This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Horse Vundo JD, Trojan Horse Generic 16

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm having a problem with my search engines. Whenever I click on a link from Google or Bing, I am redirected to a different site. My AVG shows that the Generic 16 trojan was quarintined, but every day it shows the Vundo JD showing up then being quarantined – yet it appears the next day. I ran the MBAM, GMER and DDS scans and I'm pasting the logs below. The GMER froze my computer every time I ran it, so I'm attaching the one item that looks bad. MBAM scan #1 Malwarebytes' Anti-Malware 1.43 Database version: 3508 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/7/2010 10:21:59 AM mbam-log-2010-01-07 (10-21-58).txt Scan type: Quick Scan Objects scanned: 116120 Time elapsed: 13 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 47 Registry Values Infected: 11 Registry Data Items Infected: 1 Folders Infected: 12 Files Infected: 25 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\tb12505.dll (Trojan.BHO) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{e343edfc-1e6c-4cb5-aa29-e9c922641c80} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{20ea9658-6bc3-4599-a87d-6371fe9295fc} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a16ad1e9-f69a-45af-9462-b1c286708842} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{c9ccbb35-d123-4a31-affc-9b2933132116} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{3f27be0c-6c11-374d-b024-ec32da4a37cf} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{803698bc-2d7f-3565-9d3b-10cd32c6c90c} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d52e2fc0-94d8-3904-b4f6-e208073da690} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\{d52e2fc0-94d8-3904-b4f6-e208073da690} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d52e2fc0-94d8-3904-b4f6-e208073da690} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{d52e2fc0-94d8-3904-b4f6-e208073da690} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d52e2fc0-94d8-3904-b4f6-e208073da690} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\shoppingreport (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\D (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\D.1 (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe (Security.Hijack) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ptools (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\agent.exe (Trojan.FraudPack) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\99736236 (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runeqkrh (Trojan.FakeAlert.N) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ruwrabtc (Trojan.FakeAlert.N) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qvygdudd (Trojan.FakeAlert.N) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runeqkrh (Trojan.FakeAlert.N) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ruwrabtc (Trojan.FakeAlert.N) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qvygdudd (Trojan.FakeAlert.N) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (C:\Documents and Settings\John\Application Data\PC\pc.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully. Folders Infected: C:\Documents and Settings\All Users\Application Data\99736236 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\db (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\dwld (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\report (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\res2 (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Program Files\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Program Files\ShoppingReport\Bin (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Program Files\ShoppingReport\Bin\2.6.58 (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images (Rogue.ControlCenter) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\ShoppingReport\Bin\2.6.58\ShoppingReport.dll (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tb12505.dll (Trojan.BHO) -> Delete on reboot. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\Config.xml (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\ShoppingReport\cs\res2\WhiteList.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Program Files\ShoppingReport\Uninst.exe (Adware.ShopperReports) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\guide.html (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg1.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg10.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg2.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg3.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg4.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg5.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg6.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg7.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg8.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\faq\images\gimg9.jpg (Rogue.ControlCenter) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\settings.ini (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\John\Application Data\PC\Uninstall.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ctfmon_dv.exe (Trojan.Agent) -> Quarantined and deleted successfully. MBAM scan #2 Malwarebytes' Anti-Malware 1.43 Database version: 3508 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/7/2010 11:43:03 AM mbam-log-2010-01-07 (11-43-03).txt Scan type: Quick Scan Objects scanned: 115202 Time elapsed: 9 minute(s), 12 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) GMER scan showed the following: C:\WINDOWS\system32\drivers\atapi.sys suspicious modification DDS log: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 12:44:49.78 on Thu 01/07/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.461 [GMT -7:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\Sonic Shared\CineTray.exe svchost.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\CP4GR2HV\dds[1].scr ============== Pseudo HJT Report =============== uInternet Settings,ProxyServer = http=127.0.0.1:5555 uInternet Settings,ProxyOverride = BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Nero PhotoShow Media Manager] c:\progra~1\nero\neroph~1\data\xtras\mssysmgr.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [] mRun: [StatusClient] c:\program files\hewlett-packard\toolbox2.0\apache tomcat 4.0\webapps\toolbox\statusclient\StatusClient.exe /auto mRun: [TomcatStartup] c:\program files\hewlett-packard\toolbox2.0\hpbpsttp.exe mRun: [MaxMenuMgr] "c:\program files\seagate\seagatemanager\freeagent status\StxMenuMgr.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sonicc~1.lnk - c:\program files\common files\sonic shared\CineTray.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1240510974796 DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-23 333192] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-4-23 28424] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-23 360584] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-17 285392] R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2008-10-28 156968] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S3 DIGIRPS;Digi PortServer Driver;c:\windows\system32\drivers\digirlpt.sys [2009-6-8 42432] =============== Created Last 30 ================ 2010-01-07 10:04 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 10:04 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-01-07 09:50 –d—– c:\windows\system32\wbem\Repository 2010-01-01 20:11 552 a——- c:\windows\system32\d3d8caps.dat 2010-01-01 20:10 664 a——- c:\windows\system32\d3d9caps.dat 2009-12-23 21:30 –d—– c:\docume~1\john\applic~1\PC ==================== Find3M ==================== 2010-01-03 17:46 96,512 a——- c:\windows\system32\drivers\atapi.sys 2009-11-17 09:54 12,464 a——- c:\windows\system32\avgrsstx.dll 2009-11-17 09:54 360,584 a——- c:\windows\system32\drivers\avgtdix.sys 2009-11-17 09:54 333,192 a——- c:\windows\system32\drivers\avgldx86.sys 2009-11-12 19:02 45,056 a——- c:\windows\NCUNINST.EXE 2009-10-29 00:45 916,480 a——- c:\windows\system32\wininet.dll 2009-10-20 22:38 75,776 a——- c:\windows\system32\strmfilt.dll 2009-10-20 22:38 25,088 a——- c:\windows\system32\httpapi.dll 2009-10-20 10:31 165,190 a——- c:\windows\hpoins33.dat 2009-10-13 03:30 270,336 a——- c:\windows\system32\oakley.dll 2009-10-12 06:38 149,504 a——- c:\windows\system32\rastls.dll 2009-10-12 06:38 79,872 a——- c:\windows\system32\raschap.dll ============= FINISH: 12:46:54.56 =============== DDS attach log: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 4/23/2009 10:56:54 AM System Uptime: 1/7/2010 12:40:23 PM (0 hours ago) Motherboard: ASUSTek Computer INC. | | NODUSM3 Processor: AMD Athlon™ 64 X2 Dual Core Processor 3800+ | Socket AM2 | 2004/199mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 186 GiB total, 173.714 GiB free. D: is CDROM () E: is CDROM () F: is Removable G: is Removable H: is Removable I: is Removable J: is Removable L: is FIXED (NTFS) - 466 GiB total, 463.743 GiB free. ==== Disabled Device Manager Items ============= Class GUID: Description: Device ID: ACPI\AWY0001\2&DABA3FF&0 Manufacturer: Name: PNP Device ID: ACPI\AWY0001\2&DABA3FF&0 Service: ==== System Restore Points =================== RP157: 10/9/2009 8:05:16 AM - System Checkpoint RP158: 10/10/2009 9:44:59 AM - System Checkpoint RP159: 10/12/2009 10:39:17 AM - System Checkpoint RP160: 10/12/2009 2:22:16 PM - Removed SUPERAntiSpyware Free Edition RP161: 10/12/2009 2:25:39 PM - ADVANCED REGISTRY OPTIMIZER - FIRST RUN RP162: 10/12/2009 2:57:41 PM - Installed Adobe Reader 9.1. RP163: 10/12/2009 9:40:46 PM - Software Distribution Service 3.0 RP164: 10/13/2009 10:22:52 PM - System Checkpoint RP165: 10/15/2009 11:59:49 AM - System Checkpoint RP166: 10/15/2009 7:39:56 PM - Installed Windows Media Player 11 RP167: 10/15/2009 7:40:34 PM - Installed Windows XP Media Center Edition 2005 KB925766. RP168: 10/15/2009 7:41:02 PM - Installed Windows XP Wudf01000. RP169: 10/15/2009 7:42:44 PM - Installed Windows XP MSCompPackV1. RP170: 10/15/2009 8:08:57 PM - Software Distribution Service 3.0 RP171: 10/16/2009 9:00:16 AM - Software Distribution Service 3.0 RP172: 10/17/2009 12:21:21 PM - Avg8 Update RP173: 10/17/2009 7:01:45 PM - Software Distribution Service 3.0 RP174: 10/19/2009 5:35:56 PM - System Checkpoint RP175: 10/20/2009 10:37:22 AM - Installed HP Smart Web Printing RP176: 10/20/2009 9:28:27 PM - Software Distribution Service 3.0 RP177: 10/21/2009 10:34:41 AM - Avg8 Update RP178: 10/22/2009 9:13:03 AM - Software Distribution Service 3.0 RP179: 10/23/2009 10:03:21 AM - System Checkpoint RP180: 10/24/2009 10:36:34 AM - System Checkpoint RP181: 10/26/2009 10:02:26 AM - System Checkpoint RP182: 10/27/2009 11:57:01 AM - System Checkpoint RP183: 10/28/2009 8:56:15 AM - Software Distribution Service 3.0 RP184: 10/29/2009 1:20:07 PM - System Checkpoint RP185: 10/30/2009 3:18:23 PM - System Checkpoint RP186: 10/31/2009 4:03:08 PM - System Checkpoint RP187: 11/1/2009 4:59:53 PM - System Checkpoint RP188: 11/2/2009 5:56:34 PM - System Checkpoint RP189: 11/3/2009 6:03:41 PM - System Checkpoint RP190: 11/4/2009 6:11:09 PM - Avg8 Update RP191: 11/4/2009 6:38:22 PM - Software Distribution Service 3.0 RP192: 11/6/2009 3:21:07 PM - System Checkpoint RP193: 11/8/2009 11:58:59 AM - Avg8 Update RP194: 11/10/2009 11:01:20 AM - System Checkpoint RP195: 11/11/2009 11:33:36 AM - System Checkpoint RP196: 11/11/2009 8:10:38 PM - Software Distribution Service 3.0 RP197: 11/14/2009 10:22:11 AM - System Checkpoint RP198: 11/16/2009 9:54:45 AM - System Checkpoint RP199: 11/17/2009 9:53:50 AM - Installed AVG Free 9.0 RP200: 11/18/2009 12:18:43 PM - System Checkpoint RP201: 11/19/2009 12:54:36 PM - System Checkpoint RP202: 11/20/2009 9:15:16 AM - Avg8 Update RP203: 11/21/2009 10:24:10 AM - System Checkpoint RP204: 11/22/2009 1:07:27 PM - Avg8 Update RP205: 11/22/2009 1:07:45 PM - Avg8 Update RP206: 11/23/2009 1:41:31 PM - System Checkpoint RP207: 11/24/2009 2:26:38 PM - System Checkpoint RP208: 11/25/2009 11:16:05 AM - Software Distribution Service 3.0 RP209: 11/25/2009 12:12:50 PM - Installed Sonic CinePlayer DVD Pack RP210: 11/27/2009 4:03:40 PM - Software Distribution Service 3.0 RP211: 11/30/2009 9:11:19 AM - System Checkpoint RP212: 12/1/2009 10:12:51 AM - System Checkpoint RP213: 12/2/2009 2:16:34 PM - System Checkpoint RP214: 12/4/2009 9:20:47 AM - System Checkpoint RP215: 12/6/2009 4:11:49 PM - System Checkpoint RP216: 12/8/2009 10:08:55 AM - System Checkpoint RP217: 12/9/2009 12:25:27 PM - System Checkpoint RP218: 12/9/2009 8:47:07 PM - Software Distribution Service 3.0 RP219: 12/11/2009 11:49:08 AM - System Checkpoint RP220: 12/11/2009 3:17:11 PM - Avg8 Update RP221: 12/11/2009 3:18:03 PM - Avg8 Update RP222: 12/12/2009 3:43:45 PM - System Checkpoint RP223: 12/13/2009 4:13:12 PM - System Checkpoint RP224: 12/14/2009 4:31:03 PM - System Checkpoint RP225: 12/15/2009 5:38:58 PM - System Checkpoint RP226: 12/16/2009 5:47:39 PM - System Checkpoint RP227: 12/17/2009 5:58:54 PM - System Checkpoint RP228: 12/18/2009 4:02:03 PM - Avg8 Update RP229: 12/19/2009 4:58:12 PM - System Checkpoint RP230: 12/21/2009 12:38:26 PM - System Checkpoint RP231: 12/23/2009 9:53:41 AM - Avg8 Update RP232: 12/24/2009 1:12:48 PM - System Checkpoint RP233: 12/26/2009 10:07:03 AM - System Checkpoint RP234: 12/27/2009 11:27:21 AM - System Checkpoint RP235: 12/29/2009 2:06:05 PM - System Checkpoint RP236: 12/31/2009 2:32:09 PM - System Checkpoint RP237: 1/1/2010 12:13:04 PM - Avg8 Update RP238: 1/2/2010 4:47:13 PM - System Checkpoint RP239: 1/3/2010 5:48:18 PM - System Checkpoint RP240: 1/4/2010 5:48:55 PM - System Checkpoint RP241: 1/5/2010 5:55:22 PM - System Checkpoint RP242: 1/6/2010 6:00:35 PM - System Checkpoint RP243: 1/7/2010 9:40:54 AM - Restore Operation RP244: 1/7/2010 9:49:54 AM - Restore Operation ==== Installed Programs ====================== 32 Bit HP CIO Components Installer Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.1 Audacity 1.2.6 AVG Free 9.0 BufferChm C5500 C5500_Help Cards_Calendar_OrderGift_DoMorePlugout CustomerResearchQFolder Data Fax SoftModem with SmartCP Destination Component DeviceDiscovery DeviceManagementQFolder DocProc DocProcQFolder Easy CD Creator 5 Basic ERUNT 1.1j eSupportQFolder Express Burn Express Rip GPBaseService High Definition Audio Driver Package - KB888111 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) HP Customer Participation Program 11.0 HP Imaging Device Functions 11.0 hp LaserJet 1010 Series HP Photosmart C5500 All-In-One Driver Software 11.0 Rel .4 HP Photosmart Essential 2.5 HP Photosmart Essential 3.0 HP Smart Web Printing HP Solution Center 11.0 HP Update HPPhotoSmartDiscLabel_PaperLabel HPPhotoSmartDiscLabel_PrintOnDisc HPPhotoSmartDiscLabelContent1 hpphotosmartdisclabelplugin HPPhotoSmartPhotobookWebPack1 HPProductAssistant HPSSupply InterActual Player Malwarebytes' Anti-Malware MarketResearch Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Encarta 96 Encyclopedia Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2000 Professional Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) NVIDIA Drivers OCR Software by I.R.I.S. 11.0 PanoStandAlone PS_AIO_04_C5500_ProductContext PS_AIO_04_C5500_Software PS_AIO_04_C5500_Software_Min PSSWCORE Realtek High Definition Audio Driver Scan Seagate Manager Installer Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Shop for HP Supplies SolutionCenter Sonic CinePlayer DVD Pack Status Switch Sound File Converter Toolbox TrayApp UnloadSupport Update for Windows Internet Explorer 8 (KB968220) Update for Windows Internet Explorer 8 (KB976749) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB960763) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 VideoToolkit01 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 VLC media player 0.9.2 WavePad Sound Editor WebFldrs XP WebReg Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 11 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 Yahoo! Toolbar ==== Event Viewer Messages From Past Week ======== 1/3/2010 10:05:45 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). 1/1/2010 8:19:53 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting. 1/1/2010 8:18:27 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory. 1/1/2010 8:18:27 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver. 1/1/2010 8:14:35 PM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s). 1/1/2010 8:14:35 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine. ==== End Of File ===========================
Hi Mission Man, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1
Link 2
to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks
Hi, thanks for getting back to me. I wasn't able to run combofix until today, but I've run it and now my search engines seem to be working fine. I'm still posting the combofix log for you just in case you see anything that looks wacky, but I wanted to let you know how much I appreciate your help. Thanks again, and the combofix log is as follows:

ComboFix 10-01-04.01 - John 01/09/2010 12:16:41.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.601 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe
c:\documents and settings\John\Application Data\PC
c:\documents and settings\Stories\autorun.inf
c:\windows\system32\encapi32.dll
L:\Autorun.inf

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2009-12-09 to 2010-01-09 )))))))))))))))))))))))))))))))
.

2010-01-08 21:21 . 2010-01-08 21:21 ——– d—–w- c:\program files\Seagate
2010-01-08 21:20 . 2010-01-08 21:20 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Downloaded Installations
2010-01-07 17:04 . 2009-12-30 21:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 17:04 . 2009-12-30 21:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 17:01 . 2010-01-07 17:01 ——– d—–w- c:\program files\ERUNT
2010-01-07 16:50 . 2010-01-07 16:50 ——– d—–w- c:\windows\system32\wbem\Repository
2010-01-02 03:11 . 2010-01-02 03:11 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-01-02 03:10 . 2010-01-04 00:23 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-02 03:09 . 2010-01-07 23:35 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2010-01-01 19:13 . 2009-12-11 22:18 2033432 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-12-24 19:52 . 2009-12-24 19:52 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-24 04:34 . 2009-12-24 04:34 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-12-23 16:53 . 2009-12-23 16:53 4043544 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-23 16:53 . 2009-12-11 22:17 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-23 16:53 . 2009-12-23 16:53 3966744 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-23 16:53 . 2009-12-18 23:01 294656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-18 23:02 . 2009-12-11 22:17 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-09 19:15 . 2009-11-17 16:54 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-01-07 20:19 . 2006-03-15 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-01-07 17:04 . 2009-09-04 22:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-07 04:19 . 2009-05-16 14:53 ——– d—–w- c:\documents and settings\John\Application Data\U3
2010-01-06 19:19 . 2009-11-25 19:19 ——– d—–w- c:\program files\InterActual
2009-12-06 22:54 . 2009-10-20 17:39 ——– d—–w- c:\documents and settings\John\Application Data\HPAppData
2009-11-25 19:12 . 2009-11-25 19:12 ——– d—–w- c:\program files\Common Files\Sonic Shared
2009-11-25 19:12 . 2009-11-25 19:12 ——– d—–w- c:\program files\Sonic
2009-11-17 16:55 . 2009-11-17 16:54 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-17 16:54 . 2009-04-23 18:19 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-17 16:54 . 2009-04-23 18:19 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-17 16:54 . 2009-04-23 18:19 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-17 16:54 . 2009-04-23 18:19 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-17 16:54 . 2009-04-23 18:19 ——– d—–w- c:\program files\AVG
2009-11-17 16:47 . 2009-04-23 21:51 ——– d—–w- c:\program files\Lavasoft
2009-11-17 16:47 . 2009-04-23 21:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-13 02:02 . 2009-05-11 16:16 45056 —-a-w- c:\windows\NCUNINST.EXE
2009-10-29 07:45 . 2006-03-15 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2006-03-15 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-03-15 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 17:31 . 2009-10-20 16:47 165190 —-a-w- c:\windows\hpoins33.dat
2009-10-20 16:20 . 2006-03-15 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-16 19:12 . 2009-11-17 23:47 1119488 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-10-13 10:30 . 2006-03-15 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 21:47 . 2009-08-17 20:41 33200 —-a-w- c:\documents and settings\John\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-12 13:38 . 2006-03-15 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-03-15 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-09 86016]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-04-01 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Sonic CinePlayer Quick Launch.lnk - c:\program files\Common Files\Sonic Shared\CineTray.exe [2006-7-25 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-17 16:54 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2002-08-01 07:14 684032 —-a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 12:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/23/2009 11:19 AM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/23/2009 11:19 AM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/17/2009 9:54 AM 285392]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [9/25/2009 11:32 PM 189736]
S3 DIGIRPS;Digi PortServer Driver;c:\windows\system32\drivers\digirlpt.sys [6/8/2009 12:23 PM 42432]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-Nero PhotoShow Media Manager - c:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
MSConfigStartUp-NeroFilterCheck - c:\windows\system32\NeroCheck.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-09 12:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3712)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\windows\eHome\ehSched.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2010-01-09 12:27:50 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-09 19:27

Pre-Run: 186,209,628,160 bytes free
Post-Run: 187,035,385,856 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - FA71662D3A13246F750A2BF706761CDC
Hi Mission Man,

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time if more than file is listed, into the "Suspicious files to scan" box on the top of the page:

    C:\Qoobox\Quarantine\C\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe.vir

  • Click on the Upload button
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Please note: the the file path may look like 2 paths squeezed togither but it is one complete path.



Next

Make sure these settings are correct.

Open Internet Explorer
  • at the top click Tools
  • Click Internet Options
  • Click Connections tab
  • Click Lan Settings button
  • Make sure the box beside "Use a proxy sever for your Lan" is UNchecked
  • OK your way out.


We will use combofix again but run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = 

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]



Next

MBAM has been updated, please update it and run it again.

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • VirScan results
  • combofix log
  • MBAM log

Everything still OK?

Thanks
Hi, sorry it's taken me a couple of days to get back here. When I open up VirSCAN through your link, the "suspicious files to scan" box will not let me enter anything. The cursor comes up, but I can't paste or type the file name there. Any suggestions? Thanks, Don
The VirSCAN result is as follows:

VirSCAN.org Scanned Report :
Scanned time : 2010/01/12 10:49:43 (MST)
Scanner results: Scanners did not find malware!
File Name : vlc-1.0.3-win32.exe.vir
File Size : 18030130 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 5c707790262c303361d05a144c8089f4
SHA1 : ff8e2092d9126b041f6ab0da85779058157a48c9
Online report : http://virscan.org/report/7296cb2f502378d8…3f72f6a03e.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20100112220211 2010-01-12 9.47 -
AhnLab V3 2010.01.12.03 2010.01.12 2010-01-12 1.04 -
AntiVir 8.2.1.134 7.10.2.175 2010-01-12 4.84 -
Antiy 2.0.18 20100112.3695772 2010-01-12 3.23 -
Arcavir 2009 201001121034 2010-01-12 13.90 -
Authentium 5.1.1 201001121407 2010-01-12 2.18 -
AVAST! 4.7.4 100111-0 2010-01-11 8.38 -
AVG 8.5.288 270.14.136/2616 2010-01-12 15.04 -
BitDefender 7.81008.4854272 7.29847 2010-01-13 4.63 -
CA (VET) 35.1.0 7231 2010-01-11 21.45 -
ClamAV 0.95.2 10285 2010-01-12 18.20 -
Comodo 3.13.579 3409 2010-01-12 0.98 -
CP Secure 1.3.0.5 2010.01.12 2010-01-12 1.22 -
Dr.Web 4.44.0.9170 2010.01.12 2010-01-12 26.66 -
F-Prot 4.4.4.56 20100112 2010-01-12 2.13 -
F-Secure 7.02.73807 2010.01.12.10 2010-01-12 0.21 -
Fortinet 11.365- 11.365 2010-01-12 0.25 -
GData 19.9929/19.671 20100112 2010-01-12 5.84 -
ViRobot 20100112 2010.01.12 2010-01-12 0.43 -
Ikarus T3.1.01.80 2010.01.12.74949 2010-01-12 13.82 -
JiangMin 13.0.900 2010.01.12 2010-01-12 13.53 -
Kaspersky 5.5.10 2010.01.12 2010-01-12 0.07 -
KingSoft 2009.2.5.15 2010.1.12.21 2010-01-12 5.37 -
McAfee 5.3.00 5859 2010-01-12 3.40 -
Microsoft 1.5302 2010.01.12 2010-01-12 7.87 -
Norman 6.01.09 6.01.00 2010-01-12 4.01 -
Panda 9.05.01 2010.01.12 2010-01-12 7.68 -
Trend Micro 9.120-1004 6.764.05 2010-01-12 13.63 -
Quick Heal 10.00 2010.01.12 2010-01-12 5.05 -
Rising 20.0 22.30.01.03 2010-01-12 1.13 -
Sophos 3.03.0 4.49 2010-01-13 3.05 -
Sunbelt 3.9.2389.2 5612 2010-01-11 8.01 -
Symantec 1.3.0.24 20100111.003 2010-01-11 0.33 -
nProtect 20100112.02 6856615 2010-01-12 5.54 -
The Hacker [removed] v00147 2010-01-12 0.82 -
VBA32 3.12.12.1 20100111.2153 2010-01-11 9.11 -
VirusBuster 4.5.11.10 10.119.2/2015017 2010-01-12 0.00 -

The Combo fix log is:

ComboFix 10-01-11.04 - John 01/12/2010 11:01:14.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.340 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\John\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\$NtUninstallKB922582$
c:\windows\$NtUninstallKB922582$\fltlib.dll
c:\windows\$NtUninstallKB922582$\fltmc.exe
c:\windows\$NtUninstallKB922582$\fltmgr.sys
c:\windows\$NtUninstallKB922582$\spuninst\spuninst.exe
c:\windows\$NtUninstallKB922582$\spuninst\spuninst.inf
c:\windows\$NtUninstallKB922582$\spuninst\spuninst.txt
c:\windows\$NtUninstallKB922582$\spuninst\updspapi.dll
L:\autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-12-12 to 2010-01-12 )))))))))))))))))))))))))))))))
.

2010-01-08 21:21 . 2010-01-08 21:21 ——– d—–w- c:\program files\Seagate
2010-01-08 21:20 . 2010-01-08 21:20 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Downloaded Installations
2010-01-07 17:04 . 2009-12-30 21:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 17:04 . 2009-12-30 21:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 17:01 . 2010-01-07 17:01 ——– d—–w- c:\program files\ERUNT
2010-01-07 16:50 . 2010-01-07 16:50 ——– d—–w- c:\windows\system32\wbem\Repository
2010-01-02 03:11 . 2010-01-02 03:11 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-01-02 03:10 . 2010-01-04 00:23 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-02 03:09 . 2010-01-07 23:35 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-12-24 19:52 . 2009-12-24 19:52 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-24 04:34 . 2009-12-24 04:34 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-12-23 16:53 . 2009-12-23 16:53 4043544 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-23 16:53 . 2009-12-23 16:53 3966744 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-23 16:53 . 2009-12-18 23:01 294656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-09 19:15 . 2009-11-17 16:54 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-01-07 20:19 . 2006-03-15 12:00 96512 ——w- c:\windows\system32\drivers\atapi.sys
2010-01-07 17:04 . 2009-09-04 22:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-07 04:19 . 2009-05-16 14:53 ——– d—–w- c:\documents and settings\John\Application Data\U3
2010-01-06 19:19 . 2009-11-25 19:19 ——– d—–w- c:\program files\InterActual
2009-12-06 22:54 . 2009-10-20 17:39 ——– d—–w- c:\documents and settings\John\Application Data\HPAppData
2009-11-25 19:12 . 2009-11-25 19:12 ——– d—–w- c:\program files\Common Files\Sonic Shared
2009-11-25 19:12 . 2009-11-25 19:12 ——– d—–w- c:\program files\Sonic
2009-11-17 16:55 . 2009-11-17 16:54 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-17 16:54 . 2009-04-23 18:19 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-17 16:54 . 2009-04-23 18:19 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-17 16:54 . 2009-04-23 18:19 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-17 16:54 . 2009-04-23 18:19 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-17 16:54 . 2009-04-23 18:19 ——– d—–w- c:\program files\AVG
2009-11-17 16:47 . 2009-04-23 21:51 ——– d—–w- c:\program files\Lavasoft
2009-11-17 16:47 . 2009-04-23 21:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-13 02:02 . 2009-05-11 16:16 45056 —-a-w- c:\windows\NCUNINST.EXE
2009-10-29 07:45 . 2006-03-15 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2006-03-15 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-03-15 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 17:31 . 2009-10-20 16:47 165190 —-a-w- c:\windows\hpoins33.dat
2009-10-20 16:20 . 2006-03-15 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-16 19:12 . 2009-11-17 23:47 1119488 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-09 86016]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-04-01 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Sonic CinePlayer Quick Launch.lnk - c:\program files\Common Files\Sonic Shared\CineTray.exe [2006-7-25 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-17 16:54 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2002-08-01 07:14 684032 —-a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 12:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/23/2009 11:19 AM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/23/2009 11:19 AM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/17/2009 9:54 AM 285392]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [9/25/2009 11:32 PM 189736]
S3 DIGIRPS;Digi PortServer Driver;c:\windows\system32\drivers\digirlpt.sys [6/8/2009 12:23 PM 42432]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-12 11:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-01-12 11:07:14
ComboFix-quarantined-files.txt 2010-01-12 18:07
ComboFix2.txt 2010-01-09 19:27

Pre-Run: 187,136,905,216 bytes free
Post-Run: 187,219,091,456 bytes free

- - End Of File - - 8506E1A82CDA6A4D1BC8FA03C04F380D

The MBAM scan report is as follows:

Malwarebytes' Anti-Malware 1.44
Database version: 3549
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/12/2010 11:16:34 AM
mbam-log-2010-01-12 (11-16-34).txt

Scan type: Quick Scan
Objects scanned: 113044
Time elapsed: 4 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


As far as I can tell, the problem seems to be solved. Please look over these results I've posted and let me know if there's anything else I need to do. Thanks again for all your assistance!!!!

Don
Hi Mission Man,

So far so good.

One more scan to check our handiwork.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.

Please post back with
  • ESET log
  • new DDS log taken after the ESET scan
Still ok?

Thanks
Following is the ESET log – C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Win32/Olmarik.RF virus C:\System Volume Information\_restore{23FD16A1-333D-42D7-8686-1956B638B901}\RP169\A0026891.dll Win32/Adware.HotBar.E application C:\System Volume Information\_restore{23FD16A1-333D-42D7-8686-1956B638B901}\RP169\A0026892.dll Win32/Adware.HotBar.E application C:\System Volume Information\_restore{23FD16A1-333D-42D7-8686-1956B638B901}\RP169\A0026893.dll Win32/Adware.HotBar.E application C:\System Volume Information\_restore{23FD16A1-333D-42D7-8686-1956B638B901}\RP169\A0026894.exe Win32/Adware.HotBar.E application C:\System Volume Information\_restore{23FD16A1-333D-42D7-8686-1956B638B901}\RP169\A0026895.dll Win32/Adware.HotBar.E application C:\System Volume Information\_restore{23FD16A1-333D-42D7-8686-1956B638B901}\RP169\A0026898.exe probably a variant of Win32/Adware.180Solutions application C:\System Volume Information\_restore{23FD16A1-333D-42D7-8686-1956B638B901}\RP169\A0026900.exe Win32/Adware.HotBar.E application C:\System Volume Information\_restore{23FD16A1-333D-42D7-8686-1956B638B901}\RP169\A0026901.dll a variant of Win32/Adware.HotBar.E application C:\System Volume Information\_restore{23FD16A1-333D-42D7-8686-1956B638B901}\RP169\A0026902.exe multiple threats I am now having trouble running the DDS scan. I'm a little confused – when I click on the DDS icon on the desktop, I get the log from last week, and when I try to download it again I get the message "The system cannot find the path specified." Any suggestions?
Hi Mission Man,

Use this scantool instead.

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Thanks
Thanks, I had no d=trouble running the OTL scan. Following are the two logs you requested:

OTL.txt log

OTL logfile created on: 1/13/2010 10:25:10 AM - Run 1
OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\John\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 534.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 174.21 Gb Free Space | 93.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 3.72 Gb Total Space | 3.72 Gb Free Space | 99.84% Space Free | Partition Type: FAT32
Drive L: | 465.76 Gb Total Space | 463.74 Gb Free Space | 99.57% Space Free | Partition Type: NTFS

Computer Name: JOHN1
Current User Name: John
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
PRC - C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (Seagate LLC)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (Hewlett-Packard)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Common Files\Sonic Shared\CineTray.exe (Sonic Solutions)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\John\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\AppPatch\aclayers.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\shimeng.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\linkinfo.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (FreeAgentGoNext Service) – C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (Seagate Technology LLC)
SRV - (hpqddsvc) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (hpqcxs08) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) – C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Cdr4_xp) – C:\WINDOWS\system32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k) – C:\WINDOWS\system32\drivers\cdralw2k.sys (Roxio)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (HPZid412) – C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (HPZius12) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (HSXHWBS2) – C:\WINDOWS\system32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsx) – C:\WINDOWS\system32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSX_DP) – C:\WINDOWS\system32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (cdudf_xp) – C:\WINDOWS\system32\drivers\cdudf_xp.sys (Roxio)
DRV - (dvd_2K) – C:\WINDOWS\system32\drivers\Dvd_2k.sys (Roxio)
DRV - (mmc_2K) – C:\WINDOWS\system32\drivers\Mmc_2k.sys (Roxio)
DRV - (pwd_2k) – C:\WINDOWS\system32\drivers\pwd_2K.sys (Roxio)
DRV - (UdfReadr_xp) – C:\WINDOWS\system32\drivers\udfreadr_xp.sys (Roxio)
DRV - (DIGIRPS) – C:\WINDOWS\system32\drivers\digirlpt.sys (Digi International, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/10/20 10:37:43 | 00,000,000 | —D | M]


O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [MaxMenuMgr] C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe (Seagate LLC)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe (Hewlett-Packard)
O4 - HKLM..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1240510974796 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254 192.168.254.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/23 10:54:29 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/01/13 06:38:33 | 00,000,067 | —- | M] () - L:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/13 10:23:58 | 00,544,256 | —- | C] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2010/01/13 06:40:50 | 00,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2010/01/12 13:52:17 | 00,000,000 | -HSD | C] – C:\RECYCLER
[2010/01/12 12:25:39 | 00,000,000 | —D | C] – C:\Program Files\ESET
[2010/01/12 11:07:16 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2010/01/10 13:55:13 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Recorded TV
[2010/01/09 12:04:55 | 00,000,000 | RHSD | C] – C:\cmdcons
[2010/01/09 12:03:12 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/01/09 12:03:12 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/01/09 12:03:12 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/01/09 12:03:12 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/01/09 12:02:30 | 00,000,000 | —D | C] – C:\Qoobox
[2010/01/08 14:21:42 | 00,000,000 | —D | C] – C:\Program Files\Seagate
[2010/01/08 14:20:10 | 00,000,000 | —D | C] – C:\Documents and Settings\John\Local Settings\Application Data\Downloaded Installations
[2010/01/07 10:04:08 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 10:04:04 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/07 10:01:53 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/01/07 10:01:21 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/11/17 09:52:57 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/10/15 19:49:04 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/04/23 14:02:02 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/04/23 11:18:41 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/13 10:23:43 | 00,544,256 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2010/01/13 09:21:40 | 00,000,000 | —- | M] () – C:\Documents and Settings\John\Ÿ9Ÿ9
[2010/01/13 09:19:56 | 00,043,531 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/13 09:19:51 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/13 09:19:49 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/13 09:18:27 | 03,465,216 | —- | M] () – C:\Documents and Settings\John\ntuser.dat
[2010/01/13 09:18:27 | 00,000,278 | -HS- | M] () – C:\Documents and Settings\John\ntuser.ini
[2010/01/13 09:18:15 | 06,291,456 | -H– | M] () – C:\Documents and Settings\John\Local Settings\Application Data\IconCache.db
[2010/01/13 09:02:55 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/13 07:25:51 | 00,021,504 | —- | M] () – C:\Documents and Settings\John\My Documents\Dear Michale-Lana-David-Jessica.doc
[2010/01/13 06:42:02 | 47,776,455 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/01/13 06:41:44 | 00,002,473 | —- | M] () – C:\Documents and Settings\John\Desktop\Microsoft Word.lnk
[2010/01/13 06:41:42 | 00,138,990 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/12 11:05:52 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/12 10:59:46 | 03,821,169 | R— | M] () – C:\Documents and Settings\John\Desktop\ComboFix.exe
[2010/01/11 20:27:41 | 00,040,448 | —- | M] () – C:\Documents and Settings\John\My Documents\ANTIQUE LADY.doc
[2010/01/11 14:14:25 | 00,001,475 | —- | M] () – C:\Documents and Settings\John\Desktop\Windows Explorer.lnk
[2010/01/10 13:55:03 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/09 12:23:38 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/01/09 12:05:01 | 00,000,279 | RHS- | M] () – C:\boot.ini
[2010/01/09 12:01:47 | 03,819,182 | R— | M] () – C:\Documents and Settings\John\Desktop\jgh.exe
[2010/01/09 11:40:51 | 00,000,000 | —- | M] () – C:\Documents and Settings\John\Ÿ;Ÿ;
[2010/01/08 14:53:04 | 00,030,720 | —- | M] () – C:\Documents and Settings\John\My Documents\TOSCANINI.doc
[2010/01/08 14:21:51 | 00,001,863 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2010/01/08 14:05:46 | 00,021,504 | —- | M] () – C:\Documents and Settings\John\My Documents\Margorie.doc
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/07 13:19:33 | 00,096,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atapi.sys
[2010/01/07 11:46:18 | 00,050,176 | —- | M] () – C:\Documents and Settings\John\My Documents\Malwarebytes infection log 1.doc
[2010/01/07 11:43:51 | 00,019,968 | —- | M] () – C:\Documents and Settings\John\My Documents\Malwarebytes log.doc
[2010/01/07 10:04:10 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/07 10:01:26 | 00,000,611 | —- | M] () – C:\Documents and Settings\John\Desktop\NTREGOPT.lnk
[2010/01/07 10:01:25 | 00,000,592 | —- | M] () – C:\Documents and Settings\John\Desktop\ERUNT.lnk
[2010/01/06 12:19:33 | 00,000,779 | —- | M] () – C:\Documents and Settings\All Users\Desktop\InterActual Player.lnk
[2010/01/05 10:18:41 | 00,019,968 | —- | M] () – C:\Documents and Settings\John\My Documents\Dear Julie Del.doc
[2010/01/03 17:23:40 | 00,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/01/01 20:11:17 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/12/18 16:52:30 | 00,023,552 | —- | M] () – C:\Documents and Settings\John\My Documents\Dear Georgia-12-18-09.doc
[2009/12/16 20:30:27 | 00,023,552 | —- | M] () – C:\Documents and Settings\John\My Documents\ADDRESSES E MAIL.doc
[2009/12/16 19:58:53 | 00,019,456 | —- | M] () – C:\Documents and Settings\John\My Documents\cHRISTMAS cARD 2009.doc
[2009/12/14 21:37:04 | 00,019,456 | —- | M] () – C:\Documents and Settings\John\My Documents\MERRY CHRISTMAS TO JESUS.doc
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/13 07:25:50 | 00,021,504 | —- | C] () – C:\Documents and Settings\John\My Documents\Dear Michale-Lana-David-Jessica.doc
[2010/01/11 18:34:33 | 00,040,448 | —- | C] () – C:\Documents and Settings\John\My Documents\ANTIQUE LADY.doc
[2010/01/11 14:04:48 | 00,323,072 | —- | C] () – C:\Documents and Settings\John\My Documents\Northern Adventure - Med Size - Single Spaced Chapters.doc
[2010/01/11 14:04:25 | 00,024,064 | —- | C] () – C:\Documents and Settings\John\My Documents\Northern Adventure - Cover letter, Senopsis with number of .doc
[2010/01/11 14:03:12 | 00,030,720 | —- | C] () – C:\Documents and Settings\John\My Documents\TOSCANINI.doc
[2010/01/11 14:02:39 | 00,066,048 | —- | C] () – C:\Documents and Settings\John\My Documents\Fairieland.doc
[2010/01/11 14:02:09 | 00,041,472 | —- | C] () – C:\Documents and Settings\John\My Documents\DIRTY HARRY.doc
[2010/01/11 14:01:49 | 00,073,216 | —- | C] () – C:\Documents and Settings\John\My Documents\dearbaldy.doc
[2010/01/11 14:00:34 | 00,038,400 | —- | C] () – C:\Documents and Settings\John\My Documents\ANTIQUE LADY 2-7-2001.doc
[2010/01/11 14:00:08 | 00,029,696 | —- | C] () – C:\Documents and Settings\John\My Documents\A TOWN CALLED SPOKEN.doc
[2010/01/09 12:05:00 | 00,000,209 | —- | C] () – C:\Boot.bak
[2010/01/09 12:04:57 | 00,260,272 | —- | C] () – C:\cmldr
[2010/01/09 12:03:12 | 00,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/01/09 12:03:12 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/01/09 12:03:12 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/01/09 12:03:12 | 00,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/01/09 12:03:12 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/01/09 12:01:47 | 03,819,182 | R— | C] () – C:\Documents and Settings\John\Desktop\jgh.exe
[2010/01/09 11:58:24 | 03,821,169 | R— | C] () – C:\Documents and Settings\John\Desktop\ComboFix.exe
[2010/01/08 14:21:51 | 00,001,863 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2010/01/08 14:05:46 | 00,021,504 | —- | C] () – C:\Documents and Settings\John\My Documents\Margorie.doc
[2010/01/07 11:46:18 | 00,050,176 | —- | C] () – C:\Documents and Settings\John\My Documents\Malwarebytes infection log 1.doc
[2010/01/07 11:43:51 | 00,019,968 | —- | C] () – C:\Documents and Settings\John\My Documents\Malwarebytes log.doc
[2010/01/07 10:04:10 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/07 10:01:26 | 00,000,611 | —- | C] () – C:\Documents and Settings\John\Desktop\NTREGOPT.lnk
[2010/01/07 10:01:25 | 00,000,592 | —- | C] () – C:\Documents and Settings\John\Desktop\ERUNT.lnk
[2010/01/06 18:00:31 | 03,465,216 | —- | C] () – C:\Documents and Settings\John\ntuser.dat
[2010/01/05 10:18:40 | 00,019,968 | —- | C] () – C:\Documents and Settings\John\My Documents\Dear Julie Del.doc
[2010/01/01 20:11:17 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/01/01 20:10:35 | 00,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/12/25 13:20:13 | 00,000,000 | —- | C] () – C:\Documents and Settings\John\Ÿ;Ÿ;
[2009/12/18 16:52:29 | 00,023,552 | —- | C] () – C:\Documents and Settings\John\My Documents\Dear Georgia-12-18-09.doc
[2009/12/14 21:37:04 | 00,019,456 | —- | C] () – C:\Documents and Settings\John\My Documents\MERRY CHRISTMAS TO JESUS.doc
[2009/12/14 21:36:52 | 00,019,456 | —- | C] () – C:\Documents and Settings\John\My Documents\cHRISTMAS cARD 2009.doc
[2009/11/25 12:21:46 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/11/25 12:13:27 | 00,000,055 | —- | C] () – C:\WINDOWS\WININIT.INI
[2009/10/20 08:51:23 | 00,001,483 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/09/25 10:08:36 | 00,000,067 | —- | C] () – C:\Documents and Settings\John\Application Data\Setup.txt
[2009/07/15 13:12:54 | 00,003,584 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/15 08:39:50 | 00,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/05/28 11:44:55 | 00,000,127 | —- | C] () – C:\Documents and Settings\John\Local Settings\Application Data\fusioncache.dat
[2009/05/11 08:58:47 | 00,000,648 | —- | C] () – C:\WINDOWS\hplj1010.ini
[2009/04/27 12:20:55 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/09 15:50:00 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/05/09 15:50:00 | 01,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/05/09 15:50:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/05/09 15:50:00 | 00,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/05/09 15:50:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/05/09 15:50:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/05/09 15:50:00 | 00,106,496 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/03/15 05:00:00 | 00,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2006/03/15 05:00:00 | 00,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2006/03/15 05:00:00 | 00,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2006/03/15 05:00:00 | 00,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2006/03/15 05:00:00 | 00,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2005/08/05 14:01:54 | 00,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/07/14 08:12:00 | 00,094,274 | —- | C] () – C:\WINDOWS\System32\HPBHEALR.DLL
[1999/01/22 11:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2009/11/17 09:55:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/01/09 12:15:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/10/13 11:41:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/09/14 11:54:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/10/12 14:33:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/13 10:49:54 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\NCH Swift Sound
[2009/09/06 13:26:12 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Printer Info Cache
[2009/09/25 10:08:36 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Simple Star
[2009/09/06 14:02:06 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Wal-Mart Digital Photo Viewer

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
[2010/01/13 10:23:43 | 00,544,256 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2010/01/13 09:21:40 | 00,000,000 | —- | M] () – C:\Documents and Settings\John\Ÿ9Ÿ9
[2010/01/13 09:19:56 | 00,043,531 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/13 09:19:51 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/13 09:19:49 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/13 09:18:27 | 03,465,216 | —- | M] () – C:\Documents and Settings\John\ntuser.dat
[2010/01/13 09:18:27 | 00,000,278 | -HS- | M] () – C:\Documents and Settings\John\ntuser.ini
[2010/01/13 09:18:15 | 06,291,456 | -H– | M] () – C:\Documents and Settings\John\Local Settings\Application Data\IconCache.db
[2010/01/13 09:02:55 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/13 07:25:51 | 00,021,504 | —- | M] () – C:\Documents and Settings\John\My Documents\Dear Michale-Lana-David-Jessica.doc
[2010/01/13 06:41:44 | 00,002,473 | —- | M] () – C:\Documents and Settings\John\Desktop\Microsoft Word.lnk
[2010/01/12 12:25:39 | 00,000,000 | —D | M] – C:\Program Files\ESET
[2010/01/12 11:10:46 | 00,000,000 | —D | M] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/12 11:05:52 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/12 11:04:13 | 00,000,000 | —D | M] – C:\Program Files\Common Files
[2010/01/12 10:59:46 | 03,821,169 | R— | M] () – C:\Documents and Settings\John\Desktop\ComboFix.exe
[2010/01/11 20:27:41 | 00,040,448 | —- | M] () – C:\Documents and Settings\John\My Documents\ANTIQUE LADY.doc
[2010/01/11 14:14:25 | 00,001,475 | —- | M] () – C:\Documents and Settings\John\Desktop\Windows Explorer.lnk
[2010/01/10 13:55:03 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/09 12:15:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/01/09 12:01:47 | 03,819,182 | R— | M] () – C:\Documents and Settings\John\Desktop\jgh.exe
[2010/01/09 11:40:51 | 00,000,000 | —- | M] () – C:\Documents and Settings\John\Ÿ;Ÿ;
[2010/01/08 14:53:04 | 00,030,720 | —- | M] () – C:\Documents and Settings\John\My Documents\TOSCANINI.doc
[2010/01/08 14:21:51 | 00,001,863 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2010/01/08 14:21:42 | 00,000,000 | —D | M] – C:\Program Files\Seagate
[2010/01/08 14:20:10 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Local Settings\Application Data\Downloaded Installations
[2010/01/08 14:05:46 | 00,021,504 | —- | M] () – C:\Documents and Settings\John\My Documents\Margorie.doc
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/07 11:46:18 | 00,050,176 | —- | M] () – C:\Documents and Settings\John\My Documents\Malwarebytes infection log 1.doc
[2010/01/07 11:43:51 | 00,019,968 | —- | M] () – C:\Documents and Settings\John\My Documents\Malwarebytes log.doc
[2010/01/07 10:04:10 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/07 10:01:33 | 00,000,000 | —D | M] – C:\Program Files\ERUNT
[2010/01/07 10:01:26 | 00,000,611 | —- | M] () – C:\Documents and Settings\John\Desktop\NTREGOPT.lnk
[2010/01/07 10:01:25 | 00,000,592 | —- | M] () – C:\Documents and Settings\John\Desktop\ERUNT.lnk
[2010/01/06 21:19:35 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\U3
[2010/01/06 12:19:35 | 00,000,000 | —D | M] – C:\Program Files\InterActual
[2010/01/06 12:19:33 | 00,000,779 | —- | M] () – C:\Documents and Settings\All Users\Desktop\InterActual Player.lnk
[2010/01/05 10:18:41 | 00,019,968 | —- | M] () – C:\Documents and Settings\John\My Documents\Dear Julie Del.doc
[2010/01/03 17:23:40 | 00,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/01/01 20:11:17 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/12/18 16:52:30 | 00,023,552 | —- | M] () – C:\Documents and Settings\John\My Documents\Dear Georgia-12-18-09.doc
[2009/12/16 20:30:27 | 00,023,552 | —- | M] () – C:\Documents and Settings\John\My Documents\ADDRESSES E MAIL.doc
[2009/12/16 19:58:53 | 00,019,456 | —- | M] () – C:\Documents and Settings\John\My Documents\cHRISTMAS cARD 2009.doc
[2009/12/14 21:37:04 | 00,019,456 | —- | M] () – C:\Documents and Settings\John\My Documents\MERRY CHRISTMAS TO JESUS.doc
[2009/11/17 09:52:57 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/10/20 10:31:27 | 00,001,483 | —- | M] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/10/15 19:49:04 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/10/15 11:31:25 | 00,003,584 | —- | M] () – C:\Documents and Settings\John\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/12 14:47:28 | 00,033,200 | —- | M] () – C:\Documents and Settings\John\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/09/25 10:08:36 | 00,000,067 | —- | M] () – C:\Documents and Settings\John\Application Data\Setup.txt
[2009/05/28 11:44:55 | 00,000,127 | —- | M] () – C:\Documents and Settings\John\Local Settings\Application Data\fusioncache.dat
[2009/04/23 14:02:02 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/04/23 11:18:41 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/04/23 03:38:47 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\John\Application Data\desktop.ini
[2009/04/23 03:38:47 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\desktop.ini
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/13 10:23:43 | 00,544,256 | —- | M] (OldTimer Tools) – C:\Documents and Settings\John\Desktop\OTL.exe
[2010/01/13 09:21:40 | 00,000,000 | —- | M] () – C:\Documents and Settings\John\Ÿ9Ÿ9
[2010/01/13 09:19:56 | 00,043,531 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/13 09:19:51 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/13 09:19:49 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/13 09:18:27 | 03,465,216 | —- | M] () – C:\Documents and Settings\John\ntuser.dat
[2010/01/13 09:18:27 | 00,000,278 | -HS- | M] () – C:\Documents and Settings\John\ntuser.ini
[2010/01/13 09:18:15 | 06,291,456 | -H– | M] () – C:\Documents and Settings\John\Local Settings\Application Data\IconCache.db
[2010/01/13 09:02:55 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/13 07:25:51 | 00,021,504 | —- | M] () – C:\Documents and Settings\John\My Documents\Dear Michale-Lana-David-Jessica.doc
[2010/01/13 06:42:02 | 47,776,455 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/01/13 06:41:44 | 00,002,473 | —- | M] () – C:\Documents and Settings\John\Desktop\Microsoft Word.lnk
[2010/01/13 06:41:42 | 00,138,990 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/12 11:05:52 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/12 10:59:46 | 03,821,169 | R— | M] () – C:\Documents and Settings\John\Desktop\ComboFix.exe
[2010/01/11 20:27:41 | 00,040,448 | —- | M] () – C:\Documents and Settings\John\My Documents\ANTIQUE LADY.doc
[2010/01/11 14:14:25 | 00,001,475 | —- | M] () – C:\Documents and Settings\John\Desktop\Windows Explorer.lnk
[2010/01/10 13:55:03 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/09 12:23:38 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/01/09 12:05:01 | 00,000,279 | RHS- | M] () – C:\boot.ini
[2010/01/09 12:01:47 | 03,819,182 | R— | M] () – C:\Documents and Settings\John\Desktop\jgh.exe
[2010/01/09 11:40:51 | 00,000,000 | —- | M] () – C:\Documents and Settings\John\Ÿ;Ÿ;
[2010/01/08 14:53:04 | 00,030,720 | —- | M] () – C:\Documents and Settings\John\My Documents\TOSCANINI.doc
[2010/01/08 14:21:51 | 00,001,863 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Seagate Manager.lnk
[2010/01/08 14:05:46 | 00,021,504 | —- | M] () – C:\Documents and Settings\John\My Documents\Margorie.doc
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/07 13:19:33 | 00,096,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atapi.sys
[2010/01/07 11:46:18 | 00,050,176 | —- | M] () – C:\Documents and Settings\John\My Documents\Malwarebytes infection log 1.doc
[2010/01/07 11:43:51 | 00,019,968 | —- | M] () – C:\Documents and Settings\John\My Documents\Malwarebytes log.doc
[2010/01/07 10:04:10 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/07 10:01:26 | 00,000,611 | —- | M] () – C:\Documents and Settings\John\Desktop\NTREGOPT.lnk
[2010/01/07 10:01:25 | 00,000,592 | —- | M] () – C:\Documents and Settings\John\Desktop\ERUNT.lnk
[2010/01/06 12:19:33 | 00,000,779 | —- | M] () – C:\Documents and Settings\All Users\Desktop\InterActual Player.lnk
[2010/01/05 10:18:41 | 00,019,968 | —- | M] () – C:\Documents and Settings\John\My Documents\Dear Julie Del.doc
[2010/01/03 17:23:40 | 00,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/01/01 20:11:17 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/12/18 16:52:30 | 00,023,552 | —- | M] () – C:\Documents and Settings\John\My Documents\Dear Georgia-12-18-09.doc
[2009/12/16 20:30:27 | 00,023,552 | —- | M] () – C:\Documents and Settings\John\My Documents\ADDRESSES E MAIL.doc
[2009/12/16 19:58:53 | 00,019,456 | —- | M] () – C:\Documents and Settings\John\My Documents\cHRISTMAS cARD 2009.doc
[2009/12/14 21:37:04 | 00,019,456 | —- | M] () – C:\Documents and Settings\John\My Documents\MERRY CHRISTMAS TO JESUS.doc
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== LOP Check ==========

[2009/11/17 09:55:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/01/09 12:15:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/10/13 11:41:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/09/14 11:54:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/10/12 14:33:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/13 10:49:54 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\NCH Swift Sound
[2009/09/06 13:26:12 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Printer Info Cache
[2009/09/25 10:08:36 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Simple Star
[2009/09/06 14:02:06 | 00,000,000 | —D | M] – C:\Documents and Settings\John\Application Data\Wal-Mart Digital Photo Viewer

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >

Extras.Txt log

OTL Extras logfile created on: 1/13/2010 10:25:10 AM - Run 1
OTL by OldTimer - Version 3.1.24.0 Folder = C:\Documents and Settings\John\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 534.00 Mb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 174.21 Gb Free Space | 93.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 3.72 Gb Total Space | 3.72 Gb Free Space | 99.84% Space Free | Partition Type: FAT32
Drive L: | 465.76 Gb Total Space | 463.74 Gb Free Space | 99.57% Space Free | Partition Type: NTFS

Computer Name: JOHN1
Current User Name: John
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe" = C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe:*:Enabled:javaw – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00010409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Professional
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{114AA4D3-A577-400E-A1B2-3CF75CF8D2E2}" = C5500_Help
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{26BEE28E-C285-4532-82D3-7CE3C5F805D4}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{27197499-7680-4208-8FD8-5439CDB0FDC1}" = HPProductAssistant
"{292C47B2-8DB7-47BF-896C-C3C5EE8108C4}" = hp LaserJet 1010 Series
"{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"{2AFEAA03-2DFE-4519-A629-EDAB6541ABE9}" = HPSSupply
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{49A143E9-4A6A-43E7-86B1-388194C79248}" = HP Smart Web Printing
"{4A3D0CF8-60FF-4CEF-91A4-A1F001424602}" = DocProc
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{593A6CAF-E114-4e31-884F-74FF349E8E36}" = SolutionCenter
"{5B8B9664-21C8-4A1C-AEE4-EF7B1EEB6BD3}" = PS_AIO_04_C5500_Software
"{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 Basic
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6CC1EE94-B426-478B-AE83-F83EBB4EF66A}" = HPPhotoSmartDiscLabel_PaperLabel
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70E1E357-E57C-4284-B04E-58196DC27BC1}" = PanoStandAlone
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7ED180E1-ADE9-4C69-8845-BDF518D763B8}" = hpphotosmartdisclabelplugin
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A558B0C-541D-47e0-A177-8635CE723B07}" = HP Photosmart C5500 All-In-One Driver Software 11.0 Rel .4
"{8E37A0C8-C0E7-4E7A-8739-ACF20D02E70C}" = PS_AIO_04_C5500_Software_Min
"{9A9310B0-FAD0-440E-97B1-5EE14568EF78}" = PS_AIO_04_C5500_ProductContext
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9F4EE72A-C5C9-42ad-ABEF-427690843577}" = MarketResearch
"{AA2E8A46-B45E-4aea-8A23-88AB57D04523}" = WebReg
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{BCC09E9C-3340-473D-A4FE-8580992CA77A}" = HPPhotoSmartDiscLabelContent1
"{BF08AB1C-3357-4f20-A200-8EBB8EF27C59}" = BufferChm
"{C77A7F57-0BA5-4A17-B1C4-28E1D5F5A6EC}" = C5500
"{C89B5E3A-690F-4CEE-909A-BF869E198B0A}" = Scan
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D063F201-FAC4-4D5C-B10B-615058ADE5A7}" = HP Update
"{D16B4BE6-8B10-422f-8034-96D1CA9483B5}" = GPBaseService
"{D4576E0D-2295-4B8E-B663-B68086B00EE5}" = Sonic CinePlayer DVD Pack
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Audacity_is1" = Audacity 1.2.6
"AVG9Uninstall" = AVG Free 9.0
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Data Fax SoftModem with SmartCP
"Encarta96" = Microsoft Encarta 96 Encyclopedia
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"ExpressBurn" = Express Burn
"ExpressRip" = Express Rip
"HP Imaging Device Functions" = HP Imaging Device Functions 11.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 11.0
"HPExtendedCapabilities" = HP Customer Participation Program 11.0
"HPOCR" = OCR Software by I.R.I.S. 11.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{2A30052B-831C-41D3-8044-3C0388066350}" = Seagate Manager Installer
"InterActual Player" = InterActual Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Shop for HP Supplies" = Shop for HP Supplies
"Switch" = Switch Sound File Converter
"VLC media player" = VLC media player 0.9.2
"WavePad" = WavePad Sound Editor
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/3/2010 6:52:09 PM | Computer Name = JOHN1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

Error - 1/3/2010 7:55:59 PM | Computer Name = JOHN1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

Error - 1/3/2010 8:22:57 PM | Computer Name = JOHN1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

Error - 1/3/2010 8:24:18 PM | Computer Name = JOHN1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module 3difr.x3d, version 9.1.0.0, fault address 0x0001d601.

Error - 1/3/2010 8:37:22 PM | Computer Name = JOHN1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

Error - 1/3/2010 9:02:19 PM | Computer Name = JOHN1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

Error - 1/3/2010 9:02:28 PM | Computer Name = JOHN1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

Error - 1/3/2010 9:43:19 PM | Computer Name = JOHN1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

Error - 1/3/2010 9:56:20 PM | Computer Name = JOHN1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

Error - 1/3/2010 10:28:20 PM | Computer Name = JOHN1 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office 2000 Professional – Error 1706. No valid
source could be found for product Microsoft Office 2000 Professional. The Windows
installer cannot continue.

[ System Events ]
Error - 1/9/2010 2:39:13 PM | Computer Name = JOHN1 | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 1/9/2010 2:40:37 PM | Computer Name = JOHN1 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 1/9/2010 3:16:22 PM | Computer Name = JOHN1 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 1/9/2010 3:25:23 PM | Computer Name = JOHN1 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 1/10/2010 4:56:49 PM | Computer Name = JOHN1 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 1/11/2010 12:22:48 PM | Computer Name = JOHN1 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 1/12/2010 12:01:03 PM | Computer Name = JOHN1 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 1/12/2010 12:01:03 PM | Computer Name = JOHN1 | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 1/13/2010 9:39:59 AM | Computer Name = JOHN1 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 1/13/2010 12:21:31 PM | Computer Name = JOHN1 | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.


< End of report >
I just realized I forgot to disable my AVG before running. Let me know if I need to rerun this scan with that disabled. Sorry, and thanks again for all your help.
Hi Mission Man,

I just realized I forgot to disable my AVG before running. Let me know if I need to rerun this scan with that disabled.


No that's fine.

Do you recognize these? If you created them that's fine.

C:\Documents and Settings\John\Ÿ9Ÿ9
C:\Documents and Settings\John\Ÿ;Ÿ;
I don't have any idea what those files are. When I tried to look, I got one of those boxes asking me what program I should use to open the files. Should I go ahead and delete them?
Hi Mission Man,

Yes you can delete them.


Next we'll use combofix again to correct a mistake then we'll clean up the tools and send you on your way.




Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

DeQuarantine::
C:\Qoobox\Quarantine\C\documents and settings\All Users\Application Data\vlc-1.0.3-win32.exe.vir
c\windows\$NtUninstallKB922582$


Quit::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

A log called DeQuarantine.txt will be produced. Please post it's contents.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI