This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] anivirXP08 is dominating me.

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

antivirxp08 took away my control panel and run among other things so I can't manually remove this thing. I need help plz!!!! I used The Cleaner but it freezes and causes a restart, so I dunno what to do.

Logfile of HijackThis v1.99.1
Scan saved at 03:18: VIRUS ALERT!, on 7/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lphclq6j0en13.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\antiviirus.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\tmp0.exe
C:\Program Files\tmp1.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\tmp2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.a…&tbid=66028
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66028
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: sqvgnrpx - {63BB2189-05DB-4E6B-9542-82C9A1C53C0B} - C:\WINDOWS\sqvgnrpx.dll (file missing)
O4 - HKLM\..\Run: [lphclq6j0en13] C:\WINDOWS\system32\lphclq6j0en13.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [antiviirus] C:\Program Files\antiviirus.exe
O4 - HKLM\..\Run: [c40b8b34] rundll32.exe "C:\WINDOWS\system32\uaelopjv.dll",b
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [SMshcjq6j0en13] C:\Program Files\shcjq6j0en13\shcjq6j0en13.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1193323643687
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEC6C7BD-E9B5-4E58-B72C-517D1A3F701B}: NameServer = 192.168.0.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: fsrpknov - {35B05713-AC31-4B45-BBF5-687462915BE9} - C:\WINDOWS\fsrpknov.dll
O21 - SSODL: fdxbameg - {9D5C5D80-9EDE-4133-95B8-9616A802124A} - C:\WINDOWS\fdxbameg.dll (file missing)
O21 - SSODL: CheckStat - {84cdb673-e670-4aa7-aaca-b4060f57227d} - C:\WINDOWS\Resources\CheckStat.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
[external image: Posted Image]


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Thank you for helping LDTate! My pc seems normal, other than my clock in military time. And I can finally get windows to update properly. My comp is working well and so far I haven't got a pop up from antivirxp08. I am currently with Windows XP SP2, do you recommend SP3? Thank you again for your help with me. Heres my log from Malwarebytes, and I will post my new HijackThis log next. Malwarebytes' Anti-Malware 1.20 Database version: 949 Windows 5.1.2600 Service Pack 2 3:23:28 PM 7/14/2008 mbam-log-7-14-2008 (15-23-28).txt Scan type: Quick Scan Objects scanned: 42484 Time elapsed: 5 minute(s), 14 second(s) Memory Processes Infected: 0 Memory Modules Infected: 7 Registry Keys Infected: 18 Registry Values Infected: 6 Registry Data Items Infected: 2 Folders Infected: 4 Files Infected: 42 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\akdvkcan.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\chrgbxee.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\urqnNeBR.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\mvlzbh.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\hiqbdpti.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\rfepji.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\fsrpknov.dll (Trojan.FakeAlert) -> Unloaded module successfully. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30125001-bcd3-48c5-95da-238e7abbe70a} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{30125001-bcd3-48c5-95da-238e7abbe70a} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\sqvgnrpx.btpb (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\sqvgnrpx.toolbar.1 (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{63bb2189-05db-4e6b-9542-82c9a1c53c0b} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{43fcd2cf-5569-4208-97d2-52748e0ef6a0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43fcd2cf-5569-4208-97d2-52748e0ef6a0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{25ddd24d-1a1b-41ac-919b-b6bc6dfbc2fc} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{11ea6f11-55b4-4460-ade5-b0b06736790f} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a300081f-8c81-4588-a57b-9eec7fdd012b} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a300081f-8c81-4588-a57b-9eec7fdd012b} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{35b05713-ac31-4b45-bbf5-687462915be9} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\c40b8b34 (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{63bb2189-05db-4e6b-9542-82c9a1c53c0b} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{43fcd2cf-5569-4208-97d2-52748e0ef6a0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\fsrpknov (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smshcjq6j0en13 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\fdxbameg (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\urqnnebr -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\urqnnebr -> Delete on reboot. Folders Infected: C:\Program Files\rhcgq6j0en13 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\shcjq6j0en13 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008 (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\WINDOWS\system32\778670 (Trojan.BHO) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\urqnNeBR.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\RBeNnqru.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\RBeNnqru.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\akdvkcan.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\nackvdka.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\chrgbxee.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\eexbgrhc.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mvlzbh.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\hiqbdpti.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\rfepji.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\rsdcbl.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Eric Wilson\Local Settings\Temporary Internet Files\Content.IE5\B9L73KJA\kb767887[1] (Trojan.Vundo) -> Delete on reboot. C:\Documents and Settings\Eric Wilson\Local Settings\Temporary Internet Files\Content.IE5\N9ROJKWE\kb767887[1] (Trojan.Vundo) -> Delete on reboot. C:\Program Files\rhcgq6j0en13\database.dat (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\rhcgq6j0en13\license.txt (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\rhcgq6j0en13\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\rhcgq6j0en13\MFC71ENU.DLL (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\rhcgq6j0en13\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\rhcgq6j0en13\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\rhcgq6j0en13\rhcgq6j0en13.exe.local (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\rhcgq6j0en13\Uninstall.exe (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\shcjq6j0en13\database.dat (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\shcjq6j0en13\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\shcjq6j0en13\MFC71ENU.DLL (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\shcjq6j0en13\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\shcjq6j0en13\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\shcjq6j0en13\shcjq6j0en13.exe.local (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\shcjq6j0en13\Uninstall.exe (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\WINDOWS\system32\778670\778670.dll (Trojan.BHO) -> Quarantined and deleted successfully. C:\Documents and Settings\Eric Wilson\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008.lnk (Rogue.MalwareProtector2008) -> Quarantined and deleted successfully. C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\fsrpknov.dll (Trojan.FakeAlert) -> Delete on reboot. C:\WINDOWS\gpefaowr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\system32\blphclq6j0en13.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Documents and Settings\prov1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT (Rogue.SpywareDestructor) -> Quarantined and deleted successfully. C:\Documents and Settings\Eric Wilson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT (Rogue.SpywareDestructor) -> Quarantined and deleted successfully.
With the infections you had, we need to dig deeper.

Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish
My HijackThis log, Thank You again for your help!

Logfile of HijackThis v1.99.1
Scan saved at 15:54:48, on 7/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\program files\valve\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1193323643687
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEC6C7BD-E9B5-4E58-B72C-517D1A3F701B}: NameServer = 192.168.0.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: nnnmkLeE - nnnmkLeE.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
With the infections you had, we need to dig deeper.

Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish

Remind me about the clock settings. We'll fix that when your pc is clean.
Wow. Now I have all my Files/Programs/Shortcuts back on my desktop. Hers my ComboFix log and HijackThis log. Thanks again TATE!

ComboFix 08-07-14.2 - Eric Wilson 2008-07-14 16:05:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1486 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\fsrpknov.dll
C:\WINDOWS\system32\akdvkcan.dll
C:\WINDOWS\system32\chrgbxee.dll
C:\WINDOWS\system32\hiqbdpti.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\MSVolume.dll
C:\WINDOWS\system32\mvlzbh.dll
C:\WINDOWS\system32\RBeNnqru.ini
C:\WINDOWS\system32\RBeNnqru.ini2
C:\WINDOWS\system32\rfepji.dll
C:\WINDOWS\system32\stfvieqy.ini
C:\WINDOWS\system32\vjpoleau.ini

.
((((((((((((((((((((((((( Files Created from 2008-06-14 to 2008-07-14 )))))))))))))))))))))))))))))))
.

2008-07-14 15:14 . 2008-07-14 15:14 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-07-14 15:14 . 2008-07-14 15:14 d——– C:\Documents and Settings\Eric Wilson\Application Data\Malwarebytes
2008-07-14 15:14 . 2008-07-14 15:14 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-14 15:14 . 2008-07-07 17:35 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-14 15:14 . 2008-07-07 17:35 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-13 07:33 . 2008-07-13 18:00 d——– C:\Program Files\Norton Security Scan
2008-07-12 11:11 . 2008-07-12 11:11 d——– C:\Program Files\Sun
2008-07-12 06:15 . 2008-07-12 06:21 455,263,232 –a—— C:\Backup.bkf
2008-07-12 06:13 . 2008-07-12 06:22 d——– C:\WINDOWS\system32\NtmsData
2008-07-12 04:18 . 2008-07-12 04:18 d——– C:\WINDOWS\resources
2008-07-12 04:12 . 2008-07-13 08:14 2,988 –a—— C:\WINDOWS\system32\tmp.reg
2008-07-12 03:49 . 2007-09-06 00:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-07-12 03:49 . 2006-04-27 17:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-07-12 03:49 . 2008-05-29 09:35 86,528 –a—— C:\WINDOWS\system32\VACFix.exe
2008-07-12 03:49 . 2008-05-18 21:40 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-07-12 03:49 . 2008-07-02 13:33 82,432 –a—— C:\WINDOWS\system32\IEDFix.C.exe
2008-07-12 03:49 . 2008-05-23 18:21 81,920 –a—— C:\WINDOWS\system32\404Fix.exe
2008-07-12 03:49 . 2003-06-05 21:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-07-12 03:49 . 2004-07-31 18:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-07-12 03:49 . 2007-10-04 00:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-07-11 18:01 . 2008-07-12 08:40 d——– C:\Program Files\Enigma Software Group
2008-07-11 14:11 . 2008-07-11 14:11 d——– C:\Documents and Settings\prov1\Application Data\Talkback
2008-07-11 12:44 . 2004-08-04 05:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-07-11 12:40 . 2008-07-11 12:40 d——– C:\Documents and Settings\prov1
2008-07-11 11:39 . 2008-07-12 05:48 d——– C:\Program Files\The Cleaner Free
2008-07-11 11:39 . 2008-07-11 11:39 5,376 –a—— C:\WINDOWS\system32\drivers\MS1000.sys
2008-07-11 11:15 . 2008-07-12 08:40 656 –a—— C:\WINDOWS\wininit.ini
2008-07-11 10:33 . 2008-07-11 10:33 d——– C:\Program Files\Spybot - Search & Destroy
2008-07-11 10:33 . 2008-07-11 10:49 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-11 10:24 . 2008-07-14 00:34 d——– C:\WINDOWS\system32\drivers\Avg
2008-07-11 10:24 . 2008-07-11 10:24 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-11 10:24 . 2008-07-11 10:24 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-11 10:24 . 2008-07-11 10:24 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-07-11 09:33 . 2008-07-11 09:33 d——– C:\Program Files\Common Files\Download Manager
2008-07-11 09:33 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2008-07-11 08:59 . 2008-07-14 15:23 321,792 ——— C:\WINDOWS\system32\urqnNeBR.dll
2008-07-10 13:41 . 2008-07-10 14:11 d——– C:\Program Files\SIW
2008-07-08 06:22 . 2008-07-08 06:22 0 –a—— C:\WINDOWS\Irremote.ini
2008-07-07 08:54 . 2008-07-07 08:54 d–h—– C:\WINDOWS\system32\GroupPolicy
2008-07-07 08:48 . 2008-07-07 08:48 d——– C:\Documents and Settings\Eric Wilson\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-07-07 08:42 . 2008-07-07 08:42 d——– C:\Program Files\Common Files\Adobe AIR
2008-07-05 17:46 . 2008-07-05 17:46 d——– C:\WINDOWS\nvidia icons
2008-07-05 17:46 . 2008-05-02 22:46 182,347 –a—— C:\WINDOWS\system32\nvapps.nvb
2008-07-05 17:44 . 2008-07-05 17:44 d——– C:\Program Files\SystemRequirementsLab
2008-07-05 17:44 . 2008-07-05 17:44 d——– C:\Documents and Settings\Eric Wilson\Application Data\SystemRequirementsLab
2008-07-02 19:27 . 2008-07-02 19:27 d——– C:\Program Files\iTunes
2008-07-02 19:27 . 2008-07-02 19:27 d——– C:\Program Files\iPod
2008-07-02 19:26 . 2008-07-02 19:26 d——– C:\Program Files\QuickTime
2008-07-02 19:23 . 2008-07-02 19:23 d——– C:\Program Files\Apple Software Update
2008-06-30 07:42 . 2008-06-30 07:42 d——– C:\Documents and Settings\Eric Wilson\Application Data\Publish Providers
2008-06-30 07:42 . 2008-07-05 12:01 156 –a—— C:\WINDOWS\Twunk001.MTX
2008-06-30 07:42 . 2008-07-05 12:01 3 –a—— C:\WINDOWS\Twain001.Mtx
2008-06-30 07:42 . 2008-06-30 07:42 0 –a—— C:\WINDOWS\Twunk002.MTX
2008-06-26 15:10 . 2008-06-26 15:10 42,320 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-06-24 09:08 . 2002-12-17 16:23 33,340 ——— C:\WINDOWS\system32\dbmsqlgc.dll
2008-06-24 09:08 . 2002-10-20 14:05 24,576 ——— C:\WINDOWS\system32\dbmsgnet.dll
2008-06-24 09:07 . 2008-06-24 09:07 d——– C:\Program Files\Microsoft SQL Server
2008-06-24 09:07 . 2008-06-30 07:41 d——– C:\Documents and Settings\Eric Wilson\Application Data\Sony
2008-06-24 09:07 . 1998-10-29 15:45 306,688 –a—— C:\WINDOWS\IsUninst.exe
2008-06-24 09:06 . 2008-07-10 05:26 d——– C:\Program Files\Sony
2008-06-24 09:06 . 2008-07-10 05:26 d——– C:\Documents and Settings\All Users\Application Data\Sony
2008-06-24 09:04 . 2008-07-03 13:43 d——– C:\Program Files\Sony Setup
2008-06-23 06:15 . 2008-07-12 18:19 d——– C:\Documents and Settings\All Users\Application Data\TrackMania
2008-06-15 00:06 . 2008-06-15 00:06 d——– C:\Program Files\Sierra Online
2008-06-15 00:06 . 2008-06-15 00:06 d——– C:\Documents and Settings\Eric Wilson\Application Data\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-12 16:11 ——— d—–w C:\Program Files\Java
2008-07-11 23:35 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\uTorrent
2008-07-11 15:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-07-11 15:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-07-11 14:54 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-11 11:51 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\dvdcss
2008-07-08 11:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-07-08 10:52 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\Roxio
2008-07-07 13:41 ——— d—–w C:\Program Files\Common Files\Adobe
2008-07-07 06:05 136,888 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-02 13:24 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\Xfire
2008-07-02 13:20 ——— d—–w C:\Program Files\Xfire
2008-06-24 14:06 ——— d—–w C:\Program Files\VstPlugins
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-15 05:06 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 00:34 ——— d—–w C:\Program Files\GoldWave
2008-06-10 09:06 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\Move Networks
2008-06-07 11:29 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\LimeWire
2008-06-04 12:59 ——— d—–w C:\Program Files\Postal2STP
2008-05-29 19:17 ——— d—–w C:\Program Files\VUGames
2008-05-29 19:15 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-05-28 09:00 ——— d—–w C:\Program Files\Combined Community Codec Pack
2008-05-25 17:38 ——— d—–w C:\Program Files\AVG
2008-05-23 16:39 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\PowerChallenge
2008-01-29 03:47 1,206,366 —-a-w C:\Program Files\winrar371.exe
2007-12-25 03:59 22,328 —-a-w C:\Documents and Settings\Eric Wilson\Application Data\PnkBstrK.sys
2007-11-27 22:42 13,195 —-a-w C:\Documents and Settings\Eric Wilson\ZGUICFGW.DAT
2007-11-17 00:25 22 —-a-w C:\Program Files\dvdshrink32setup.zip
2007-10-25 13:17 28,556,584 —-a-w C:\Program Files\avg75free_488a1138.exe
2007-10-25 13:16 12,413,440 —-a-w C:\Program Files\avgas-setup-7.5.1.43.exe
2007-10-25 13:15 423,736 —-a-w C:\Program Files\AVGrootkitSetup-1.1.0.42.exe
2007-03-13 22:20 35,979 —-a-w C:\Program Files\Photoshop CS3 Read Me.html
1998-12-09 01:53 99,840 —-a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 01:53 70,144 —-a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 01:53 48,640 —-a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 01:53 31,744 —-a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 01:53 186,368 —-a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 01:53 17,920 —-a-w C:\Program Files\Common Files\IRASRIAL.DLL
.
—-a-w		 7,608,700 2003-03-08 06:09:06  C:\Documents and Settings\Eric Wilson\My Documents\Traktor v1.06\TRAKTOR STUDIO MIXER BEST DJ SOFTWARE EVER .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\valve\steam\steam.exe" [2008-06-05 21:05 1271032]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [N/A]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [N/A]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 12:06 77824]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-11 10:24 1232152]
"SkyTel"="SkyTel.EXE" [2006-05-16 05:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-12-18 22:12 16062464 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 14:05:56 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 15:39 294400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\counter-strike\\hl.exe"=
"C:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\half-life 2 deathmatch\\hl2.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\team fortress 2\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\portal\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\usmc233expert\\garrysmod\\hl2.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Documents and Settings\\Eric Wilson\\My Documents\\Downloads\\HLDJ\\hldj.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\source sdk base\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\ricochet\\hl.exe"=
"C:\\Documents and Settings\\Eric Wilson\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"C:\\Program Files\\Postal2STP\\System\\Postal2MP.exe"=
"C:\\Program Files\\Sierra Online\\FreeStyle Street Basketball™\\FreeStyle.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\common\\trackmania nations forever\\TmForever.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"17673:TCP"= 17673:TCP:BitComet 17673 TCP
"17673:UDP"= 17673:UDP:BitComet 17673 UDP
"22778:TCP"= 22778:TCP:BitComet 22778 TCP
"22778:UDP"= 22778:UDP:BitComet 22778 UDP
"25134:TCP"= 25134:TCP:BitComet 25134 TCP
"25134:UDP"= 25134:UDP:BitComet 25134 UDP
"27000:UDP"= 27000:UDP:port
"27001:UDP"= 27001:UDP:port

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-11 10:24]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-11 10:24]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-11 10:24]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-11 10:24]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-07-08 03:36:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-13 23:00:09 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
- - - - ORPHANS REMOVED - - - -

Notify-nnnmkLeE - nnnmkLeE.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-14 16:16:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\searchindexer.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-07-14 16:20:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-14 21:19:52

Pre-Run: 306,324,742,144 bytes free
Post-Run: 306,223,509,504 bytes free

255 — E O F — 2008-07-09 08:00:31
Logfile of HijackThis v1.99.1
Scan saved at 16:32:12, on 7/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\program files\valve\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1193323643687
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEC6C7BD-E9B5-4E58-B72C-517D1A3F701B}: NameServer = 192.168.0.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
Open notepad and copy/paste the text in the Codebox below into it:

File::
C:\WINDOWS\system32\urqnNeBR.dll
C:\WINDOWS\Irremote.ini

Folder::
C:\Program Files\Bonjour

RenV::
C:\Documents and Settings\Eric Wilson\My Documents\Traktor v1.06\TRAKTOR STUDIO MIXER BEST DJ SOFTWARE EVER .exe

Save this as Save this as "CFScript"


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
My pc is the same(great), no pop up windows and i have only been to a couple sites. My clock being military is the only remnant i can see from antivirxp08. Thank you again Tate! Here is combofix log

ComboFix 08-07-14.2 - Eric Wilson 2008-07-14 16:49:47.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1465 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Eric Wilson\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\Irremote.ini
C:\WINDOWS\system32\urqnNeBR.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Bonjour
C:\Program Files\Bonjour\mdnsNSP.dll
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Irremote.ini
C:\WINDOWS\system32\urqnNeBR.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-14 to 2008-07-14 )))))))))))))))))))))))))))))))
.

2008-07-14 15:14 . 2008-07-14 15:14 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-07-14 15:14 . 2008-07-14 15:14 d——– C:\Documents and Settings\Eric Wilson\Application Data\Malwarebytes
2008-07-14 15:14 . 2008-07-14 15:14 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-14 15:14 . 2008-07-07 17:35 34,296 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-14 15:14 . 2008-07-07 17:35 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-07-13 07:33 . 2008-07-13 18:00 d——– C:\Program Files\Norton Security Scan
2008-07-12 11:11 . 2008-07-12 11:11 d——– C:\Program Files\Sun
2008-07-12 06:15 . 2008-07-12 06:21 455,263,232 –a—— C:\Backup.bkf
2008-07-12 06:13 . 2008-07-12 06:22 d——– C:\WINDOWS\system32\NtmsData
2008-07-12 04:18 . 2008-07-12 04:18 d——– C:\WINDOWS\resources
2008-07-12 04:12 . 2008-07-13 08:14 2,988 –a—— C:\WINDOWS\system32\tmp.reg
2008-07-12 03:49 . 2007-09-06 00:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-07-12 03:49 . 2006-04-27 17:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-07-12 03:49 . 2008-05-29 09:35 86,528 –a—— C:\WINDOWS\system32\VACFix.exe
2008-07-12 03:49 . 2008-05-18 21:40 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-07-12 03:49 . 2008-07-02 13:33 82,432 –a—— C:\WINDOWS\system32\IEDFix.C.exe
2008-07-12 03:49 . 2008-05-23 18:21 81,920 –a—— C:\WINDOWS\system32\404Fix.exe
2008-07-12 03:49 . 2003-06-05 21:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-07-12 03:49 . 2004-07-31 18:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-07-12 03:49 . 2007-10-04 00:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-07-11 18:01 . 2008-07-12 08:40 d——– C:\Program Files\Enigma Software Group
2008-07-11 14:11 . 2008-07-11 14:11 d——– C:\Documents and Settings\prov1\Application Data\Talkback
2008-07-11 12:44 . 2004-08-04 05:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-07-11 12:40 . 2008-07-11 12:40 d——– C:\Documents and Settings\prov1
2008-07-11 11:39 . 2008-07-12 05:48 d——– C:\Program Files\The Cleaner Free
2008-07-11 11:39 . 2008-07-11 11:39 5,376 –a—— C:\WINDOWS\system32\drivers\MS1000.sys
2008-07-11 11:15 . 2008-07-12 08:40 656 –a—— C:\WINDOWS\wininit.ini
2008-07-11 10:33 . 2008-07-11 10:33 d——– C:\Program Files\Spybot - Search & Destroy
2008-07-11 10:33 . 2008-07-11 10:49 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-11 10:24 . 2008-07-14 00:34 d——– C:\WINDOWS\system32\drivers\Avg
2008-07-11 10:24 . 2008-07-11 10:24 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-11 10:24 . 2008-07-11 10:24 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-11 10:24 . 2008-07-11 10:24 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-07-11 09:33 . 2008-07-11 09:33 d——– C:\Program Files\Common Files\Download Manager
2008-07-11 09:33 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2008-07-10 13:41 . 2008-07-10 14:11 d——– C:\Program Files\SIW
2008-07-07 08:54 . 2008-07-07 08:54 d–h—– C:\WINDOWS\system32\GroupPolicy
2008-07-07 08:48 . 2008-07-07 08:48 d——– C:\Documents and Settings\Eric Wilson\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-07-07 08:42 . 2008-07-07 08:42 d——– C:\Program Files\Common Files\Adobe AIR
2008-07-05 17:46 . 2008-07-05 17:46 d——– C:\WINDOWS\nvidia icons
2008-07-05 17:46 . 2008-05-02 22:46 182,347 –a—— C:\WINDOWS\system32\nvapps.nvb
2008-07-05 17:44 . 2008-07-05 17:44 d——– C:\Program Files\SystemRequirementsLab
2008-07-05 17:44 . 2008-07-05 17:44 d——– C:\Documents and Settings\Eric Wilson\Application Data\SystemRequirementsLab
2008-07-02 19:27 . 2008-07-02 19:27 d——– C:\Program Files\iTunes
2008-07-02 19:27 . 2008-07-02 19:27 d——– C:\Program Files\iPod
2008-07-02 19:26 . 2008-07-02 19:26 d——– C:\Program Files\QuickTime
2008-07-02 19:23 . 2008-07-02 19:23 d——– C:\Program Files\Apple Software Update
2008-06-30 07:42 . 2008-06-30 07:42 d——– C:\Documents and Settings\Eric Wilson\Application Data\Publish Providers
2008-06-30 07:42 . 2008-07-05 12:01 156 –a—— C:\WINDOWS\Twunk001.MTX
2008-06-30 07:42 . 2008-07-05 12:01 3 –a—— C:\WINDOWS\Twain001.Mtx
2008-06-30 07:42 . 2008-06-30 07:42 0 –a—— C:\WINDOWS\Twunk002.MTX
2008-06-26 15:10 . 2008-06-26 15:10 42,320 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-06-24 09:08 . 2002-12-17 16:23 33,340 ——— C:\WINDOWS\system32\dbmsqlgc.dll
2008-06-24 09:08 . 2002-10-20 14:05 24,576 ——— C:\WINDOWS\system32\dbmsgnet.dll
2008-06-24 09:07 . 2008-06-24 09:07 d——– C:\Program Files\Microsoft SQL Server
2008-06-24 09:07 . 2008-06-30 07:41 d——– C:\Documents and Settings\Eric Wilson\Application Data\Sony
2008-06-24 09:07 . 1998-10-29 15:45 306,688 –a—— C:\WINDOWS\IsUninst.exe
2008-06-24 09:06 . 2008-07-10 05:26 d——– C:\Program Files\Sony
2008-06-24 09:06 . 2008-07-10 05:26 d——– C:\Documents and Settings\All Users\Application Data\Sony
2008-06-24 09:04 . 2008-07-03 13:43 d——– C:\Program Files\Sony Setup
2008-06-23 06:15 . 2008-07-12 18:19 d——– C:\Documents and Settings\All Users\Application Data\TrackMania
2008-06-15 00:06 . 2008-06-15 00:06 d——– C:\Program Files\Sierra Online
2008-06-15 00:06 . 2008-06-15 00:06 d——– C:\Documents and Settings\Eric Wilson\Application Data\InstallShield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-12 16:11 ——— d—–w C:\Program Files\Java
2008-07-11 23:35 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\uTorrent
2008-07-11 15:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-07-11 15:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-07-11 14:54 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-11 11:51 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\dvdcss
2008-07-08 11:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-07-08 10:52 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\Roxio
2008-07-07 13:41 ——— d—–w C:\Program Files\Common Files\Adobe
2008-07-07 06:05 136,888 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-02 13:24 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\Xfire
2008-07-02 13:20 ——— d—–w C:\Program Files\Xfire
2008-06-24 14:06 ——— d—–w C:\Program Files\VstPlugins
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-15 05:06 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 00:34 ——— d—–w C:\Program Files\GoldWave
2008-06-10 09:06 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\Move Networks
2008-06-07 11:29 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\LimeWire
2008-06-04 12:59 ——— d—–w C:\Program Files\Postal2STP
2008-05-29 19:17 ——— d—–w C:\Program Files\VUGames
2008-05-29 19:15 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-05-28 09:00 ——— d—–w C:\Program Files\Combined Community Codec Pack
2008-05-25 17:38 ——— d—–w C:\Program Files\AVG
2008-05-23 16:39 ——— d—–w C:\Documents and Settings\Eric Wilson\Application Data\PowerChallenge
2008-01-29 03:47 1,206,366 —-a-w C:\Program Files\winrar371.exe
2007-12-25 03:59 22,328 —-a-w C:\Documents and Settings\Eric Wilson\Application Data\PnkBstrK.sys
2007-11-27 22:42 13,195 —-a-w C:\Documents and Settings\Eric Wilson\ZGUICFGW.DAT
2007-11-17 00:25 22 —-a-w C:\Program Files\dvdshrink32setup.zip
2007-10-25 13:17 28,556,584 —-a-w C:\Program Files\avg75free_488a1138.exe
2007-10-25 13:16 12,413,440 —-a-w C:\Program Files\avgas-setup-7.5.1.43.exe
2007-10-25 13:15 423,736 —-a-w C:\Program Files\AVGrootkitSetup-1.1.0.42.exe
2007-03-13 22:20 35,979 —-a-w C:\Program Files\Photoshop CS3 Read Me.html
1998-12-09 01:53 99,840 —-a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-09 01:53 70,144 —-a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-09 01:53 48,640 —-a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-09 01:53 31,744 —-a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-09 01:53 186,368 —-a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-09 01:53 17,920 —-a-w C:\Program Files\Common Files\IRASRIAL.DLL
.

((((((((((((((((((((((((((((( snapshot@2008-07-14_16.19.43.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-14 21:51:41 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_664.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\valve\steam\steam.exe" [2008-06-05 21:05 1271032]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 12:06 77824]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-11 10:24 1232152]
"SkyTel"="SkyTel.EXE" [2006-05-16 05:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-12-18 22:12 16062464 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 14:05:56 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 15:39 294400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\counter-strike\\hl.exe"=
"C:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\half-life 2 deathmatch\\hl2.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\team fortress 2\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\portal\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\usmc233expert\\garrysmod\\hl2.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Documents and Settings\\Eric Wilson\\My Documents\\Downloads\\HLDJ\\hldj.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\source sdk base\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\[removed]\\ricochet\\hl.exe"=
"C:\\Documents and Settings\\Eric Wilson\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"C:\\Program Files\\Postal2STP\\System\\Postal2MP.exe"=
"C:\\Program Files\\Sierra Online\\FreeStyle Street Basketball™\\FreeStyle.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\common\\trackmania nations forever\\TmForever.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"17673:TCP"= 17673:TCP:BitComet 17673 TCP
"17673:UDP"= 17673:UDP:BitComet 17673 UDP
"22778:TCP"= 22778:TCP:BitComet 22778 TCP
"22778:UDP"= 22778:UDP:BitComet 22778 UDP
"25134:TCP"= 25134:TCP:BitComet 25134 TCP
"25134:UDP"= 25134:UDP:BitComet 25134 UDP
"27000:UDP"= 27000:UDP:port
"27001:UDP"= 27001:UDP:port

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-11 10:24]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-11 10:24]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-11 10:24]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-11 10:24]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-07-08 03:36:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-13 23:00:09 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKLM-Run-NBKeyScan - C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-14 16:52:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\searchindexer.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-07-14 16:56:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-14 21:56:00
ComboFix2.txt 2008-07-14 21:20:04

Pre-Run: 306,199,916,544 bytes free
Post-Run: 306,181,734,400 bytes free

247 — E O F — 2008-07-09 08:00:31
And new HijackThis log….I forgot to mention that after reboot, I got a Window security alert saying my virus protection is off, which it is.

Logfile of HijackThis v1.99.1
Scan saved at 17:02:35, on 7/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\program files\valve\steam\steam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66028
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1193323643687
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEC6C7BD-E9B5-4E58-B72C-517D1A3F701B}: NameServer = 192.168.0.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
We're not finished yet, but lets fix the time.

To set your time format in Windows XP go to the Start Button then select the Control Panel. In the Control Panel select the Regional and Language Options.

Now select the Customize button in the Standards and formats section, notice the legend for the different time formats on the bottom of the window. Now select the Time tab and then click on the drop down menu arrow next to the Time format box. You now have four different time display options to choose from, two are 12 hour time formats and two are 24 hour (military) type formats.

Choose the h:mm:ss tt select to change to the default windows format. Then click on Apply or OK to finalize your selection.
Thx Tate, fixed the time. Do you recommend SP3? And what about my virus protection being turned off after the reboot? Thank you again you have been awesome!

Thx Tate, fixed the time. Do you recommend SP3? And what about my virus protection being turned off after the reboot? Thank you again you have been awesome!

AVG8 should be running.
After doing the below, I'd try updating to SP3.


Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    Here's my usual all clean post

    Log looks good :D


    You need to create a new Clean restore point.

    Note: This will remove all previous Restore Points

    Click Start Menu > Run > copy and paste

    %SystemRoot%\System32\restore\rstrui.exe

    Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

    Double-click My Computer.
    Click the Tools menu, and then click Folder Options.
    Click the View tab.
    Check "Hide file extensions for known file types."
    Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
    Check "Hide protected operating system files."
    Click Apply, and then click OK.

    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:
    Note: I no longer suggest Zone Alarm

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI