppData\Local\msf3-dev\modules\exploits\windows\browser\.svn\text-base\ie_createobject.rb.svn-base JS/TrojanDownloader.Psyme.NCX trojan
C:\Users\Travis\AppData\Local\msf3-dev\modules\exploits\windows\browser\.svn\text-base\ie_xml_corruption.rb.svn-base JS/Exploit.CVE-2008-4844.A trojan
C:\Users\Travis\AppData\Local\msf32\modules\exploits\windows\browser\ie_createobject.rb JS/TrojanDownloader.Psyme.NCX trojan
C:\Users\Travis\AppData\Local\msf32\modules\exploits\windows\browser\.svn\text-base\ie_createobject.rb.svn-base JS/TrojanDownloader.Psyme.NCX trojan
C:\Windows\msa.exe a variant of Win32/Kryptik.ZN trojan
C:\Windows\System32\msxml71.dll Win32/TrojanDownloader.FakeAlert.AFG trojan
C:\Windows\System32\net.net a variant of Win32/TrojanClicker.Punad.AA trojan

I deleted the files through the program, but didn't fix the problem.
I was able to get into safe mode, change the name of the file on the desktop and run hijack this.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:52:23 PM, on 7/22/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Safe mode with network support

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1FD79A59-37B1-459B-9097-09F9FAB8A523} - (no file)
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: CDNSCacheObj Object - {376892AE-1825-4E5F-9F85-23F9640051CC} - C:\Windows\XviDplg.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Cognac] C:\Users\Travis\AppData\Local\Temp\b.exe
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\ARO.exe -rem
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apache2.2 - Apache Software Foundation - D:\Rivatuner\xampp\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MySQL - Unknown owner - D:\Rivatuner\xampp\mysql\bin\mysqld.exe
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - D:\Rivatuner\xampp\service.exe

–
End of file - 6428 bytes
[external image: Posted Image]

Hi LoCoELF, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I will be back to you shortly with instructions. :)
Thanks Raktor! I was actually able to get into malware bytes and do a quick scan, here was the results. Malwarebytes' Anti-Malware 1.39 Database version: 2421 Windows 6.0.6002 Service Pack 2 7/22/2009 9:45:27 PM mbam-log-2009-07-22 (21-45-22).txt Scan type: Quick Scan Objects scanned: 79627 Time elapsed: 2 minute(s), 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 15 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 6 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\dnscache.dnscacheobj (Trojan.BHO) -> No action taken. HKEY_CLASSES_ROOT\TypeLib\{1fd79a59-37b1-459b-9097-09f9fab8a523} (Trojan.BHO) -> No action taken. HKEY_CLASSES_ROOT\Interface\{b97f9125-71a1-48d0-b920-f140ef8de809} (Trojan.BHO) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{376892ae-1825-4e5f-9f85-23f9640051cc} (Trojan.BHO) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{376892ae-1825-4e5f-9f85-23f9640051cc} (Trojan.BHO) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{376892ae-1825-4e5f-9f85-23f9640051cc} (Trojan.BHO) -> No action taken. HKEY_CLASSES_ROOT\dnscache.dnscacheobj.1 (Trojan.BHO) -> No action taken. HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> No action taken. HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\net (Trojan.Agent) -> No action taken. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Cognac (Trojan.FakeAlert) -> No action taken. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Windows\XviDplg.dll (Trojan.BHO) -> No action taken. C:\Windows\msb.exe (Trojan.Agent) -> No action taken. C:\Windows\system32\uacinit.dll (Trojan.Agent) -> No action taken. c:\Windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> No action taken. C:\Windows\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job (Trojan.Downloader) -> No action taken. C:\install.exe (Trojan.Agent) -> No action taken. I had to run that in safe mode. I'm now able to run malwarebytes in normal mode, and currently doing a full scan.
I ran a full scan on malwarebytes this morning. Malwarebytes' Anti-Malware 1.39 Database version: 2488 Windows 6.0.6002 Service Pack 2 7/23/2009 9:22:52 AM mbam-log-2009-07-23 (09-22-45).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 217202 Time elapsed: 29 minute(s), 44 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\Typelib\{e24211b3-a78a-c6a9-d317-70979ace5058} (Trojan.FakeAlert) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\Windows\System32\drivers\vsfocexcemwvvq.sys (Trojan.TDSS) -> No action taken. C:\Windows\system32\uacinit.dll (Trojan.Agent) -> No action taken.
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • If you don't know or understand something, please don't hesitate to say or ask! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Please do not use any tools such as Combofix, Vundofix, or HijackThis fixes without instruction to do so!
  • Finally, stay with this topic until I give you the final 'All clear' post! :thumbup:

1) Disable Windows Defender
It appears you are running Windows Defender. This might interfere with fixes we are about to do, so we need to disable it. To disable your Windows Defender Real-time Protection.

  • Open Windows Defender
  • Click Tools
  • Click General Settings
  • Scroll down to Real Time Protection Options
  • Uncheck Turn on Real Time Protection (recommended)
  • Close Windows Defender

Note:Once your log is clean you can re-enable Windows Defender Real Time Protection.

2) Uninstall Programs
Metasploit Framework is a hacking tool. As well as the legalities surrounding it, it will throw up false positives through our scans.
Registry Optimizers/Cleaners are not neccessarily malicious - but they can break things.
Please uninstall some programs from your computer.
  • Click Start then Run.
  • In the open text entry box, type appwiz.cpl and press enter.
  • Locate the following program(s):
    Metasploit Framework
    Advanced Registry Optimizer
  • Press the "Remove" or "Change/Remove" button to uninstall the program, for each program you have to remove.
  • When finished, close the Add/Remove Programs window.

3) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

4) GMER
Please download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and put it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


5) What You Will Need To Post:
  • DDS logs
  • GMER log
Thanks Raktor! I ran into some problems doing part one and two of what you asked. Windows defender seems to have disappeared? Start Menu > says file can not be found and through Windows Security Alerts it's not found. Metasploit and Advanced Registry Optimizer could not be found through the windows uninstall program. I can't even find a folder for ARO, even though it shows on start menu that it's in my program files. Here is the logs: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 11:15:23.49 on Thu 07/23/2009 Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_10 Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3326.2096 [GMT -7:00] SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\ASUS\Six Engine\SixEngine.exe C:\Windows\system32\taskeng.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Program Files\Skype\Phone\Skype.exe C:\Windows\ehome\ehtray.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Windows\system32\wbem\unsecapp.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Java\jre6\bin\jucheck.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\Windows\system32\msiexec.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\taskeng.exe C:\Users\Travis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G9IGTK3L\dds[1].pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {1FD79A59-37B1-459B-9097-09F9FAB8A523} - No File BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL AppInit_DLLs: avgrsstx.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\travis\appdata\roaming\mozilla\firefox\profiles\mrdq9282.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-22 64160] R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2008-6-23 150568] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-7-22 335752] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-7-22 108552] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-5-15 176128] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-22 298776] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456] R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-4-23 95544] R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\L1E60x86.sys [2008-10-20 47616] S2 XAMPP;XAMPP Service;d:\rivatuner\xampp\service.exe [2007-12-21 60928] S3 PsSdk41;PsSdk41;c:\windows\system32\drivers\pssdk41.sys [2009-5-1 37440] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-4-27 79888] S4 Apache2.2;Apache2.2;d:\rivatuner\xampp\apache\bin\httpd.exe [2008-12-10 24636] =============== Created Last 30 ================ 2009-07-23 11:00 181,239,639 a——- c:\windows\MEMORY.DMP 2009-07-23 09:26 –d—– c:\programdata\avg7 2009-07-22 21:41 –d—– c:\users\travis\appdata\roaming\Malwarebytes 2009-07-22 20:50 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-22 20:50 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-22 20:50 –d—– c:\programdata\Malwarebytes 2009-07-22 20:50 –d—– c:\progra~2\Malwarebytes 2009-07-22 19:08 –d-h— C:\$AVG8.VAULT$ 2009-07-22 18:50 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-07-22 18:50 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-07-22 18:50 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-07-22 18:50 –d—– c:\windows\system32\drivers\Avg 2009-07-22 18:50 –d—– c:\programdata\avg8 2009-07-22 18:50 –d—– c:\program files\AVG 2009-07-22 18:50 –d—– c:\progra~2\avg8 2009-07-22 18:47 –d—– c:\users\travis\appdata\roaming\AVG8 2009-07-22 14:33 15,688 a——- c:\windows\system32\lsdelete.exe 2009-07-22 13:50 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-07-22 13:50 -cd-h— c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864} 2009-07-22 13:50 -cd-h— c:\progra~2\{EF63305C-BAD7-4144-9208-D65528260864} 2009-07-22 13:50 –d—– c:\programdata\Lavasoft 2009-07-22 13:50 –d—– c:\program files\Lavasoft 2009-07-22 13:38 42,496 a——- c:\windows\system32\vsfoceruikfpkt.dll 2009-07-22 13:38 85 a——- c:\windows\system32\vsfocelog.dat 2009-07-22 13:35 –d—– c:\users\travis\appdata\roaming\Sammsoft 2009-07-22 08:13 –d—– c:\users\travis\appdata\roaming\quickhit.football.QHFootball.8546B1890A6B85B099F9D0733AC3C3D3855F0E72.1 2009-07-14 10:20 289,792 a——- c:\windows\system32\atmfd.dll 2009-07-14 10:20 156,672 a——- c:\windows\system32\t2embed.dll 2009-07-14 10:20 72,704 a——- c:\windows\system32\fontsub.dll 2009-07-14 10:20 23,552 a——- c:\windows\system32\lpk.dll 2009-07-14 10:20 10,240 a——- c:\windows\system32\dciman32.dll 2009-07-09 22:58 –d—– c:\windows\system32\vi-VN 2009-07-09 22:58 –d—– c:\windows\system32\eu-ES 2009-07-09 22:58 –d—– c:\windows\system32\ca-ES 2009-07-09 22:55 –d—– c:\windows\system32\SPReview 2009-07-09 22:51 928,768 a——- c:\windows\system32\scavenge.dll 2009-07-09 22:51 57,856 a——- c:\windows\system32\compcln.exe 2009-07-09 22:49 2,167,808 a——- c:\windows\system32\mmcndmgr.dll 2009-07-09 22:47 –d—– c:\windows\system32\EventProviders 2009-07-09 08:40 –d—– c:\programdata\ATI 2009-07-05 08:15 2,569 a——- c:\windows\system32\GamParse.INI 2009-06-30 13:37 –d—– C:\Temp 2009-06-29 19:48 –d—– c:\program files\Everquest 2009-06-29 19:46 –d—– c:\windows\system32\Skins 2009-06-29 19:46 969 a——- c:\windows\system32\eqp_config.xml 2009-06-29 13:28 4,608 a——- c:\windows\system32\W95Inf32.DLL 2009-06-29 13:28 2,272 a——- c:\windows\system32\W95Inf16.DLL 2009-06-29 13:10 –d—– c:\users\travis\appdata\roaming\CoreFTP ==================== Find3M ==================== 2009-07-09 23:04 86,016 a——- c:\windows\inf\infstor.dat 2009-07-09 23:04 51,200 a——- c:\windows\inf\infpub.dat 2009-07-09 23:04 143,360 a——- c:\windows\inf\infstrng.dat 2009-07-09 22:58 665,600 a——- c:\windows\inf\drvindex.dat 2009-05-15 20:24 442,368 a——- c:\windows\system32\ATIDEMGX.dll 2009-05-15 20:24 335,872 a——- c:\windows\system32\atieclxx.exe 2009-05-15 20:23 176,128 a——- c:\windows\system32\atiesrxx.exe 2009-05-15 20:22 159,744 a——- c:\windows\system32\atitmmxx.dll 2009-05-15 20:22 356,352 a——- c:\windows\system32\atipdlxx.dll 2009-05-15 20:22 278,528 a——- c:\windows\system32\Oemdspif.dll 2009-05-15 20:22 11,776 a——- c:\windows\system32\atimuixx.dll 2009-05-15 20:22 43,520 a——- c:\windows\system32\ati2edxx.dll 2009-05-15 20:19 2,411,008 a——- c:\windows\system32\atidxx32.dll 2009-05-15 20:08 3,064,832 a——- c:\windows\system32\atiumdag.dll 2009-05-15 19:53 2,847,744 a——- c:\windows\system32\atiumdva.dll 2009-05-15 19:42 51,712 a——- c:\windows\system32\atimpc32.dll 2009-05-15 19:42 51,712 a——- c:\windows\system32\amdpcom32.dll 2009-05-15 19:41 172,032 a——- c:\windows\system32\atiadlxx.dll 2009-05-15 19:40 11,376,640 a——- c:\windows\system32\atioglxx.dll 2009-05-15 19:00 53,248 a——- c:\windows\system32\aticalrt.dll 2009-05-15 19:00 53,248 a——- c:\windows\system32\aticalcl.dll 2009-05-15 18:59 3,174,400 a——- c:\windows\system32\aticaldd.dll 2009-05-05 12:33 118,784 a——- c:\windows\system32\atibtmon.exe 2009-04-28 02:47 499,712 a——- c:\windows\system32\msvcp71.dll 2009-04-28 02:47 348,160 a——- c:\windows\system32\msvcr71.dll 2008-10-23 21:17 174 a–sh— c:\program files\desktop.ini 2006-11-02 05:40 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 05:40 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 05:40 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 05:40 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 11:16:38.91 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft® Windows Vista™ Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 10/20/2008 12:59:17 PM System Uptime: 7/23/2009 10:59:38 AM (1 hours ago) Motherboard: ASUSTeK Computer INC. | | P5Q-PRO Processor: Intel® Core™2 Duo CPU E8500 @ 3.16GHz | LGA 775 | 2670/333mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 466 GiB total, 400.321 GiB free. D: is FIXED (NTFS) - 74 GiB total, 47.952 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== ==== Installed Programs ====================== AccessDiver v4.402 Acrobat.com Ad-Aware Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.1 Adobe Shockwave Player 11.5 AGEIA PhysX v7.09.13 Apple Mobile Device Support Apple Software Update Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver ATI Catalyst Install Manager ATI Catalyst Registration AVG Free 8.5 BitTorrent Bonjour Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center HydraVision Full Catalyst Control Center InstallProxy ccc-core-static ccc-utility CCC Help English CCleaner (remove only) Darkfall DivX Codec DivX Web Player EPU-6 Engine GamParse GIMP 2.6.3 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) iTunes Java™ 6 Update 10 LimeWire 4.18.8 Malwarebytes' Anti-Malware Microsoft .NET Framework 3.5 SP1 Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Ultimate 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2008 Management Objects Microsoft SQL Server Compact 3.5 SP1 Design Tools English Microsoft SQL Server Compact 3.5 SP1 English Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32 mIRC Mozilla Firefox (3.0.12) QuickHitFootball QuickTime Realtek High Definition Audio Driver Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office Word 2007 (KB969604) Skype™ 3.8 SQL Server System CLR Types Trillian Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB969907) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Outlook 2007 Junk Email Filter (kb971933) VC80CRTRedist - 8.0.50727.762 Ventrilo Client VLC media player 0.9.8a WinRAR archiver World of Warcraft FREE Trial ==== End Of File ===========================
I made a mistake on the GMER forgot to uncheck show all (Well to my credit it was unchecked, and I checked it) I'll edit out the other posts, hopefully they'll get deleted.

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-23 11:50:33
Windows 6.0.6002 Service Pack 2


—- System - GMER 1.0.15 —-

Code 85DD8130 ZwEnumerateKey
Code 85F432E0 ZwFlushInstructionCache
Code 85F3E2DD IofCallDriver
Code 85E2012E IofCompleteRequest
Code 85E3812D ZwSaveKey
Code 85F3946D ZwSaveKeyEx

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
—- Processes - GMER 1.0.15 —-

Library \\?\globalroot\systemroot\system32\UACsrqxfcpgmw.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [792] 0x01930000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [864] 0x00950000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [976] 0x00950000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1000] 0x00930000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [1032] 0x00950000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1076] 0x00950000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1092] 0x00940000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1256] 0x00940000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [1492] 0x00DE0000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\Iexplore.exe [1536] 0x00E40000
Library \\?\globalroot\systemroot\system32\UAClfiwpmxtpi.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1612] 0x00E20000

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: copy of MBR

—- EOF - GMER 1.0.15 —-
Please don't run anymore MBAM scans (or scans with other tools) unless instructed.

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Please download Combofix from either of the links below, and save it to your desktop.
You must rename it before saving it. Save it as Combo-Fix.exe.

[external image: Posted Image]

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
  • Double click on Combo-Fix.exe & follow the prompts. Close all browsers/windows first.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here you go Raktor ComboFix 09-07-23.02 - Travis 07/23/2009 22:42.1.2 - NTFSx86 Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3326.2095 [GMT -7:00] Running from: c:\users\[removed]\Desktop\Combo-Fix.exe SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-51003140-4199384537-3980697693-500 c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\AVI Codec Pack + c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\AVI Codec Pack +\Check For Updates.lnk c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\AVI Codec Pack +\Uninstall.lnk c:\windows\system32\drivers\UACuriynxxbsd.sys c:\windows\system32\UACbnqvxnpmvm.dll c:\windows\system32\uacinit.dll c:\windows\system32\UACjtccjjkllu.dll c:\windows\system32\UAClfiwpmxtpi.dll c:\windows\system32\UACppwoerekvs.dat c:\windows\system32\UACsrqxfcpgmw.dll c:\windows\system32\UACtbeaivotis.dll c:\windows\system32\UACtbpsqbhbep.db c:\windows\system32\vsfocelog.dat c:\windows\system32\vsfoceruikfpkt.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_UACd.sys ((((((((((((((((((((((((( Files Created from 2009-06-24 to 2009-07-24 ))))))))))))))))))))))))))))))) . 2009-07-24 05:47 . 2009-07-24 05:47 ——– d—–w- c:\users\Travis\AppData\Local\temp 2009-07-23 16:26 . 2009-07-23 16:26 ——– d—–w- c:\progra~2\avg7 2009-07-23 04:41 . 2009-07-23 04:41 ——– d—–w- c:\users\Travis\AppData\Roaming\Malwarebytes 2009-07-23 03:50 . 2009-07-13 20:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-23 03:50 . 2009-07-23 03:50 ——– d—–w- c:\progra~2\Malwarebytes 2009-07-23 03:50 . 2009-07-13 20:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-07-23 02:08 . 2009-07-23 15:36 ——– d–h–w- C:\$AVG8.VAULT$ 2009-07-23 01:50 . 2009-07-23 01:50 11952 —-a-w- c:\windows\system32\avgrsstx.dll 2009-07-23 01:50 . 2009-07-23 01:50 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2009-07-23 01:50 . 2009-07-23 01:50 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2009-07-23 01:50 . 2009-07-23 01:50 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-07-23 01:50 . 2009-07-24 00:48 ——– d—–w- c:\windows\system32\drivers\Avg 2009-07-23 01:50 . 2009-07-23 16:26 ——– d—–w- c:\progra~2\avg8 2009-07-23 01:50 . 2009-07-23 01:50 ——– d—–w- c:\program files\AVG 2009-07-23 01:47 . 2009-07-23 01:47 ——– d—–w- c:\users\Travis\AppData\Roaming\AVG8 2009-07-22 22:49 . 2009-07-22 22:49 ——– d—–w- c:\users\Travis\AppData\Local\Adobe 2009-07-22 21:33 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe 2009-07-22 20:50 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys 2009-07-22 20:50 . 2009-07-22 20:50 ——– dc-h–w- c:\progra~2\{EF63305C-BAD7-4144-9208-D65528260864} 2009-07-22 20:50 . 2009-07-22 20:50 ——– d—–w- c:\progra~2\Lavasoft 2009-07-22 20:50 . 2009-07-22 20:50 ——– d—–w- c:\program files\Lavasoft 2009-07-22 20:35 . 2009-07-22 20:35 ——– d—–w- c:\users\Travis\AppData\Roaming\Sammsoft 2009-07-22 15:13 . 2009-07-22 15:13 ——– d—–w- c:\users\Travis\AppData\Roaming\quickhit.football.QHFootball.8546B1890A6B85B099F9D0733AC3C3D3855F0E72.1 2009-07-14 17:20 . 2009-06-15 14:53 156672 —-a-w- c:\windows\system32\t2embed.dll 2009-07-14 17:20 . 2009-06-15 14:52 23552 —-a-w- c:\windows\system32\lpk.dll 2009-07-14 17:20 . 2009-06-15 14:52 72704 —-a-w- c:\windows\system32\fontsub.dll 2009-07-14 17:20 . 2009-06-15 14:51 10240 —-a-w- c:\windows\system32\dciman32.dll 2009-07-14 17:20 . 2009-06-15 12:42 289792 —-a-w- c:\windows\system32\atmfd.dll 2009-07-10 05:58 . 2009-07-10 05:58 ——– d—–w- c:\windows\system32\ca-ES 2009-07-10 05:58 . 2009-07-10 05:58 ——– d—–w- c:\windows\system32\eu-ES 2009-07-10 05:58 . 2009-07-10 05:58 ——– d—–w- c:\windows\system32\vi-VN 2009-07-10 05:55 . 2009-07-10 05:55 ——– d—–w- c:\windows\system32\SPReview 2009-07-10 05:51 . 2009-04-11 06:28 928768 —-a-w- c:\windows\system32\scavenge.dll 2009-07-10 05:51 . 2009-04-11 06:27 57856 —-a-w- c:\windows\system32\compcln.exe 2009-07-10 05:49 . 2009-04-11 06:28 2167808 —-a-w- c:\windows\system32\mmcndmgr.dll 2009-07-10 05:47 . 2009-07-10 05:47 ——– d—–w- c:\windows\system32\EventProviders 2009-07-09 15:51 . 2009-07-09 15:51 ——– d—–w- c:\users\Travis\AppData\Roaming\InstallShield 2009-07-09 15:40 . 2009-07-09 15:40 ——– d—–w- c:\progra~2\ATI 2009-07-03 03:48 . 2009-07-03 03:48 ——– d—–w- c:\users\Travis\AppData\Local\Apps 2009-07-03 03:48 . 2009-07-05 15:14 ——– d—–w- c:\users\Travis\AppData\Local\Deployment 2009-06-30 20:37 . 2009-06-30 20:37 ——– d—–w- C:\Temp 2009-06-30 02:48 . 2009-06-30 02:49 ——– d—–w- c:\program files\Everquest 2009-06-30 02:46 . 2009-06-30 02:46 ——– d—–w- c:\windows\system32\Skins 2009-06-29 20:28 . 1998-04-05 07:00 4608 —-a-w- c:\windows\system32\W95Inf32.DLL 2009-06-29 20:28 . 1998-04-05 07:00 2272 —-a-w- c:\windows\system32\W95Inf16.DLL 2009-06-29 20:10 . 2009-06-30 03:01 ——– d—–w- c:\users\Travis\AppData\Roaming\CoreFTP . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-24 05:14 . 2008-10-21 02:20 ——– d—–w- c:\users\Travis\AppData\Roaming\Skype 2009-07-24 05:13 . 2008-10-21 02:22 ——– d—–w- c:\users\Travis\AppData\Roaming\skypePM 2009-07-24 04:47 . 2008-10-21 00:20 ——– d—–w- c:\program files\Trillian 2009-07-23 15:45 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Journal 2009-07-22 20:40 . 2009-05-01 03:37 ——– d—–w- c:\program files\Microsoft Silverlight 2009-07-22 20:06 . 2009-05-01 23:19 ——– d—–w- c:\users\Travis\AppData\Roaming\mIRC 2009-07-22 18:41 . 2008-11-19 20:51 ——– d—–w- c:\users\Travis\AppData\Roaming\LimeWire 2009-07-22 15:14 . 2009-01-13 06:07 ——– d—–w- c:\program files\Common Files\Adobe AIR 2009-07-22 15:14 . 2009-01-13 06:07 38208 —-a-w- c:\users\Travis\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe 2009-07-21 16:16 . 2008-12-26 22:30 ——– d—–w- c:\users\Travis\AppData\Roaming\gtk-2.0 2009-07-18 05:58 . 2002-01-01 07:39 1356 —-a-w- c:\users\Travis\AppData\Local\d3d9caps.dat 2009-07-15 10:02 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2009-07-15 10:02 . 2008-10-20 21:45 ——– d—–w- c:\progra~2\Microsoft Help 2009-07-10 05:58 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Calendar 2009-07-10 05:58 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Sidebar 2009-07-10 05:58 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Photo Gallery 2009-07-10 05:58 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Collaboration 2009-07-10 05:58 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat 2009-07-10 05:54 . 2006-11-02 12:35 37665 —-a-w- c:\windows\Fonts\GlobalUserInterface.CompositeFont 2009-07-09 15:51 . 2008-10-20 20:21 ——– d–h–w- c:\program files\InstallShield Installation Information 2009-07-09 15:40 . 2008-10-20 20:07 99864 —-a-w- c:\users\Travis\AppData\Local\GDIPFONTCACHEV1.DAT 2009-07-09 15:36 . 2008-10-24 05:31 ——– d—–w- c:\program files\ATI 2009-07-09 15:36 . 2008-10-24 05:31 ——– d—–w- c:\program files\ATI Technologies 2009-07-09 15:30 . 2008-10-20 21:47 ——– d—–w- c:\program files\Microsoft Works 2009-05-16 04:01 . 2009-05-16 04:01 4933632 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2009-05-16 03:24 . 2008-09-24 02:20 442368 —-a-w- c:\windows\system32\ATIDEMGX.dll 2009-05-16 03:24 . 2009-05-16 03:24 335872 —-a-w- c:\windows\system32\atieclxx.exe 2009-05-16 03:23 . 2009-05-16 03:23 176128 —-a-w- c:\windows\system32\atiesrxx.exe 2009-05-16 03:22 . 2008-09-24 02:19 159744 —-a-w- c:\windows\system32\atitmmxx.dll 2009-05-16 03:22 . 2008-09-24 02:18 356352 —-a-w- c:\windows\system32\atipdlxx.dll 2009-05-16 03:22 . 2009-05-16 03:22 278528 —-a-w- c:\windows\system32\Oemdspif.dll 2009-05-16 03:22 . 2009-05-16 03:22 11776 —-a-w- c:\windows\system32\atimuixx.dll 2009-05-16 03:22 . 2008-09-24 02:18 43520 —-a-w- c:\windows\system32\ati2edxx.dll 2009-05-16 03:19 . 2009-05-16 03:19 2411008 —-a-w- c:\windows\system32\atidxx32.dll 2009-05-16 03:08 . 2008-09-24 02:02 3064832 —-a-w- c:\windows\system32\atiumdag.dll 2009-05-16 02:53 . 2008-09-24 01:41 2847744 —-a-w- c:\windows\system32\atiumdva.dll 2009-05-16 02:42 . 2009-05-16 02:42 51712 —-a-w- c:\windows\system32\atimpc32.dll 2009-05-16 02:42 . 2009-05-16 02:42 51712 —-a-w- c:\windows\system32\amdpcom32.dll 2009-05-16 02:41 . 2008-09-24 01:27 172032 —-a-w- c:\windows\system32\atiadlxx.dll 2009-05-16 02:40 . 2009-05-16 02:40 11376640 —-a-w- c:\windows\system32\atioglxx.dll 2009-05-16 02:27 . 2009-05-16 02:27 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2009-05-16 02:00 . 2009-05-16 02:00 53248 —-a-w- c:\windows\system32\aticalrt.dll 2009-05-16 02:00 . 2009-05-16 02:00 53248 —-a-w- c:\windows\system32\aticalcl.dll 2009-05-16 01:59 . 2009-05-16 01:59 3174400 —-a-w- c:\windows\system32\aticaldd.dll 2009-05-05 19:33 . 2009-05-05 19:33 118784 —-a-w- c:\windows\system32\atibtmon.exe 2009-05-02 18:53 . 2009-05-02 02:25 37440 —-a-w- c:\windows\system32\drivers\pssdk41.sys 2009-04-28 09:47 . 2009-04-28 09:47 499712 —-a-w- c:\windows\system32\msvcp71.dll 2009-04-28 09:47 . 2009-04-28 09:47 348160 —-a-w- c:\windows\system32\msvcr71.dll 2009-04-28 03:39 . 2009-05-02 23:30 41424 —-a-w- c:\windows\system32\drivers\VBoxUSBMon.sys 2009-04-28 03:39 . 2009-04-28 03:39 79888 —-a-w- c:\windows\system32\drivers\VBoxNetAdp.sys 2009-04-28 03:39 . 2009-05-02 23:30 100944 —-a-w- c:\windows\system32\drivers\VBoxDrv.sys 2009-07-22 14:13 . 2008-10-23 14:41 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-30 21755688] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2009-04-11 2153472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-12 136600] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304] "ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2008-05-02 307200] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-23 1948440] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-20 6144000] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(B):ba,5c,a7,4f,24,01,ca,01 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{CF0E4234-74EB-4E11-9596-FCDE87342AD5}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{7EA3C2B3-19AD-4025-95AF-E82AF8DBB963}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{244C7C6D-0C26-435F-94CB-4C6D51EA7BCB}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{43E7BD1A-6D25-4746-9FB5-62F3F31E77AC}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{92B41743-B792-4A00-9C06-D66533C5F354}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{89A531FC-697C-406E-AFD2-602A2EDF1CCE}"= c:\program files\Skype\Phone\Skype.exe:Skype "TCP Query User{6D1BBE01-140F-4F6B-B8BA-3B8341243CBB}c:\\program files\\trillian\\trillian.exe"= UDP:c:\program files\trillian\trillian.exe:Trillian "UDP Query User{F6E9EA46-9E67-4709-8E13-C87B06A50D34}c:\\program files\\trillian\\trillian.exe"= TCP:c:\program files\trillian\trillian.exe:Trillian "{66CA948C-494D-4259-948E-3BABB0C947FD}"= UDP:d:\carp**\Ventrilo\Ventrilo.exe:Ventrilo.exe "{F4CE1742-54E3-449B-9FC4-1F5806C58D5E}"= TCP:d:\carp**\Ventrilo\Ventrilo.exe:Ventrilo.exe "TCP Query User{06917D9E-0A5D-48E4-867D-375D4ECB64D8}d:\\program files\\limewire\\limewire.exe"= UDP:d:\program files\limewire\limewire.exe:LimeWire "UDP Query User{5F356751-41BB-42BA-B401-30D419DE9346}d:\\program files\\limewire\\limewire.exe"= TCP:d:\program files\limewire\limewire.exe:LimeWire "{74621EB4-1FD2-41DC-973E-C22E6D6F2302}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{F7E5B904-2688-413F-BB8E-718424477AD9}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{9CF8DF57-C647-4F2C-A09B-7D34F3C96109}"= UDP:d:\program files\iTunes\iTunes.exe:iTunes "{615B8948-B3C2-478E-957B-AA59A7F81A4F}"= TCP:d:\program files\iTunes\iTunes.exe:iTunes "TCP Query User{336CD6BD-5939-4B56-A485-35C98CBD7DF9}c:\\program files\\savage 2\\savage2.exe"= UDP:c:\program files\savage 2\savage2.exe:savage2 "UDP Query User{298005F4-BBAF-497E-A7EF-090EF0F93C8C}c:\\program files\\savage 2\\savage2.exe"= TCP:c:\program files\savage 2\savage2.exe:savage2 "TCP Query User{904AE48D-22E0-4532-9938-25E591438700}c:\\program files\\darkfall\\lobby.exe"= UDP:c:\program files\darkfall\lobby.exe:Lobby "UDP Query User{B7465E23-9D37-4CF6-9CAD-49EFC24253EE}c:\\program files\\darkfall\\lobby.exe"= TCP:c:\program files\darkfall\lobby.exe:Lobby "TCP Query User{CC1DAACE-1664-413D-B1D8-836C525C0D69}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java™ Platform SE binary "UDP Query User{D71FC1F2-1DAE-4520-BAF8-B2646D120157}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java™ Platform SE binary "TCP Query User{BC56EC5E-1F4A-4D56-9089-5EFC1D1EC825}c:\\program files\\darkfall\\lobby.exe"= UDP:c:\program files\darkfall\lobby.exe:Lobby "UDP Query User{99F8E96C-8A2B-4F11-B5F9-69E1D5248919}c:\\program files\\darkfall\\lobby.exe"= TCP:c:\program files\darkfall\lobby.exe:Lobby "TCP Query User{63669F79-AE46-4D8E-9747-B8154BFD1917}c:\\program files\\trillian\\trillian.exe"= UDP:c:\program files\trillian\trillian.exe:Trillian "UDP Query User{8735BCE0-7071-4FB6-8D9A-F177F2E185C3}c:\\program files\\trillian\\trillian.exe"= TCP:c:\program files\trillian\trillian.exe:Trillian "{550AB0A3-AE9C-4BBC-8F5C-DF51547B5C84}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{8281245F-15AC-4687-B6B2-D9BCBDA7327B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{16F6A87B-3234-40B8-A835-DD0D6D8573D0}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{49EE3086-7C86-4DCF-B3E5-BD1ACEFE9922}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "{210B24D9-C5A2-4A69-ABC8-A3D395B64E9F}"= UDP:d:\program files\BitTorrent\bittorrent.exe:BitTorrent (TCP-In) "{7A61B2DC-0684-4443-AD1F-C47141D32AFA}"= TCP:d:\program files\BitTorrent\bittorrent.exe:BitTorrent (UDP-In) "TCP Query User{7E32BB35-444F-456B-9006-695A0AF70037}d:\\program files\\hacking\\mirc\\mirc.exe"= UDP:d:\program files\hacking\mirc\mirc.exe:mIRC "UDP Query User{F0D5633F-3208-423B-93B2-2A6E190E8269}d:\\program files\\hacking\\mirc\\mirc.exe"= TCP:d:\program files\hacking\mirc\mirc.exe:mIRC "TCP Query User{42A9BBAF-8C98-437B-B761-C659106A64F0}d:\\program files\\metasploit\\framework3\\bin\\rubyw.exe"= UDP:d:\program files\metasploit\framework3\bin\rubyw.exe:Ruby interpreter "UDP Query User{1AC013C5-BDDF-4FF8-AE7D-885E1A568AAB}d:\\program files\\metasploit\\framework3\\bin\\rubyw.exe"= TCP:d:\program files\metasploit\framework3\bin\rubyw.exe:Ruby interpreter "{BF12435E-DA03-44A7-B230-470E65A19399}"= UDP:d:\program files\LimeWire\LimeWire.exe:LimeWire "{7093E6E1-EDB1-4D83-B346-367FBAC2308F}"= TCP:d:\program files\LimeWire\LimeWire.exe:LimeWire "TCP Query User{8A01C345-09B6-4E2F-A7F0-6F09802C7902}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java™ Platform SE binary "UDP Query User{982CD7F1-B2D6-4E03-BB90-3C65B555A4EB}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java™ Platform SE binary "TCP Query User{21E5CE78-83A6-42E8-8168-2AF45F3D28A5}c:\\program files\\sony\\station\\launchpad\\launchpad.exe"= UDP:c:\program files\sony\station\launchpad\launchpad.exe:LaunchPad "UDP Query User{7010753A-E9EF-4174-B63E-977F9F8A62C4}c:\\program files\\sony\\station\\launchpad\\launchpad.exe"= TCP:c:\program files\sony\station\launchpad\launchpad.exe:LaunchPad "TCP Query User{49CD92EE-8410-4FE3-A107-B5CF4E54FDDD}c:\\program files\\everquest\\everquest\\eqvoiceservice.exe"= UDP:c:\program files\everquest\everquest\eqvoiceservice.exe:EQVoiceService "UDP Query User{99AFF390-CF9E-4BFB-AB49-5CFF0B7B6354}c:\\program files\\everquest\\everquest\\eqvoiceservice.exe"= TCP:c:\program files\everquest\everquest\eqvoiceservice.exe:EQVoiceService "TCP Query User{DDC1FEB6-C262-498B-953C-6D9C6BF2CEA5}c:\\program files\\sony\\station\\launchpad\\launchpad.exe"= UDP:c:\program files\sony\station\launchpad\launchpad.exe:LaunchPad "UDP Query User{AB1C60A3-C3F6-4D89-9E18-38C38626418F}c:\\program files\\sony\\station\\launchpad\\launchpad.exe"= TCP:c:\program files\sony\station\launchpad\launchpad.exe:LaunchPad "TCP Query User{9FA7FC34-0A8F-447B-8BEF-336E8E16529C}c:\\program files\\everquest\\everquest\\eqvoiceservice.exe"= UDP:c:\program files\everquest\everquest\eqvoiceservice.exe:EQVoiceService "UDP Query User{DB84E13F-6642-48FB-9D84-4869233B56FF}c:\\program files\\everquest\\everquest\\eqvoiceservice.exe"= TCP:c:\program files\everquest\everquest\eqvoiceservice.exe:EQVoiceService "TCP Query User{2B809683-2F0C-4F6B-8ABD-5FA76E435BFF}d:\\program files\\hacking\\mirc\\mirc.exe"= UDP:d:\program files\hacking\mirc\mirc.exe:mIRC "UDP Query User{42C7B995-CACF-4C12-8DFA-B8FD2BC47214}d:\\program files\\hacking\\mirc\\mirc.exe"= TCP:d:\program files\hacking\mirc\mirc.exe:mIRC "{7343E758-B023-4043-BA20-42CC394AC5C8}"= c:\program files\Skype\Phone\Skype.exe:Skype "{537B0C52-FE52-4932-B608-23781CAD5CA3}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe "{C7FE8591-CCA1-40FC-A2AD-04F6799F4952}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List] "d:\\Program Files\\BitTorrent\\bittorrent.exe"= d:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [7/22/2009 1:50 PM 64160] R0 mv61xx;mv61xx;c:\windows\System32\drivers\mv61xx.sys [6/23/2008 3:21 PM 150568] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [7/22/2009 6:50 PM 335752] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [7/22/2009 6:50 PM 108552] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [5/15/2009 8:23 PM 176128] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/22/2009 6:50 PM 298776] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 7:49 AM 1029456] R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\System32\drivers\AtiHdmi.sys [4/23/2009 10:43 PM 95544] R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [10/20/2008 1:24 PM 47616] S2 XAMPP;XAMPP Service;d:\rivatuner\xampp\service.exe [12/21/2007 4:01 AM 60928] S3 PsSdk41;PsSdk41;c:\windows\System32\drivers\pssdk41.sys [5/1/2009 7:25 PM 37440] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\System32\drivers\VBoxNetAdp.sys [4/27/2009 8:39 PM 79888] S4 Apache2.2;Apache2.2;d:\rivatuner\xampp\apache\bin\httpd.exe [12/10/2008 1:10 AM 24636] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\Travis\AppData\Roaming\Mozilla\Firefox\Profiles\mrdq9282.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . Completion time: 2009-07-24 22:48 ComboFix-quarantined-files.txt 2009-07-24 05:48 Pre-Run: 428,400,353,280 bytes free Post-Run: 428,611,063,808 bytes free 257 — E O F — 2009-07-23 19:10

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI