This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Ave.exe part 2

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

sorry for taking so long to respond, here's the new combofix log. It was running while the internet was on and didn't ask to update or anything. ComboFix 10-03-16.03 - Owner 0/2010 Sat 14:20:17.3.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.932.81.1033.18.2046.1553 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: Trend Micro Internet Security *On-access scanning enabled* (Outdated) {7D2296BC-32CC-4519-917E-52E652474AF5} FW: Trend Micro Personal Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6} . ((((((((((((((((((((((((( Files Created from 2010-02-20 to 2010-03-20 ))))))))))))))))))))))))))))))) . 2010-03-16 01:38 . 2010-03-16 01:38 ——– d—–w- c:\windows\system32\wbem\Repository 2010-03-11 04:48 . 2010-03-11 04:48 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\PunkBuster 2010-03-11 04:47 . 2010-03-20 05:58 139128 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys 2010-03-11 04:47 . 2010-03-11 04:47 138056 —-a-w- c:\documents and settings\Owner\Application Data\PnkBstrK.sys 2010-03-11 04:47 . 2010-03-20 06:29 215128 —-a-w- c:\windows\system32\PnkBstrB.exe 2010-03-11 04:47 . 2010-03-11 04:47 75064 —-a-w- c:\windows\system32\PnkBstrA.exe 2010-03-11 04:47 . 2010-03-11 04:47 2434856 —-a-w- c:\windows\system32\pbsvc_bc2.exe 2010-03-05 09:19 . 2010-03-05 09:19 ——– d—–w- c:\documents and settings\Owner\Application Data\Octoshape 2010-02-24 05:50 . 2010-02-24 05:50 ——– d—–w- c:\program files\dumps . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-20 18:31 . 2008-12-13 23:55 ——– d—–w- c:\program files\cFosSpeed 2010-03-20 18:10 . 2008-12-13 21:06 ——– d—–w- c:\program files\Steam 2010-03-17 19:36 . 2008-12-19 06:22 664 —-a-w- c:\windows\system32\d3d9caps.dat 2010-03-16 19:00 . 2009-02-23 02:38 ——– d—–w- c:\documents and settings\Owner\Application Data\uTorrent 2010-03-10 18:36 . 2009-11-11 02:26 79488 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-03-10 05:47 . 2009-07-09 02:32 ——– d—–w- c:\documents and settings\Owner\Application Data\Ubisoft 2010-03-09 19:13 . 2008-12-20 00:05 1 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2010-03-07 09:57 . 2009-04-24 05:36 954272 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2010-03-07 04:37 . 2009-03-01 22:03 ——– d—–w- c:\documents and settings\Owner\Application Data\Skype 2010-03-07 04:36 . 2009-03-01 22:51 ——– d—–w- c:\documents and settings\Owner\Application Data\skypePM 2010-03-05 01:49 . 2008-12-09 23:36 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-03-02 01:01 . 2008-12-13 20:45 ——– d—–w- c:\program files\PowerArchiver 2010-02-26 08:46 . 2009-10-10 00:46 ——– d—–w- c:\program files\Heroes of Newerth 2010-02-22 02:38 . 2009-12-06 07:13 ——– d—–w- c:\program files\Emerald Viewer 2010-02-13 10:53 . 2008-12-14 22:11 ——– d—–w- c:\documents and settings\Owner\Application Data\mIRC 2010-02-13 10:01 . 2008-12-14 22:11 ——– d—–w- c:\program files\mIRC 2010-02-13 01:40 . 2010-02-13 01:40 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE 2010-02-13 01:20 . 2010-02-13 01:20 ——– d—–w- c:\program files\2K Games 2010-02-13 00:45 . 2010-02-12 20:12 ——– d—–w- c:\documents and settings\Owner\Application Data\Bioshock2 2010-02-12 08:59 . 2010-02-12 08:59 ——– d-sh–w- c:\documents and settings\All Users\Application Data\SecuROM 2010-02-08 04:38 . 2010-02-08 04:38 117427 —-a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\digitaleditions\digitaleditions.exe 2010-02-07 05:05 . 2010-02-07 05:05 ——– d—–w- c:\program files\Stardock 2010-01-27 18:31 . 2010-01-24 05:46 ——– d—–w- c:\program files\Mass Effect 2 2010-01-24 06:33 . 2008-12-28 07:31 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard 2010-01-24 06:33 . 2009-06-12 01:06 ——– d—–w- c:\program files\AGEIA Technologies 2010-01-24 06:33 . 2008-12-09 23:46 ——– d—–w- c:\program files\NVIDIA Corporation 2010-01-24 06:30 . 2009-11-03 23:49 ——– d—–w- c:\program files\Common Files\BioWare 2010-01-20 05:39 . 2009-07-23 18:13 ——– d—–w- c:\program files\Microsoft Silverlight 2010-01-12 21:47 . 2010-01-12 21:47 103784 —-a-w- c:\documents and settings\Owner\GoToAssistDownloadHelper.exe 2010-01-08 18:37 . 2008-12-15 18:00 31352 —-a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-01-05 10:00 . 2008-04-14 12:00 832512 ——w- c:\windows\system32\wininet.dll 2010-01-05 10:00 . 2008-04-14 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll 2010-01-05 10:00 . 2008-04-14 12:00 17408 —-a-w- c:\windows\system32\corpol.dll 2009-12-31 16:50 . 2008-04-14 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys 2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll 2008-12-13 20:11 . 2008-12-13 20:11 75 –sh–r- c:\windows\ICMET20.BIN . ——- Sigcheck ——- [7] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\sfcfiles.dll c:\windows\System32\sfcfiles.dll … is missing !! . ((((((((((((((((((((((((((((( SnapShot@2010-03-17_02.13.42 ))))))))))))))))))))))))))))))))))))))))) . + 2010-03-20 18:19 . 2010-03-20 18:19 16384 c:\windows\Temp\Perflib_Perfdata_300.dat + 2009-07-01 23:19 . 2010-03-17 03:46 316785 c:\windows\system32\drivers\etc\tmvsthfud.bin - 2009-07-01 23:19 . 2009-07-23 22:30 316785 c:\windows\system32\drivers\etc\tmvsthfud.bin + 2009-07-01 23:19 . 2010-03-17 03:45 316785 c:\windows\system32\drivers\etc\tmvsthfss.bin - 2009-07-01 23:19 . 2009-07-23 22:29 316785 c:\windows\system32\drivers\etc\tmvsthfss.bin + 2009-01-01 09:45 . 2009-01-01 09:45 3317760 c:\windows\system32\config\systemprofile\ntuser.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files\steam\steam.exe" [2010-02-24 1217872] "DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "cFosSpeed"="c:\program files\cFosSpeed\cFosSpeed.exe" [2007-07-10 838608] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952] "IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2008-04-14 44032] "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168] "Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2007-09-06 1426432] "CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2007-09-07 626688] "Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-09-11 880640] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-30 61440] "LELA"="c:\program files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" [2008-05-01 131072] "nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-04-09 648504] "lxdxmon.exe"="c:\program files\Lexmark 3600-4600 Series\lxdxmon.exe" [2008-03-20 668328] "EzPrint"="c:\program files\Lexmark 3600-4600 Series\ezprint.exe" [2008-03-20 107176] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696] "VX3000"="c:\windows\vVX3000.exe" [2008-08-05 721936] "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-05 160800] "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-01-31 1398024] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-12-23 113664] Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696] forteManager.lnk - c:\program files\LG Soft India\forteManager\bin\Monitor.exe [2008-12-14 1126400] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Steam\\steamapps\\darkanarchy\\team fortress 2\\hl2.exe"= "c:\\Program Files\\mIRC\\mirc.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\WINDOWS\\system32\\lxdxcoms.exe"= "c:\\WINDOWS\\system32\\lxdxcfg.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxpswx.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxtime.exe"= "c:\\Program Files\\Lexmark 3600-4600 Series\\lxdxmon.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxjswx.exe"= "c:\\Program Files\\Lexmark 3600-4600 Series\\Wireless\\lxdxwpss.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\Steam\\Steam.exe"= "c:\\Documents and Settings\\Owner\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"= "c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"= "c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"= "c:\\Program Files\\Lexmark 3600-4600 Series\\lxdxlscn.exe"= "c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"= "c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"= "c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\SecondLife\\SLVoice.exe"= "c:\\Program Files\\Emerald Viewer\\SLVoice.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Steam\\steamapps\\darkanarchy\\counter-strike\\hl.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\audiosurf\\engine\\QuestViewer.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\street fighter iv\\SF4Launcher.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\grand theft auto iv\\RGSC\\RGSCLauncher.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\osmos\\osmos.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Steam\\steamapps\\common\\battlefield bad company 2\\BFBC2Game.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "67:UDP"= 67:UDP:DHCP Discovery Service R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service –> c:\windows\system32\lxdxcoms.exe -service [?] R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [7/1/2009 10:40 PM 52624] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2/15/2008 11:39 PM 36368] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/28/2008 3:19 AM 24652] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2/15/2008 11:39 PM 333328] R3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [7/1/2009 10:41 PM 488768] R3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [7/1/2009 10:41 PM 648456] S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/14/2008 6:22 AM 685816] S2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [4/18/2008 5:30 AM 204800] S2 lxdxCATSCustConnectService;lxdxCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdxserv.exe [12/19/2008 10:31 PM 98984] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [11/3/2009 8:00 PM 25832] S3 LGDDCDevice;LGDDCDevice;c:\program files\LG Soft India\forteManager\bin\I2CDriver.sys [12/14/2008 5:59 AM 14336] S3 LGII2CDevice;LGII2CDevice;c:\program files\LG Soft India\forteManager\bin\PII2CDriver.sys [12/14/2008 5:59 AM 13312] . . ——- Supplementary Scan ——- . IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\43vh8bpq.default\ FF - prefs.js: browser.startup.homepage - optimum.net FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;= FF - plugin: c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071505000010.dll FF - plugin: c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071505000011.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-1644491937-1965331169-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "?慴"=hex:ae,e2,c2,f2,e3,5f,8e,44,b4,1c,d3,8b,0f,dc,ee,73,70,b7,8a,df,05,65,a6, ce,ae,36,d6,a3,a6,1c,84,e3,35,c7,9c,6b,7a,3e,0d,03,ab,96,08,f4,d3,33,62,33,\ "?祥"=hex:d2,dd,c2,f0,01,71,ed,00,5f,ec,f5,bb,f9,fe,5e,e2 [HKEY_USERS\S-1-5-21-1644491937-1965331169-682003330-1003\Software\SecuROM\License information*] "datasecu"=hex:8b,61,b2,62,d6,6f,31,a4,f8,6a,84,28,4f,f4,81,e6,9b,f0,f7,3b,d3, ca,40,7a,93,45,4d,5d,71,09,9c,24,78,4f,24,8d,34,1d,f5,57,f3,52,e5,b7,f3,c0,\ "rkeysecu"=hex:a9,79,04,9f,8b,41,9d,3a,c1,c2,f0,06,51,7b,c9,ad . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(1296) c:\windows\system32\Ati2evxx.dll . Completion time: 2010-03-20 14:32:36 ComboFix-quarantined-files.txt 2010-03-20 18:32 ComboFix2.txt 2010-03-17 02:54 ComboFix3.txt 2010-03-17 02:15 Pre-Run: 165,626,707,968 bytes free Post-Run: 166,577,266,688 bytes free - - End Of File - - 1DF1948951F8554D3A1FB472A63DA87C
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    If you used DeFogger
    You must remember to re-enable your Emulation drivers once we are finished, double click DeFogger to run the tool.

    • The application window will appear
    • Click the Re-enable button to re-enable your CD Emulation drivers
    • Click Yes to continue
    • A 'Finished!' message will appear
    • Click OK
    • DeFogger will now ask to reboot the machine - click OK
    IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

    Your Emulation drivers are now re-enabled.


    To be on the safe side, I would also change all my passwords.



    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:
I'm having a problem, my emulation drivers is not working after I uninstalled Combofix. your post says to use DeFogger but you never told me to download it. Should I download and run it to re enable my emulation drivers? here is an attachment of the problem I am getting when I boot up.

Attachments:

I never had you run defogger to disable.

download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Please download [url=http://www.jpshortstuff.247fixes.com/Defogger.exe][color=blue][b]DeFogger[/b][/color][/url] to your [b]desktop[/b].

Double click [b]DeFogger[/b] to run the tool.
[list][*] The application window will appear[*] Click the [b]Disable[/b] button to disable your CD Emulation drivers[*] Click [b]Yes[/b] to continue[*] A [b]'Finished!'[/b] message will appear[*] Click [b]OK[/b][*] DeFogger will now ask to reboot the machine - click [b]OK[/b][/list]
[b][color=red]IMPORTANT![/color][/b] If you receive an error message while running DeFogger, please post the log [b]defogger_disable[/b] which will appear on your desktop.

[b]Do not[/b] re-enable these drivers until otherwise instructed.


To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

To re-enable your Emulation drivers, double click [b]DeFogger[/b] to run the tool.
[list][*] The application window will appear[*] Click the [b]Re-enable[/b] button to re-enable your CD Emulation drivers[*] Click [b]Yes[/b] to continue[*] A [b]'Finished!'[/b] message will appear[*] Click [b]OK[/b][*] DeFogger will now ask to reboot the machine - click [b]OK[/b][/list]
[b][color=red]IMPORTANT![/color][/b] If you receive an error message while running DeFogger, please post the log [b]defogger_enable[/b] which will appear on your desktop.

Your Emulation drivers are now re-enabled.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI