This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Definite infection

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi again,

Alright it wasn't me this time! A younger cousin was using my computer and says he ended up following a link to a .wmv file. He said that when he opened up the site, windows media opened and then after a few seconds (with of course no video) the computer blue screened. Now my computer is acting slowly, in spurts, with things like the start menu becoming dysfunctional occasionally. What luck I have with this carp**! Here's the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:38:15 PM, on 7/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Utopia\Angel\Angel.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - *{0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [GEST] m‘|\ü
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Utopia Angel] "C:\Utopia\Angel\Angel.exe"
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2…15106/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7960 bytes
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Here is DDS:


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 13:14:51.31 on Sat 08/01/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2233 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Chris\Desktop\dds.pif
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [Utopia Angel] "c:\utopia\angel\Angel.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [GEST] m‘|\ü
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [CTHelper] CTHELPER.EXE
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su2/ocx/15106/CTPID.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\m7fwci6o.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-30 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-3-30 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-30 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-3-30 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-30 298776]
R2 GEST Service;GEST Service for program management.;c:\program files\gigabyte\energysaver\GSvr.exe [2009-2-25 68136]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-6-16 24652]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2008-10-8 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2008-10-8 1324056]
S2 ASKService;ASKService; [x]
S2 ASKUpgrade;ASKUpgrade; [x]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2009-2-25 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2008-10-8 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2008-10-8 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2008-10-8 72728]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2008-10-8 72728]

=============== Created Last 30 ================

2009-08-01 13:14 –d-h— c:\windows\PIF
2009-07-31 14:25 389,120 a——- c:\windows\system32\CF17320.exe
2009-07-31 14:25 –ds—- C:\ComboFix
2009-07-21 15:36 –d—– c:\program files\Free Window Registry Repair
2009-07-18 22:00 266,360 a——- c:\windows\system32\TweakUI.exe
2009-07-18 22:00 160,217 a——- c:\windows\system32\PowerToysLicense.rtf
2009-07-18 20:59 -cd—– c:\windows\system32\dllcache\cache
2009-07-03 18:41 1,080 a——- c:\windows\system32\settingsbkup.sfm
2009-07-03 18:41 1,080 a——- c:\windows\system32\settings.sfm

==================== Find3M ====================

2009-07-31 13:29 16,608 a——- c:\windows\gdrv.sys
2009-07-27 09:23 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-07-13 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-29 12:12 827,392 a——- c:\windows\system32\wininet.dll
2009-06-29 12:12 78,336 a——- c:\windows\system32\ieencode.dll
2009-06-29 12:12 17,408 ——– c:\windows\system32\corpol.dll
2009-06-29 08:51 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-06-24 17:21 137,888 a——- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-24 17:20 189,288 a——- c:\windows\system32\PnkBstrB.exe
2009-06-23 17:38 75,064 a——- c:\windows\system32\PnkBstrA.exe
2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll

============= FINISH: 13:15:03.98 ===============

Here is the attach, although it says to attach it you guys always say to post things:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 2/25/2009 4:01:56 AM
System Uptime: 7/31/2009 1:26:42 PM (24 hours ago)

Motherboard: Gigabyte Technology Co., Ltd. | | EP45-UD3R
Processor: Intel Pentium III Xeon processor | Socket 775 | 3166/333mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 466 GiB total, 432.127 GiB free.
E: is CDROM (CDFS)
F: is CDROM ()
G: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP177: 7/18/2009 10:04:00 PM - System Checkpoint
RP178: 7/19/2009 10:17:11 PM - System Checkpoint
RP179: 7/20/2009 10:54:38 PM - System Checkpoint
RP180: 7/21/2009 3:49:32 PM - Software Distribution Service 3.0
RP181: 7/22/2009 4:21:27 PM - System Checkpoint
RP182: 7/23/2009 4:22:31 PM - System Checkpoint
RP183: 7/24/2009 6:08:43 PM - System Checkpoint
RP184: 7/25/2009 6:21:40 PM - System Checkpoint
RP185: 7/26/2009 7:21:40 PM - System Checkpoint
RP186: 7/27/2009 9:23:21 AM - Avg8 Update
RP187: 7/27/2009 9:23:55 AM - Avg8 Update
RP188: 7/28/2009 9:33:40 AM - System Checkpoint
RP189: 7/29/2009 9:57:40 AM - System Checkpoint
RP190: 7/29/2009 4:00:22 PM - Software Distribution Service 3.0
RP191: 7/30/2009 4:00:13 PM - Software Distribution Service 3.0

==== Installed Programs ======================

7-Zip 4.65
Acrobat.com
Active@ KillDisk FREE Suite
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.1
AIM 6
AVG 8.5
Browser Configuration Utility
CDisplay 1.8
Creative Audio Control Panel
Creative Console Launcher
Creative MediaSource 5
Creative Software AutoUpdate
Creative System Information
DAEMON Tools Toolbar
Day of Defeat: Source
Dell Photo Printer 720
Dystopia
Energy Saver Advance B8.1015.1
Free Window Registry Repair
Gigabyte Raid Configurer
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows XP (KB938759)
Hotfix for Windows XP (KB952287)
Insurgency
Java™ 6 Update 13
Java™ 6 Update 7
Left 4 Dead
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft AppLocale
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Silverlight
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows Application Compatibility Database
Mozilla Firefox (3.0.12)
MSXML 6.0 Parser (KB925673)
NVIDIA Drivers
NVIDIA PhysX
OpenAL
OpenOffice.org 3.0
PartitionMagic
PASW Statistics 17.0
Plants Vs Zombies
PowerQuest PartitionMagic 8.0 Demo
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
SeaTools for Windows
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
Sound Blaster X-Fi
Spybot - Search & Destroy
Starcraft
Steam
System Requirements Lab
Team Fortress 2
Tweak UI
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Utopia Target Finder 1.4
Viewpoint Media Player
Volume Panel
Vuze
Vuze Toolbar
Warhammer 40,000: Dawn of War II
WebFldrs XP
Windows Communication Foundation
Windows Internet Explorer 7
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0

==== Event Viewer Messages From Past Week ========

8/1/2009 11:02:25 AM, error: Dhcp [1002] - The IP address lease 192.168.100.11 for the Network Card with network address 001FD0D1253E has been denied by the DHCP server 192.168.100.1 (The DHCP Server sent a DHCPNACK message).
8/1/2009 11:02:12 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
8/1/2009 11:02:04 AM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 001FD0D1253E has been denied by the DHCP server 192.168.100.1 (The DHCP Server sent a DHCPNACK message).

==== End Of File ===========================


Finally here is gmer.txt:

GMER 1.0.15.15011 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-01 13:21:00
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT spmz.sys ZwCreateKey [0xB9EA70E0]
SSDT spmz.sys ZwEnumerateKey [0xB9EC5CA4]
SSDT spmz.sys ZwEnumerateValueKey [0xB9EC6032]
SSDT spmz.sys ZwOpenKey [0xB9EA70C0]
SSDT spmz.sys ZwQueryKey [0xB9EC610A]
SSDT spmz.sys ZwQueryValueKey [0xB9EC5F8A]
SSDT spmz.sys ZwSetValueKey [0xB9EC619C]

INT 0x62 ? 8AD9BBF8
INT 0x63 ? 8AB3DF00
INT 0x63 ? 8AB3DF00
INT 0x73 ? 8AD9BBF8
INT 0x73 ? 8AD9BBF8
INT 0x73 ? 8AE0DBF8
INT 0x73 ? 8AB3DF00
INT 0x73 ? 8AD9BBF8
INT 0x82 ? 8AD9BBF8
INT 0x83 ? 8AB3DF00
INT 0xA4 ? 8AB3DF00
INT 0xA4 ? 8AB3DF00
INT 0xA4 ? 8AB3DF00
INT 0xA4 ? 8AB3DF00
INT 0xB4 ? 8AB3DF00

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8AE091F8
Device \FileSystem\Fastfat \FatCdrom 89137500

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBPDO-0 8AB11478
Device \Driver\usbuhci \Device\USBPDO-1 8AB11478
Device \Driver\usbuhci \Device\USBPDO-2 8AB11478
Device \Driver\usbehci \Device\USBPDO-3 8AAE71F8
Device \Driver\usbuhci \Device\USBPDO-4 8AB11478

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBPDO-5 8AB11478
Device \Driver\PCI_PNP0400 \Device\00000049 spmz.sys
Device \Driver\usbuhci \Device\USBPDO-6 8AB11478
Device \Driver\Ftdisk \Device\HarddiskVolume1 8AE0B1F8
Device \Driver\usbehci \Device\USBPDO-7 8AAE71F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x98 0x02 0x39 0xA4 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x7B 0x47 0xE6 0xBB …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD7 0xDD 0xDD 0x19 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA6 0xD1 0xAB 0xCA …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xC7 0x4C 0x9F 0x63 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xE9 0x92 0x43 0x5F …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA6 0xD1 0xAB 0xCA …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xC7 0x4C 0x9F 0x63 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xE9 0x92 0x43 0x5F …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x98 0x02 0x39 0xA4 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x7B 0x47 0xE6 0xBB …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD7 0xDD 0xDD 0x19 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA6 0xD1 0xAB 0xCA …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xC7 0x4C 0x9F 0x63 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xE9 0x92 0x43 0x5F …
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-

2009-07-31 14:25

–ds—- C:\ComboFix


Did you run ComboFix on your own?

If so please post the log - it can be found at C:\ComboFix.txt
I think I accidentally ran it some time ago… but I thought it was before I did that scan? Not sure.

ComboFix 09-07-14.08 - Chris 07/18/2009 20:57.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2198 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\system32\lsprst7.dll
c:\windows\system32\prsgrc.dll

.
((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 )))))))))))))))))))))))))))))))
.

2009-07-15 05:21 . 2009-07-15 05:21 ——– d—–w- c:\windows\LastGood
2009-06-29 20:32 . 2009-06-29 20:32 ——– d—–w- c:\documents and settings\Chris\Local Settings\Application Data\AVG Security Toolbar
2009-06-29 12:52 . 2009-06-29 12:51 832144 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-29 12:51 . 2009-06-29 12:51 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-29 12:51 . 2009-06-29 12:51 ——– d—–w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-24 18:09 . 2009-06-24 18:09 ——– d—–w- c:\program files\Utopia Target Finder
2009-06-24 18:09 . 2005-05-23 20:08 17513 —-a-w- c:\windows\system32\utopiatarget.dll
2009-06-23 21:38 . 2009-06-24 21:21 137888 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-23 21:38 . 2009-06-24 21:20 189288 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-06-23 21:38 . 2009-06-23 21:38 ——– d—–w- c:\windows\system32\LogFiles
2009-06-23 21:38 . 2009-06-23 21:38 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-06-23 21:38 . 2009-06-23 21:38 ——– d—–w- c:\documents and settings\Chris\Local Settings\Application Data\PunkBuster

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-17 21:07 . 2009-02-25 19:37 ——– d—–w- c:\program files\Steam
2009-07-08 12:42 . 2009-02-25 09:05 16608 —-a-w- c:\windows\gdrv.sys
2009-06-29 12:51 . 2009-03-30 15:41 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-29 12:51 . 2009-03-30 15:41 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-29 12:51 . 2009-03-30 15:41 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-28 18:23 . 2009-02-26 07:19 1 —-a-w- c:\documents and settings\Chris\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-16 23:29 . 2009-02-25 10:34 ——– d—–w- c:\program files\AIM6
2009-06-16 23:25 . 2009-06-16 23:25 ——– d—–w- c:\program files\Viewpoint
2009-06-16 23:25 . 2009-02-25 10:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-16 23:18 . 2009-06-16 23:18 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-06-16 14:36 . 2004-08-12 14:07 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-12 13:57 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-14 20:44 . 2009-03-01 21:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-04 04:55 . 2009-06-04 04:55 ——– d—–w- c:\program files\Seagate
2009-06-04 04:55 . 2009-02-25 21:32 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-03 19:09 . 2004-08-12 14:03 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-30 08:56 . 2009-05-30 08:56 29926 —-a-r- c:\documents and settings\Chris\Application Data\Microsoft\Installer\{394BE3D9-7F57-4638-A8D1-1D88671913B7}\_18be6784.exe
2009-05-30 08:56 . 2009-05-30 08:56 29422 —-a-r- c:\documents and settings\Chris\Application Data\Microsoft\Installer\{394BE3D9-7F57-4638-A8D1-1D88671913B7}\_294823.exe
2009-05-30 08:13 . 2009-02-26 18:00 ——– d—–w- c:\documents and settings\Chris\Application Data\Azureus
2009-05-28 20:00 . 2009-05-27 19:56 25 —-a-w- c:\windows\popcinfot.dat
2009-05-26 17:20 . 2009-03-01 21:44 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 17:19 . 2009-03-01 21:44 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-19 05:36 . 2009-06-16 23:18 97072 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\bsetutil.exe
2009-05-19 05:36 . 2009-06-16 23:18 2884832 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\vwpt.exe
2009-05-19 05:36 . 2009-06-16 23:18 28 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\unregister.bat
2009-05-19 05:36 . 2009-06-16 23:18 25 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\register.bat
2009-05-19 05:36 . 2009-06-16 23:18 1484856 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\toolbar.exe
2009-05-19 05:36 . 2009-06-16 23:18 142040 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\alsetup.exe
2009-05-19 05:36 . 2009-06-16 23:18 30512 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\Uninstaller.exe
2009-05-19 05:36 . 2009-06-16 23:18 111920 —-a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\AOLSearch.dll
2009-05-07 15:32 . 2004-08-12 13:59 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-04 08:20 . 2009-02-25 09:05 19576 —-a-w- c:\documents and settings\Chris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-01 19:57 . 2009-03-30 15:41 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-30 07:51 . 2009-04-30 01:01 186 —-a-w- c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\prsgrc.dll
2009-04-30 01:02 . 2009-04-30 01:02 1024 —-a-w- c:\windows\system32\grcauth2.dll
2009-04-30 01:02 . 2009-04-30 01:02 1024 —-a-w- c:\windows\system32\grcauth1.dll
2009-04-30 00:59 . 2009-04-30 00:59 1025 —-a-w- c:\windows\system32\sysprs7.dll
2009-04-29 04:56 . 2004-08-12 14:09 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-12 13:58 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-26 20:19 . 2009-02-25 09:27 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-04-22 04:20 . 2009-04-22 04:20 14311680 —-a-w- c:\windows\system32\xlive.dll
2009-04-22 04:20 . 2009-04-22 04:20 13642496 —-a-w- c:\windows\system32\xlivefnt.dll
2009-06-13 17:01 . 2009-02-25 09:32 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Steam"="c:\program files\steam\steam.exe" [2009-06-10 1217784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Utopia Angel"="c:\utopia\Angel\Angel.exe" [2009-07-06 3628544]
"AdobeUpdater6"="c:\program files\Common Files\Adobe\Updater6\Adobe_Updater.exe" [2009-01-08 2521464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-11-19 1966080]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2008-08-06 233576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-29 1948440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-07-23 16804864]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SoundMan.exe [2008-06-18 77824]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\alcwzrd.exe [2008-06-19 2808832]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2006-05-24 17920]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\Ctxfihlp.exe [2008-10-08 23552]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-09 1657376]

c:\documents and settings\Chris\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-29 12:51 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dawn of war 2\\DOW2.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\statistics.com"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\paswstat.exe"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\statistics.exe"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\SPSSWinWrapIDE.exe"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\paswstat.com"=
"c:\\Program Files\\Steam\\steamapps\\[removed]\\dystopia\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\[removed]\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\plants vs zombies\\PlantsVsZombies.exe"=
"c:\\Program Files\\Steam\\steamapps\\[removed]\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\[removed]\\insurgency\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/30/2009 11:41 AM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/30/2009 11:41 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/30/2009 11:41 AM 906520]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/30/2009 11:41 AM 298776]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2/25/2009 5:06 AM 68136]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/16/2009 7:25 PM 24652]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [10/8/2008 2:21 AM 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [10/8/2008 2:21 AM 1324056]
S2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe –> c:\program files\AskBarDis\bar\bin\AskService.exe [?]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe –> c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2/25/2009 3:24 PM 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [10/8/2008 2:21 AM 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [10/8/2008 2:21 AM 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [10/8/2008 2:21 AM 72728]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [10/8/2008 2:21 AM 72728]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)


.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\m7fwci6o.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-18 20:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-07-19 21:01
ComboFix-quarantined-files.txt 2009-07-19 01:01
ComboFix2.txt 2009-03-01 22:43

Pre-Run: 463,153,565,696 bytes free
Post-Run: 463,169,118,208 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
187 — E O F — 2009-07-15 20:01
Thank-you,

Please do the following:

Please download mbr.exe from >>HERE<<and save it to your desktop,
  • click the downloaded file to run the scan (a window will open briefly, then close).
  • The scan will create an mbr.log on your desktop
  • please copy/paste those contents in your next reply.
Hi,

Please delete the copy of Combofix that you have on your machine - it is outdated (right click the icon - choose - delete)

Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

ComboFix 09-07-31.04 - Chris 08/01/2009 16:14.4.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2165 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-07-01 to 2009-08-01 )))))))))))))))))))))))))))))))
.

2009-07-29 22:10 . 2009-07-29 22:10 3775175 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-21 21:13 . 2009-06-14 20:07 1004800 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-07-21 19:36 . 2009-07-21 19:37 ——– d—–w- c:\program files\Free Window Registry Repair
2009-07-19 02:00 . 2003-06-25 20:05 266360 —-a-w- c:\windows\system32\TweakUI.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-01 17:13 . 2009-02-25 19:37 ——– d—–w- c:\program files\Steam
2009-07-31 17:29 . 2009-02-25 09:05 16608 —-a-w- c:\windows\gdrv.sys
2009-07-31 17:28 . 2009-05-15 23:09 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-29 22:12 . 2009-03-01 21:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-29 20:08 . 2009-02-25 10:54 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-27 13:23 . 2009-03-30 15:41 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-21 21:13 . 2009-06-29 12:51 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-07-13 17:36 . 2009-03-01 21:44 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 17:36 . 2009-03-01 21:44 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-29 16:12 . 2004-08-12 14:09 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-12 13:58 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-12 13:56 17408 ——w- c:\windows\system32\corpol.dll
2009-06-29 12:51 . 2009-06-29 12:51 ——– d—–w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-29 12:51 . 2009-03-30 15:41 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-29 12:51 . 2009-03-30 15:41 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-28 18:23 . 2009-02-26 07:19 1 —-a-w- c:\documents and settings\Chris\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-24 21:21 . 2009-06-23 21:38 137888 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-24 21:20 . 2009-06-23 21:38 189288 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-06-24 18:09 . 2009-06-24 18:09 ——– d—–w- c:\program files\Utopia Target Finder
2009-06-23 21:38 . 2009-06-23 21:38 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-06-16 23:29 . 2009-02-25 10:34 ——– d—–w- c:\program files\AIM6
2009-06-16 23:25 . 2009-06-16 23:25 ——– d—–w- c:\program files\Viewpoint
2009-06-16 23:25 . 2009-02-25 10:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-07 15:32 . 2004-08-12 13:59 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-04 08:20 . 2009-02-25 09:05 19576 —-a-w- c:\documents and settings\Chris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-26 05:45 . 2009-02-25 09:32 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Utopia Angel"="c:\utopia\Angel\Angel.exe" [2009-07-06 3628544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m‘|\ü" [X]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-11-19 1966080]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2008-08-06 233576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-29 1948440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-07-23 16804864]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SoundMan.exe [2008-06-18 77824]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\alcwzrd.exe [2008-06-19 2808832]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2006-05-24 17920]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\Ctxfihlp.exe [2008-10-08 23552]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-09 1657376]

c:\documents and settings\Chris\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-29 12:51 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dawn of war 2\\DOW2.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\statistics.com"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\paswstat.exe"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\statistics.exe"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\SPSSWinWrapIDE.exe"=
"c:\\Program Files\\SPSSInc\\PASWStatistics17\\paswstat.com"=
"c:\\Program Files\\Steam\\steamapps\\[removed]\\dystopia\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\[removed]\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\plants vs zombies\\PlantsVsZombies.exe"=
"c:\\Program Files\\Steam\\steamapps\\[removed]\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\[removed]\\insurgency\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/30/2009 11:41 AM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/30/2009 11:41 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/30/2009 11:41 AM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/30/2009 11:41 AM 298776]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [2/25/2009 5:06 AM 68136]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/16/2009 7:25 PM 24652]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [10/8/2008 2:21 AM 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [10/8/2008 2:21 AM 1324056]
S2 ASKService;ASKService; [x]
S2 ASKUpgrade;ASKUpgrade; [x]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2/25/2009 3:24 PM 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [10/8/2008 2:21 AM 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [10/8/2008 2:21 AM 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [10/8/2008 2:21 AM 72728]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [10/8/2008 2:21 AM 72728]

— Other Services/Drivers In Memory —

*NewlyCreated* - AUJASNKJ
*NewlyCreated* - MBR
*Deregistered* - aujasnkj
*Deregistered* - mbr
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\m7fwci6o.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-01 16:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-08-01 16:17
ComboFix-quarantined-files.txt 2009-08-01 20:17
ComboFix2.txt 2009-07-19 01:01

Pre-Run: 463,910,846,464 bytes free
Post-Run: 463,886,516,224 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
164 — E O F — 2009-07-30 20:00





I think Teatimer for Spybot MIGHT have been on, although I had thought it was off.
Hi,

Please do the following:

Go to Start >run type msconfig

press OK

Go to the Services tab > look for ASKUpgrade service - if it is there - disable it and then advise me.

NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Malwarebytes' Anti-Malware 1.39 Database version: 2542 Windows 5.1.2600 Service Pack 3 8/1/2009 8:21:24 PM mbam-log-2009-08-01 (20-21-24).txt Scan type: Quick Scan Objects scanned: 83057 Time elapsed: 3 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) And the Kaspersky: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Saturday, August 1, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Saturday, August 01, 2009 22:28:33 Records in database: 2570997 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ E:\ F:\ G:\ Scan statistics: Files scanned: 58838 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 00:44:48 No malware has been detected. The scan area is clean. The selected area was scanned. Nothing so far it seems. But my computer is still occasionally freezing completely for short periods of time, losing access to the start menu intermittently, getting fragments of closed windows frozen onto the desktop for periods of time. No blue screens since that first one though.

Go to Start >run type msconfig
press OK
Go to the Services tab > look for ASKUpgrade service - if it is there - disable it and then advise me.


can you please answer this request from my previous post


thank-you
Ah, yes. I did that, then it told me that I should restart for the settings to take effect. So I let it restart, then I disabled AVG and performed the malware scans.
Hi,

Please do the following:

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
OTL logfile created on: 8/1/2009 10:50:25 PM - Run 1
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Documents and Settings\Chris\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 430.87 Gb Free Space | 92.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 625.36 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OPTIMUS-PRIME
Current User Name: Chris
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2004/03/04 11:30:48 | 00,311,296 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\System32\LEXBCES.EXE
PRC - [2004/03/04 11:26:20 | 00,174,592 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\System32\LEXPPS.EXE
PRC - [2008/10/31 21:04:40 | 00,307,200 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2008/07/23 04:51:26 | 16,804,864 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\RTHDCPL.EXE
PRC - [2008/06/18 06:01:56 | 00,077,824 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SOUNDMAN.EXE
PRC - [2005/11/04 19:07:56 | 00,049,152 | —- | M] (Creative Technology Ltd.) – C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
PRC - [2006/05/24 00:20:41 | 00,017,920 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\CTHELPER.EXE
PRC - [2008/08/06 17:31:44 | 00,233,576 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
PRC - [2008/10/08 00:41:36 | 00,023,552 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\CTXFIHLP.EXE
PRC - [2009/06/29 08:51:33 | 01,948,440 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2008/10/08 00:37:38 | 01,212,928 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\CTXFISPI.EXE
PRC - [2009/03/09 05:19:17 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/06/29 08:51:31 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [1999/12/13 02:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\CTsvcCDA.exe
PRC - [2008/09/24 18:35:14 | 00,068,136 | —- | M] () – C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
PRC - [2009/03/09 05:19:15 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/02/09 14:18:00 | 00,163,908 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvsvc32.exe
PRC - [2009/06/23 17:38:21 | 00,075,064 | —- | M] () – C:\WINDOWS\System32\PnkBstrA.exe
PRC - [2009/06/24 17:20:51 | 00,189,288 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.exe
PRC - [2007/01/04 17:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2009/07/27 09:23:37 | 00,907,032 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/06/29 08:51:37 | 00,486,680 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/05/01 15:57:23 | 00,594,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/06/29 08:51:37 | 00,692,504 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2009/06/29 08:51:37 | 00,692,504 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2008/04/13 20:12:41 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wscntfy.exe
PRC - [2009/08/01 22:47:49 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Chris\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - File not found – – (ASKService [Auto | Stopped])
SRV - File not found – – (ASKUpgrade [Disabled | Stopped])
SRV - [2005/09/23 08:28:32 | 00,029,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2009/07/27 09:23:37 | 00,907,032 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
SRV - [2009/06/29 08:51:31 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - [2005/09/23 08:28:56 | 00,066,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/02/25 15:24:45 | 00,079,360 | —- | M] (Creative Labs) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe – (Creative Audio Engine Licensing Service [On_Demand | Stopped])
SRV - [1999/12/13 02:01:00 | 00,044,032 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\CTsvcCDA.exe – (Creative Service for CDROM Access [Auto | Running])
SRV - [2008/10/31 21:04:40 | 00,307,200 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe – (CTAudSvcService [Auto | Running])
SRV - [2006/10/20 22:21:24 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/09/24 18:35:14 | 00,068,136 | —- | M] () – C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe – (GEST Service [Auto | Running])
SRV - [2008/04/13 20:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2006/10/30 04:33:58 | 00,741,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2009/03/09 05:19:15 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2004/03/04 11:30:48 | 00,311,296 | —- | M] (Lexmark International, Inc.) – C:\WINDOWS\System32\LEXBCES.EXE – (LexBceS [Auto | Running])
SRV - [2006/10/30 04:34:02 | 00,122,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2009/02/09 14:18:00 | 00,163,908 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\nvsvc32.exe – (NVSvc [Auto | Running])
SRV - [2009/06/23 17:38:21 | 00,075,064 | —- | M] () – C:\WINDOWS\System32\PnkBstrA.exe – (PnkBstrA [Auto | Running])
SRV - [2009/06/24 17:20:51 | 00,189,288 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.exe – (PnkBstrB [Auto | Running])
SRV - [2007/01/04 17:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2009/07/27 09:23:39 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86 [System | Running])
DRV - [2009/06/29 08:51:37 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
DRV - [2009/05/01 15:57:20 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX [System | Running])
DRV - [2008/10/08 02:21:38 | 00,171,032 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\CT20XUT.SYS – (CT20XUT [On_Demand | Stopped])
DRV - [2008/10/08 02:21:38 | 00,171,032 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\CT20XUT.SYS – (CT20XUT.SYS [On_Demand | Running])
DRV - [2008/10/08 02:21:46 | 00,511,000 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\drivers\ctac32k.sys – (ctac32k [On_Demand | Running])
DRV - [2008/10/08 02:21:50 | 00,526,232 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\drivers\ctaud2k.sys – (ctaud2k [On_Demand | Running])
DRV - [2008/10/08 02:21:54 | 00,347,080 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\drivers\ctdvda2k.sys – (ctdvda2k [On_Demand | Stopped])
DRV - [2008/10/08 02:21:44 | 01,324,056 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\CTEXFIFX.SYS – (CTEXFIFX [On_Demand | Stopped])
DRV - [2008/10/08 02:21:44 | 01,324,056 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\CTEXFIFX.SYS – (CTEXFIFX.SYS [On_Demand | Running])
DRV - [2008/10/08 02:21:40 | 00,072,728 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\CTHWIUT.SYS – (CTHWIUT [On_Demand | Stopped])
DRV - [2008/10/08 02:21:40 | 00,072,728 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\CTHWIUT.SYS – (CTHWIUT.SYS [On_Demand | Running])
DRV - [2008/10/08 02:21:58 | 00,014,360 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\drivers\ctprxy2k.sys – (ctprxy2k [On_Demand | Running])
DRV - [2008/10/08 02:22:00 | 00,158,744 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\drivers\ctsfm2k.sys – (ctsfm2k [On_Demand | Running])
DRV - [2008/10/08 02:22:02 | 00,095,768 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\drivers\emupia2k.sys – (emupia [On_Demand | Running])
DRV - [2009/08/01 20:15:04 | 00,016,608 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys – (gdrv [On_Demand | Running])
DRV - [2008/10/08 02:22:04 | 01,177,624 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\System32\drivers\ha20x2k.sys – (ha20x2k [On_Demand | Running])
DRV - [2008/04/13 12:36:05 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2008/07/24 06:02:44 | 04,749,824 | R— | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\System32\drivers\RtkHDAud.sys – (IntcAzAudAddService [On_Demand | Running])
DRV - [2008/07/30 22:21:08 | 00,079,960 | R— | M] (JMicron Technology Corp.) – C:\WINDOWS\system32\DRIVERS\jraid.sys – (JRAID [Boot | Running])
DRV - [2009/02/09 14:18:00 | 06,307,328 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Running])
DRV - [2008/10/08 02:21:56 | 00,130,072 | —- | M] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\ctoss2k.sys – (ossrv [On_Demand | Running])
DRV - [2009/06/24 17:21:00 | 00,137,888 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys – (PnkBstrK [On_Demand | Stopped])
DRV - [2002/09/16 18:14:32 | 00,004,228 | —- | M] (PowerQuest Corporation) – C:\WINDOWS\System32\drivers\PQNTDRV.sys – (PQNTDrv [System | Running])
DRV - [2004/08/12 10:03:49 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2008/08/07 07:14:56 | 00,111,360 | R— | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys – (RTLE8023xp [On_Demand | Running])
DRV - [2008/04/13 12:39:15 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2009/04/26 16:19:48 | 00,721,904 | —- | M] () – C:\WINDOWS\System32\Drivers\sptd.sys – (sptd [Boot | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - URLSearchHook: *{0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - Reg Error: Key error. File not found
IE - URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: avg@igeared:2.506.026.001
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.12
FF - prefs.js..network.proxy.type: 4

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/06/29 08:52:35 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/03/01 19:02:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared [2009/07/28 12:24:52 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/27 17:29:37 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/07/26 01:45:43 | 00,000,000 | —D | M]

[2009/02/25 05:32:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\mozilla\Extensions
[2009/02/25 05:32:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/01 18:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\mozilla\Firefox\Profiles\m7fwci6o.default\extensions
[2009/02/26 14:00:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\mozilla\Firefox\Profiles\m7fwci6o.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/08/01 18:08:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/07/26 01:45:43 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/02/25 17:30:22 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/03/01 19:02:57 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/03/31 11:51:44 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/07/26 01:45:38 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/07/26 01:45:38 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/09 05:19:09 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/02/06 12:44:28 | 01,447,296 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/07/26 01:45:40 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/02/27 12:13:42 | 00,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2007/04/16 13:07:12 | 00,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2009/01/19 19:28:04 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/01/19 19:28:04 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/29 16:32:46 | 00,001,489 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg_igeared.xml
[2009/01/19 19:28:04 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/01/19 19:28:04 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/01/19 19:28:04 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/01/19 19:28:04 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/01/19 19:28:04 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (316785 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10870 more lines…
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS\System32\xRaidSetup.exe (Gigabyte Technology Corp.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [GEST] File not found
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Utopia Angel] C:\Utopia\Angel\Angel.exe ()
O4 - Startup: C:\Documents and Settings\Chris\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 57 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 56 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su2…15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/25 05:00:14 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [1998/12/13 03:43:32 | 00,000,040 | R— | M] () - E:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[4 C:\WINDOWS\*.tmp files]
[2009/08/01 22:47:48 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Chris\Desktop\OTL.exe
[2009/08/01 17:26:27 | 00,000,112 | —- | C] () – C:\Documents and Settings\Chris\Desktop\GamersHell.url
[2009/08/01 17:26:16 | 62,852,4408 | —- | C] (Stardock Entertainment, Inc. ) – C:\Documents and Settings\Chris\Desktop\Demigod_demo.exe
[2009/08/01 16:58:05 | 00,000,000 | —D | C] – C:\WINDOWS\pss
[2009/08/01 16:46:05 | 62,798,4158 | —- | C] () – C:\Documents and Settings\Chris\Desktop\Demigod_demo.zip
[2009/08/01 16:17:11 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netlogon.dll
[2009/08/01 16:17:11 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\srsvc.dll
[2009/08/01 16:17:08 | 03,597,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mshtml.dll
[2009/08/01 16:17:08 | 00,142,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\aec.sys
[2009/08/01 16:14:04 | 00,219,648 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/08/01 16:14:04 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/08/01 16:14:04 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/08/01 16:14:04 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/08/01 16:14:04 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/08/01 16:14:04 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/08/01 16:14:04 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/01 16:14:04 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/08/01 16:14:00 | 00,000,000 | –SD | C] – C:\Combo-Fix
[2009/08/01 16:11:44 | 03,152,071 | R— | C] () – C:\Documents and Settings\Chris\Desktop\Combo-Fix.exe
[2009/08/01 15:33:50 | 00,071,680 | —- | C] () – C:\Documents and Settings\Chris\Desktop\mbr.exe
[2009/08/01 13:17:13 | 00,287,232 | —- | C] () – C:\Documents and Settings\Chris\Desktop\gmer.exe
[2009/08/01 13:16:21 | 00,278,846 | —- | C] () – C:\Documents and Settings\Chris\Desktop\gmer.zip
[2009/08/01 13:14:05 | 00,359,932 | —- | C] () – C:\Documents and Settings\Chris\Desktop\dds.pif
[2009/08/01 13:14:03 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/07/31 14:25:08 | 00,000,000 | –SD | C] – C:\ComboFix
[2009/07/31 13:47:32 | 00,000,000 | —D | C] – C:\Qoobox
[2009/07/30 08:57:34 | 00,062,859 | —- | C] () – C:\Documents and Settings\Chris\Desktop\1248958364271.jpg
[2009/07/27 19:47:06 | 00,021,294 | —- | C] () – C:\Documents and Settings\Chris\Desktop\Hilda3.jpg
[2009/07/27 19:46:04 | 00,013,519 | —- | C] () – C:\Documents and Settings\Chris\Desktop\oshilda.jpg
[2009/07/27 19:45:38 | 00,023,389 | —- | C] () – C:\Documents and Settings\Chris\Desktop\outlawhilda2.jpg
[2009/07/27 19:28:08 | 00,588,748 | —- | C] () – C:\Documents and Settings\Chris\Desktop\evangelionc.jpg
[2009/07/21 17:39:32 | 00,174,206 | —- | C] () – C:\Documents and Settings\Chris\Desktop\seagate.JPG
[2009/07/21 17:17:57 | 00,000,000 | —D | C] – C:\Documents and Settings\Chris\Desktop\SV353SV17C-2DMoose
[2009/07/21 17:11:38 | 00,077,312 | —- | C] () – C:\Documents and Settings\Chris\Desktop\drivedetect.exe
[2009/07/21 15:36:59 | 00,000,718 | —- | C] () – C:\Documents and Settings\Chris\Desktop\Free Window Registry Repair.lnk
[2009/07/21 15:36:58 | 00,000,000 | —D | C] – C:\Program Files\Free Window Registry Repair
[2009/07/21 15:36:39 | 00,798,000 | —- | C] () – C:\Documents and Settings\Chris\Desktop\RegpairSetup.exe
[2009/07/21 15:29:01 | 17,828,326 | —- | C] () – C:\Documents and Settings\Chris\My Documents\vlc-1.0.0-win32.exe
[2009/07/18 22:00:49 | 00,266,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TweakUI.exe
[2009/07/18 22:00:49 | 00,160,217 | —- | C] () – C:\WINDOWS\System32\PowerToysLicense.rtf
[2009/07/18 20:59:56 | 01,614,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/07/18 20:59:56 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/07/18 20:59:56 | 00,927,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/07/18 20:59:56 | 00,792,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/07/18 20:59:56 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/07/18 20:59:56 | 00,435,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/07/18 20:59:56 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/07/18 20:59:56 | 00,295,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/07/18 20:59:56 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/07/18 20:59:56 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/07/18 20:59:56 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/07/18 20:59:56 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/07/18 20:59:56 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/07/18 20:59:56 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/07/18 20:59:56 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/07/18 20:59:56 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/07/18 20:59:56 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/07/18 20:59:56 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/07/18 20:59:56 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/07/18 20:59:56 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/07/18 20:59:56 | 00,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/07/18 20:59:56 | 00,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/07/18 20:59:56 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/07/18 20:59:55 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/07/18 20:59:55 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/07/18 20:59:55 | 01,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/07/18 20:59:55 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/07/18 20:59:55 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/07/18 20:59:55 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/07/18 20:59:55 | 00,361,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/07/18 20:59:55 | 00,182,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/07/18 20:59:55 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/07/18 20:59:55 | 00,082,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/07/18 20:59:55 | 00,036,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/07/18 20:59:55 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/07/18 20:59:55 | 00,000,000 | —D | C] – C:\WINDOWS\System32\dllcache\cache
[2009/07/07 04:29:56 | 31,501,8579 | —- | C] () – C:\Documents and Settings\Chris\Desktop\bg2-1.2b.exe
[2009/07/03 18:41:48 | 00,001,080 | —- | C] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/07/03 18:41:48 | 00,001,080 | —- | C] () – C:\WINDOWS\System32\settings.sfm
[2009/06/24 14:09:30 | 00,017,513 | —- | C] () – C:\WINDOWS\System32\utopiatarget.dll
[2009/06/23 17:38:36 | 00,137,888 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/04/29 21:02:55 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth2.dll
[2009/04/29 21:02:54 | 00,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth1.dll
[2009/04/29 20:59:11 | 00,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009/04/22 00:19:06 | 00,172,173 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2009/03/13 15:40:04 | 00,000,155 | —- | C] () – C:\WINDOWS\dellstat.ini
[2009/03/13 15:39:38 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\dlbcvs.dll
[2009/03/13 15:39:38 | 00,000,373 | —- | C] () – C:\WINDOWS\System32\dlbccoin.ini
[2009/02/25 05:27:57 | 00,721,904 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008/11/12 02:54:00 | 01,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/11/12 02:54:00 | 01,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/11/12 02:54:00 | 01,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/11/12 02:54:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/10/08 01:08:38 | 00,020,936 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2008/10/08 00:41:40 | 00,002,560 | —- | C] () – C:\WINDOWS\System32\CtxfiRes.dll
[2008/10/08 00:41:40 | 00,002,560 | —- | C] () – C:\WINDOWS\CTXFIRES.DLL
[2008/10/07 10:13:30 | 00,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 00,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 00,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 00,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 00,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 00,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 00,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 00,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 00,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 00,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/09/12 22:22:40 | 00,000,054 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/05/24 01:00:48 | 00,037,888 | —- | C] () – C:\WINDOWS\System32\CTBURST.DLL
[2006/05/24 00:38:39 | 00,060,928 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2005/07/26 17:13:12 | 00,000,321 | —- | C] () – C:\WINDOWS\System32\kill.ini
[2005/06/07 09:10:50 | 00,070,656 | —- | C] () – C:\WINDOWS\System32\CTMMACTL.DLL
[2004/08/12 10:09:17 | 00,000,477 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/12 10:07:01 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/08/01 22:47:49 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Chris\Desktop\OTL.exe
[2009/08/01 21:29:59 | 00,002,193 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2009/08/01 20:17:38 | 00,000,477 | —- | M] () – C:\WINDOWS\win.ini
[2009/08/01 20:17:38 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/08/01 20:17:38 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/08/01 20:15:04 | 00,016,608 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2009/08/01 20:14:58 | 00,205,161 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/08/01 20:14:56 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/08/01 20:14:55 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/01 20:14:53 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/01 20:13:46 | 00,055,828 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000002-00001102-00000005-00311102}.rfx
[2009/08/01 20:13:46 | 00,055,828 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000005-00000000-00000002-00001102-00000005-00311102}.rfx
[2009/08/01 20:13:46 | 00,000,788 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000002-00001102-00000005-00311102}.rfx
[2009/08/01 17:03:44 | 39,452,016 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/08/01 17:03:44 | 00,055,994 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/08/01 16:53:49 | 62,798,4158 | —- | M] () – C:\Documents and Settings\Chris\Desktop\Demigod_demo.zip
[2009/08/01 16:12:14 | 03,152,071 | R— | M] () – C:\Documents and Settings\Chris\Desktop\Combo-Fix.exe
[2009/08/01 15:33:50 | 00,071,680 | —- | M] () – C:\Documents and Settings\Chris\Desktop\mbr.exe
[2009/08/01 13:16:21 | 00,278,846 | —- | M] () – C:\Documents and Settings\Chris\Desktop\gmer.zip
[2009/08/01 13:14:05 | 00,359,932 | —- | M] () – C:\Documents and Settings\Chris\Desktop\dds.pif
[2009/07/30 11:16:36 | 00,287,232 | —- | M] () – C:\Documents and Settings\Chris\Desktop\gmer.exe
[2009/07/30 08:57:35 | 00,062,859 | —- | M] () – C:\Documents and Settings\Chris\Desktop\1248958364271.jpg
[2009/07/29 21:51:48 | 62,852,4408 | —- | M] (Stardock Entertainment, Inc. ) – C:\Documents and Settings\Chris\Desktop\Demigod_demo.exe
[2009/07/28 03:14:28 | 00,048,128 | —- | M] () – C:\Documents and Settings\Chris\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/27 19:47:07 | 00,021,294 | —- | M] () – C:\Documents and Settings\Chris\Desktop\Hilda3.jpg
[2009/07/27 19:46:05 | 00,013,519 | —- | M] () – C:\Documents and Settings\Chris\Desktop\oshilda.jpg
[2009/07/27 19:45:39 | 00,023,389 | —- | M] () – C:\Documents and Settings\Chris\Desktop\outlawhilda2.jpg
[2009/07/27 19:28:09 | 00,588,748 | —- | M] () – C:\Documents and Settings\Chris\Desktop\evangelionc.jpg
[2009/07/27 09:23:39 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/23 15:05:26 | 00,000,112 | —- | M] () – C:\Documents and Settings\Chris\Desktop\GamersHell.url
[2009/07/21 17:39:32 | 00,174,206 | —- | M] () – C:\Documents and Settings\Chris\Desktop\seagate.JPG
[2009/07/21 17:11:39 | 00,077,312 | —- | M] () – C:\Documents and Settings\Chris\Desktop\drivedetect.exe
[2009/07/21 16:42:52 | 00,002,329 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SeaTools for Windows.lnk
[2009/07/21 15:36:59 | 00,000,718 | —- | M] () – C:\Documents and Settings\Chris\Desktop\Free Window Registry Repair.lnk
[2009/07/21 15:36:48 | 00,798,000 | —- | M] () – C:\Documents and Settings\Chris\Desktop\RegpairSetup.exe
[2009/07/21 15:29:46 | 17,828,326 | —- | M] () – C:\Documents and Settings\Chris\My Documents\vlc-1.0.0-win32.exe
[2009/07/19 09:33:02 | 03,597,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/07/19 09:33:02 | 03,597,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/07/19 09:33:02 | 03,597,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mshtml.dll
[2009/07/19 09:32:59 | 06,067,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/07/19 09:32:59 | 06,067,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/07/18 21:24:43 | 00,316,785 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/07/15 16:01:59 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/13 13:36:34 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/13 13:36:12 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/13 05:48:54 | 00,219,648 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/07/09 01:18:16 | 00,000,599 | —- | M] () – C:\Documents and Settings\Chris\Desktop\Utopia Angel.lnk
[2009/07/07 11:10:56 | 24,539,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/07/07 04:48:46 | 31,501,8579 | —- | M] () – C:\Documents and Settings\Chris\Desktop\bg2-1.2b.exe
[2009/07/03 18:41:48 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/07/03 18:41:48 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm

========== LOP Check ==========

[2009/06/29 08:51:55 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/02/25 06:34:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/07/21 17:13:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/02/26 14:00:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/02/25 05:37:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/04/29 21:01:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2009/04/29 21:01:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SPSS
[2009/02/25 06:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/16 19:25:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/30 11:41:49 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Chris\Application Data
[2009/02/25 06:37:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\acccore
[2009/05/09 18:21:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\AVGTOOLBAR
[2009/05/30 04:13:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\Azureus
[2009/02/25 05:38:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\DAEMON Tools
[2009/04/26 16:43:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\DAEMON Tools Lite
[2009/02/25 05:38:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\DAEMON Tools Pro
[2009/02/26 03:19:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\OpenOffice.org
[2009/02/25 17:47:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Chris\Application Data\SystemRequirementsLab
[2004/08/12 10:01:19 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/08/01 20:14:55 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI