This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

your system is infected wallpaper

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

had a trojan and multiple malware spyware infections on my system. The wallpaper on my computer was the "your system is infected" wallpaper and wouldn't allow me to change it.

I've used trojan hunter to remove the trojan.
I've used spybot search and destroy and AVG to remove everything else I could find.

While running scans to get rid of the stuff, my computer login started auto logging me out so I had to use bartpe to modify the registry. I modified a hive to have the correct userinit.exe file and unloaded it afterwards then restarted which fixed my auto logout problem. Then my internet stopped working at some point during the process. I thought my antivirus was blocking it so I removed avg and spybot and neither of those fixed it. I used an executable I found in a forum somewhere called LSPfix.exe which removed the protocols that were not allowing me to connect. After that the only thing left seemed to be the desktop background not allowing me to remove it and I'm sure there are still some residual issues leftover from the messy cleanups from the 3 programs I was using.

I decided I would try this forum thing to clear up the rest.
I've followed the instructions given prior to posting a new topic.
My desktop is now back to normal so I'm pretty much happy but I guess I'll see if there's anything further I need to remove just in case.

here is the mbam log
—————————–
Malwarebytes' Anti-Malware 1.42
Database version: 3442
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

12/27/2009 7:44:30 PM
mbam-log-2009-12-27 (19-44-30).txt

Scan type: Quick Scan
Objects scanned: 115456
Time elapsed: 9 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 4
Registry Data Items Infected: 4
Folders Infected: 3
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{24e9519b-3f70-429b-99bc-4b2b49b96f66} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijacker) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0bc5e8c9-6eff-4976-9a3c-d74148442ce7} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{24e9519b-3f70-429b-99bc-4b2b49b96f66} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\VirusHeat 4.3 (Rogue.VirusHeat) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\375013 (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\InternetSecurity2010 (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\AVR10.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\My Documents\My Documents.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\My Documents\My Music\My Music.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\My Documents\My Pictures\My Pictures.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Owner\My Documents\My Videos\My Video.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Antivirus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Online Spyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\critical_warning.html (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wsaupdater.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

here is the gmer ark.txt log
————————————
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-27 21:40:11
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\uwlcraoc.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\drivers\hjgruirbepfucb.sys (*** hidden *** ) [SYSTEM] hjgruiirnvdpmy <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy@imagepath \systemroot\system32\drivers\hjgruirbepfucb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\main\injector@* hjgruiwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\drivers\hjgruirbepfucb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\hjgruinjwmtnow.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\hjgruixdqlohxt.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\hjgruievbmnmru.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\hjgruibrfbxjlq.dat
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy@imagepath \systemroot\system32\drivers\hjgruirbepfucb.sys
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\main@aid 10096
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\main\injector@* hjgruiwsp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\drivers\hjgruirbepfucb.sys
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\hjgruinjwmtnow.dll
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\hjgruixdqlohxt.dat
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\hjgruievbmnmru.dll
Reg HKLM\SYSTEM\ControlSet002\Services\hjgruiirnvdpmy\[removed] \systemroot\system32\hjgruibrfbxjlq.dat

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\Temp\544000a5-b47d-440e-b2a2-2cb35d8f961a.tmp 32768 bytes
File C:\WINDOWS\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll (size mismatch) 68608/69120 bytes executable
File C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll (size mismatch) 5025792/5238784 bytes executable
File C:\WINDOWS\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll (size mismatch) 503808/507904 bytes executable
File C:\WINDOWS\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll (size mismatch) 36864/77824 bytes executable
File C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a 0 bytes
File C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll 32768 bytes executable
File C:\WINDOWS\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll (size mismatch) 5050368/5062656 bytes executable
File C:\WINDOWS\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll (size mismatch) 86016/77824 bytes executable
File C:\WINDOWS\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll (size mismatch) 823296/839680 bytes executable
File C:\WINDOWS\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll (size mismatch) 5316608/5025792 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\3faf9dfbb18456409dc074848c18d184 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\3faf9dfbb18456409dc074848c18d184\Accessibility.ni.dll 26624 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\0a9fb63a14f85d4ebef31e58030b0e19 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\0a9fb63a14f85d4ebef31e58030b0e19\AspNetMMCExt.ni.dll 860160 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\d550549a63130d42b72742de617e10b1 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\d550549a63130d42b72742de617e10b1\CustomMarshalers.ni.dll 237568 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\index1b.dat 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\index1c.dat 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\c19430783bd49e4691774b82bb65e4be 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\c19430783bd49e4691774b82bb65e4be\Microsoft.Build.Engine.ni.dll 880640 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas# 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\00b95b2726965c459fecff17d5f3378f 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\00b95b2726965c459fecff17d5f3378f\Microsoft.Build.Tasks.ni.dll 1691648 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti# 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\7624e0d4ab7bed4cb56423c49995b60a 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\7624e0d4ab7bed4cb56423c49995b60a\Microsoft.Build.Utilities.ni.dll 163840 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas# 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\0581a21899856544b1de28ae6d46b27f 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\0581a21899856544b1de28ae6d46b27f\Microsoft.VisualBasic.ni.dll 1724416 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba2e82e6f4f45541809d600981ef1e26 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\ba2e82e6f4f45541809d600981ef1e26\System.ni.dll 8093696 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\e7b9024e47eab5429a5df6f386a936f4 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\e7b9024e47eab5429a5df6f386a936f4\System.Configuration.ni.dll 962560 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\e7b37c1d8340034583513ed04f127926 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\e7b37c1d8340034583513ed04f127926\System.Data.ni.dll 6688768 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\e00774b232dd8e4aa1f61aff65ad1743 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\e00774b232dd8e4aa1f61aff65ad1743\System.Deployment.ni.dll 1712128 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\babf6e09f213da4499c74567fb8cfeb7 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Design\babf6e09f213da4499c74567fb8cfeb7\System.Design.ni.dll 10723328 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\8565e316badd4c4d9b69cbf13fc8161b 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\8565e316badd4c4d9b69cbf13fc8161b\System.DirectoryServices.Protocols.ni.dll 512000 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c16b4c46ac16c94cb4e2817f9f941810 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c16b4c46ac16c94cb4e2817f9f941810\System.DirectoryServices.ni.dll 1220608 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7023275231ed684b8a63fa783511697a 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7023275231ed684b8a63fa783511697a\System.Drawing.ni.dll 1626112 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi# 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\2cbbde11a0643e48abd6ccb0d4a5efc2 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\2cbbde11a0643e48abd6ccb0d4a5efc2\System.Drawing.Design.ni.dll 229376 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\4696e4a4e31d3b45a9ab7b3c0b9a7685 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\4696e4a4e31d3b45a9ab7b3c0b9a7685\System.EnterpriseServices.ni.dll 659456 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\4696e4a4e31d3b45a9ab7b3c0b9a7685\System.EnterpriseServices.Wrapper.dll 294912 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\fe597ba09b85f842814f477094a23bf2 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Security\fe597ba09b85f842814f477094a23bf2\System.Security.ni.dll 729088 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\88e1aca13e3bbe4782d20a51fee37c05 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\88e1aca13e3bbe4782d20a51fee37c05\System.Transactions.ni.dll 684032 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\8ce7fbd99767254cb239f308c8836ea8 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\8ce7fbd99767254cb239f308c8836ea8\System.Web.ni.dll 11808768 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\f3c4a22572f7ba4fa5228d24056e9942 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\f3c4a22572f7ba4fa5228d24056e9942\System.Web.Mobile.ni.dll 2310144 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE# 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\c85889d30313fb4186b19924fe355432 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\c85889d30313fb4186b19924fe355432\System.Web.RegularExpressions.ni.dll 237568 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\1593c2f998023747904e1ec14e4ad336 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\1593c2f998023747904e1ec14e4ad336\System.Web.Services.ni.dll 1945600 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f04c7e3adcc6b1458a4b4df225a7a8a3 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f04c7e3adcc6b1458a4b4df225a7a8a3\System.Windows.Forms.ni.dll 13107200 bytes executable
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\98391a004413614fb27d4007fd54828d 0 bytes
File C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\98391a004413614fb27d4007fd54828d\System.Xml.ni.dll 5640192 bytes executable

—- EOF - GMER 1.0.15 —-

Here is the DDS logs
DDS
—————————–

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:40:43.29 on Sun 12/27/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1982.1213 [GMT -8:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ResChanger 2005\ResChanger2005.exe
C:\Program Files\Curse\CurseClient.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.exe
C:\Program Files\OpenOffice.org 2.2\program\soffice.BIN
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\wscntfy.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Compaq_Owner\Desktop\theresafixstuff\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uURLSearchHooks: H - No File
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: CKeyScramblerBHO Object: {2b9f5787-88a5-4945-90e7-c4b18563bc5e} - c:\program files\keyscrambler\KeyScramblerIE.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\compaq_owner\desktop\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
uRun: [ResChanger 2005] c:\program files\reschanger 2005\ResChanger2005.exe
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [CurseClient] c:\program files\curse\CurseClient.exe -silent
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: []
mRun: [PCDrProfiler]
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [HP Software Update] c:\program files\hp\hp software update\HPwuSchd2.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [THGuard] "c:\program files\trojanhunter 5.2\THGuard.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
StartupFolder: c:\docume~1\compaq~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.2\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\compaq~1.lnk - c:\program files\compaq connections\5577497\program\Compaq Connections.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\Kodak Software Updater.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - {B745F984-EF2E-40D6-A9AC-D8CED7230E61} - c:\program files\keyscrambler\KeyScramblerIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: LMIinit - LMIinit.dll
Notify: xxyayAPI - xxyayAPI.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: {f43bfc6c-47cc-4798-8798-a0721b8ed7ab} - No File

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\c9y8pwje.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com
FF - component: c:\documents and settings\compaq_owner\application data\mozilla\firefox\profiles\c9y8pwje.default\extensions\[removed]\components\piclensstub.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-12-27 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-12-27 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-12-27 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-12-27 285392]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-8-11 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2009-12-27 47640]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2008-3-31 112992]
S2 spupdsvc;Windows Service Pack Installer update service;c:\windows\system32\spupdsvc.exe [2006-2-21 26488]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]

=============== Created Last 30 ================

2009-12-27 21:28 –d—– c:\windows\system32\XPSViewer
2009-12-27 21:28 224 a——- c:\windows\system32\spupdsvc.inf
2009-12-27 21:27 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-12-27 21:27 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2009-12-27 21:27 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-12-27 21:27 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-12-27 21:27 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-27 21:27 117,760 ——– c:\windows\system32\prntvpt.dll
2009-12-27 21:27 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-12-27 21:27 –d—– C:\cfb7edf4b2f423d148776d48cdb0e6cf
2009-12-27 19:57 –d—– c:\docume~1\alluse~1\applic~1\LogMeIn
2009-12-27 19:57 28,984 a——- c:\windows\system32\LMIport.dll
2009-12-27 19:57 83,288 a——- c:\windows\system32\LMIRfsClientNP.dll
2009-12-27 19:57 47,640 a——- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-12-27 19:57 87,352 a——- c:\windows\system32\LMIinit.dll
2009-12-27 19:57 1,024 a——- C:\.rnd
2009-12-27 19:57 –d—– c:\program files\LogMeIn
2009-12-27 19:32 –d—– c:\docume~1\compaq~1\applic~1\Malwarebytes
2009-12-27 19:32 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-27 19:32 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-12-27 19:32 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-12-27 19:32 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-27 18:52 12,464 a——- c:\windows\system32\avgrsstx.dll
2009-12-27 18:52 360,584 a——- c:\windows\system32\drivers\avgtdix.sys
2009-12-27 18:52 333,192 a——- c:\windows\system32\drivers\avgldx86.sys
2009-12-27 18:52 –d—– c:\windows\system32\drivers\Avg
2009-12-27 18:52 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2009-12-27 16:12 –d—– c:\docume~1\compaq~1\applic~1\AVG9
2009-12-26 04:03 –d—– C:\WINDOWS.0
2009-12-25 17:23 –d—– c:\docume~1\compaq~1\applic~1\TrojanHunter
2009-12-25 15:15 –d—– c:\program files\TrojanHunter 5.2
2009-12-25 14:44 –d-h— C:\$AVG
2009-12-25 14:43 12,464 a——- c:\windows\system32\avgrsstx.dll.old
2009-12-25 14:43 –d—– c:\program files\AVG
2009-12-25 14:43 –d—– c:\docume~1\alluse~1\applic~1\avg9
2009-12-20 22:20 0 a——- c:\windows\system32\32114.exe
2009-12-18 14:05 0 a——- c:\windows\system32\6334.exe
2009-12-18 13:45 0 a——- c:\windows\system32\18467.exe
2009-12-01 14:44 –d—– c:\program files\Ventrilo
2009-12-01 14:44 210 a——- c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2009-12-01 14:43 –d—– c:\program files\common files\Wise Installation Wizard

==================== Find3M ====================

2009-10-29 11:08 3,070,976 ——– c:\windows\system32\dllcache\mshtml.dll
2009-10-28 21:38 667,136 a——- c:\windows\system32\wininet.dll
2009-10-28 21:38 667,136 ——– c:\windows\system32\dllcache\wininet.dll
2009-10-28 21:38 1,509,888 ——– c:\windows\system32\dllcache\shdocvw.dll
2009-10-28 21:38 627,712 ——– c:\windows\system32\dllcache\urlmon.dll
2009-10-20 21:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 21:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-20 21:38 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll
2009-10-20 21:38 25,088 ——– c:\windows\system32\dllcache\httpapi.dll
2009-10-20 08:20 265,728 ——– c:\windows\system32\dllcache\http.sys
2009-10-15 12:14 1,810 a——- c:\docume~1\compaq~1\applic~1\wklnhst.dat
2009-10-13 02:30 270,336 a——- c:\windows\system32\oakley.dll
2009-10-13 02:30 270,336 ——– c:\windows\system32\dllcache\oakley.dll
2009-10-12 05:38 149,504 a——- c:\windows\system32\rastls.dll
2009-10-12 05:38 149,504 ——– c:\windows\system32\dllcache\rastls.dll
2009-10-12 05:38 79,872 a——- c:\windows\system32\raschap.dll
2009-10-12 05:38 79,872 ——– c:\windows\system32\dllcache\raschap.dll

============= FINISH: 21:41:25.56 ===============

attach
————————————-

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 5/25/2007 2:25:41 PM
System Uptime: 12/27/2009 8:02:15 PM (1 hours ago)

Motherboard: ASUSTek Computer INC. | | Amberine M
Processor: AMD Athlon™ 64 Processor 3200+ | Socket 939 | 1989/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 179 GiB total, 85.613 GiB free.
D: is FIXED (FAT32) - 7 GiB total, 0.371 GiB free.
E: is Removable
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\9C05F411D800
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\9C05F411D800
Service: NIC1394

==== System Restore Points ===================

RP734: 10/2/2009 2:47:54 PM - System Checkpoint
RP735: 10/4/2009 1:13:30 PM - System Checkpoint
RP736: 10/5/2009 2:49:43 PM - System Checkpoint
RP737: 10/8/2009 1:21:59 AM - System Checkpoint
RP738: 10/9/2009 1:35:17 AM - System Checkpoint
RP739: 10/10/2009 3:51:13 AM - System Checkpoint
RP740: 10/11/2009 11:40:38 PM - System Checkpoint
RP741: 10/13/2009 2:20:33 AM - System Checkpoint
RP742: 10/14/2009 12:25:39 PM - System Checkpoint
RP743: 10/15/2009 2:19:53 PM - System Checkpoint
RP744: 10/16/2009 9:30:23 AM - Software Distribution Service 3.0
RP745: 10/17/2009 7:12:00 PM - System Checkpoint
RP746: 10/18/2009 8:43:20 PM - System Checkpoint
RP747: 10/20/2009 12:37:02 AM - System Checkpoint
RP748: 10/21/2009 10:30:23 AM - System Checkpoint
RP749: 10/22/2009 4:26:30 PM - System Checkpoint
RP750: 10/25/2009 11:57:26 PM - System Checkpoint
RP751: 10/27/2009 3:24:57 AM - System Checkpoint
RP752: 10/28/2009 1:34:17 PM - System Checkpoint
RP753: 10/29/2009 4:46:08 PM - System Checkpoint
RP754: 10/30/2009 6:29:59 PM - System Checkpoint
RP755: 11/4/2009 4:00:48 AM - Software Distribution Service 3.0
RP756: 11/11/2009 3:00:51 AM - Software Distribution Service 3.0
RP757: 11/19/2009 9:37:28 PM - System Checkpoint
RP758: 11/20/2009 9:38:45 PM - System Checkpoint
RP759: 11/22/2009 2:19:59 AM - System Checkpoint
RP760: 11/23/2009 12:10:10 PM - System Checkpoint
RP761: 11/25/2009 3:00:52 AM - Software Distribution Service 3.0
RP762: 11/27/2009 3:48:14 PM - System Checkpoint
RP763: 12/1/2009 2:40:45 PM - Removed Ventrilo Client
RP764: 12/1/2009 2:44:28 PM - Installed Ventrilo Client
RP765: 12/2/2009 5:30:46 PM - System Checkpoint
RP766: 12/4/2009 8:00:12 AM - System Checkpoint
RP767: 12/9/2009 2:08:44 AM - System Checkpoint
RP768: 12/9/2009 3:00:16 AM - Software Distribution Service 3.0
RP769: 12/11/2009 9:02:12 AM - System Checkpoint
RP770: 12/20/2009 10:02:59 PM - Removed Battlefield 2142
RP771: 12/20/2009 10:05:02 PM - Removed J2SE Runtime Environment 5.0 Update 5
RP772: 12/20/2009 10:07:45 PM - Removed MSXML 4.0 SP2 (KB927978)
RP773: 12/20/2009 10:08:18 PM - Removed MSXML 4.0 SP2 (KB936181)
RP774: 12/20/2009 10:09:27 PM - Removed Java™ 6 Update 3
RP775: 12/25/2009 2:43:01 PM - Installed AVG Free 9.0
RP776: 12/25/2009 5:57:32 PM - Avg8 Update
RP777: 12/25/2009 6:23:19 PM - Removed AVG Free 9.0
RP778: 12/25/2009 6:24:30 PM - Installed AVG Free 9.0
RP779: 12/26/2009 1:56:58 PM - Installed AVG Free 9.0
RP780: 12/27/2009 3:34:06 PM - System Checkpoint
RP781: 12/27/2009 4:25:41 PM - Removed AVG Free 9.0
RP782: 12/27/2009 4:26:55 PM - Installed AVG Free 9.0
RP783: 12/27/2009 6:50:59 PM - Installed AVG Free 9.0
RP784: 12/27/2009 7:05:19 PM - Avg8 Update
RP785: 12/27/2009 7:23:24 PM - Automatic Restore Point
RP786: 12/27/2009 7:25:01 PM - Automatic Restore Point
RP787: 12/27/2009 7:26:23 PM - Automatic Restore Point
RP788: 12/27/2009 7:26:51 PM - Automatic Restore Point
RP789: 12/27/2009 7:57:06 PM - Installed LogMeIn
RP790: 12/27/2009 9:08:56 PM - Software Distribution Service 3.0

==== Installed Programs ======================

Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.0
Agere Systems PCI-SV92PP Soft Modem
Apple Software Update
AstroPop Deluxe from Compaq (remove only)
ATI Control Panel
ATI Display Driver
AVG Free 9.0
Belarc Advisor 7.2
BufferChm
CCScore
Chikka Messenger V4
Command & Conquer 3
Command & Conquer Tiberian Sun
Command & Conquer™ 3: Kane's Wrath
Command & Conquer™ Red Alert™ 3
Compaq Connections (remove only)
Compaq Organize
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
Critical Update for Windows Media Player 11 (KB959772)
CueTour
Curse Client
Customer Experience Enhancement
Day of Defeat: Source
Destinations
DeviceManagementQFolder
EA Download Manager
ERUNT 1.1j
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSSONIC
ESSTOOLS
essvatgt
FullDPAppQFolder
Guild Wars
Half-Life 2: Deathmatch
Half-Life 2: Lost Coast
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Boot Optimizer
HP DVD Play 1.0
HP Game Console and games
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Rhapsody
HP Software Update
HP Support Overview
HP Web Helper
HpSdpAppCoreApp
InstantShareDevices
Java™ 6 Update 7
Java™ SE Runtime Environment 6
KeyScrambler
kgcbaby
kgcbase
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
KSU
LimeWire 4.18.1
LogMeIn
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Age of Empires II
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft IntelliPoint 6.3
Microsoft IntelliType Pro 6.3
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office Standard Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Microsoft Works 7.0
Mozilla Firefox (3.0.16)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB954459)
netbrdg
Netscape Browser (remove only)
Norton Internet Security 2006 (Symantec Corporation)
Notifier
NVIDIA Drivers
Oblivion
OfotoXMI
OpenOffice.org 2.2
OptionalContentQFolder
PCDADDIN
PCDHELP
PhotoGallery
Quicken 2006
RandMap
ResChanger 2005
Rhapsody
Risk®
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB976325)
SFR
SHASTA
SKIN0001
SkinsHP1
SKINXSDK
Sonic MyDVD SlideShow
Sonic Update Manager
Sonic_PrimoSDK
Source SDK Base 2007
SPORE™
Spybot - Search & Destroy
Star Wars Empire at War
Star Wars Empire at War Forces of Corruption
Starcraft
staticcr
The Battle for Middle-earth ™ II
The Lord of the Rings, The Rise of the Witch-king
tooltips
TrojanHunter 5.2
Unload
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB953356)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Ventrilo Client
VPRINTOL
Warcraft III: All Products
WebFldrs XP
Westwood Shared Internet Components
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WIRELESS
World of Warcraft
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger

==== Event Viewer Messages From Past Week ========

12/27/2009 8:12:40 PM, error: Service Control Manager [7031] - The AVG Free WatchDog service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
12/27/2009 8:12:21 PM, error: Service Control Manager [7031] - The AVG Free WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
12/27/2009 8:05:12 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: iaStor IntelIde ViaIde
12/27/2009 5:18:04 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
12/27/2009 5:16:12 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
12/26/2009 7:03:07 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
12/25/2009 8:47:54 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 BANTExt Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL
12/25/2009 8:47:54 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
12/25/2009 8:47:54 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/25/2009 8:47:54 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/25/2009 8:47:54 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
12/25/2009 8:47:32 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
12/25/2009 3:12:53 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: %%2147952506
12/20/2009 9:51:07 PM, error: Service Control Manager [7023] - The HID Input Service service terminated with the following error: The specified module could not be found.
12/20/2009 9:51:07 PM, error: Service Control Manager [7000] - The MCSTRM service failed to start due to the following error: The system cannot find the file specified.
12/20/2009 10:08:37 PM, error: SideBySide [36] - The assembly x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a has missing or invalid files; recovery of this assembly failed.
12/20/2009 10:08:08 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.

==== End Of File ===========================
Hi there,

Still a little Malware showing, let's sort that out.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 09-12-29.06 - Compaq_Owner 12/30/2009 11:25:14.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1982.1241 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\theresafixstuff\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Compaq_Owner\Desktop\Internet Security 2010.lnk
c:\documents and settings\Compaq_Owner\Local Settings\Temp\IadHide5.dll
c:\documents and settings\Compaq_Owner\Start Menu\Internet Security 2010.lnk
c:\program files\Mozilla Firefox\searchplugins\search.xml
c:\windows\system32\18467.exe
c:\windows\system32\32114.exe
c:\windows\system32\6334.exe
c:\windows\system32\drivers\hjgruirbepfucb.sys
c:\windows\system32\hjgruibrfbxjlq.dat
c:\windows\system32\hjgruixdqlohxt.dat
c:\windows\unins000.dat
c:\windows\unins000.exe
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_hjgruiirnvdpmy
——-\Service_hjgruiirnvdpmy


((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-30 )))))))))))))))))))))))))))))))
.

2009-12-28 03:57 . 2009-12-28 03:57 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\LogMeIn
2009-12-28 03:57 . 2009-12-28 03:57 ——– d—–w- c:\documents and settings\All Users\Application Data\LogMeIn
2009-12-28 03:57 . 2009-12-28 03:57 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ICS
2009-12-28 03:57 . 2009-09-29 03:34 47416 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2009-12-28 03:57 . 2009-09-29 03:34 28984 —-a-w- c:\windows\system32\LMIport.dll
2009-12-28 03:57 . 2009-09-29 03:34 83288 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-12-28 03:57 . 2008-08-11 20:41 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-12-28 03:57 . 2009-09-29 03:34 87352 —-a-w- c:\windows\system32\LMIinit.dll
2009-12-28 03:57 . 2009-12-30 19:08 ——– d—–w- c:\program files\LogMeIn
2009-12-28 03:32 . 2009-12-28 03:32 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2009-12-28 03:32 . 2009-12-04 00:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-28 03:32 . 2009-12-28 03:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-28 03:32 . 2009-12-28 03:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-28 03:32 . 2009-12-04 00:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-28 03:29 . 2009-12-28 03:30 ——– d—–w- c:\program files\ERUNT
2009-12-28 02:56 . 2009-12-28 02:56 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\AVG Security Toolbar
2009-12-28 02:52 . 2009-12-28 02:52 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-12-28 02:52 . 2009-12-28 02:52 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-28 02:52 . 2009-12-28 02:52 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-28 02:52 . 2009-12-28 02:52 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-28 02:52 . 2009-12-30 19:14 ——– d—–w- c:\windows\system32\drivers\Avg
2009-12-28 02:52 . 2009-12-28 02:52 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-12-28 00:12 . 2009-12-28 00:12 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\AVG9
2009-12-26 12:03 . 2009-12-26 12:05 ——– d—–w- C:\WINDOWS.0
2009-12-26 01:23 . 2009-12-26 01:23 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\TrojanHunter
2009-12-25 23:15 . 2009-12-26 21:43 ——– d—–w- c:\program files\TrojanHunter 5.2
2009-12-25 22:44 . 2009-12-25 22:44 ——– d—–w- C:\$AVG
2009-12-25 22:43 . 2009-12-25 22:43 ——– d—–w- c:\program files\AVG
2009-12-25 22:43 . 2009-12-28 02:51 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2009-12-01 22:44 . 2009-12-01 22:44 ——– d—–w- c:\program files\Ventrilo
2009-12-01 22:43 . 2009-12-01 22:43 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-30 19:38 . 2007-08-22 03:09 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\OpenOffice.org2
2009-12-29 19:47 . 2007-05-25 22:11 ——– d—–w- c:\program files\World of Warcraft
2009-12-29 00:20 . 2009-07-14 23:56 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\Red Alert 3
2009-12-28 05:28 . 2009-12-28 05:28 ——– d—–w- c:\program files\MSBuild
2009-12-28 05:28 . 2009-12-28 05:28 ——– d—–w- c:\program files\Reference Assemblies
2009-12-28 02:51 . 2009-12-28 03:05 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-28 02:51 . 2009-12-28 03:05 3967256 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-28 02:51 . 2009-12-28 03:05 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-28 02:51 . 2009-12-28 03:05 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-28 02:51 . 2009-12-28 03:05 916248 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2009-12-28 02:51 . 2007-08-22 02:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-28 02:36 . 2007-08-22 02:26 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-28 00:41 . 2006-02-22 01:38 ——– d—–w- c:\program files\Google
2009-12-26 01:22 . 2006-02-22 01:15 ——– d—–w- c:\program files\music_now
2009-12-25 22:43 . 2009-12-26 01:57 12464 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgrsstx.dll
2009-12-25 22:43 . 2009-12-26 01:57 360584 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2009-12-25 22:43 . 2009-12-26 01:57 333192 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2009-12-25 22:43 . 2009-12-26 01:57 28424 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2009-12-25 22:43 . 2009-12-26 01:57 503576 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgrsx.exe
2009-12-21 06:09 . 2006-02-22 00:58 ——– d—–w- c:\program files\Java
2009-12-21 06:03 . 2007-06-10 04:40 ——– d—–w- c:\program files\Electronic Arts
2009-12-01 22:35 . 2009-02-21 19:06 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\Ventrilo
2009-10-29 05:38 . 2004-08-04 11:00 667136 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 11:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 11:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 11:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-15 20:14 . 2007-05-25 21:44 1810 —-a-w- c:\documents and settings\Compaq_Owner\Application Data\wklnhst.dat
2009-10-13 10:30 . 2004-08-04 11:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 11:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 11:00 79872 —-a-w- c:\windows\system32\raschap.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 21:01 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ResChanger 2005"="c:\program files\ResChanger 2005\ResChanger2005.exe" [2005-05-26 885248]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240]
"CurseClient"="c:\program files\Curse\CurseClient.exe" [2009-07-30 1935360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-10 249856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-14 344064]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-12 7630848]
"nwiz"="nwiz.exe" [2006-08-12 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-12 86016]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2008-06-10 1442888]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"THGuard"="c:\program files\TrojanHunter 5.2\THGuard.exe" [2009-11-26 1069728]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-28 2033432]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-2-21 27136]

c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]

c:\documents and settings\LogMeInRemoteUser\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-2-21 27136]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - c:\program files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-2-21 36903]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-2-20 282624]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-28 02:52 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-29 03:34 87352 —-a-w- c:\windows\system32\LMIinit.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.1.0-enUS-downloader.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\Electronic Arts\\The Lord of the Rings, The Rise of the Witch-king\\game.dat"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War Forces of Corruption\\swfoc.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Warcraft III\\Frozen Throne.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\Program Files\\TrojanHunter 5.2\\THGuard.exe"=
"c:\\Program Files\\TrojanHunter 5.2\\TrojanHunter.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\Program Files\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.12.game"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Warcraft 3

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/27/2009 6:52 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/27/2009 6:52 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/27/2009 6:51 PM 285392]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [8/11/2008 12:41 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [12/27/2009 7:57 PM 47640]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [3/31/2008 11:09 PM 112992]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder

2009-12-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 18:42]

2009-12-30 c:\windows\Tasks\TrojanHunter LiveUpdate.job
- c:\program files\TrojanHunter 5.2\Tools\LiveUpdate\LiveUpdate.exe [2009-12-25 23:51]

2009-12-26 c:\windows\Tasks\TrojanHunter Scanner.job
- c:\program files\TrojanHunter 5.2\thcl.exe [2009-12-25 23:51]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\c9y8pwje.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com
FF - component: c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\c9y8pwje.default\extensions\[removed]\components\piclensstub.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
HKLM-Run-PCDrProfiler - (no file)
Notify-xxyayAPI - xxyayAPI.dll
AddRemove-Chikka Messenger V4 - c:\progra~1\CHIKKA~1\CHIKKA~1.4\UNWISE.EXE
AddRemove-Steam App 218 - c:\progra~1\Steam\steam.exe
AddRemove-Steam App 300 - c:\progra~1\Steam\steam.exe
AddRemove-Steam App 320 - c:\progra~1\Steam\steam.exe
AddRemove-Steam App 340 - c:\progra~1\Steam\steam.exe
AddRemove-{8BCAFB73-49AE-4AC4-00A1-70E4EC38BD4E} - c:\program files\Electronic Arts\The Lord of the Rings
AddRemove-{D7DBA21A-CDE5-42EC-BB1C-AE4B3E616B9A}_is1 - c:\windows\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-30 11:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-4133691677-1634982083-711402031-1009\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b2,23,20,0f,b5,79,56,f8,78,cd,e4,cc,c9,2c,1e,09,59,89,7c,31,24,03,bd,
aa,e0,61,97,25,56,e4,f5,ef,2a,b0,9b,c5,79,53,1b,2f,97,2f,93,85,46,27,64,e2,\
"??"=hex:69,6f,5c,46,6a,89,f9,ee,2d,48,e0,10,87,42,1e,12

[HKEY_USERS\S-1-5-21-4133691677-1634982083-711402031-1009\Software\SecuROM\License information*]
"datasecu"=hex:33,d2,65,cf,21,d0,c6,84,81,bd,ed,d1,2c,b9,7a,8a,b0,c9,14,06,c4,
a5,a2,aa,84,4e,af,69,7f,5a,03,cb,01,4f,c8,25,43,5d,f1,bd,ac,94,da,77,1e,3b,\
"rkeysecu"=hex:0a,5c,59,79,03,15,80,4b,f9,30,78,ca,85,b1,c0,ca
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll

- - - - - - - > 'explorer.exe'(2180)
c:\docume~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wscntfy.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\OpenOffice.org 2.2\program\soffice.exe
c:\program files\OpenOffice.org 2.2\program\soffice.BIN
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\windows\ALCXMNTR.EXE
.
**************************************************************************
.
Completion time: 2009-12-30 11:43:09 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-30 19:43

Pre-Run: 91,440,443,392 bytes free
Post-Run: 91,754,749,952 bytes free

- - End Of File - - BD86449AA80498F86C7ACB6E7070F547
does this look right? i thought i ran gmer like you said, but this is all the text i got back.
the comp is remote from where i'm at so i couldn't tell you if its running better or not. it was running fine a day or 2 ago when i was there.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-30 18:04:35
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\uwlcraoc.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat bb-run.sys (Promise Disk Accelerator/Promise Technology, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Looks fine, that's how it should look.

It may be best to wait until you had a chance to use the machine directly, but once you are happy that all is well, click Start >> Run and use the following command to uninstall ComboFix:
ComboFix /uninstall
This will flush the System Restore, delete backups and hide hidden files, among other things.

I hope everything is sorted now.
I tried to run ComboFix /uninstall from the run command, but windows was unable to find it. I tried looking for it in the original directory I downloaded it to and renamed it, but it's not there anymore. So I can't uninstall ComboFix. Did I do something wrong?
Just kidding. Trojan Hunter had quarantined it during a routine trojan scan along with a couple other files. I restored them and was able to run ComboFix /uninstall just fine. Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI