This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected w/Trojan, Browser Highjacked

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I didn't get any email notification for your last 2 replies.. Got the last when I reloaded the page.

Yes, email notifications are messed up for some reason

That's why I hadn't noticed you had replied. Sorry about that. I don't want to waste your time. Waiting for CF to finish.

I just keep hitting IE refresh :thumbup:
The Notepad box opened on its own this time. Here's the log:

ComboFix 10-07-10.01 - R40 07/10/2010 14:49:25.2.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((( Files Created from 2010-06-10 to 2010-07-10 )))))))))))))))))))))))))))))))
.

2010-07-10 20:48 . 2009-08-07 02:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-07-10 20:48 . 2009-08-07 02:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-07-10 20:48 . 2010-07-10 20:48 ——– d—–w- c:\windows\LastGood
2010-07-09 19:47 . 2010-07-09 19:47 ——– d—–w- c:\program files\Microsoft Silverlight
2010-07-09 18:57 . 2010-07-09 18:57 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-07-09 18:57 . 2010-07-09 18:57 ——– d—–w- c:\program files\IObit
2010-07-09 18:06 . 2010-07-09 18:06 ——– d—–w- c:\documents and settings\R40\Application Data\Malwarebytes
2010-07-09 18:05 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-09 18:05 . 2010-07-09 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-09 18:05 . 2010-07-10 18:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-09 18:05 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-09 17:54 . 2010-07-09 17:54 ——– d—–w- c:\program files\CCleaner
2010-07-08 04:32 . 2010-07-08 04:32 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-07-07 21:28 . 2010-07-07 21:28 ——– d—–w- c:\program files\iPod
2010-07-07 21:27 . 2010-07-07 21:31 ——– d—–w- c:\program files\iTunes
2010-07-07 21:27 . 2010-07-07 21:31 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-07 21:20 . 2010-07-07 21:22 ——– d—–w- c:\program files\QuickTime
2010-07-07 21:12 . 2010-07-07 21:12 ——– d—–w- c:\program files\Bonjour
2010-07-07 21:09 . 2010-07-07 21:10 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\jcrcingip
2010-07-07 20:53 . 2010-07-07 20:53 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-07 20:49 . 2010-07-07 20:49 72504 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-07-04 16:49 . 2010-07-04 16:49 ——– d—–w- C:\spoolerlogs
2010-07-02 15:32 . 2010-07-02 15:32 ——– d–h–r- c:\documents and settings\R40\Application Data\SecuROM
2010-07-02 15:31 . 2010-07-02 15:31 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-07-01 22:57 . 2010-07-08 01:04 ——– d—–w- c:\program files\EA GAMES
2010-07-01 22:57 . 2007-04-04 22:39 442368 —-a-r- c:\windows\system32\vp6vfw.dll
2010-06-27 18:52 . 2010-06-27 18:52 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\HighAndes
2010-06-27 18:52 . 2010-06-27 18:52 ——– d—–w- c:\documents and settings\Guest\Application Data\HighAndes
2010-06-27 18:33 . 2010-06-27 22:29 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\WMTools Downloaded Files
2010-06-13 21:38 . 2010-06-13 21:38 503808 —-a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcp71.dll
2010-06-13 21:38 . 2010-06-13 21:38 12800 —-a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-d3d.dll
2010-06-13 21:38 . 2010-06-13 21:38 499712 —-a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\jmc.dll
2010-06-13 21:38 . 2010-06-13 21:38 61440 —-a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-sse.dll
2010-06-13 21:38 . 2010-06-13 21:38 348160 —-a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcr71.dll
2010-06-13 14:36 . 2010-06-13 14:36 ——– d—–w- c:\program files\Java
2010-06-13 14:20 . 2010-06-13 14:20 ——– d—–w- c:\program files\Common Files\Java
2010-06-13 14:11 . 2010-06-13 14:11 503808 —-a-w- c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcp71.dll
2010-06-13 14:11 . 2010-06-13 14:11 12800 —-a-w- c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-d3d.dll
2010-06-13 14:11 . 2010-06-13 14:11 499712 —-a-w- c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\jmc.dll
2010-06-13 14:11 . 2010-06-13 14:11 61440 —-a-w- c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-sse.dll
2010-06-13 14:11 . 2010-06-13 14:11 348160 —-a-w- c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcr71.dll
2010-06-13 14:10 . 2010-06-13 14:36 411368 —-a-w- c:\windows\system32\deployJava1.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-10 19:56 . 2008-04-14 12:00 36352 —-a-w- c:\windows\system32\drivers\intelppm.sys
2010-07-10 05:14 . 2010-02-20 19:40 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-09 18:03 . 2010-04-16 03:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-07 21:28 . 2010-01-06 04:20 ——– d—–w- c:\program files\Common Files\Apple
2010-07-02 00:05 . 2009-12-25 17:37 ——– d—–w- c:\documents and settings\R40\Application Data\Unity
2010-07-02 00:05 . 2009-12-25 16:56 ——– d—–w- c:\program files\Unity
2010-06-09 08:06 . 2010-06-09 08:06 976832 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\AdobeARM.exe
2010-06-09 08:06 . 2010-06-09 08:06 70584 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\AdobeExtractFiles.dll
2010-06-09 08:06 . 2010-06-09 08:06 331176 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\ReaderUpdater.exe
2010-06-09 08:06 . 2010-06-09 08:06 331176 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\AcrobatUpdater.exe
2010-06-05 21:35 . 2010-06-05 21:35 ——– d—–w- c:\documents and settings\All Users\Application Data\PlayFirst
2010-06-05 21:34 . 2010-06-05 21:34 ——– d—–w- c:\documents and settings\R40\Application Data\PlayFirst
2010-06-05 21:32 . 2010-06-05 21:32 ——– d—–w- c:\program files\PlayFirst
2010-06-02 03:33 . 2010-06-02 03:33 ——– d—–w- c:\documents and settings\Guest\Application Data\SEGA
2010-05-31 18:17 . 2010-05-31 18:16 ——– d—–w- c:\program files\Canon Creative
2010-05-18 23:35 . 2010-05-18 23:35 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 197920 —-a-w- c:\windows\system32\dnssdX.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-15 17:16 . 2010-04-16 03:53 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-05-06 23:47 . 2010-05-06 23:47 355574 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_4030872FF57CBB7F004FA6.exe
2010-05-06 23:47 . 2010-05-06 23:47 7886 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_6FEFF9B68218417F98F549.exe
2010-05-06 23:47 . 2010-05-06 23:47 7886 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_21F3885A18D238E15AAE81.exe
2010-05-06 23:47 . 2010-05-06 23:47 355574 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_D707CE1C009F1381803C2C.exe
2010-05-06 23:47 . 2010-05-06 23:47 355574 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_27BA116C85EAB83CD5A215.exe
2010-05-06 10:41 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2008-04-14 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2008-04-14 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-20 03:47 . 2010-03-06 15:16 3062048 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-04-20 03:47 . 2010-03-06 15:16 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-13 01:14 . 2010-02-23 23:27 664 -c–a-w- c:\documents and settings\Guest\Local Settings\Application Data\d3d9caps.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 88363]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-10-02 94208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-12 1280344]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2002-11-7 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-21 21:11 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 04:45 28672 —-a-w- c:\windows\system32\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-12-01 01:16 24576 —-a-w- c:\windows\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2008-01-22 19:23 81920 ——w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 18:43 248040 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2003-06-24 19:33 561152 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2003-06-24 19:34 126976 —-a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\konami\\Yu-Gi-Oh! ONLINE 3\\yo3.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/5/2009 9:14 PM 108552]
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [7/9/2010 11:57 AM 312152]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/15/2010 7:26 PM 93320]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NlsSrv32.exe [5/6/2010 4:47 PM 61440]
S0 cerc6;cerc6; [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/5/2009 9:14 PM 335240]
S4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe –> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe –> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
.
Contents of the 'Scheduled Tasks' folder

2010-04-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-04-16 19:22]

2010-04-15 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-04-16 19:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\R40\Application Data\Mozilla\Firefox\Profiles\vnz7idzn.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-10 14:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(724)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\tphklock.dll

- - - - - - - > 'explorer.exe'(8144)
c:\windows\system32\WININET.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-07-10 14:59:04
ComboFix-quarantined-files.txt 2010-07-10 21:58

Pre-Run: 16,371,773,440 bytes free
Post-Run: 16,333,910,016 bytes free

- - End Of File - - 4FBCF347F7D71A4959BFC3F66BDFC852
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\drivers\avgtdix.sys 
c:\windows\system32\drivers\avgldx86.sys
c:\progra~1\AVG\AVG8\avgemc.exe
c:\progra~1\AVG\AVG8\avgwdsvc.exe
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcp71.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-d3d.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\jmc.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-sse.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcr71.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcp71.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-d3d.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\jmc.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-sse.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcr71.dll

Folder::
c:\progra~1\AVG\AVG8
c:\progra~1\AVG

Driver::
avgtdix
cerc6
avgldx86
avgemc
avgwdsvc

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Here it is:

ComboFix 10-07-10.01 - R40 07/10/2010 15:23:26.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.145 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\R40\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

FILE ::
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\jmc.dll"
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcp71.dll"
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcr71.dll"
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-d3d.dll"
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-sse.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\jmc.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcp71.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcr71.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-d3d.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-sse.dll"
"c:\progra~1\AVG\AVG8\avgemc.exe"
"c:\progra~1\AVG\AVG8\avgwdsvc.exe"
"c:\windows\system32\drivers\avgldx86.sys"
"c:\windows\system32\drivers\avgtdix.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\jmc.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcp71.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcr71.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-d3d.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-sse.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\jmc.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcp71.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcr71.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-d3d.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-sse.dll
c:\windows\system32\drivers\avgldx86.sys
c:\windows\system32\drivers\avgtdix.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_AVGLDX86
——-\Legacy_AVGTDIX
——-\Service_AvgLdx86
——-\Service_AvgTdiX
——-\Service_cerc6
——-\Legacy_avg8emc
——-\Legacy_avg8wd
——-\Service_avg8emc
——-\Service_avg8wd


((((((((((((((((((((((((( Files Created from 2010-06-10 to 2010-07-10 )))))))))))))))))))))))))))))))
.

2010-07-10 20:48 . 2009-08-07 02:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-07-10 20:48 . 2009-08-07 02:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-07-10 20:48 . 2010-07-10 20:48 ——– d—–w- c:\windows\LastGood.Tmp
2010-07-09 19:47 . 2010-07-09 19:47 ——– d—–w- c:\program files\Microsoft Silverlight
2010-07-09 18:57 . 2010-07-09 18:57 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-07-09 18:57 . 2010-07-09 18:57 ——– d—–w- c:\program files\IObit
2010-07-09 18:06 . 2010-07-09 18:06 ——– d—–w- c:\documents and settings\R40\Application Data\Malwarebytes
2010-07-09 18:05 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-09 18:05 . 2010-07-09 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-09 18:05 . 2010-07-10 18:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-09 18:05 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-09 17:54 . 2010-07-09 17:54 ——– d—–w- c:\program files\CCleaner
2010-07-08 04:32 . 2010-07-08 04:32 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-07-07 21:28 . 2010-07-07 21:28 ——– d—–w- c:\program files\iPod
2010-07-07 21:27 . 2010-07-07 21:31 ——– d—–w- c:\program files\iTunes
2010-07-07 21:27 . 2010-07-07 21:31 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-07 21:20 . 2010-07-07 21:22 ——– d—–w- c:\program files\QuickTime
2010-07-07 21:12 . 2010-07-07 21:12 ——– d—–w- c:\program files\Bonjour
2010-07-07 21:09 . 2010-07-07 21:10 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\jcrcingip
2010-07-07 20:53 . 2010-07-07 20:53 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-04 16:49 . 2010-07-04 16:49 ——– d—–w- C:\spoolerlogs
2010-07-02 15:32 . 2010-07-02 15:32 ——– d–h–r- c:\documents and settings\R40\Application Data\SecuROM
2010-07-02 15:31 . 2010-07-02 15:31 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-07-01 22:57 . 2010-07-08 01:04 ——– d—–w- c:\program files\EA GAMES
2010-07-01 22:57 . 2007-04-04 22:39 442368 —-a-r- c:\windows\system32\vp6vfw.dll
2010-06-27 18:52 . 2010-06-27 18:52 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\HighAndes
2010-06-27 18:52 . 2010-06-27 18:52 ——– d—–w- c:\documents and settings\Guest\Application Data\HighAndes
2010-06-27 18:33 . 2010-06-27 22:29 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\WMTools Downloaded Files
2010-06-13 14:36 . 2010-06-13 14:36 ——– d—–w- c:\program files\Java
2010-06-13 14:20 . 2010-06-13 14:20 ——– d—–w- c:\program files\Common Files\Java
2010-06-13 14:10 . 2010-06-13 14:36 411368 —-a-w- c:\windows\system32\deployJava1.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-10 19:56 . 2008-04-14 12:00 36352 —-a-w- c:\windows\system32\drivers\intelppm.sys
2010-07-10 05:14 . 2010-02-20 19:40 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-09 18:03 . 2010-04-16 03:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-07 21:28 . 2010-01-06 04:20 ——– d—–w- c:\program files\Common Files\Apple
2010-07-07 20:49 . 2010-07-07 20:49 72504 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-07-02 00:05 . 2009-12-25 17:37 ——– d—–w- c:\documents and settings\R40\Application Data\Unity
2010-07-02 00:05 . 2009-12-25 16:56 ——– d—–w- c:\program files\Unity
2010-06-09 08:06 . 2010-06-09 08:06 976832 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\AdobeARM.exe
2010-06-09 08:06 . 2010-06-09 08:06 70584 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\AdobeExtractFiles.dll
2010-06-09 08:06 . 2010-06-09 08:06 331176 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\ReaderUpdater.exe
2010-06-09 08:06 . 2010-06-09 08:06 331176 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\AcrobatUpdater.exe
2010-06-05 21:35 . 2010-06-05 21:35 ——– d—–w- c:\documents and settings\All Users\Application Data\PlayFirst
2010-06-05 21:34 . 2010-06-05 21:34 ——– d—–w- c:\documents and settings\R40\Application Data\PlayFirst
2010-06-05 21:32 . 2010-06-05 21:32 ——– d—–w- c:\program files\PlayFirst
2010-06-02 03:33 . 2010-06-02 03:33 ——– d—–w- c:\documents and settings\Guest\Application Data\SEGA
2010-05-31 18:17 . 2010-05-31 18:16 ——– d—–w- c:\program files\Canon Creative
2010-05-18 23:35 . 2010-05-18 23:35 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 197920 —-a-w- c:\windows\system32\dnssdX.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-15 17:16 . 2010-04-16 03:53 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-05-06 23:47 . 2010-05-06 23:47 355574 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_4030872FF57CBB7F004FA6.exe
2010-05-06 23:47 . 2010-05-06 23:47 7886 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_6FEFF9B68218417F98F549.exe
2010-05-06 23:47 . 2010-05-06 23:47 7886 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_21F3885A18D238E15AAE81.exe
2010-05-06 23:47 . 2010-05-06 23:47 355574 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_D707CE1C009F1381803C2C.exe
2010-05-06 23:47 . 2010-05-06 23:47 355574 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_27BA116C85EAB83CD5A215.exe
2010-05-06 10:41 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2008-04-14 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2008-04-14 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-20 03:47 . 2010-03-06 15:16 3062048 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-04-20 03:47 . 2010-03-06 15:16 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-13 01:14 . 2010-02-23 23:27 664 -c–a-w- c:\documents and settings\Guest\Local Settings\Application Data\d3d9caps.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 88363]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-10-02 94208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-12 1280344]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2002-11-7 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-21 21:11 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 04:45 28672 —-a-w- c:\windows\system32\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-12-01 01:16 24576 —-a-w- c:\windows\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2008-01-22 19:23 81920 ——w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 18:43 248040 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2003-06-24 19:33 561152 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2003-06-24 19:34 126976 —-a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\konami\\Yu-Gi-Oh! ONLINE 3\\yo3.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [7/9/2010 11:57 AM 312152]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/15/2010 7:26 PM 93320]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NlsSrv32.exe [5/6/2010 4:47 PM 61440]
.
Contents of the 'Scheduled Tasks' folder

2010-04-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-04-16 19:22]

2010-04-15 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-04-16 19:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\R40\Application Data\Mozilla\Firefox\Profiles\vnz7idzn.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-10 15:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(900)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\tphklock.dll

- - - - - - - > 'explorer.exe'(4252)
c:\windows\system32\WININET.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\S24EvMon.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\AGRSMMSG.exe
c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\windows\system32\rundll32.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\RegSrvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-10 15:42:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-10 22:41
ComboFix2.txt 2010-07-10 21:59

Pre-Run: 16,340,803,584 bytes free
Post-Run: 16,275,640,320 bytes free

- - End Of File - - 2737F4E9769DD2FD9C5003FFA3FD7A06
I got this box: Error deleting file or folder Cannot delete avgrsstx: Access is denied. Make sure the disk is not full or write protected and that the file is not currently in use. OK

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI