This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] System Slow and looks like something controlling it

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/16 21:24
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================

Drivers
——————-
Name: 8a2e0481.sys
Image Path: C:\WINDOWS\System32\drivers\8a2e0481.sys
Address: 0xB1206000 Size: 92544 File Visible: No Signed: -
Status: -

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB11A2000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBADF8000 Size: 8192 File Visible: No Signed: -
Status: -

Name: MSIVXdqysflcugeawynrkwcjfdecuuovxyvbx.sys
Image Path: C:\WINDOWS\system32\drivers\MSIVXdqysflcugeawynrkwcjfdecuuovxyvbx.sys
Address: 0xB1400000 Size: 180224 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xAE917000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
——————-
#: 035 Function Name: NtCreateEvent
Status: Hooked by "C:\WINDOWS\System32\drivers\8a2e0481.sys" at address 0xb120c795

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\drivers\8a2e0481.sys" at address 0xb120a785

#: 047 Function Name: NtCreateProcess
Status: Hooked by "PCTCore.sys" at address 0xba6a5282

#: 048 Function Name: NtCreateProcessEx
Status: Hooked by "PCTCore.sys" at address 0xba6a5474

#: 063 Function Name: NtDeleteKey
Status: Hooked by "PCTCore.sys" at address 0xba6b6d00

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "PCTCore.sys" at address 0xba6b6fb8

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\drivers\8a2e0481.sys" at address 0xb120a845

#: 192 Function Name: NtRenameKey
Status: Hooked by "PCTCore.sys" at address 0xba6b7422

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "PCTCore.sys" at address 0xba6a4f32

Hidden Services
——————-
Service Name: 8a2e0481
Image Path: C:\WINDOWS\System32\drivers\8a2e0481.sys

Service Name: MSIVXserv.sys
Image Path: C:\WINDOWS\system32\drivers\MSIVXdqysflcugeawynrkwcjfdecuuovxyvbx.sys

==EOF==





DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 21:21:57.31 on Wed 09/16/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1349 [GMT -4:00]

AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Ahead\InCD\InCDsrv.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Starfield\Desktop Notifier\wben.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESRI\License\arcgis9x\lmgrd.exe
C:\Documents and Settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\ESRI\License\arcgis9x\lmgrd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Documents and Settings\George\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESRI\License\arcgis9x\ARCGIS.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
svchost
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\George\Application Data\mjusbsp\magicJack.exe
C:\Documents and Settings\George\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\George\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\George\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\George\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uURLSearchHooks: N/A: {00a6faf6-072e-44cf-8957-5838f569a31d} - c:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
mURLSearchHooks: H - No File
BHO: MyWebSearch Search Assistant BHO: {00a6faf1-072e-44cf-8957-5838f569a31d} - c:\program files\mywebsearch\bar\1.bin\MWSSRCAS.DLL
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: mwsBar BHO: {07b18ea1-a523-4961-b6bb-170de4475cca} - c:\program files\mywebsearch\bar\1.bin\MWSBAR.DLL
BHO: ZILLAbar Browser Helper Object: {1827766b-9f49-4854-8034-f6ee26fcb1ec} - c:\program files\stopzilla!\SZSG.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: STOPzilla Browser Helper Object: {e3215f20-3212-11d6-9f8b-00d0b743919d} - c:\program files\stopzilla!\SZIEBHO.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: STOPzilla: {98828ded-a591-462f-83ba-d2f62a68b8b8} - c:\program files\stopzilla!\SZSG.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [wben] "c:\program files\starfield\desktop notifier\wben.exe"
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [cdloader] "c:\documents and settings\george\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MyWebSearch Email Plugin] c:\progra~1\mywebs~1\bar\1.bin\mwsoemon.exe
uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H
uRun: [Google Update] "c:\documents and settings\george\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [SunJavaUpdateSched] c:\program files\java\j2re1.4.2_03\bin\jusched.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [InCD] c:\program files\ahead\incd\InCD.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [MyWebSearch Plugin] rundll32 c:\progra~1\mywebs~1\bar\1.bin\M3PLUGIN.DLL,UPF
mRun: [My Web Search Bar] rundll32 c:\progra~1\mywebs~1\bar\1.bin\MWSBAR.DLL,S
mRun: [MyWebSearch Email Plugin] c:\progra~1\mywebs~1\bar\1.bin\mwsoemon.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [PromoReg] c:\windows\temp\_ex-08.exe
mRun: [Fmumubuworucato] rundll32.exe "c:\windows\ebuxidigib.dll",e
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\george\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\documents and settings\george\start menu\programs\startup\ikowin32.exe
StartupFolder: c:\docume~1\george\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office12\GROOVE.EXE
StartupFolder: c:\docume~1\george\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
IE: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=GR
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\common files\is3\anti-spyware\iS3lsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
TCP: NameServer = 85.255.112.88,85.255.112.236
TCP: {A0C8C6C0-7CA3-42E4-8A1B-DEDEAC705A30} = 85.255.112.88,85.255.112.236
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: LMIinit - LMIinit.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli wplesysg.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\george\applic~1\mozilla\firefox\profiles\v99bwai6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://google.com
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://george-hall.net/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\george\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\george\application data\mozilla\firefox\profiles\v99bwai6.default\extensions\[removed]\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\george\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPMyWebS.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
FF - HiddenExtension: XUL Cache: {FD0A3298-AA20-4BD9-A666-FBA35A003554} - c:\documents and settings\george\local settings\application data\{FD0A3298-AA20-4BD9-A666-FBA35A003554}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-8-8 130936]
R0 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [2009-5-12 61328]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-19 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-3-19 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-19 108552]
R2 ArcGIS License Manager;ArcGIS License Manager;c:\program files\esri\license\arcgis9x\lmgrd.exe [2009-3-19 1431440]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-4 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-19 297752]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-7-24 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2009-8-19 47640]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
S2 gupdate1c9a8f19d0e6a37;Google Update Service (gupdate1c9a8f19d0e6a37);c:\program files\google\update\GoogleUpdate.exe [2009-3-19 133104]
S2 MyWebSearchService;My Web Search Service;c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe [2009-7-3 28762]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-8-8 348752]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-8-8 1097096]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]

=============== Created Last 30 ================

2009-09-16 21:10 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-16 21:10 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-09-16 21:10 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-09-16 21:10 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-09-16 20:59 –d—– c:\windows\system32\appmgmt
2009-09-16 17:56 –d—– c:\program files\iPod
2009-09-16 17:56 –d—– c:\program files\iTunes
2009-09-16 17:56 –d—– c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-05 01:54 94,208 a——- c:\windows\system32\QuickTimeVR.qtx
2009-09-05 01:54 69,632 a——- c:\windows\system32\QuickTime.qts
2009-09-03 17:24 754 a——- c:\windows\WORDPAD.INI
2009-08-31 07:26 120 a——- c:\windows\Wzixiviyifa.dat
2009-08-24 00:51 –d—– c:\windows\system32\LogFiles
2009-08-22 14:01 –d—– c:\program files\WinPcap
2009-08-22 14:00 92,544 a——- c:\windows\system32\drivers\8a2e0481.sys
2009-08-22 14:00 –d—– c:\docume~1\alluse~1\applic~1\16824214
2009-08-19 06:59 –d—– c:\docume~1\alluse~1\applic~1\LogMeIn
2009-08-19 06:59 83,288 a——- c:\windows\system32\LMIRfsClientNP.dll
2009-08-19 06:59 47,640 a——- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-08-19 06:59 28,984 a——- c:\windows\system32\LMIport.dll
2009-08-19 06:59 87,352 a——- c:\windows\system32\LMIinit.dll
2009-08-19 06:59 1,024 a——- C:\.rnd
2009-08-19 06:58 –d—– c:\program files\LogMeIn

==================== Find3M ====================

2009-08-28 19:42 2,065,696 a——- c:\windows\system32\usbaaplrc.dll
2009-08-28 19:42 40,448 a——- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 08:07 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 08:07 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-07-20 14:57 17,408 a—-r– c:\windows\system32\SZIO5.dll
2009-07-20 14:56 311,296 a—-r– c:\windows\system32\SZBase5.dll
2009-07-20 14:56 540,672 a—-r– c:\windows\system32\SZComp5.dll
2009-07-09 15:52 126,976 a—-r– c:\windows\system32\IS3HTUI5.dll
2009-07-09 15:52 393,216 a—-r– c:\windows\system32\IS3DBA5.dll
2009-07-09 15:51 385,024 a—-r– c:\windows\system32\IS3UI5.dll
2009-07-09 15:51 61,440 a—-r– c:\windows\system32\IS3Hks5.dll
2009-07-09 15:51 23,040 a—-r– c:\windows\system32\IS3XDat5.dll
2009-07-09 15:50 225,280 a—-r– c:\windows\system32\IS3Win325.dll
2009-07-09 15:50 94,208 a—-r– c:\windows\system32\IS3Inet5.dll
2009-07-09 15:50 90,112 a—-r– c:\windows\system32\IS3Svc5.dll
2009-07-09 15:47 724,992 a—-r– c:\windows\system32\IS3Base5.dll
2009-07-03 07:46 28,672 a——- c:\windows\system32\f3PSSavr.scr

============= FINISH: 21:22:21.56 ===============

Attachments:

Hi psycho7244, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Please download exeHelper by Raktor to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


Next

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).


Next

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • exeHelper log
  • GooredFix log
  • combofix log
How's the computer?

Thanks
exeHelper by Raktor - 09
Build 20090916
Run at 16:29:02 on 09/17/09
Now searching…
Checking for numerical processes…
Checking for bad processes…
Checking for bad files…
Resetting filetype association for .exe
Resetting filetype association for .com
–Finished–



GooredFix by jpshortstuff (12.07.09)
Log created at 17:20 on 17/09/2009 (George)
Firefox version 3.5.3 (en-US)

========== GooredScan ==========

Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{F38F3839-8C4E-4BD5-9874-8B53BEEE87AE} -> Success!
Deleting C:\Documents and Settings\George\Local Settings\Application Data\{F38F3839-8C4E-4BD5-9874-8B53BEEE87AE} -> Success!

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [23:12 19/03/2009]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"avg@igeared"="C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared" [13:09 01/07/2009]

———- Old Logs ———-
GooredFix[20.31.20_17-09-2009].txt
GooredFix[20.39.16_17-09-2009].txt

-=E.O.F=-




ComboFix 09-09-16.05 - George 09/17/2009 17:00.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1545 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\George\Application Data\wiaserva.log
c:\documents and settings\George\Start Menu\Programs\PlayMYDVD
c:\documents and settings\George\Start Menu\Programs\PlayMYDVD\Uninstall.lnk
c:\documents and settings\George\Start Menu\Programs\Startup\ikowin32.exe
c:\program files\FunWebProducts
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\1.bin\F3DTactl.dll
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTmlmu.dll
c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\1.bin\F3REGHK.DLL
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
c:\program files\MyWebSearch\bar\1.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSSrcas.dll
c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\00031936
c:\program files\MyWebSearch\bar\Cache\0008D02A
c:\program files\MyWebSearch\bar\Cache\000D92CA
c:\program files\MyWebSearch\bar\Cache\00311FED
c:\program files\MyWebSearch\bar\Cache\01CC7AB0
c:\program files\MyWebSearch\bar\Cache\02361E25
c:\program files\MyWebSearch\bar\Cache\0240951A
c:\program files\MyWebSearch\bar\Cache\027646F3
c:\program files\MyWebSearch\bar\Cache\027D2466
c:\program files\MyWebSearch\bar\Cache\0304161D
c:\program files\MyWebSearch\bar\Cache\0440EE9A
c:\program files\MyWebSearch\bar\Cache\069DC355
c:\program files\MyWebSearch\bar\Cache\076101A1
c:\program files\MyWebSearch\bar\Cache\076444A7
c:\program files\MyWebSearch\bar\Cache\07BCE33D
c:\program files\MyWebSearch\bar\Cache\080F1E82
c:\program files\MyWebSearch\bar\Cache\08920EF4
c:\program files\MyWebSearch\bar\Cache\0B8F71DB
c:\program files\MyWebSearch\bar\Cache\0F4AE6F7
c:\program files\MyWebSearch\bar\Cache\100076E2
c:\program files\MyWebSearch\bar\Cache\111C4E94
c:\program files\MyWebSearch\bar\Cache\1765DE5F
c:\program files\MyWebSearch\bar\Cache\1F0210A7
c:\program files\MyWebSearch\bar\Cache\1F021412.bin
c:\program files\MyWebSearch\bar\Cache\1F02151B.bin
c:\program files\MyWebSearch\bar\Cache\1F021625.bin
c:\program files\MyWebSearch\bar\Cache\1F0217BB.bin
c:\program files\MyWebSearch\bar\Cache\1F021886.bin
c:\program files\MyWebSearch\bar\Cache\1F0219BF.bin
c:\program files\MyWebSearch\bar\Cache\1F021A7A.bin
c:\program files\MyWebSearch\bar\Cache\1FB48836
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\PlayMYDVD
c:\program files\PlayMYDVD\Uninstall.exe
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\ebuxidigib.dll
c:\windows\Installer\18c9be10.msi
c:\windows\system32\drivers\8a2e0481.sys
c:\windows\system32\drivers\MSIVXdqysflcugeawynrkwcjfdecuuovxyvbx.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\f3PSSavr.scr
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXsflhaxikkujsqhqtpwxjxwadbxtppcbh.dll
c:\windows\system32\MSIVXxpbshmciscoewxseqrophxwuuijnvydo.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\wplesysg.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSIVXserv.sys
——-\Legacy_MSIVXserv.sys
——-\Legacy_MYWEBSEARCHSERVICE
——-\Legacy_npf
——-\Service_8a2e0481
——-\Service_MyWebSearchService
——-\Service_npf


((((((((((((((((((((((((( Files Created from 2009-08-17 to 2009-09-17 )))))))))))))))))))))))))))))))
.

2009-09-17 20:59 . 2009-09-17 20:59 ——– d—–w- c:\documents and settings\George\Local Settings\Application Data\{F38F3839-8C4E-4BD5-9874-8B53BEEE87AE}
2009-09-17 01:19 . 2009-09-17 01:19 ——– d—–w- c:\program files\ERUNT
2009-09-17 01:10 . 2009-09-10 18:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-17 01:10 . 2009-09-17 01:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-17 01:10 . 2009-09-17 01:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-17 01:10 . 2009-09-10 18:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-16 21:56 . 2009-09-16 21:56 ——– d—–w- c:\program files\iPod
2009-09-16 21:56 . 2009-09-16 21:57 ——– d—–w- c:\program files\iTunes
2009-09-16 21:56 . 2009-09-16 21:57 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-01 01:05 . 2009-09-01 01:05 ——– d—–w- c:\documents and settings\George\Local Settings\Application Data\Temp
2009-08-31 11:26 . 2009-09-15 19:38 120 —-a-w- c:\windows\Wzixiviyifa.dat
2009-08-24 04:51 . 2009-08-24 04:51 ——– d—–w- c:\windows\system32\LogFiles
2009-08-22 18:00 . 2009-08-23 05:01 ——– d—–w- c:\documents and settings\All Users\Application Data\16824214
2009-08-19 10:59 . 2009-08-19 10:59 ——– d—–w- c:\documents and settings\George\Local Settings\Application Data\LogMeIn
2009-08-19 10:59 . 2009-08-19 10:59 ——– d—–w- c:\documents and settings\All Users\Application Data\LogMeIn
2009-08-19 10:59 . 2008-10-17 00:35 83288 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-08-19 10:59 . 2008-10-17 00:35 28984 —-a-w- c:\windows\system32\LMIport.dll
2009-08-19 10:59 . 2008-07-24 22:46 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-08-19 10:59 . 2008-10-17 00:35 87352 —-a-w- c:\windows\system32\LMIinit.dll
2009-08-19 10:58 . 2009-09-17 20:54 ——– d—–w- c:\program files\LogMeIn

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-17 21:09 . 2009-08-15 20:15 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-09-17 07:25 . 2009-03-20 00:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-17 00:50 . 2009-08-08 10:51 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-17 00:49 . 2009-03-20 15:57 ——– d—–w- c:\documents and settings\George\Application Data\mjusbsp
2009-09-16 21:59 . 2009-03-20 15:57 ——– d—–w- c:\documents and settings\George\Application Data\Apple Computer
2009-09-16 21:56 . 2009-03-20 15:55 ——– d—–w- c:\program files\Common Files\Apple
2009-09-16 21:54 . 2009-03-20 15:56 ——– d—–w- c:\program files\QuickTime
2009-09-15 10:40 . 2009-03-19 23:58 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-09-03 23:10 . 2009-04-04 21:58 ——– d—–w- c:\documents and settings\George\Application Data\FileZilla
2009-09-02 22:52 . 2009-03-25 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-28 23:42 . 2009-03-20 15:55 40448 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 23:42 . 2009-03-20 15:55 2065696 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 12:07 . 2009-03-19 23:07 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 12:07 . 2009-03-19 23:06 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 12:07 . 2009-03-19 23:06 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-23 09:00 . 2009-03-19 23:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-15 20:15 . 2009-08-15 20:15 ——– d—–w- c:\program files\STOPzilla!
2009-08-15 20:15 . 2009-08-15 20:15 ——– d—–w- c:\program files\Common Files\iS3
2009-08-08 11:03 . 2009-08-08 10:56 ——– d—–w- c:\documents and settings\George\Application Data\GetRightToGo
2009-08-08 10:52 . 2009-08-08 10:51 ——– d—–w- c:\program files\Spyware Doctor
2009-08-08 10:52 . 2009-08-08 10:51 ——– d—–w- c:\program files\Common Files\PC Tools
2009-08-08 10:51 . 2009-08-08 10:51 ——– d—–w- c:\documents and settings\George\Application Data\PC Tools
2009-08-08 10:51 . 2009-08-08 10:51 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-08-03 21:10 . 2009-08-01 11:51 ——– d—–w- c:\documents and settings\George\Application Data\Move Networks
2009-07-20 18:57 . 2009-07-20 18:57 17408 —-a-r- c:\windows\system32\SZIO5.dll
2009-07-20 18:56 . 2009-07-20 18:56 311296 —-a-r- c:\windows\system32\SZBase5.dll
2009-07-20 18:56 . 2009-07-20 18:56 540672 —-a-r- c:\windows\system32\SZComp5.dll
2009-07-20 10:24 . 2009-07-20 10:24 ——– d—–w- c:\program files\FLV Player
2009-07-19 22:31 . 2009-06-01 00:43 ——– d—–w- c:\program files\FileZilla FTP Client
2009-07-09 19:52 . 2009-07-09 19:52 126976 —-a-r- c:\windows\system32\IS3HTUI5.dll
2009-07-09 19:52 . 2009-07-09 19:52 393216 —-a-r- c:\windows\system32\IS3DBA5.dll
2009-07-09 19:51 . 2009-07-09 19:51 385024 —-a-r- c:\windows\system32\IS3UI5.dll
2009-07-09 19:51 . 2009-07-09 19:51 61440 —-a-r- c:\windows\system32\IS3Hks5.dll
2009-07-09 19:51 . 2009-07-09 19:51 23040 —-a-r- c:\windows\system32\IS3XDat5.dll
2009-07-09 19:50 . 2009-07-09 19:50 225280 —-a-r- c:\windows\system32\IS3Win325.dll
2009-07-09 19:50 . 2009-07-09 19:50 94208 —-a-r- c:\windows\system32\IS3Inet5.dll
2009-07-09 19:50 . 2009-07-09 19:50 90112 —-a-r- c:\windows\system32\IS3Svc5.dll
2009-07-09 19:47 . 2009-07-09 19:47 724992 —-a-r- c:\windows\system32\IS3Base5.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"wben"="c:\program files\Starfield\Desktop Notifier\wben.exe" [2009-06-25 338456]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-20 39408]
"cdloader"="c:\documents and settings\George\Application Data\mjusbsp\cdloader2.exe" [2009-08-01 50520]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376]
"Google Update"="c:\documents and settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-01 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-28 2007832]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2004-09-13 1450096]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-22 339968]

c:\documents and settings\George\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE [2007-8-29 340856]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-8-24 101784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 12:07 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-17 00:35 87352 —-a-w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Python25\\pythonw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Google\\Picasa3\\Picasa3.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\\Program Files\\Quantum GIS\\qgis_help.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\George\\Application Data\\mjusbsp\\magicJack.exe"=

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [8/8/2009 6:52 AM 130936]
R0 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/19/2009 7:06 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/19/2009 7:07 PM 108552]
R2 ArcGIS License Manager;ArcGIS License Manager;c:\program files\ESRI\License\arcgis9x\lmgrd.exe [3/19/2009 8:28 PM 1431440]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/4/2009 8:38 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/19/2009 7:06 PM 297752]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [8/19/2009 6:59 AM 47640]
S2 gupdate1c9a8f19d0e6a37;Google Update Service (gupdate1c9a8f19d0e6a37);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2009 8:20 PM 133104]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [8/8/2009 6:51 AM 348752]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder

2009-09-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-09-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-20 00:19]

2009-09-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-20 00:19]

2009-09-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-20 00:19]

2009-09-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1500820517-682003330-1003Core.job
- c:\documents and settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-01 05:27]

2009-09-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1500820517-682003330-1003UA.job
- c:\documents and settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-01 05:27]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=GR
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
FF - ProfilePath - c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\v99bwai6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://google.com
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://george-hall.net/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\George\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\v99bwai6.default\extensions\[removed]\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\George\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMyWebS.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: XUL Cache: {F38F3839-8C4E-4BD5-9874-8B53BEEE87AE} - c:\documents and settings\George\Local Settings\Application Data\{F38F3839-8C4E-4BD5-9874-8B53BEEE87AE}\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
HKLM-Run-Fmumubuworucato - c:\windows\ebuxidigib.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-17 17:10
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll

- - - - - - - > 'lsass.exe'(744)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll

- - - - - - - > 'explorer.exe'(2732)
c:\program files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\windows\system32\LMIRfsClientNP.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\LogMeIn\x86\ramaint.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\documents and settings\George\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\iPod\bin\iPodService.exe
c:\documents and settings\George\Application Data\mjusbsp\st00000\mjsetup.exe
c:\documents and settings\George\Application Data\mjusbsp\magicJack.exe
.
**************************************************************************
.
Completion time: 2009-09-17 17:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-17 21:17

Pre-Run: 350,413,721,600 bytes free
Post-Run: 350,484,160,512 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

413 — E O F — 2009-03-20 21:28
Hi psycho7244,

Your system has been infected by one or more Rootkits/Backdoor Trojans.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

I suggest you read:

  • Danger: Remote Access Trojans.
  • When should I re-format? How should I reinstall?
  • How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?


µTorrent
You have µTorrent, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

You have 2 antivirus programs running. They will conflict and cause problems. I suggest you uninstall one of them. There is no problem with Spyware Doctor without the antivirus portion. You do however have another antispyware prgram Stopzilla already installed.



We wll use combofix again but run it differently.

Please read through these instructions to familarize yourself with what to expect when this tool runs

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
Do Not copy the word CODE

File::
c:\windows\Wzixiviyifa.dat

Folder::
c:\documents and settings\All Users\Application Data\16824214

FireFox::
FF - ProfilePath - c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\v99bwai6.default\
FF - HiddenExtension: XUL Cache: {F38F3839-8C4E-4BD5-9874-8B53BEEE87AE} - c:\documents and settings\George\Local Settings\Application Data\{F38F3839-8C4E-4BD5-9874-8B53BEEE87AE}\

Registry::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]



Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • combofix log
  • MBAM log

Everything still ok?

Thanks
I now keep getting alerts for Trojan Horse Clicker.aalx I just saw your post, I will address it first.
ComboFix 09-09-16.05 - George 09/18/2009 19:12.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1426 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Help\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\George\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe

.
((((((((((((((((((((((((( Files Created from 2009-08-18 to 2009-09-18 )))))))))))))))))))))))))))))))
.

2009-09-18 22:57 . 2009-09-18 22:57 ——– d—–w- c:\windows\system32\vmm32
2009-09-18 22:52 . 2009-09-18 22:52 ——– d—–w- c:\documents and settings\All Users\Application Data\SITEguard
2009-09-18 22:48 . 2009-09-18 22:48 ——– d—–w- C:\found.001
2009-09-17 21:44 . 2009-09-17 21:45 ——– d—–w- c:\program files\iTunes
2009-09-17 21:42 . 2009-09-17 21:42 ——– d—–w- c:\program files\Windows Installer Clean Up
2009-09-17 21:41 . 2009-09-17 21:41 ——– d—–w- c:\program files\MSECACHE
2009-09-17 01:19 . 2009-09-17 01:19 ——– d—–w- c:\program files\ERUNT
2009-09-17 01:10 . 2009-09-10 18:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-17 01:10 . 2009-09-17 01:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-17 01:10 . 2009-09-17 01:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-17 01:10 . 2009-09-10 18:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-16 21:56 . 2009-09-16 21:56 ——– d—–w- c:\program files\iPod
2009-09-16 21:56 . 2009-09-16 21:57 ——– d—–w- c:\program files\XXXX_iTunes
2009-09-16 21:56 . 2009-09-16 21:57 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-01 01:05 . 2009-09-01 01:05 ——– d—–w- c:\documents and settings\George\Local Settings\Application Data\Temp
2009-08-31 11:26 . 2009-09-15 19:38 120 —-a-w- c:\windows\Wzixiviyifa.dat
2009-08-24 04:51 . 2009-08-24 04:51 ——– d—–w- c:\windows\system32\LogFiles
2009-08-22 18:00 . 2009-08-23 05:01 ——– d—–w- c:\documents and settings\All Users\Application Data\16824214

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-18 23:13 . 2009-08-08 10:51 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-18 23:05 . 2009-08-15 20:15 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-09-18 23:04 . 2009-03-20 15:57 ——– d—–w- c:\documents and settings\George\Application Data\mjusbsp
2009-09-18 15:55 . 2009-08-19 10:58 ——– d—–w- c:\program files\LogMeIn
2009-09-18 08:26 . 2009-03-20 00:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-16 21:59 . 2009-03-20 15:57 ——– d—–w- c:\documents and settings\George\Application Data\Apple Computer
2009-09-16 21:56 . 2009-03-20 15:55 ——– d—–w- c:\program files\Common Files\Apple
2009-09-16 21:54 . 2009-03-20 15:56 ——– d—–w- c:\program files\QuickTime
2009-09-15 10:40 . 2009-03-19 23:58 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-09-03 23:10 . 2009-04-04 21:58 ——– d—–w- c:\documents and settings\George\Application Data\FileZilla
2009-09-02 22:52 . 2009-03-25 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-28 23:42 . 2009-03-20 15:55 40448 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 23:42 . 2009-03-20 15:55 2065696 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 12:07 . 2009-03-19 23:07 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 12:07 . 2009-03-19 23:06 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 12:07 . 2009-03-19 23:06 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-23 09:00 . 2009-03-19 23:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-19 10:59 . 2009-08-19 10:59 ——– d—–w- c:\documents and settings\All Users\Application Data\LogMeIn
2009-08-15 20:15 . 2009-08-15 20:15 ——– d—–w- c:\program files\STOPzilla!
2009-08-15 20:15 . 2009-08-15 20:15 ——– d—–w- c:\program files\Common Files\iS3
2009-08-08 11:03 . 2009-08-08 10:56 ——– d—–w- c:\documents and settings\George\Application Data\GetRightToGo
2009-08-03 21:10 . 2009-08-01 11:51 ——– d—–w- c:\documents and settings\George\Application Data\Move Networks
2009-07-20 18:57 . 2009-07-20 18:57 17408 —-a-r- c:\windows\system32\SZIO5.dll
2009-07-20 18:56 . 2009-07-20 18:56 311296 —-a-r- c:\windows\system32\SZBase5.dll
2009-07-20 18:56 . 2009-07-20 18:56 540672 —-a-r- c:\windows\system32\SZComp5.dll
2009-07-09 19:52 . 2009-07-09 19:52 126976 —-a-r- c:\windows\system32\IS3HTUI5.dll
2009-07-09 19:52 . 2009-07-09 19:52 393216 —-a-r- c:\windows\system32\IS3DBA5.dll
2009-07-09 19:51 . 2009-07-09 19:51 385024 —-a-r- c:\windows\system32\IS3UI5.dll
2009-07-09 19:51 . 2009-07-09 19:51 61440 —-a-r- c:\windows\system32\IS3Hks5.dll
2009-07-09 19:51 . 2009-07-09 19:51 23040 —-a-r- c:\windows\system32\IS3XDat5.dll
2009-07-09 19:50 . 2009-07-09 19:50 225280 —-a-r- c:\windows\system32\IS3Win325.dll
2009-07-09 19:50 . 2009-07-09 19:50 94208 —-a-r- c:\windows\system32\IS3Inet5.dll
2009-07-09 19:50 . 2009-07-09 19:50 90112 —-a-r- c:\windows\system32\IS3Svc5.dll
2009-07-09 19:47 . 2009-07-09 19:47 724992 —-a-r- c:\windows\system32\IS3Base5.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-17_21.10.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-18 22:59 . 2004-10-29 22:01 19456 c:\windows\system32\ReinstallBackups\0016\DriverFiles\IntelNic.dll
- 2009-07-31 10:19 . 2004-10-29 22:01 19456 c:\windows\system32\ReinstallBackups\0016\DriverFiles\IntelNic.dll
- 2009-07-31 10:19 . 2004-11-16 14:16 36864 c:\windows\system32\ReinstallBackups\0016\DriverFiles\e100bmsg.dll
+ 2009-09-18 22:59 . 2004-11-16 13:16 36864 c:\windows\system32\ReinstallBackups\0016\DriverFiles\e100bmsg.dll
- 2009-09-16 21:57 . 2009-05-18 18:17 26600 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspiWDM.sys
+ 2009-09-17 21:45 . 2009-05-18 18:17 26600 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspiWDM.sys
- 2009-03-19 22:18 . 2009-03-19 22:18 45056 c:\windows\Installer\{FCD9CD52-7222-4672-94A0-A722BA702FD0}\NewShortcut1.EXE
+ 2009-03-19 22:18 . 2009-09-18 22:57 45056 c:\windows\Installer\{FCD9CD52-7222-4672-94A0-A722BA702FD0}\NewShortcut1.EXE
+ 2009-09-18 22:50 . 2009-09-18 22:50 53248 c:\windows\ERDNT\AutoBackup\9-18-2009\Users\00000002\UsrClass.dat
+ 2009-09-17 21:11 . 2009-09-17 21:11 53248 c:\windows\ERDNT\AutoBackup\9-17-2009\Users\00000002\UsrClass.dat
+ 2009-09-18 22:59 . 2004-11-16 21:52 126976 c:\windows\system32\ReinstallBackups\0016\DriverFiles\Prounstl.exe
- 2009-07-31 10:19 . 2004-11-16 22:52 126976 c:\windows\system32\ReinstallBackups\0016\DriverFiles\Prounstl.exe
+ 2009-09-18 22:59 . 2004-10-14 20:30 155648 c:\windows\system32\ReinstallBackups\0016\DriverFiles\e100b325.sys
- 2009-07-31 10:19 . 2004-10-14 21:30 155648 c:\windows\system32\ReinstallBackups\0016\DriverFiles\e100b325.sys
+ 2009-09-17 21:45 . 2008-04-17 17:12 107368 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspi.dll
- 2009-09-16 21:57 . 2008-04-17 17:12 107368 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspi.dll
+ 2009-09-17 21:42 . 2009-09-17 21:42 472064 c:\windows\Installer\130b37.msi
+ 2009-09-16 21:58 . 2009-09-17 21:46 102400 c:\windows\Installer\{EC2A8F27-4FBF-4E41-B27B-FE822511B761}\iTunesIco.exe
- 2009-09-16 21:58 . 2009-09-16 21:58 102400 c:\windows\Installer\{EC2A8F27-4FBF-4E41-B27B-FE822511B761}\iTunesIco.exe
+ 2009-09-18 22:50 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\9-18-2009\ERDNT.EXE
+ 2009-09-17 21:11 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\9-17-2009\ERDNT.EXE
+ 2009-03-19 23:37 . 2009-09-18 03:54 3817984 c:\windows\Installer\1db62a.msi
- 2009-03-19 23:37 . 2009-09-17 20:19 3817984 c:\windows\Installer\1db62a.msi
+ 2009-09-17 21:46 . 2009-09-17 21:46 4597248 c:\windows\Installer\130b3e.msi
+ 2009-09-18 22:50 . 2009-09-18 22:50 3731456 c:\windows\ERDNT\AutoBackup\9-18-2009\Users\00000001\NTUSER.DAT
+ 2009-09-17 21:11 . 2009-09-17 21:11 3715072 c:\windows\ERDNT\AutoBackup\9-17-2009\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 13:55 1090816 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"wben"="c:\program files\Starfield\Desktop Notifier\wben.exe" [2009-06-25 338456]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-20 39408]
"cdloader"="c:\documents and settings\George\Application Data\mjusbsp\cdloader2.exe" [2009-08-01 50520]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376]
"Google Update"="c:\documents and settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-01 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-28 2007832]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2004-09-13 1450096]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-22 339968]

c:\documents and settings\George\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE [2007-8-29 340856]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-8-24 101784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 12:07 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-17 00:35 87352 —-a-w- c:\windows\system32\LMIinit.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Python25\\pythonw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Google\\Picasa3\\Picasa3.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\\Program Files\\Quantum GIS\\qgis_help.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\George\\Application Data\\mjusbsp\\magicJack.exe"=

R0 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/19/2009 7:06 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/19/2009 7:07 PM 108552]
R2 ArcGIS License Manager;ArcGIS License Manager;c:\program files\ESRI\License\arcgis9x\lmgrd.exe [3/19/2009 8:28 PM 1431440]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/4/2009 8:38 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/19/2009 7:06 PM 297752]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [8/19/2009 6:59 AM 47640]
S2 gupdate1c9a8f19d0e6a37;Google Update Service (gupdate1c9a8f19d0e6a37);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2009 8:20 PM 133104]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder

2009-09-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-09-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-20 00:19]

2009-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-20 00:19]

2009-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-20 00:19]

2009-09-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1500820517-682003330-1003Core.job
- c:\documents and settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-01 05:27]

2009-09-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1500820517-682003330-1003UA.job
- c:\documents and settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-01 05:27]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=GR
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\v99bwai6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://google.com
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://george-hall.net/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\George\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\v99bwai6.default\extensions\[removed]\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\George\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMyWebS.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-18 19:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\LMIinit.dll
c:\windows\system32\WINSPOOL.DRV
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-09-18 19:20
ComboFix-quarantined-files.txt 2009-09-18 23:20
ComboFix2.txt 2009-09-17 21:17

Pre-Run: 351,262,396,416 bytes free
Post-Run: 351,239,516,160 bytes free

250 — E O F — 2009-03-20 21:28




Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 5.1.2600 Service Pack 3

9/18/2009 7:28:26 PM
mbam-log-2009-09-18 (19-28-26).txt

Scan type: Quick Scan
Objects scanned: 125094
Time elapsed: 4 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 57
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\16824214 (Rogue.Multiple) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\16824214\16824214 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\16824214\pc16824214ins (Rogue.Multiple) -> Quarantined and deleted successfully.
Hi psycho7244,

Sorry, for the delay.

No problem. :)

c:\documents and settings\George\Desktop\Help\Combo-Fix.exe

Combofix is not on your desktop. In order for some of the things we use the program for, it must be on the desktop not in a folder on the desktop. It also wasn't ran with the CFScript.


Open windows explorer (right click the Start button and click Explore)

navigate to this folder
C:\WINDOWS
  • Click on the folder
  • In the right hand panel, locate Wzixiviyifa.dat
  • Right click on Wzixiviyifa.dat , select delete
  • Close windows explorer.

You have some very old vulnerable java installed.

  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 16
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u14-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs and uninstall

Java 2 Runtime Environment, SE v1.4.2_03

Do not uninstall Java TM 6 Update 16 if found! :yeah:

Reboot your computer.

  • Double-click on the saved file ( jre-6u16-windows-i586-p.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply along with a new HijackThis log.

Please post back with
  • Kaspersky log
  • new DDS log taken last
Any issues with the computer?

Thanks
ComboFix 09-09-18.02 - George 09/19/2009 8:30.4.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1307 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\George\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\windows\Wzixiviyifa.dat"
.

((((((((((((((((((((((((( Files Created from 2009-08-19 to 2009-09-19 )))))))))))))))))))))))))))))))
.

2009-09-18 23:21 . 2009-09-18 23:21 ——– d—–w- c:\documents and settings\George\Application Data\Malwarebytes
2009-09-18 23:11 . 2009-09-18 23:20 ——– d—–w- C:\Combo-Fix
2009-09-18 22:57 . 2009-09-18 22:57 ——– d—–w- c:\windows\system32\vmm32
2009-09-18 22:52 . 2009-09-18 22:52 ——– d—–w- c:\documents and settings\All Users\Application Data\SITEguard
2009-09-18 22:48 . 2009-09-18 22:48 ——– d—–w- C:\found.001
2009-09-17 21:44 . 2009-09-17 21:45 ——– d—–w- c:\program files\iTunes
2009-09-17 21:42 . 2009-09-17 21:42 ——– d—–w- c:\program files\Windows Installer Clean Up
2009-09-17 21:41 . 2009-09-17 21:41 ——– d—–w- c:\program files\MSECACHE
2009-09-17 01:19 . 2009-09-17 01:19 ——– d—–w- c:\program files\ERUNT
2009-09-17 01:10 . 2009-09-10 18:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-17 01:10 . 2009-09-17 01:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-17 01:10 . 2009-09-17 01:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-17 01:10 . 2009-09-10 18:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-16 21:56 . 2009-09-16 21:56 ——– d—–w- c:\program files\iPod
2009-09-16 21:56 . 2009-09-16 21:57 ——– d—–w- c:\program files\XXXX_iTunes
2009-09-16 21:56 . 2009-09-16 21:57 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-01 01:05 . 2009-09-01 01:05 ——– d—–w- c:\documents and settings\George\Local Settings\Application Data\Temp
2009-08-24 04:51 . 2009-08-24 04:51 ——– d—–w- c:\windows\system32\LogFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-19 12:29 . 2009-08-08 10:51 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-19 12:19 . 2009-09-19 12:18 4192 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-09-19 12:18 . 2009-08-15 20:15 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-09-19 12:17 . 2009-03-20 15:57 ——– d—–w- c:\documents and settings\George\Application Data\mjusbsp
2009-09-19 12:16 . 2009-08-19 10:58 ——– d—–w- c:\program files\LogMeIn
2009-09-19 09:27 . 2009-03-20 00:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-16 21:59 . 2009-03-20 15:57 ——– d—–w- c:\documents and settings\George\Application Data\Apple Computer
2009-09-16 21:56 . 2009-03-20 15:55 ——– d—–w- c:\program files\Common Files\Apple
2009-09-16 21:54 . 2009-03-20 15:56 ——– d—–w- c:\program files\QuickTime
2009-09-15 10:40 . 2009-03-19 23:58 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-09-03 23:10 . 2009-04-04 21:58 ——– d—–w- c:\documents and settings\George\Application Data\FileZilla
2009-09-02 22:52 . 2009-03-25 20:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-28 23:42 . 2009-03-20 15:55 40448 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 23:42 . 2009-03-20 15:55 2065696 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 12:07 . 2009-03-19 23:07 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 12:07 . 2009-03-19 23:06 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 12:07 . 2009-03-19 23:06 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-23 09:00 . 2009-03-19 23:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-19 10:59 . 2009-08-19 10:59 ——– d—–w- c:\documents and settings\All Users\Application Data\LogMeIn
2009-08-15 20:15 . 2009-08-15 20:15 ——– d—–w- c:\program files\STOPzilla!
2009-08-15 20:15 . 2009-08-15 20:15 ——– d—–w- c:\program files\Common Files\iS3
2009-08-08 11:03 . 2009-08-08 10:56 ——– d—–w- c:\documents and settings\George\Application Data\GetRightToGo
2009-08-03 21:10 . 2009-08-01 11:51 ——– d—–w- c:\documents and settings\George\Application Data\Move Networks
2009-07-20 18:57 . 2009-07-20 18:57 17408 —-a-r- c:\windows\system32\SZIO5.dll
2009-07-20 18:56 . 2009-07-20 18:56 311296 —-a-r- c:\windows\system32\SZBase5.dll
2009-07-20 18:56 . 2009-07-20 18:56 540672 —-a-r- c:\windows\system32\SZComp5.dll
2009-07-09 19:52 . 2009-07-09 19:52 126976 —-a-r- c:\windows\system32\IS3HTUI5.dll
2009-07-09 19:52 . 2009-07-09 19:52 393216 —-a-r- c:\windows\system32\IS3DBA5.dll
2009-07-09 19:51 . 2009-07-09 19:51 385024 —-a-r- c:\windows\system32\IS3UI5.dll
2009-07-09 19:51 . 2009-07-09 19:51 61440 —-a-r- c:\windows\system32\IS3Hks5.dll
2009-07-09 19:51 . 2009-07-09 19:51 23040 —-a-r- c:\windows\system32\IS3XDat5.dll
2009-07-09 19:50 . 2009-07-09 19:50 225280 —-a-r- c:\windows\system32\IS3Win325.dll
2009-07-09 19:50 . 2009-07-09 19:50 94208 —-a-r- c:\windows\system32\IS3Inet5.dll
2009-07-09 19:50 . 2009-07-09 19:50 90112 —-a-r- c:\windows\system32\IS3Svc5.dll
2009-07-09 19:47 . 2009-07-09 19:47 724992 —-a-r- c:\windows\system32\IS3Base5.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-17_21.10.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-18 22:59 . 2004-10-29 22:01 19456 c:\windows\system32\ReinstallBackups\0016\DriverFiles\IntelNic.dll
- 2009-07-31 10:19 . 2004-10-29 22:01 19456 c:\windows\system32\ReinstallBackups\0016\DriverFiles\IntelNic.dll
- 2009-07-31 10:19 . 2004-11-16 14:16 36864 c:\windows\system32\ReinstallBackups\0016\DriverFiles\e100bmsg.dll
+ 2009-09-18 22:59 . 2004-11-16 13:16 36864 c:\windows\system32\ReinstallBackups\0016\DriverFiles\e100bmsg.dll
- 2009-09-16 21:57 . 2009-05-18 18:17 26600 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspiWDM.sys
+ 2009-09-17 21:45 . 2009-05-18 18:17 26600 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspiWDM.sys
- 2009-03-19 22:18 . 2009-03-19 22:18 45056 c:\windows\Installer\{FCD9CD52-7222-4672-94A0-A722BA702FD0}\NewShortcut1.EXE
+ 2009-03-19 22:18 . 2009-09-18 22:57 45056 c:\windows\Installer\{FCD9CD52-7222-4672-94A0-A722BA702FD0}\NewShortcut1.EXE
+ 2009-09-19 12:17 . 2009-09-19 12:17 53248 c:\windows\ERDNT\AutoBackup\9-19-2009\Users\00000002\UsrClass.dat
+ 2009-09-18 22:50 . 2009-09-18 22:50 53248 c:\windows\ERDNT\AutoBackup\9-18-2009\Users\00000002\UsrClass.dat
+ 2009-09-17 21:11 . 2009-09-17 21:11 53248 c:\windows\ERDNT\AutoBackup\9-17-2009\Users\00000002\UsrClass.dat
- 2009-07-31 10:19 . 2004-11-16 22:52 126976 c:\windows\system32\ReinstallBackups\0016\DriverFiles\Prounstl.exe
+ 2009-09-18 22:59 . 2004-11-16 21:52 126976 c:\windows\system32\ReinstallBackups\0016\DriverFiles\Prounstl.exe
- 2009-07-31 10:19 . 2004-10-14 21:30 155648 c:\windows\system32\ReinstallBackups\0016\DriverFiles\e100b325.sys
+ 2009-09-18 22:59 . 2004-10-14 20:30 155648 c:\windows\system32\ReinstallBackups\0016\DriverFiles\e100b325.sys
- 2009-09-16 21:57 . 2008-04-17 17:12 107368 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspi.dll
+ 2009-09-17 21:45 . 2008-04-17 17:12 107368 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspi.dll
+ 2009-09-17 21:42 . 2009-09-17 21:42 472064 c:\windows\Installer\130b37.msi
- 2009-09-16 21:58 . 2009-09-16 21:58 102400 c:\windows\Installer\{EC2A8F27-4FBF-4E41-B27B-FE822511B761}\iTunesIco.exe
+ 2009-09-16 21:58 . 2009-09-17 21:46 102400 c:\windows\Installer\{EC2A8F27-4FBF-4E41-B27B-FE822511B761}\iTunesIco.exe
+ 2009-09-19 12:17 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\9-19-2009\ERDNT.EXE
+ 2009-09-18 22:50 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\9-18-2009\ERDNT.EXE
+ 2009-09-17 21:11 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\9-17-2009\ERDNT.EXE
+ 2009-03-19 23:37 . 2009-09-19 12:04 3817984 c:\windows\Installer\1db62a.msi
- 2009-03-19 23:37 . 2009-09-17 20:19 3817984 c:\windows\Installer\1db62a.msi
+ 2009-09-17 21:46 . 2009-09-17 21:46 4597248 c:\windows\Installer\130b3e.msi
+ 2009-09-19 12:17 . 2009-09-19 12:17 3743744 c:\windows\ERDNT\AutoBackup\9-19-2009\Users\00000001\NTUSER.DAT
+ 2009-09-18 22:50 . 2009-09-18 22:50 3731456 c:\windows\ERDNT\AutoBackup\9-18-2009\Users\00000001\NTUSER.DAT
+ 2009-09-17 21:11 . 2009-09-17 21:11 3715072 c:\windows\ERDNT\AutoBackup\9-17-2009\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 13:55 1090816 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"wben"="c:\program files\Starfield\Desktop Notifier\wben.exe" [2009-06-25 338456]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-20 39408]
"cdloader"="c:\documents and settings\George\Application Data\mjusbsp\cdloader2.exe" [2009-08-01 50520]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376]
"Google Update"="c:\documents and settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-01 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-28 2007832]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2004-09-13 1450096]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-22 339968]

c:\documents and settings\George\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-10-30 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 12:07 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-17 00:35 87352 —-a-w- c:\windows\system32\LMIinit.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Python25\\pythonw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Google\\Picasa3\\Picasa3.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"c:\\Program Files\\Quantum GIS\\qgis_help.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\George\\Application Data\\mjusbsp\\magicJack.exe"=

R0 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/19/2009 7:06 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/19/2009 7:07 PM 108552]
R2 ArcGIS License Manager;ArcGIS License Manager;c:\program files\ESRI\License\arcgis9x\lmgrd.exe [3/19/2009 8:28 PM 1431440]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/4/2009 8:38 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/19/2009 7:06 PM 297752]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [8/19/2009 6:59 AM 47640]
S2 gupdate1c9a8f19d0e6a37;Google Update Service (gupdate1c9a8f19d0e6a37);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2009 8:20 PM 133104]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder

2009-09-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-09-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-20 00:19]

2009-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-20 00:19]

2009-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-20 00:19]

2009-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1500820517-682003330-1003Core.job
- c:\documents and settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-01 05:27]

2009-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1500820517-682003330-1003UA.job
- c:\documents and settings\George\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-01 05:27]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\v99bwai6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://google.com
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://george-hall.net/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-19 08:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-09-19 8:36
ComboFix-quarantined-files.txt 2009-09-19 12:36
ComboFix2.txt 2009-09-19 12:26
ComboFix3.txt 2009-09-18 23:20
ComboFix4.txt 2009-09-17 21:17

Pre-Run: 350,816,223,232 bytes free
Post-Run: 350,810,648,576 bytes free

235 — E O F — 2009-03-20 21:28



——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, September 19, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, September 19, 2009 13:44:48
Records in database: 2861219
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Objects scanned: 225235
Threats found: 8
Infected objects found: 19
Suspicious objects found: 0
Scan duration: 06:44:00


File name / Threat / Threats count
C:\Documents and Settings\George\Desktop\DOWNLOAD\MyWebFaceSetup2.3.50.45.GRfox000.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.a.ax 1
C:\Qoobox\Quarantine\C\Documents and Settings\George\Start Menu\Programs\Startup\ikowin32.exe.vir Infected: Trojan-Spy.Win32.Zbot.aaul 1
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL.vir Infected: not-a-virus:Monitor.Win32.Agent.c 1
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL.vir Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ax 1
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE.vir Infected: not-a-virus:AdTool.Win32.MyWebSearch.cl 1
C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ff 1
C:\Qoobox\Quarantine\C\WINDOWS\wplesysg.dll.vir Infected: Trojan-Downloader.Win32.Mufanom.ddy 1
C:\System Volume Information\_restore{D90C4CB6-DABB-4573-8EDD-300097BBD444}\RP173\A0024481.exe Infected: Trojan-Spy.Win32.Zbot.aaul 1
C:\System Volume Information\_restore{D90C4CB6-DABB-4573-8EDD-300097BBD444}\RP173\A0024495.DLL Infected: not-a-virus:Monitor.Win32.Agent.c 1
C:\System Volume Information\_restore{D90C4CB6-DABB-4573-8EDD-300097BBD444}\RP173\A0024499.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ax 1
C:\System Volume Information\_restore{D90C4CB6-DABB-4573-8EDD-300097BBD444}\RP173\A0024508.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.cl 1
C:\System Volume Information\_restore{D90C4CB6-DABB-4573-8EDD-300097BBD444}\RP173\A0024512.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ff 1
C:\System Volume Information\_restore{D90C4CB6-DABB-4573-8EDD-300097BBD444}\RP173\A0024534.dll Infected: Trojan-Downloader.Win32.Mufanom.ddy 1


Selected area has been scanned.
Hi psycho7244,

One file to remove. The other dections are already quaratined files or old system Restore points. All of these will be removed when we remove our tools. We'll clean out the temp folders at the same time.

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Services
    
    :Files
    C:\Documents and Settings\George\Desktop\DOWNLOAD\MyWebFaceSetup2.3.50.45.GRfox000.exe 
    
    :Commands
    [Purity]
    [emptytemp]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Please post back with the OTM log and let us know how your computer is now.

Thanks
All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Documents and Settings\George\Desktop\DOWNLOAD\MyWebFaceSetup2.3.50.45.GRfox000.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: George ->Temp folder emptied: 85543560 bytes ->Temporary Internet Files folder emptied: 86026 bytes ->Java cache emptied: 37429627 bytes ->FireFox cache emptied: 97394386 bytes ->Google Chrome cache emptied: 413500320 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 65603 bytes User: LogMeInRemoteUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: NetworkService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32835 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1225527 bytes %systemroot%\System32 .tmp files removed: 2577 bytes Windows Temp folder emptied: 2048 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 605.85 mb OTM by OldTimer - Version 3.0.0.6 log created on 09192009_200447 Files moved on Reboot… Registry entries deleted on Reboot…
Hi psycho7244,

Ok, we'll clean up.

From your desktop, please delete
  • any notepads/logs that we created
  • RootRepeal.exe
  • exeHelper.com
  • GooredFix.exe

Click the Start button, click Run. Copy and paste the following line into the run box and click OK

Combofix /u


Open OTM then click the Clean Up button. You may get prompted by your firewall that OTM wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep MBAM updated and use it regularly.


Updates and upgrades

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Just add a firewall.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware, IMO)


You should also use
Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI