This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE8 and FireFox 3.6.3 Hijacked

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run AVG Free 9.0, Spybot - Search & Destroy, and Malwarebytes. My browsers are still hijacked. My HijackThis Log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 12:34:22 AM, on 7/14/2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\arservice.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe – End of file - 2176 bytes
Hello there, tpabrian

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
OTL log
GMER log

Good Day!
Thanks for your assistance Conspire.

Here are the files you requested.

Gmer.txt

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-17 13:40:31
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fxldqpob.sys


—- Kernel code sections - GMER 1.0.15 —-

.rsrc C:\WINDOWS\System32\DRIVERS\RDPCDD.sys entry point in ".rsrc" section [0xF7D0DC14]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\svchost.exe[1128] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
.text C:\WINDOWS\system32\svchost.exe[1128] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
.text C:\WINDOWS\system32\svchost.exe[1128] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
.text C:\WINDOWS\system32\svchost.exe[1128] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 00C4000A
.text C:\WINDOWS\Explorer.EXE[1836] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\WINDOWS\Explorer.EXE[1836] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C0000A
.text C:\WINDOWS\Explorer.EXE[1836] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs F7A13400
Device -> \Driver\atapi \Device\Harddisk0\DR0 85A1EEC5

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\System32\DRIVERS\RDPCDD.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
OTL.txt - Part 1

OTL logfile created on: 7/16/2010 3:10:21 PM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 449.00 Mb Available Physical Memory | 47.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.04 Gb Total Space | 165.87 Gb Free Space | 74.04% Space Free | Partition Type: NTFS
Drive D: | 8.82 Gb Total Space | 0.60 Gb Free Space | 6.82% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WILLY
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\arservice.exe (Microsoft)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (ARSVC) – C:\WINDOWS\arservice.exe (Microsoft)


========== Driver Services (SafeList) ==========

DRV - (intelppm) – C:\WINDOWS\System32\DRIVERS\intelppm.sys File not found
DRV - (ftsata2) – C:\WINDOWS\System32\DRIVERS\ftsata2.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)
DRV - (HSXHWBS2) – C:\WINDOWS\system32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsx) – C:\WINDOWS\system32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSX_DP) – C:\WINDOWS\system32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/07/13 16:23:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/15 08:55:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/15 08:55:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.22\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009/08/14 17:28:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.22\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2008/09/29 21:43:49 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions
[2008/09/29 21:43:49 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\pt34vw46.default\extensions
[2010/07/13 18:31:03 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/08/05 13:25:23 | 000,028,488 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2009/08/05 13:25:23 | 000,185,232 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2009/08/05 13:25:30 | 000,046,408 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\atmccli.dll
[2009/08/05 13:25:34 | 000,099,216 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2009/08/05 13:25:21 | 000,061,840 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll

O1 HOSTS File: ([2010/07/11 01:13:26 | 000,411,890 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14235 more lines…
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [PCDrProfiler] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/08/28 20:03:30 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 08:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 00:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks, Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)
OTL.txt - Part 2

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)

========== Files/Folders - Created Within 30 Days ==========

[2010/07/16 15:07:45 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2010/07/13 23:37:31 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Administrator\PrivacIE
[2010/07/13 23:34:29 | 000,000,000 | -HSD | C] – C:\Documents and Settings\HP_Administrator\IETldCache
[2010/07/13 22:55:16 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2010/07/13 22:54:15 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/07/13 22:54:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2010/07/13 20:15:08 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Uniblue
[2010/07/13 20:15:02 | 000,000,000 | —D | C] – C:\Program Files\Uniblue
[2010/07/13 18:35:08 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/07/13 16:26:18 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/07/13 16:25:41 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/13 16:25:38 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/07/13 16:25:33 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/07/13 16:25:30 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/07/13 16:25:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/07/13 16:22:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/07/13 15:45:15 | 000,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2010/07/10 23:07:13 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/07/10 23:07:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/07/10 20:28:24 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\qwkfuflxo
[2010/07/10 17:38:03 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/10 17:38:03 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/09 23:45:49 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
[2010/07/09 23:41:36 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\mpfwgbvdk
[2010/07/09 23:41:06 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/09 23:40:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/09 23:33:52 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/09 23:33:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/09 23:33:50 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/09 23:33:50 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/09 23:27:26 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2010/07/05 23:26:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/19 14:36:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/19 14:36:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/19 14:24:19 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\smqnnbosw
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/16 15:08:03 | 000,284,915 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\gmer.zip
[2010/07/16 15:07:45 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2010/07/16 15:05:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/16 12:23:01 | 000,000,000 | —- | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\prvlcl.dat
[2010/07/16 09:50:39 | 062,044,352 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/07/16 09:05:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/14 00:33:48 | 008,912,896 | -H– | M] () – C:\Documents and Settings\HP_Administrator\NTUSER.DAT
[2010/07/14 00:33:27 | 000,002,006 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.lnk
[2010/07/14 00:02:47 | 000,271,490 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2010/07/14 00:02:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/14 00:02:13 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/14 00:02:09 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2010/07/13 23:35:21 | 000,000,826 | —- | M] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/13 20:15:05 | 000,000,760 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RegistryBooster.lnk
[2010/07/13 18:57:53 | 000,000,186 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2010/07/13 16:25:42 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/13 16:25:42 | 000,001,518 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/07/13 16:25:40 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/07/13 16:25:33 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/07/13 16:25:32 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/07/13 16:25:30 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/07/13 16:14:57 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/07/13 15:45:16 | 000,000,701 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\SpywareBlaster.lnk
[2010/07/13 14:14:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/07/11 01:13:26 | 000,411,890 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/10 23:36:13 | 000,004,542 | —- | M] () – C:\WINDOWS\WININIT.INI
[2010/07/10 18:48:43 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/07/09 23:43:32 | 000,000,000 | —- | M] () – C:\WINDOWS\onifetahefozujec.dll
[2010/07/09 23:42:29 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/09 23:42:29 | 000,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/07/09 23:33:54 | 000,000,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/05 20:49:58 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/23 09:43:42 | 000,001,740 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/16 15:08:10 | 000,284,915 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\gmer.zip
[2010/07/13 23:34:15 | 1005,113,344 | -HS- | C] () – C:\hiberfil.sys
[2010/07/13 21:14:06 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\prvlcl.dat
[2010/07/13 20:15:05 | 000,000,760 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RegistryBooster.lnk
[2010/07/13 18:35:11 | 000,002,006 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.lnk
[2010/07/13 16:25:42 | 000,001,518 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/07/13 16:25:30 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/07/13 16:25:14 | 062,044,352 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/07/13 15:45:16 | 000,000,701 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\SpywareBlaster.lnk
[2010/07/09 23:43:32 | 000,000,000 | —- | C] () – C:\WINDOWS\onifetahefozujec.dll
[2010/07/09 23:42:29 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/09 23:42:29 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/07/09 23:33:54 | 000,000,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/31 23:52:04 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2007/08/29 21:12:12 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2007/08/29 19:59:12 | 000,000,059 | —- | C] () – C:\WINDOWS\wpd99.drv
[2007/08/29 19:59:11 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2007/04/10 08:14:45 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/28 20:31:48 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/08/28 20:11:54 | 000,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/08/28 20:06:49 | 000,014,316 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/08/28 20:06:43 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/08/28 20:03:43 | 000,000,219 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/08/28 19:52:21 | 000,004,542 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/08/28 19:51:43 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/08/28 19:46:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/08/28 19:42:51 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/28 19:42:51 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/08/28 19:41:34 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/08/28 19:19:33 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/08/28 19:19:33 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/08/28 19:19:17 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2006/06/16 07:58:18 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/05 17:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 19:19:16 | 000,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/09/16 16:24:26 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/07/26 03:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
OTL.txt - Part 3

========== LOP Check ==========

[2010/07/05 22:11:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/07/13 16:22:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/03/29 09:29:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2007/08/30 00:48:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2010/07/13 19:19:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/08/28 19:56:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/07/13 14:14:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========


========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/08/28 20:03:30 | 000,000,100 | —- | M] () – C:\AUTOEXEC.BAT
[2006/12/09 12:50:01 | 000,000,211 | RHS- | M] () – C:\BOOT.BAK
[2006/12/09 13:01:33 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/09 17:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/08/30 17:02:02 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/14 00:02:09 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2006/08/28 20:10:43 | 000,000,051 | —- | M] () – C:\hpWebHelper.log
[2005/08/30 17:02:02 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/08/30 17:02:02 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/09 17:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/09 17:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/07/14 00:02:08 | 1509,949,440 | -HS- | M] () – C:\pagefile.sys
[2009/10/21 10:59:18 | 000,000,825 | —- | M] () – C:\updatedatfix.log

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >
[2006/02/19 06:28:56 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll

< %systemroot%\Fonts\*.ini >
[2005/08/30 17:01:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
OTL.txt - Part 5

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\*. /mp /s >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %systemroot%\system32\*.dll /lockedfiles >
[2005/07/26 00:39:44 | 001,267,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/08/30 09:51:10 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/30 09:51:10 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/30 09:51:10 | 000,888,832 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2007/03/08 11:36:28 | 000,577,536 | —- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 – C:\WINDOWS\system32\user32.dll
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2004/08/09 17:00:00 | 000,082,944 | —- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 – C:\WINDOWS\system32\ws2_32.dll
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
OTL.txt - Part 6

< %systemroot%\system32\ws2help.dll /md5 >
[2004/08/09 17:00:00 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9BEACB911CA61E5881102188AB7FB431 – C:\WINDOWS\system32\ws2help.dll
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
I an not able to send you the last few lines of the OTL.txt log file. I am not sure why I keep getting error:

Internet Explorer cannot display the webpage

Hello there,

Conspire needs to leave so I will continue helping you here. Seems you're infected with one of the TDL3 rootkit infections.

We will begin with Combofix here.

Download and Run ComboFix

Note to readers of this post other than the starter of this thread:
ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.

Download Combofix from any of the links below, and save it to your desktop.
Link 1
Link 2

Please refer to this page for full instructions on how to run ComboFix.

  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click ComboFix.exe to start the program. Agree to the prompts.
  • When ComboFix is finished, a log report (C:\ComboFix.txt) will open. Post back with it.
Leave your computer alone while ComboFix is running.

ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.
Here is the ComboFix log file:

ComboFix 10-07-18.05 - HP_Administrator 07/19/2010 14:41:24.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.533 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\onifetahefozujec.dll
c:\windows\xpsp1hfm.log
D:\Autorun.inf

Infected copy of c:\windows\system32\drivers\rdpcdd.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
.

2010-07-19 18:43 . 2010-07-19 18:43 ——– d—–w- c:\windows\LastGood
2010-07-17 18:32 . 2010-07-17 18:32 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-07-16 18:59 . 2010-07-16 18:59 574976 —-a-w- c:\temp\OTL.exe
2010-07-14 04:33 . 2010-07-14 04:33 388096 —-a-r- c:\documents and settings\HP_Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-14 04:30 . 2010-07-14 04:30 1402880 —-a-w- c:\temp\HiJackThis.msi
2010-07-14 03:37 . 2010-07-14 03:37 ——– d-sh–w- c:\documents and settings\HP_Administrator\PrivacIE
2010-07-14 03:34 . 2010-07-14 03:34 ——– d-sh–w- c:\documents and settings\HP_Administrator\IETldCache
2010-07-14 03:18 . 2010-07-14 03:18 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-07-14 03:13 . 2010-07-14 03:13 ——– d-sh–w- c:\documents and settings\Administrator\IECompatCache
2010-07-14 03:12 . 2010-07-14 03:12 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2010-07-14 03:08 . 2010-07-14 03:08 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-07-14 02:54 . 2010-07-14 02:54 ——– dc-h–w- c:\windows\ie8
2010-07-14 02:44 . 2010-07-14 02:44 16883056 —-a-w- c:\temp\IE8-WindowsXP-x86-ENU.exe
2010-07-14 01:57 . 2010-07-14 01:57 11508680 —-a-w- c:\temp\windows-kb890830-v3.9.exe
2010-07-14 01:14 . 2010-07-19 17:52 0 —-a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\prvlcl.dat
2010-07-14 00:15 . 2010-07-14 00:15 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Uniblue
2010-07-14 00:15 . 2010-07-14 00:15 ——– d—–w- c:\program files\Uniblue
2010-07-13 22:35 . 2010-07-13 22:35 ——– d—–w- c:\program files\Trend Micro
2010-07-13 22:34 . 2010-07-13 22:34 812344 —-a-w- c:\temp\HJTInstall.exe
2010-07-13 22:33 . 2010-07-13 22:33 5037512 —-a-w- c:\temp\registrybooster.exe
2010-07-13 20:26 . 2010-07-13 20:26 ——– d—–w- C:\$AVG
2010-07-13 20:25 . 2010-07-13 20:25 12536 —-a-w- c:\windows\system32\avgrsstx.dll
2010-07-13 20:25 . 2010-07-13 20:25 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-13 20:25 . 2010-07-13 20:25 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-13 20:25 . 2010-07-13 20:25 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-07-13 20:25 . 2010-07-19 17:36 ——– d—–w- c:\windows\system32\drivers\Avg
2010-07-13 20:22 . 2010-07-13 20:22 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-07-13 20:06 . 2010-07-13 20:06 2133536 —-a-w- c:\temp\avg_free_stb_all_9_115_cnet.exe
2010-07-13 19:45 . 2010-07-13 19:48 ——– d—–w- c:\program files\SpywareBlaster
2010-07-13 19:44 . 2010-07-13 19:44 3103640 —-a-w- c:\temp\spywareblastersetup43.exe
2010-07-11 03:07 . 2010-07-11 03:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-11 03:07 . 2010-07-11 03:09 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-11 00:28 . 2010-07-11 01:24 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\qwkfuflxo
2010-07-10 21:35 . 2010-07-10 21:35 ——– d-s—w- c:\documents and settings\LocalService\UserData
2010-07-10 03:45 . 2010-07-10 03:45 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2010-07-10 03:42 . 2010-07-10 03:42 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-10 03:42 . 2010-07-10 03:42 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-07-10 03:41 . 2010-07-10 03:50 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\mpfwgbvdk
2010-07-10 03:40 . 2010-07-10 03:40 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-10 03:34 . 2010-07-10 03:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-07-10 03:33 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-10 03:33 . 2010-07-10 03:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-10 03:33 . 2010-07-10 03:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-10 03:33 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-10 03:29 . 2010-07-10 03:29 ——– d-sh–w- c:\documents and settings\Administrator\UserData
2010-07-06 03:46 . 2010-07-06 03:46 16409960 —-a-w- c:\temp\spybotsd162.exe
2010-07-06 03:26 . 2010-07-13 23:19 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-06 03:25 . 2010-07-06 03:26 36600008 —-a-w- c:\temp\sdasetup.exe
2010-07-06 02:03 . 2010-07-06 02:03 53785488 —-a-w- c:\temp\setup_av_free.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-14 13:07 . 2009-01-23 13:57 1 —-a-w- c:\documents and settings\HP_Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-07-13 20:22 . 2008-10-09 13:21 ——– d—–w- c:\program files\AVG
2010-07-06 02:11 . 2010-02-23 18:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-06-11 07:15 . 2007-07-05 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-21 18:14 . 2009-10-06 15:55 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-02 05:56 . 2004-08-09 21:00 1850880 —-a-w- c:\windows\system32\win32k.sys
2009-08-05 17:25 . 2009-08-05 17:25 28488 —-a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2009-08-05 17:25 . 2009-08-05 17:25 185232 —-a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2009-08-05 17:25 . 2009-08-05 17:25 46408 —-a-w- c:\program files\mozilla firefox\plugins\atmccli.dll
2009-08-05 17:25 . 2009-08-05 17:25 99216 —-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/13/2010 4:25 PM 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/13/2010 4:25 PM 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [7/13/2010 4:24 PM 308136]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/14/2010 4:45 PM 135664]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
.
Contents of the 'Scheduled Tasks' folder

2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 20:45]

2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 20:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\pt34vw46.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-PCDrProfiler - (no file)
AddRemove-AntiVir PersonalEdition Classic - c:\program files\AntiVir PersonalEdition Classic\SETUP.EXE
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-19 14:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-07-19 14:51:58
ComboFix-quarantined-files.txt 2010-07-19 18:51

Pre-Run: 178,009,432,064 bytes free
Post-Run: 178,376,077,312 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 9EDF19FB12EFFF77DA6D619F1317FAF5
How's your computer running?

You're still running Service Pack 2. It is no longer updated and supported. Support for Windows XP Sp2 was ended a while back. Take a read here: http://windows.microsoft.com/en-us/windows…-packs?os=other

I recommend you update to Service Pack 3 through Windows Automatic Updates or downloading the offline package: http://www.microsoft.com/downloads/details…;displaylang=en Instruction on doing so can be found here: http://support.microsoft.com/kb/322389

—

Let's continue with an online scan to confirm if there's anything else.

Run ESET Online Scan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
You can refer to this animation by neomage if needed.

Once that is all done, please proceed with a new OTL scan and post that log as well in your next reply.

With Regards,
Extremeboy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI