This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Various Trojans, Spyware, Malware, etc.

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi! I'm terrible at computer care and upkeep.

Sometime ago, about a week I'd say, I got hit with a random malware self-installing "your computer is infected omg fix now click here!" deal, so I installed and ran SuperAntiSpyware. That seemed to fix it, until the next day when I got an AVG popup at startup saying two system files were "infected", however I could not clean them because they were white listed and apparently would break my computer if something was done. On top of that, two DLL error messages appeared, which I'm assuming were remnants of what SAS fixed the first time. Nothing bad was happening, so I shrugged it off like an absolute moron and assumed I was fine.

Fast forward to today, and I'm just casually browsing the web, nothing bad, the AVG popup came up again at startup, the DLL errors as well. Suddenly I get hit with yet another malware self installer thing, except it's like 40 times more annoying and now it's changed my wallpaper background to a green screen with a "WARNING YOU ARE INFECTED BLAH BLAH BLAH" black square in the middle. carp** is popping up in my taskbar, fake warning windows are appearing, I'm about ready to bang my head into the desk. Immediately I run SAS with a full scan and restart. Now on startup it gives me a presumably fake virus warning before starting up windows explorer or anything else, forcing me to click okay. It's also disabled task manager, the crafty bugger. I had a screencap of said error(s) but now it won't even let me open MSPaint, telling me it's "infected". The occasional STOPzilla installer pops up as well, hasn't that thing been around forever?

So here we are, I'm bathing in malware and other garbage and I'd like to change my habits of keeping my machine in relatively good condition…

I've followed the "Are you Infected?" Thread to the letter. Here are the requested logs.


MBAM:

Malwarebytes' Anti-Malware 1.44
Database version: 3659
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11

1/29/2010 2:11:20 PM
mbam-log-2010-01-29 (14-11-20).txt

Scan type: Quick Scan
Objects scanned: 112999
Time elapsed: 6 minute(s), 30 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 2
Registry Keys Infected: 10
Registry Values Infected: 8
Registry Data Items Infected: 12
Folders Infected: 6
Files Infected: 18

Memory Processes Infected:
C:\WINDOWS\system32\smss32.exe (Trojan.FakeAlert) -> Unloaded process successfully.

Memory Modules Infected:
C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll (Trojan.Chksyn) -> Delete on reboot.
C:\WINDOWS\system32\helper32.dll (Trojan.FakeAlert) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{009541a0-3b00-1f1c-00f3-040224001c01} (Trojan.Chksyn) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{abcdecef-4b15-11d1-abed-709549c10000} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{abcdece2-4b15-11d1-abed-709549c10000} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{23d67d31-818d-867d-7224-964e5ec3d90d} (Adware.BHO.AR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{23d67d31-818d-867d-7224-964e5ec3d90d} (Adware.BHO.AR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{23d67d31-818d-867d-7224-964e5ec3d90d} (Adware.BHO.AR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\IS2010 (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dot1XCfg (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zivisasof (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\swupdate (Trojan.Chksyn) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smss32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rthdbpl (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.starsdoor.com (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vuzebusavi (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon32.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon32.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\winlogon32.exe) Good: (userinit.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe logon.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\All Users\Application Data\SalesMon (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon\Data (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\InternetSecurity2010 (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D} (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content (Trojan.Swisyn) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll (Trojan.Chksyn) -> Delete on reboot.
C:\WINDOWS\system32\QEECcW0o7.dll (Adware.BHO.AR) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Setup.tmp (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\weosnmxcar.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul (Trojan.Swisyn) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smss32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\helper32.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS\system32\Winlogon32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Start Menu\Internet Security 2010.lnk (Rogue.InternetSecurity2010) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\logon.exe (Backdoor.Bot) -> Delete on reboot.
C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\Local.dtd (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\Ui.dtd (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\warning.html (Trojan.FakeAlert) -> Quarantined and deleted successfully.

________________________________________________________________________

MBAM also tells me that it couldn't remove 3 things but that they would be added to the "delete on reboot" list;

C:\\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll
C:\\WINDOWS\system32\helper32.dll
C:\\WINDOWS\system32\logon.exe

I did not reboot when it prompted me to, so I could run the other tools.

________________________________________________________________________


DDS:


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:18:36.92 on Fri 01/29/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2558.1713 [GMT -8:00]

AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Panda Internet Security 2008 *On-access scanning disabled* (Outdated) {4570FB70-5C9E-47E9-B16C-A3A6A06C4BF0}
FW: Panda Internet Security 2008 *disabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\game folder\-steam-\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
C:\Program Files\Hamachi\hamachi.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Game Folder\-Steam-\Tortoise SVN\bin\TSVNCache.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Owner\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.naver.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWinlogon: Shell=Explorer.exe logon.exe
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.3.7.16.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: {C553F7A7-DFBA-329A-AEB9-158E32152B60} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [Steam] "c:\game folder\-steam-\steam.exe" -silent
uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [imekrmig] l:\ime\imkr\imekrmig.exe
mRun: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\hamachi.lnk - c:\program files\hamachi\hamachi.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\LOGITE~1.LNK -
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\run_startmenu.cmd
uPolicies-explorer: NoViewOnDrive = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.3.7.16.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: buy-internet-security10.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download25.com
Trusted Zone: buy-internet-security10.com
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} - hxxps://www.e-games.com.my/com/EGamesPlugin.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://spaces.msn.com//PhotoUpload/MsnPUpld.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263605422203
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1224466539359
DPF: {6F750200-1362-4815-A476-88533DE61D0C} - hxxp://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/ultrashim.cab
DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - hxxp://acs.pandasoftware.com/activescan/as5free/asinst.cab
DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxps://members.hangame.com/common/HanSetup1020.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: avldr - avldr.dll
Notify: WBSrv - c:\progra~1\stardock\object~1\window~1\wbsrv.dll
AppInit_DLLs: difebebu.dll c:\windows\system32\lokubaja.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - SABShellExecuteHook Class
LSA: Notification Packages = scecli piseraho.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\2030lu65.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.madnesscombat.net/
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\2030lu65.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension.dll
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\ign\download manager\npfpdlm.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npWebLaunch.dll
FF - plugin: c:\program files\thrixxx\weblaunch\binaries\npWebLaunch.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: google.toolbar.linkdoctor.enabled - false
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-3-9 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-9 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-3-9 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-9 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-9 297752]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-9-16 1174664]
R3 JRSUKD25;JRSUKD25;c:\windows\system32\JRSUKD25.SYS [2009-7-2 12600]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [2006-8-28 10664]
S3 JRSKD24;JRSKD24;c:\windows\system32\JRSKD24.SYS [2009-7-2 34744]
S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\drivers\libusb0.sys [2010-1-11 29184]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 oflpydin;oflpydin;\??\c:\docume~1\owner\locals~1\temp\oflpydin.sys –> c:\docume~1\owner\locals~1\temp\oflpydin.sys [?]
S3 PciCon;PciCon;\??\e:\pcicon.sys –> e:\PciCon.sys [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\screamingbaudio.sys –> c:\windows\system32\drivers\ScreamingBAudio.sys [?]
S3 uisp;Motorola USB ICP driver;c:\windows\system32\drivers\usbicp.sys –> c:\windows\system32\drivers\usbicp.sys [?]

=============== Created Last 30 ================

2010-01-29 14:16 54,016 a——- c:\windows\system32\drivers\jogxcl.sys
2010-01-29 14:03 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2010-01-29 14:03 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-29 14:03 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-29 14:03 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-29 14:03 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-29 13:19 0 a——- c:\windows\system32\19169.exe
2010-01-29 12:59 0 a——- c:\windows\system32\26500.exe
2010-01-29 12:39 0 a——- c:\windows\system32\6334.exe
2010-01-29 12:19 0 a——- c:\windows\system32\18467.exe
2010-01-29 11:58 34,304 ——– c:\windows\system32\helper32.dll
2010-01-14 17:52 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-14 17:52 –d—– c:\program files\SUPERAntiSpyware
2010-01-14 17:47 –dsh— c:\docume~1\owner\applic~1\SystemProc
2010-01-14 15:35 50,180 ——– c:\windows\system32\logon.exe
2010-01-11 07:59 –d—– c:\program files\Sony
2010-01-11 03:11 43,520 a——- c:\windows\system32\libusb0.dll
2010-01-11 03:11 29,184 a——- c:\windows\system32\drivers\libusb0.sys
2010-01-06 05:30 –d—– c:\program files\DAEMON Tools Lite
2010-01-01 01:55 515,416 a——- c:\windows\system32\XAudio2_5.dll
2010-01-01 01:55 1,974,616 a——- c:\windows\system32\D3DCompiler_42.dll
2010-01-01 01:55 1,892,184 a——- c:\windows\system32\D3DX9_42.dll

==================== Find3M ====================

2010-01-18 06:14 5,632 a–sh— c:\program files\Thumbs.db
2010-01-06 05:31 691,696 a——- c:\windows\system32\drivers\sptd.sys
2009-11-07 14:25 86,016 a——- c:\windows\system32\frapsvid.dll
2009-03-18 21:18 22,328 a——- c:\docume~1\owner\applic~1\PnkBstrK.sys
2008-06-03 04:44 71,304 ac—— c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT
2006-11-12 01:39 1 ac—— c:\documents and settings\owner\SI.bin
2005-08-16 10:58 936 ac—— c:\docume~1\owner\applic~1\wklnhst.dat

============= FINISH: 14:19:21.25 ===============


DDS Attach.txt I'm unsure what to do here, if I should add it as an attachment or just leave it in the post. "Are you Infected?" Says not to attach any logs, and post them instead.


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 8/1/2005 8:24:02 AM
System Uptime: 1/29/2010 1:34:28 PM (1 hours ago)

Motherboard: | | MS-7093
Processor: AMD Athlon™ 64 Processor 4000+ | Socket 939 | 2387/199mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 183 GiB total, 10.935 GiB free.
D: is FIXED (FAT32) - 4 GiB total, 1.351 GiB free.
E: is CDROM (UDF)
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is CDROM ()
K: is CDROM ()
L: is FIXED (NTFS) - 466 GiB total, 379.105 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: PlayLinc Adapter
Device ID: ROOT\NET\0000
Manufacturer: Super Computer Inc.
Name: PlayLinc Adapter
PNP Device ID: ROOT\NET\0000
Service: hamachi_oem

==== System Restore Points ===================

RP1009: 1/6/2010 5:31:09 AM - SPTD setup V1.62
RP1010: 1/8/2010 9:26:44 PM - System Checkpoint
RP1011: 1/9/2010 9:34:58 PM - System Checkpoint
RP1012: 1/10/2010 10:56:33 PM - System Checkpoint
RP1013: 1/11/2010 3:18:16 AM - Unsigned driver install
RP1014: 1/11/2010 7:39:39 AM - Removed Microsoft Visual C++ 2005 Redistributable
RP1015: 1/11/2010 7:40:17 AM - Installed Microsoft Visual C++ 2005 Redistributable
RP1016: 1/11/2010 7:41:28 AM - Installed Vegas Pro 9.0
RP1017: 1/11/2010 7:57:49 AM - Removed Vegas Pro 9.0
RP1018: 1/11/2010 7:59:35 AM - Installed Vegas Pro 9.0
RP1019: 1/13/2010 6:45:25 PM - System Checkpoint
RP1020: 1/14/2010 5:52:15 PM - Installed SUPERAntiSpyware Free Edition
RP1021: 1/15/2010 9:10:39 PM - System Checkpoint
RP1022: 1/18/2010 12:37:14 AM - System Checkpoint
RP1023: 1/18/2010 4:42:44 PM - Avg8 Update
RP1024: 1/19/2010 8:46:32 PM - System Checkpoint
RP1025: 1/21/2010 10:27:36 PM - System Checkpoint
RP1026: 1/23/2010 7:11:53 PM - System Checkpoint
RP1027: 1/26/2010 8:55:19 AM - System Checkpoint
RP1028: 1/29/2010 11:44:06 AM - System Checkpoint
RP1029: 1/29/2010 2:01:19 PM - Automatic Restore Point

==== Installed Programs ======================

??? ?? ????
ÇѰÔÀÓ º¸¾ÈÆÐÄ¡
7-Zip 4.42
ABBYY FineReader 5.0 Sprint
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.0
Adobe Shockwave Player
AIM 6.0
Alcohol 120%
AOL Instant Messenger
Apple Software Update
Audiosurf
Autodesk DirectConnect 2.0
AV Voice Changer Software DIAMOND 6.0
AVG 8.5
Battlefield 2™
Battlefield 2142
BitComet 1.16
Borderlands
Bullet Candy
Call of Duty® 4 - Modern Warfare™ 1.2 Patch
Call of Duty® 4 - Modern Warfare™ 1.3 Patch
Call of Duty® 4 - Modern Warfare™ 1.4 Patch
Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch
Call of Duty® 4 - Modern Warfare™ 1.6 Patch
Call of Duty® 4 - Modern Warfare™ 1.7 Patch
CCleaner (remove only)
ClientKeeper KeyPro with E2E for 32bit
Crazy Machines II
CuteFTP 8 Home
Data Lifeguard Tools
Dawn of War - Dark Crusade
Dawn of War - Soulstorm
Dawn Of War - Winter Assault
DawnOfWar
dBpowerAMP Music Converter
Deadlock
Defence Alliance 2
DesertCombat 0.7
Digital Media Reader
DivX Content Uploader
DivX Web Player
Doom 3
Dropbox
DVD-CLONER V3.00 Build 880
DVD Shrink 3.2
DVDFab Decrypter 2.9.3.2
Dystopia
EA Download Manager
End It All
Enemy Territory - QUAKE Wars™ 1.1 Patch
ERUNT 1.1j
Far Cry (Patch 1.3)
FaxTools
FEAR
FMS
Fraps (remove only)
FrostWire 4.18.1
GameSpy Arcade
GCFScape 1.7.4
GoldWave v5.23
Google Chrome
Google Toolbar for Internet Explorer
Google Video Player
Groove Games\Land Of The Dead
Half-Life
Half-Life® 2
Hamachi 1.0.3.0
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
ŒŽ–¾‚è‚̃‰ƒYƒxƒŠƒB `‚‚ñšƒf‚ê‡U`1.00
IGN Download Manager 2.2.2
IrfanView (remove only)
JAM's Jedi Knight KT v2.0
Java™ 6 Update 11
Java™ 6 Update 4
Java™ 6 Update 5
Java™ 6 Update 7
K-Lite Codec Pack 2.65 Full
Kaspersky Online Scanner
Killing Floor SDK
KODAK EASYSHARE Gallery Upload ActiveX Control
Left 4 Dead
Left 4 Dead 2
Left 4 Dead 2 Add-on Support
Left 4 Dead 2 Authoring Tools
Lexmark Skin: Helix
Lexmark Skin: Nature TV2
Lexmark X1100 Series
Logitech GamePanel Software 3.02.173
Logitech SetPoint
LoudMo Contextual Ad Assistant
Macromedia Extension Manager
Macromedia Flash 8 Video Encoder
Malwarebytes' Anti-Malware
MapleStory
Maya 8.5 Documentation (en_US)
MediaCoder 0.6.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Global IME for Office XP (Korean)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2005
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Windows Journal Viewer
Microsoft WSE 3.0 Runtime
Microsoft® Winter Fun Pack 2004 for Windows® XP
Mirror's Edge™
Monster Hunter Frontier Online
Mozilla Firefox (3.5.7)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB925673)
Multimedia Keyboard Driver
Musicmatch® Jukebox
Natural Selection 3.2
Nero BurnRights
Nero OEM
NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)
Notepad++
NVIDIA Drivers
NVIDIA PhysX
Oblivion - Knights of the Nine
Oblivion - Orrery
Oblivion - Spell Tomes
Oblivion - Wizard's Tower
OpenAL
Paint Express 1.30
Paint.NET v3.36
Pando Media Booster
PlayLinc
PowerDVD
PowerISO
PRE-Flight
Psychonauts
PunkBuster Services
Quake III Arena
QuickTime
RealFlight G2 Simulator
RealFlight Simulator
RealPlayer Basic
Realtek AC'97 Audio
RealWorld Cursor Editor
RegCure 1.6.0.0
S.T.A.L.K.E.R.: Shadow of Chernobyl
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Sentinel System Driver
Serious Sam HD: The First Encounter
SierraHome Print Artist 12.0
SoftV92 Data Fax Modem with SmartCP
Source SDK Base - Orange Box
SpeechRedist
SPORE™
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
Star Wars Battlefront II
Steam™
STOPzilla!
SUPERAntiSpyware Free Edition
Sven Co-op 4.0B
System Requirements Lab
The Lord of the Rings - Conquest™
The Sims™ 3
Tom Clancy's Rainbow Six Vegas 2
TortoiseSVN 1.4.7.11792 (32 bit)
TurboTax Deluxe 2005
TurboTax ItsDeductible 2005
Uniblue Registry Booster
Uniblue SpeedUpMyPC
Uniblue System Tweaker
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB953356)
Vegas Pro 9.0
Ventrilo Client
Ventrilo Server
Viewpoint Media Player
VLC media player 0.9.9
VTFEdit 1.2.5
WebFldrs XP
WexTech AnswerWorks
Winamp
WinDirStat 1.1.2
WindowBlinds
Windows Backup Utility
Windows Communication Foundation
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
WinRAR archiver
World of Warcraft
XML Paper Specification Shared Components Pack 1.0
XYZ RGB Texture Package
Yahoo! Toolbar
Zombie Shooter 2 v 1.0

==== Event Viewer Messages From Past Week ========

1/25/2010 4:16:33 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
1/23/2010 6:55:57 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
1/23/2010 6:55:57 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/23/2010 6:55:10 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: szkg
1/23/2010 6:55:10 PM, error: Service Control Manager [7000] - The Microsoft Kernel Acoustic Echo Canceller service failed to start due to the following error: Access is denied.
1/23/2010 6:55:10 PM, error: Service Control Manager [7000] - The DS1410D service failed to start due to the following error: The system cannot find the file specified.

==== End Of File ===========================


________________________________________________________________

GMER would not run correctly, it would open, automatically scan several things, then "encounter an error" and crash.

Should I reboot my system and try GMER again?

Update: I just got another AVG alert;

C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1028\A0550019.exe

Trojan horse Generic 16.AQYI

I clicked heal, seems to have fixed that minor issue for now.
Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix *
  • Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
  • Post a fresh DDS log as well.
  • Let me know how the PC is behaving.
* There are two points to note from the instructions page:

1) The Recovery Console.

It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete some, but not all, of it's removal tasks without the installation of the Console so, should you choose not to allow the installation, you may not get the results you hoped for.

2) Disabling your Anti-Virus.

CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for!
Hello Noviciate! Thank you for your time and wisdom on this matter.

I was unable to deactivate AVG before running Combofix, as there were no deactivation options in the UI and I had no idea which process(es) to end in task manager, there were several SYSTEM processes with avg in the name but I did not want to take chances. I was a little worried when CF was working but it looks like things are a lot better now. However, it looks like Windows Updates are deactivated for some reason, and in Security Center the option to turn them back on is greyed out. I'm guessing I may have to re-scan with Combofix, am I right?

Here's the CF log and a fresh DDS log;


ComboFix:

ComboFix 10-01-29.05 - Owner 01/29/2010 19:05:02.4.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Panda Internet Security 2008 *On-access scanning disabled* (Outdated) {4570FB70-5C9E-47E9-B16C-A3A6A06C4BF0}
FW: Panda Internet Security 2008 *disabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\Flags.dtd
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\UA.dtd
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\UAcpt.dtd
c:\documents and settings\Owner\Application Data\SystemProc
c:\documents and settings\Owner\Desktop\Internet Security 2010.lnk
C:\install.exe
c:\recycler\NPROTECT
c:\recycler\S-1-5-21-3384769280-30235777-3098955120-1003
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\42KJE738.ocx
c:\windows\system32\6334.exe
c:\windows\system32\SIntf16.dll

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - c:\windows\system32\dllcache\atapi.sys

.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.

2010-01-29 22:03 . 2010-01-29 22:03 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-01-29 22:03 . 2010-01-08 00:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-29 22:03 . 2010-01-29 22:03 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-29 22:03 . 2010-01-29 22:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-29 22:03 . 2010-01-08 00:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-29 22:01 . 2010-01-29 22:02 ——– d—–w- c:\program files\ERUNT
2010-01-15 01:52 . 2010-01-15 01:52 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-15 01:52 . 2010-01-15 01:52 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-01-11 16:00 . 2010-01-11 16:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Sony
2010-01-11 15:59 . 2010-01-11 15:59 ——– d—–w- c:\program files\Sony
2010-01-11 11:11 . 2008-12-01 08:47 43520 —-a-w- c:\windows\system32\libusb0.dll
2010-01-11 11:11 . 2007-05-11 08:12 29184 —-a-w- c:\windows\system32\drivers\libusb0.sys
2010-01-06 13:30 . 2010-01-06 13:31 ——– d—–w- c:\program files\DAEMON Tools Lite
2010-01-01 09:55 . 2009-09-05 01:44 515416 —-a-w- c:\windows\system32\XAudio2_5.dll
2010-01-01 09:55 . 2009-09-05 01:29 1974616 —-a-w- c:\windows\system32\D3DCompiler_42.dll
2010-01-01 09:55 . 2009-09-05 01:29 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 03:22 . 2007-04-18 03:17 ——– d—–w- c:\documents and settings\Owner\Application Data\Hamachi
2010-01-22 15:40 . 2007-08-25 05:51 ——– d—–w- c:\program files\BitComet
2010-01-18 14:14 . 2009-06-20 07:42 5632 –sha-w- c:\program files\Thumbs.db
2010-01-15 01:52 . 2006-12-10 22:14 ——– d—–w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2010-01-15 01:51 . 2006-12-01 01:28 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-11 16:04 . 2008-08-16 08:06 ——– d—–w- c:\documents and settings\Owner\Application Data\Sony
2010-01-06 13:31 . 2006-11-12 10:04 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-01-06 13:30 . 2009-06-09 01:25 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-01-05 03:13 . 2009-06-11 05:15 ——– d—–w- c:\documents and settings\Owner\Application Data\Microsoft Games
2009-11-18 06:28 . 2009-06-14 00:11 25 —-a-w- c:\windows\popcinfot.dat
2009-11-07 22:25 . 2009-11-07 22:25 86016 —-a-w- c:\windows\system32\frapsvid.dll
.

——- Sigcheck ——-

[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys
[7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys
[-] 2004-08-04 05:59 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [——] . . c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-10-08 21:18 77824 —-a-w- c:\documents and settings\Owner\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-10-08 21:18 77824 —-a-w- c:\documents and settings\Owner\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-10-08 21:18 77824 —-a-w- c:\documents and settings\Owner\Application Data\Dropbox\bin\DropboxExt.3.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\game folder\-steam-\steam.exe" [2009-10-27 1217808]
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-02 133104]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-10-22 2923192]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-10 2043160]
"imekrmig"="l:\ime\IMKR\imekrmig.exe" [2001-01-09 44544]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2009-05-04 354312]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2009-05-04 1572872]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-05-04 2817544]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
Hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2007-4-17 625952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-31 02:09 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2005-12-07 04:16 176128 —-a-w- c:\progra~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
path=
backup=
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 19:00 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
2005-07-23 07:25 28160 —-a-w- c:\windows\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 18:50 155648 -c–a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-03-27 17:03 13684736 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-03-27 17:03 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2009-03-27 17:03 1657376 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-02-01 06:13 385024 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowWnd]
2003-09-19 16:09 36864 —-a-w- c:\windows\ShowWnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-11-10 13:43 136600 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\counter-strike source\\hl2.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Game Folder\\-Warhammer 40K Dawn of War-\\The Dark Crusade\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\source sdk base\\hl2.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Java\\jre1.6.0_04\\bin\\javaw.exe"=
"c:\\Alcohol 120%\\Alcohol 120% v1.9.2.1705 Multilanguage + serial (OK)\\Alcohol 120\\Alcohol.exe"=
"c:\\Game Folder\\-Steam-\\steam.exe"=
"c:\\Game Folder\\-Warhammer 40K Dawn of War-\\Soulstorm\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Game Folder\\=Ventrillo=\\VENT SERVER\\ventrilo_srv.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\zombie panic! source\\hl2.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\diprip warm up\\hl2.exe"=
"c:\\WINDOWS\\system32\\xa16737546.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\xa46950765.exe"=
"c:\\Game Folder\\=Ventrillo=\\Ventrilo.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\source sdk base 2007\\hl2.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\synergy\\hl2.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\half-life\\hl.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\dystopia\\hl2.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Game Folder\\Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Game Folder\\Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\chaosrain112\\insurgency\\hl2.exe"=
"l:\\Games\\Battlefield 2\\BF2.exe"=
"l:\\Games\\Battlefield 2142\\BF2142.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\common\\left 4 dead 2\\left4dead2.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\common\\left 4 dead 2\\bin\\SDKLauncher.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\common\\stalker shadow of chernobyl\\bin\\XR_3DA.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\common\\killingfloor\\System\\KFEd.exe"=
"c:\\Game Folder\\-Steam-\\SteamApps\\common\\serious sam hd the first encounter\\Bin\\SamHD.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14860:TCP"= 14860:TCP:Frostwire
"3784:TCP"= 3784:TCP:Vent Server
"22889:TCP"= 22889:TCP:BitComet 22889 TCP
"22889:UDP"= 22889:UDP:BitComet 22889 UDP
"56160:TCP"= 56160:TCP:Pando Media Booster
"56160:UDP"= 56160:UDP:Pando Media Booster
"3724:TCP"= 3724:TCP:Blizzard Updater
"6112:TCP"= 6112:TCP:Blizzard Updater
"59018:TCP"= 59018:TCP:Pando Media Booster
"59018:UDP"= 59018:UDP:Pando Media Booster

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [8/28/2005 7:56 PM 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [8/28/2005 7:56 PM 5248]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [3/9/2009 4:28 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/9/2009 4:28 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/9/2009 4:28 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/9/2009 5:35 PM 297752]
R3 JRSUKD25;JRSUKD25;c:\windows\system32\JRSUKD25.SYS [7/2/2009 10:11 AM 12600]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [8/28/2006 11:54 PM 10664]
S3 JRSKD24;JRSKD24;c:\windows\system32\JRSKD24.SYS [7/2/2009 10:11 AM 34744]
S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\drivers\libusb0.sys [1/11/2010 3:11 AM 29184]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 oflpydin;oflpydin;\??\c:\docume~1\Owner\LOCALS~1\Temp\oflpydin.sys –> c:\docume~1\Owner\LOCALS~1\Temp\oflpydin.sys [?]
S3 PciCon;PciCon;\??\e:\pcicon.sys –> e:\PciCon.sys [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys –> c:\windows\system32\drivers\ScreamingBAudio.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/12/2006 2:04 AM 691696]
.
Contents of the 'Scheduled Tasks' folder

2010-01-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3147262485-678377544-2497640554-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-02 19:22]

2010-01-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3147262485-678377544-2497640554-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-02 19:22]

2010-01-30 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 23:20]

2010-01-30 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 23:20]

2010-01-11 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-06-10 23:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.naver.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Google; Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate; English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
Trusted Zone: buy-internet-security10.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download25.com
Trusted Zone: buy-internet-security10.com
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxps://members.hangame.com/common/HanSetup1020.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\2030lu65.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.madnesscombat.net/
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\2030lu65.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npWebLaunch.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -

BHO-{C553F7A7-DFBA-329A-AEB9-158E32152B60} - (no file)
Toolbar-SITEguard - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
Notify-avldr - avldr.dll
AddRemove-8D12n2Y2I - c:\windows\system32\8D12n2Y2I.exe
AddRemove-DeadlockDeinstKey - c:\game folder\-deadlock-\DeIsL1.isu
AddRemove-PRE-Flight - c:\program files\flte simulator\preflight\Uninst.isu
AddRemove-Quake III Arena - c:\documents and settings\owner\desktop\nick's crazy friggin' game folder\-quake 3 arena-\QIII.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-29 19:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8ADA2428]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba16cfc3
\Driver\ACPI -> ACPI.sys @ 0xb9f57cb8
\Driver\atapi -> 0x8ada2428
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xb9dbfbc3
PacketIndicateHandler -> NDIS.sys @ 0xb9dcbb21
SendHandler -> NDIS.sys @ 0xb9dbfd33
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3147262485-678377544-2497640554-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-3147262485-678377544-2497640554-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a7,ee,7a,02,ee,0b,05,ed,f7,86,ea,84,f9,f9,a8,5f,61,86,d1,2a,ad,88,5c,
53,86,92,35,5c,f4,c3,01,9a,1a,7f,ec,e1,14,01,10,ae,15,d0,94,0c,b8,3d,ba,aa,\
"??"=hex:e2,06,90,c3,a9,ab,f7,ca,1c,f7,63,d7,3e,f2,89,5d

[HKEY_USERS\S-1-5-21-3147262485-678377544-2497640554-1003\Software\SecuROM\License information*]
"datasecu"=hex:1d,9a,e3,63,ed,14,d3,4e,f3,ee,a1,48,4d,6c,45,dc,a5,a9,b0,bb,be,
57,33,5c,85,8d,fd,96,dd,66,65,ec,17,03,89,b2,20,3d,0c,87,a0,d7,ae,fb,eb,c8,\
"rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49

[HKEY_LOCAL_MACHINE\software\Classes\.application\bootstrap]
@DACL=(02 0000)
@="bootstrap.application.1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\run\OptionalComponents\MAPI]
@DACL=(02 0000)
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(824)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\progra~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll

- - - - - - - > 'explorer.exe'(2168)
c:\game folder\-Steam-\Tortoise SVN\bin\tortoisesvn.dll
c:\game folder\-Steam-\Tortoise SVN\bin\intl3_svn.dll
c:\documents and settings\Owner\Application Data\Dropbox\bin\DropboxExt.3.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Stardock\Object Desktop\WindowBlinds\tray.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\game folder\-Steam-\Tortoise SVN\bin\TSVNCache.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDMedia.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDClock.exe
.
**************************************************************************
.
Completion time: 2010-01-29 19:35:27 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-30 03:35

Pre-Run: 11,658,502,144 bytes free
Post-Run: 11,972,337,664 bytes free

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - E0EB8428AA36EE0DC8631ED434D3FC4F

DDS:


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:38:56.18 on Fri 01/29/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2558.1891 [GMT -8:00]

AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Panda Internet Security 2008 *On-access scanning disabled* (Outdated) {4570FB70-5C9E-47E9-B16C-A3A6A06C4BF0}
FW: Panda Internet Security 2008 *disabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\Game Folder\-Steam-\Tortoise SVN\bin\TSVNCache.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Logitech\GamePanel Software\LCD Manager\lcdmon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\game folder\-steam-\steam.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
C:\Program Files\Hamachi\hamachi.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.naver.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.3.7.16.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google;: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [Steam] "c:\game folder\-steam-\steam.exe" -silent
uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [imekrmig] l:\ime\imkr\imekrmig.exe
mRun: [Launch LgDeviceAgent] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\hamachi.lnk - c:\program files\hamachi\hamachi.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\LOGITE~1.LNK -
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\run_startmenu.cmd
IE: &D;&ownload; &with; BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: &Google; Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate; English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.3.7.16.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: buy-internet-security10.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download25.com
Trusted Zone: buy-internet-security10.com
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} - hxxps://www.e-games.com.my/com/EGamesPlugin.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://spaces.msn.com//PhotoUpload/MsnPUpld.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263605422203
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1224466539359
DPF: {6F750200-1362-4815-A476-88533DE61D0C} - hxxp://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/ultrashim.cab
DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - hxxp://acs.pandasoftware.com/activescan/as5free/asinst.cab
DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} - hxxps://members.hangame.com/common/HanSetup1020.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: WBSrv - c:\progra~1\stardock\object~1\window~1\wbsrv.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\2030lu65.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.madnesscombat.net/
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\2030lu65.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension.dll
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-3-9 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-9 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-3-9 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-9 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-9 297752]
R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-9-16 1174664]
R3 JRSUKD25;JRSUKD25;c:\windows\system32\JRSUKD25.SYS [2009-7-2 12600]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [2006-8-28 10664]
S3 JRSKD24;JRSKD24;c:\windows\system32\JRSKD24.SYS [2009-7-2 34744]
S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\drivers\libusb0.sys [2010-1-11 29184]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 oflpydin;oflpydin;\??\c:\docume~1\owner\locals~1\temp\oflpydin.sys –> c:\docume~1\owner\locals~1\temp\oflpydin.sys [?]
S3 PciCon;PciCon;\??\e:\pcicon.sys –> e:\PciCon.sys [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\screamingbaudio.sys –> c:\windows\system32\drivers\ScreamingBAudio.sys [?]
S3 uisp;Motorola USB ICP driver;c:\windows\system32\drivers\usbicp.sys –> c:\windows\system32\drivers\usbicp.sys [?]

=============== Created Last 30 ================

2010-01-29 18:47 261,632 a——- c:\windows\PEV.exe
2010-01-29 18:47 77,312 a——- c:\windows\MBR.exe
2010-01-29 18:47 161,792 a——- c:\windows\SWREG.exe
2010-01-29 18:47 98,816 a——- c:\windows\sed.exe
2010-01-29 14:03 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2010-01-29 14:03 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-29 14:03 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-01-29 14:03 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-29 14:03 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-14 17:52 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-14 17:52 –d—– c:\program files\SUPERAntiSpyware
2010-01-11 07:59 –d—– c:\program files\Sony
2010-01-11 03:11 43,520 a——- c:\windows\system32\libusb0.dll
2010-01-11 03:11 29,184 a——- c:\windows\system32\drivers\libusb0.sys
2010-01-06 05:30 –d—– c:\program files\DAEMON Tools Lite
2010-01-01 01:55 515,416 a——- c:\windows\system32\XAudio2_5.dll
2010-01-01 01:55 1,974,616 a——- c:\windows\system32\D3DCompiler_42.dll
2010-01-01 01:55 1,892,184 a——- c:\windows\system32\D3DX9_42.dll

==================== Find3M ====================

2010-01-18 06:14 5,632 a–sh— c:\program files\Thumbs.db
2010-01-06 05:31 691,696 a——- c:\windows\system32\drivers\sptd.sys
2009-11-07 14:25 86,016 a——- c:\windows\system32\frapsvid.dll
2009-03-18 21:18 22,328 a——- c:\docume~1\owner\applic~1\PnkBstrK.sys
2008-06-03 04:44 71,304 ac—— c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT
2006-11-12 01:39 1 ac—— c:\documents and settings\owner\SI.bin
2005-08-16 10:58 936 ac—— c:\docume~1\owner\applic~1\wklnhst.dat

============= FINISH: 19:39:19.93 ===============

DDS Attach.txt:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 8/1/2005 8:24:02 AM
System Uptime: 1/29/2010 7:16:58 PM (0 hours ago)

Motherboard: | | MS-7093
Processor: AMD Athlon™ 64 Processor 4000+ | Socket 939 | 2387/199mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 183 GiB total, 11.186 GiB free.
D: is FIXED (FAT32) - 4 GiB total, 1.352 GiB free.
E: is CDROM (UDF)
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is CDROM ()
L: is FIXED (NTFS) - 466 GiB total, 379.105 GiB free.
O: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: PlayLinc Adapter
Device ID: ROOT\NET\0000
Manufacturer: Super Computer Inc.
Name: PlayLinc Adapter
PNP Device ID: ROOT\NET\0000
Service: hamachi_oem

==== System Restore Points ===================

RP1009: 1/6/2010 5:31:09 AM - SPTD setup V1.62
RP1010: 1/8/2010 9:26:44 PM - System Checkpoint
RP1011: 1/9/2010 9:34:58 PM - System Checkpoint
RP1012: 1/10/2010 10:56:33 PM - System Checkpoint
RP1013: 1/11/2010 3:18:16 AM - Unsigned driver install
RP1014: 1/11/2010 7:39:39 AM - Removed Microsoft Visual C++ 2005 Redistributable
RP1015: 1/11/2010 7:40:17 AM - Installed Microsoft Visual C++ 2005 Redistributable
RP1016: 1/11/2010 7:41:28 AM - Installed Vegas Pro 9.0
RP1017: 1/11/2010 7:57:49 AM - Removed Vegas Pro 9.0
RP1018: 1/11/2010 7:59:35 AM - Installed Vegas Pro 9.0
RP1019: 1/13/2010 6:45:25 PM - System Checkpoint
RP1020: 1/14/2010 5:52:15 PM - Installed SUPERAntiSpyware Free Edition
RP1021: 1/15/2010 9:10:39 PM - System Checkpoint
RP1022: 1/18/2010 12:37:14 AM - System Checkpoint
RP1023: 1/18/2010 4:42:44 PM - Avg8 Update
RP1024: 1/19/2010 8:46:32 PM - System Checkpoint
RP1025: 1/21/2010 10:27:36 PM - System Checkpoint
RP1026: 1/23/2010 7:11:53 PM - System Checkpoint
RP1027: 1/26/2010 8:55:19 AM - System Checkpoint
RP1028: 1/29/2010 11:44:06 AM - System Checkpoint
RP1029: 1/29/2010 2:01:19 PM - Automatic Restore Point

==== Installed Programs ======================


??? ?? ????
ÇѰÔÀÓ º¸¾ÈÆÐÄ¡
7-Zip 4.42
ABBYY FineReader 5.0 Sprint
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.0
Adobe Shockwave Player
AIM 6.0
AOL Instant Messenger
Apple Software Update
Audiosurf
Autodesk DirectConnect 2.0
AV Voice Changer Software DIAMOND 6.0
AVG 8.5
Battlefield 2™
Battlefield 2142
BitComet 1.16
Borderlands
Bullet Candy
Call of Duty® 4 - Modern Warfare™ 1.2 Patch
Call of Duty® 4 - Modern Warfare™ 1.3 Patch
Call of Duty® 4 - Modern Warfare™ 1.4 Patch
Call of Duty® 4 - Modern Warfare™ 1.5 Multiplayer Patch
Call of Duty® 4 - Modern Warfare™ 1.6 Patch
Call of Duty® 4 - Modern Warfare™ 1.7 Patch
CCleaner (remove only)
ClientKeeper KeyPro with E2E for 32bit
Crazy Machines II
CuteFTP 8 Home
Data Lifeguard Tools
Dawn of War - Dark Crusade
Dawn of War - Soulstorm
Dawn Of War - Winter Assault
DawnOfWar
dBpowerAMP Music Converter
Defence Alliance 2
DesertCombat 0.7
Digital Media Reader
DivX Content Uploader
DivX Web Player
Doom 3
Dropbox
DVD-CLONER V3.00 Build 880
DVD Shrink 3.2
DVDFab Decrypter 2.9.3.2
Dystopia
EA Download Manager
End It All
Enemy Territory - QUAKE Wars™ 1.1 Patch
ERUNT 1.1j
Far Cry (Patch 1.3)
FaxTools
FEAR
FMS
Fraps (remove only)
FrostWire 4.18.1
GameSpy Arcade
GCFScape 1.7.4
GoldWave v5.23
Google Chrome
Google Toolbar for Internet Explorer
Google Video Player
Groove Games\Land Of The Dead
Half-Life
Half-Life® 2
Hamachi 1.0.3.0
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
ŒŽ–¾‚è‚̃‰ƒYƒxƒŠƒB `‚‚ñšƒf‚ê‡U`1.00
IGN Download Manager 2.2.2
IrfanView (remove only)
JAM's Jedi Knight KT v2.0
Java™ 6 Update 11
Java™ 6 Update 4
Java™ 6 Update 5
Java™ 6 Update 7
K-Lite Codec Pack 2.65 Full
Kaspersky Online Scanner
Killing Floor SDK
KODAK EASYSHARE Gallery Upload ActiveX Control
Left 4 Dead
Left 4 Dead 2
Left 4 Dead 2 Add-on Support
Left 4 Dead 2 Authoring Tools
Lexmark Skin: Helix
Lexmark Skin: Nature TV2
Lexmark X1100 Series
Logitech GamePanel Software 3.02.173
Logitech SetPoint
Macromedia Extension Manager
Macromedia Flash 8 Video Encoder
Malwarebytes' Anti-Malware
MapleStory
Maya 8.5 Documentation (en_US)
MediaCoder 0.6.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Global IME for Office XP (Korean)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2005
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Windows Journal Viewer
Microsoft WSE 3.0 Runtime
Microsoft® Winter Fun Pack 2004 for Windows® XP
Mirror's Edge™
Monster Hunter Frontier Online
Mozilla Firefox (3.5.7)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB925673)
Multimedia Keyboard Driver
Musicmatch® Jukebox
Natural Selection 3.2
Nero BurnRights
Nero OEM
NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)
Notepad++
NVIDIA Drivers
NVIDIA PhysX
Oblivion - Knights of the Nine
Oblivion - Orrery
Oblivion - Spell Tomes
Oblivion - Wizard's Tower
OpenAL
Paint Express 1.30
Paint.NET v3.36
Pando Media Booster
PlayLinc
PowerDVD
PowerISO
Psychonauts
PunkBuster Services
QuickTime
RealFlight G2 Simulator
RealFlight Simulator
RealPlayer Basic
Realtek AC'97 Audio
RealWorld Cursor Editor
RegCure 1.6.0.0
S.T.A.L.K.E.R.: Shadow of Chernobyl
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Sentinel System Driver
Serious Sam HD: The First Encounter
SierraHome Print Artist 12.0
SoftV92 Data Fax Modem with SmartCP
Source SDK Base - Orange Box
SpeechRedist
SPORE™
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
Star Wars Battlefront II
Steam™
STOPzilla!
SUPERAntiSpyware Free Edition
Sven Co-op 4.0B
System Requirements Lab
The Lord of the Rings - Conquest™
The Sims™ 3
Tom Clancy's Rainbow Six Vegas 2
TortoiseSVN 1.4.7.11792 (32 bit)
TurboTax Deluxe 2005
TurboTax ItsDeductible 2005
Uniblue Registry Booster
Uniblue SpeedUpMyPC
Uniblue System Tweaker
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB953356)
Vegas Pro 9.0
Ventrilo Client
Ventrilo Server
Viewpoint Media Player
VLC media player 0.9.9
VTFEdit 1.2.5
WebFldrs XP
WexTech AnswerWorks
Winamp
WinDirStat 1.1.2
WindowBlinds
Windows Backup Utility
Windows Communication Foundation
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
WinRAR archiver
World of Warcraft
XML Paper Specification Shared Components Pack 1.0
XYZ RGB Texture Package
Yahoo! Toolbar
Zombie Shooter 2 v 1.0

==== Event Viewer Messages From Past Week ========

1/29/2010 6:47:48 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p asc3550 cbidf cd20xrnt CmdIde Cpqarray dac2w2k dac960nt dpti2o hpn i2omp ini910u IntelIde mraid35x perc2 perc2hib ql1080 Ql10wnt ql12160 ql1240 ql1280 sisagp Sparrow symc810 symc8xx sym_hi sym_u3 szkg TosIde ultra viaagp ViaIde
1/28/2010 1:27:16 PM, error: Service Control Manager [7000] - The Microsoft Kernel Acoustic Echo Canceller service failed to start due to the following error: Access is denied.
1/28/2010 1:27:15 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: szkg
1/28/2010 1:27:15 PM, error: Service Control Manager [7000] - The DS1410D service failed to start due to the following error: The system cannot find the file specified.
1/27/2010 6:35:57 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
1/27/2010 6:35:57 AM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/25/2010 4:16:33 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

==== End Of File ===========================

Other than that, everything seems to be as it was, other than some webpages not showing all images for some reason, as well as videos on sites like youtube not loading. I did see something removed that said macromedia/flash on it, do I need to re-download flash player?

NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)

This forum doesn't support software piracy and this entry in your Add/Remove Programs list is evidence that you do. I suggest that you uninstall it and avoid such things in future as they will bar you from receiving assistance here.

We'll address the Windows Updates issue a little later after an MBAM scan. Please update it and then run a full scan and let me have the log that it produces. Allow it to fix whatever it finds and reboot the PC if necessary first.

You can uninstall and reinstall Flash and see if that solves this particular issue and let me know how you get on.

NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)

This forum doesn't support software piracy and this entry in your Add/Remove Programs list is evidence that you do. I suggest that you uninstall it and avoid such things in future as they will bar you from receiving assistance here.

We'll address the Windows Updates issue a little later after an MBAM scan. Please update it and then run a full scan and let me have the log that it produces. Allow it to fix whatever it finds and reboot the PC if necessary first.

You can uninstall and reinstall Flash and see if that solves this particular issue and let me know how you get on.


Hm, I don't recall having that, but I don't use NOD32 anyway so I will remove it. This is a shared computer so it's possible somebody else may have downloaded it.

About 40 minutes into the scan MBAM found 4 things, while simultaneously AVG found 5, all in System Volume Information. I tried repairing the files through AVG but nothing seemed to work so I allowed MBAM to delete the files and restart.

Here's the MBAM log:


Malwarebytes' Anti-Malware 1.44
Database version: 3663
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11

1/30/2010 2:54:35 PM
mbam-log-2010-01-30 (14-54-35).txt

Scan type: Full Scan (C:\|D:\|L:\|)
Objects scanned: 422455
Time elapsed: 2 hour(s), 23 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1029\A0550082.dll (Adware.BHO.AR) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1029\A0550106.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1029\A0550108.dll (Trojan.Chksyn) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1029\A0550311.sys (Malware.Trace) -> Quarantined and deleted successfully.

Also reinstalling flash did solve the images and video problem.

Update: Another AVG alert.

C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1029\A0550083.exe

Trojan horse Crypt.NRZ

Process name: C:\WINDOWS\system32\svchost.exe
Process ID: 1244

I clicked Heal.

Update 2: Yet another AVG alert.

C:\System Volume Information\ … A0550085.exe

Trojan horse SHeur2.CISG

Same process name and ID.

Is this spreading somehow? Combofix and MBAM obviously missed something.

Update 3: Same thing;

C:\System Volume Information\ … A0550086.exe

Trojan horse SHeur2.CISG

The only difference with these is the last number in the filename….
You can ignore any detections in C:\System Volume Information - these are files held within restore points made by System restore and pose no direct threat to your PC. We'll address these a little later too.

Download RootRepeal from one of the locations below and save it to your Desktop:
Location 1
Location 2
Location 3
  • Double click RootRepeal.exe to fire up the tool and OK any Windows confirmation if necessary.
  • Ensure that the Report Tab is selected at the bottom.
  • Click the Scan button, check ALL the boxes in the window that appears and then click OK.
  • Check the box next to your main hard drive - usually C: and click OK
  • Put the kettle on and perhaps open a packet of biscuits - the scan will take some time.
  • Once the scan has completed a Notepad window will open with the results in.
  • These results will also be saved to the root of your main drive as \RootRepeal report date time.txt
Let me have a copy of the contents in your next reply.
We'll try something else then.

Go here and click the Download EXE button at the top and save the file to your Desktop - the file is randomly named to try to sidestep the actions of certain malicious files.
Double click the file to begin:
  • If you get a pop-up regarding rootkit activity and are asked if you want to scan, click No, and then Save… the log with any name to a handy location - the Desktop is always a good choice.
    If you don't get the warning about rootkit activity you don't need to save the log.
  • Make sure all the boxes on the right of the screen are checked, EXCEPT for
    • Sections
    • IAT/EAT
    • Show All
    • All drives except your main one, which is usually C:\.
  • Click the Scan button on the right.
  • When the scan has completed, (you'll have time for a snack and a cuppa!), click the Save… button and again save the log with any name to a handy location.
Post the contents of the log(s) into your next reply. The Preview option on the forum may show the whole log(s) being posted, but they sometimes get cut down when the actual post is made, so please check the post once it is completed.
GMER would not run correctly, just like when I made my initial post:

GMER would not run correctly, it would open, automatically scan several things, then "encounter an error" and crash.


GMER doesn't give me any popup, I can't do anything while it starts up, file paths flash by in the bottom of the window, and then it crashes. I've randomly renamed it and run it several times, but to no avail.

I'm a little worried here.
Another interesting development just occurred;

I was going to do a little bit of work in Goldwave, a sound editor, and to do so I have to turn off WindowBlinds, an external Windows Theme program. Some stupid little error prevents Goldwave from working with WindowBlinds on.

So I deactivate WB, and then my windows UI freaks out, it goes completely black and the computer then starts running slow. Task Manager also mysteriously stops working. So I try to restart the machine but I get an infinitely repeating "Ending program… RUNDLL". I bite my lip and hold the power button to turn the computer off, as using normal means would not work. I wait for it to boot back up, only this time it's noticeably slower. When it finally finishes, I get repeated messages about blocking "Windows Logon UI" and "Windows Logon UI has encountered an error and needs to close". I repeatedly press enter to get rid of the messages and after a little while they stop.

Weird?

SAS and MBAM scans came up clean, so I'm not sure what the problem is.
Was this a one-off problem that may just have been your PC's sense of humour, has it happened before, or since? Are there any other issues with the PC apart from this?

Was this a one-off problem that may just have been your PC's sense of humour, has it happened before, or since?
Are there any other issues with the PC apart from this?


I've never had that happen before when working with Windowblinds. Normally it would just close as normal and the default windows theme would appear again, no problems. I'm a little scared to try it again now.

Apart from that, the computer seems to be booting and shutting down considerably slower. I'm not sure what would cause that. I'm not sure if the computer is clean myself, with things like that happening, as well as RootRepeal and GMER not being able to run. Possibly, though, it could be because ComboFix or one of the other scanners may have removed files or processes needed to smoothly operate these things. After all, I was not able to deactivate AVG when I ran ComboFix, and you said yourself problems may occur if it was run with an AV still running.

I'm really hoping I won't have to reformat or anything like that. I doubt I will need to, but the thought is still in the back of my mind. Suggestions?
The problem with your machine is that I don't know what the problem is. It is possible that you have active malware onboard, or you may not. Your machine may also be suffering from the after effects of the infections already removed, or it may not. Both RR and GMER may be crashing because something is actively blocking them, or they may just not like your machine for some reason. I can't see anything nasty in your logs that I can identify as such, but that doesn't mean it isn't there, or that it is. You get the picture! I've spent an hour trying to see what may not be there anyway and i'm no further forward in offering any useful suggestion, so that's it for tonight. If tomorrow brings nothing better i'll ask around for second and third opinions, but you may just find that reformatting is the only option available to you to guarantee a clean and workable machine, i'm afraid. Sadly the people who code the malware are smarter than I am, but on the plus side I don't charge for this information! :smack:
Well it's still nice to have a second opinion from a knowledgeable individual such as yourself. This machine is pretty dated and I never really did any upkeep on it as far as cleaning out old junk in the hard drives went. It's been due for a reformat and fresh windows install for a long time, but I absolutely loathe doing all of the necessary steps for that. Still, it's probably for the best. I'll see what I can do about backing up all of the important things like music, pictures, and the like. I've also been contemplating upgrading to Windows 7, but I've heard there are still some compatibility issues with some programs, yet at the same time it's more stable and easier on system memory. Anyway, thanks for your time and patience. Look forward to hearing back tomorrow.
Try this and see if it gets GMER to run:

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Once you have rebooted, try the GMER instructions again - your CD emulator has been known to interfere with GMER and this may be the solution, or not! ;)
Simply run DeFogger again and re-enable to put things back how they were.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI