This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] antivirus xp2008/popups/trogans HELP!

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

computer has antivirus xp 2008, redirects self to ad websites, can't turn on firewall or do ms updates. Ran avg, restarted and did HiJackThis. Here is the log. I appreciate any help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:33:10 AM, on 9/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\HPHipm09.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\EH422ZDB\HiJackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=63.199.37.11:3128;http=63.199.37.11:3128;https=63.199.37.11:3128;socks=63.19
9.37.11:3128
O2 - BHO: (no name) - {0076C234-2AE1-43E0-BE7F-12C145C36700} - C:\WINDOWS\system32\jkkHBTJc.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3CB3AD6C-464E-45B6-95EB-CCE9130CBC6E} - C:\WINDOWS\system32\mlJYolij.dll (file missing)
O2 - BHO: (no name) - {5BAA70E7-E291-4431-B5AB-DC10A2535619} - C:\WINDOWS\system32\opnmLdcY.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: agadoo browser enhancer - {77fb3526-e39b-5361-88f1-32849b15ec12} - C:\WINDOWS\system32\ohklkzsvqr.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: {587d3506-9163-d9d8-d6e4-353a6e742a8d} - {d8a247e6-a353-4e6d-8d9d-36196053d785} - C:\WINDOWS\system32\uyezmi.dll
O2 - BHO: (no name) - {E6E8BEE5-3075-4DF1-993D-BEF6343024B0} - C:\WINDOWS\system32\efcBtSli.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [{c78f3ec2-1103-a7cd-47ef-548d50ca235e}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\ohklkzsvqr.dll" DllStub
O4 - HKLM\..\Run: [33b0b847] rundll32.exe "C:\WINDOWS\system32\scklgqbd.dll",b
O4 - HKLM\..\Run: [BM30838bdb] Rundll32.exe "C:\WINDOWS\system32\qebmfuwg.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1192644168390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1192644151343
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll uyezmi.dll
O20 - Winlogon Notify: efcBtSli - efcBtSli.dll (file missing)
O20 - Winlogon Notify: jkkHBTJc - jkkHBTJc.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe

–
End of file - 10550 bytes
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.

jpshortstuff
Hi

Your copy of HijackThis needs to be in a folder of it's own. When HijackThis fixes anything, it makes backups of the original files in the folder it is in. For this reason it cannot be run from a Zip file or from Temporary folders because the backups will be deleted. Having the backups could be VITAL to restoring your system if something went wrong in the fix process!

1. Please go to your My Documents folder, right-click and select New > Folder then name the folder 'HJT'.

2. Copy and paste HijackThis.exe to the new folder.


You appear to have some Symantec related entries in your log. Are these remainders of a Symantec installation that you once had? You are already running AVG Anti-Virus, and you should not run more than one Anti-Virus at a time due to the problems it can cause, so I am just making sure.


Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Please open the AVG Control Center program -> double-click on the "AVG Resident Shield" component (looks like this: [external image: Posted Image]) -> deselect the "Turn on AVG Resident Shield" checkmark and save the setting.
When you need to enable the AVG Resident Shield, ( I'll let you know when) just open the AVG Control Center program -> double-click on the "AVG Resident Shield" component -> select the "Turn on AVG Resident Shield" checkmark and save the setting.

Windows Defender.

Open Windows Defender.

Click on Tools, General Settings.
Scroll down and uncheck Turn on real-time protection (recommended).
After you uncheck this, click on the Save button and close Windows Defender.

After all of the fixes are complete it is very important that you enable Real-time Protection again.

Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I need to see another log from HijackThis.
  • Run Hijackthis.
  • Click on Open the Misc Tools section.
  • Next click on Open uninstall manager.
  • Press the Save list button.
  • Save the file to your desktop, with the default name of uninstall_list
  • Copy & Paste the entire contents of that file in your in your next post.
Logs To Include In Your Next Reply:
  • ComboFix Log (C:\ComboFix.txt)
  • New HijackThis Log
  • HijackThis Uninstall List
Thanks.
I am having a hard time because the computer is REALLY acting up, so I am on another computer right now waiting for IE to load. Unfortunately I didn't save the HIJACKTHIS program, I just said to "run" it. Should I download it again, or do the other steps first?
Hi jpshortstuff!
I finally was able to run the pgms by copying them from another computer onto a thumb drive and install them that way. Here are my logs…the computer seems much better, at least as far as getting on the internet. Any other suggestions would be appreciated to keep this computer clean and running smoothly!
Thanks a bunch!

ComboFix 08-09-10.04 - HP_Owner 2008-09-11 11:02:43.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
C:\Documents and Settings\HP_Owner\Application Data\rhcnetj0e1sq
C:\Documents and Settings\HP_Owner\Cookies\[removed][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[removed][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[removed][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[removed][2].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@revsci[1].txt
C:\Documents and Settings\HP_Owner\Cookies\[removed][1].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@trafficmp[2].txt
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\BM30838bdb.txt
C:\WINDOWS\BM30838bdb.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aicuej.dll
C:\WINDOWS\system32\avrvhqwf.dll
C:\WINDOWS\system32\bxktsqdi.dll
C:\WINDOWS\system32\dbqglkcs.ini
C:\WINDOWS\system32\dnwhjynk.dll
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\ewelsvcu.ini
C:\WINDOWS\system32\gfkzfi.dll
C:\WINDOWS\system32\ictfqwii.dll
C:\WINDOWS\system32\izvjah.dll
C:\WINDOWS\system32\jiloYJlm.ini
C:\WINDOWS\system32\jiloYJlm.ini2
C:\WINDOWS\system32\jpgexrek.ini
C:\WINDOWS\system32\knyjhwnd.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\nwdvxw.dll
C:\WINDOWS\system32\odmvpals.ini
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qebmfuwg.dll
C:\WINDOWS\system32\rhvckwos.dll
C:\WINDOWS\system32\rjrnvqra.dll
C:\WINDOWS\system32\ryqudyqk.dll
C:\WINDOWS\system32\scklgqbd.dll
C:\WINDOWS\system32\slapvmdo.dll
C:\WINDOWS\system32\sqvnlmwk.dll
C:\WINDOWS\system32\suohbg.dll
C:\WINDOWS\system32\svncwbpy.ini
C:\WINDOWS\system32\tibfkcln.ini
C:\WINDOWS\system32\uuvwiudb.dll
C:\WINDOWS\system32\uyezmi.dll
C:\WINDOWS\system32\vkivkree.dll
C:\WINDOWS\system32\vvbfeais.ini
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\system32\xobqkace.dll
C:\WINDOWS\system32\YcdLmnpo.ini
C:\WINDOWS\system32\YcdLmnpo.ini2
C:\WINDOWS\system32\ypbwcnvs.dll
C:\WINDOWS\system32\yxekun.dll
C:\WINDOWS\system32\zxdnt3d.cfg
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-08-11 to 2008-09-11 )))))))))))))))))))))))))))))))
.

2008-09-11 06:30 . 2008-09-11 06:30 167,936 –a—— C:\WINDOWS\system32\ohklkzsvqr.dll
2008-09-04 11:06 . 2008-09-04 11:06 5,476 –a—— C:\WINDOWS\system32\etsqajea.dll
2008-08-29 12:01 . 2008-09-10 12:01 d–h—– C:\$AVG8.VAULT$
2008-08-29 11:55 . 2008-08-29 11:55 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-29 11:55 . 2008-08-29 11:55 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-29 11:55 . 2008-08-29 11:55 12,936 –a—— C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-08-29 11:55 . 2008-08-29 11:55 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-08-29 11:54 . 2008-09-11 10:06 d——– C:\WINDOWS\system32\drivers\Avg
2008-08-29 11:54 . 2008-08-29 11:54 d——– C:\Program Files\AVG
2008-08-29 11:54 . 2008-09-03 11:00 d——– C:\Documents and Settings\HP_Owner\Application Data\AVGTOOLBAR
2008-08-29 11:54 . 2008-08-29 11:54 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-08-29 09:09 . 2008-09-03 14:07 d——– C:\Program Files\rhcnetj0e1sq
2008-08-28 14:08 . 2008-09-11 10:23 71,817 –a—— C:\WINDOWS\system32\pxgkefadpjmupfflk.exe
2008-08-28 14:07 . 2008-09-04 14:39 d——– C:\WINDOWS\system32\wTR02
2008-08-28 14:07 . 2008-09-04 14:39 d——– C:\WINDOWS\system32\towl
2008-08-28 14:07 . 2008-09-04 14:38 d——– C:\WINDOWS\system32\sec
2008-08-28 14:07 . 2008-09-04 14:36 d——– C:\WINDOWS\system32\drives
2008-08-28 14:07 . 2008-08-28 14:08 d——– C:\Temp\dax41
2008-08-28 14:07 . 2008-09-11 11:05 d——– C:\Temp
2008-08-28 11:42 . 2008-08-28 11:42 d——– C:\WINDOWS\system32\scripting
2008-08-28 11:42 . 2008-08-28 11:42 d——– C:\WINDOWS\system32\en
2008-08-28 11:42 . 2008-08-28 11:42 d——– C:\WINDOWS\system32\bits
2008-08-28 11:42 . 2008-08-28 11:42 d——– C:\WINDOWS\l2schemas
2008-08-28 11:40 . 2008-08-28 11:42 d——– C:\WINDOWS\ServicePackFiles
2008-08-28 11:31 . 2008-08-28 11:31 d——– C:\WINDOWS\EHome
2008-08-25 09:47 . 2004-08-03 22:41 404,990 ——— C:\WINDOWS\system32\drivers\slntamr.sys
2008-08-25 09:46 . 2008-04-13 17:12 4,274,816 ——— C:\WINDOWS\system32\nv4_disp.dll
2008-08-25 09:45 . 2008-04-13 17:11 397,312 ——— C:\WINDOWS\system32\mmcex.dll
2008-08-25 09:45 . 2008-04-13 17:11 184,320 ——— C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-25 09:45 . 2008-04-13 17:11 106,496 ——— C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-25 09:45 . 2008-04-13 17:11 86,016 ——— C:\WINDOWS\system32\mdmxsdk.dll
2008-08-25 09:45 . 2008-04-13 17:12 33,792 ——— C:\WINDOWS\system32\mmcperf.exe
2008-08-25 09:45 . 2004-08-03 22:41 11,868 ——— C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-08-25 09:44 . 2008-04-13 17:11 61,440 ——— C:\WINDOWS\system32\kmsvc.dll
2008-08-25 09:44 . 2008-04-13 17:11 37,376 ——— C:\WINDOWS\system32\l2gpstore.dll
2008-08-25 09:44 . 2008-04-13 17:09 6,144 ——— C:\WINDOWS\system32\kbdpash.dll
2008-08-25 09:44 . 2008-04-13 17:09 6,144 ——— C:\WINDOWS\system32\kbdnepr.dll
2008-08-25 09:44 . 2008-04-13 17:09 6,144 ——— C:\WINDOWS\system32\kbdiultn.dll
2008-08-25 09:44 . 2008-04-13 17:09 6,144 ——— C:\WINDOWS\system32\kbdbhc.dll
2008-08-25 09:43 . 2004-08-03 22:41 1,041,536 ——— C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-08-25 09:43 . 2004-08-03 22:41 685,056 ——— C:\WINDOWS\system32\drivers\hsfcxts2.sys
2008-08-25 09:43 . 2004-08-03 22:41 220,032 ——— C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2008-08-25 09:43 . 2008-04-13 11:36 46,464 ——— C:\WINDOWS\system32\drivers\gagp30kx.sys
2008-08-25 09:43 . 2008-04-13 17:11 32,285 ——— C:\WINDOWS\system32\hsfcisp2.dll
2008-08-25 09:43 . 2008-04-13 11:46 25,600 ——— C:\WINDOWS\system32\drivers\hidbth.sys
2008-08-25 09:43 . 2008-04-13 11:45 19,200 ——— C:\WINDOWS\system32\drivers\hidir.sys
2008-08-25 09:43 . 2007-09-17 01:48 1,261 ——— C:\WINDOWS\system32\pid.inf
2008-08-25 09:41 . 2008-04-13 17:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-08-19 09:35 . 2008-07-18 22:07 270,880 –a—— C:\WINDOWS\system32\mucltui.dll
2008-08-18 10:18 . 2008-06-13 04:05 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-08-18 10:18 . 2008-06-13 04:05 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-18 10:16 . 2008-05-08 07:02 203,136 ——— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-08-18 10:15 . 2008-04-11 12:04 691,712 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-18 10:03 . 2008-07-18 22:07 29,728 –a—— C:\WINDOWS\system32\mucltui.dll.mui

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-10 21:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-09-10 21:17 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-08-28 18:49 61,440 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2008-08-28 18:49 45,056 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2008-08-28 18:49 44,032 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2008-08-28 18:49 40,960 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2008-08-28 18:49 32,768 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2008-08-28 18:49 32,768 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2008-08-28 18:49 287,310 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection.dll
2008-08-28 18:49 163,840 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
2006-08-23 19:07 426 —-a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
2004-08-04 12:00 94,784 –sh–w C:\WINDOWS\twain.dll
2008-04-14 00:12 50,688 –sh–w C:\WINDOWS\twain_32.dll
2004-07-30 15:04 1,216 –sh–w C:\WINDOWS\Twunk_16.dll
2004-07-30 15:04 1,216 –sh–w C:\WINDOWS\Twunk_32.dll
2006-01-06 16:47 22 –sha-w C:\WINDOWS\SMINST\HPCD.sys
2008-04-14 00:11 1,028,096 –sha-w C:\WINDOWS\system32\mfc42.dll
2008-04-14 00:12 57,344 –sh–w C:\WINDOWS\system32\msvcirt.dll
2008-04-14 00:12 413,696 –sha-w C:\WINDOWS\system32\msvcp60.dll
2008-04-14 00:12 343,040 –sha-w C:\WINDOWS\system32\msvcrt.dll
2008-04-14 00:12 551,936 –sh–w C:\WINDOWS\system32\oleaut32.dll
2008-04-14 00:12 84,992 –sh–w C:\WINDOWS\system32\olepro32.dll
2008-04-14 00:12 11,776 –sh–w C:\WINDOWS\system32\regsvr32.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77fb3526-e39b-5361-88f1-32849b15ec12}]
2008-09-11 06:30 167936 –a—— C:\WINDOWS\system32\ohklkzsvqr.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-03 68856]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-25 443968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-08 114688]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-15 180269]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-25 196608]
"HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" [2001-10-25 311296]
"CXMon"="C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-09-19 45056]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-15 98304]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 1235736]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-09-21 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-09-21 C:\WINDOWS\ALCWZRD.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
DING!.lnk - C:\Program Files\Southwest Airlines\Ding\Ding.exe [2006-06-22 462848]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll uyezmi.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-08-29 12936]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-29 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-29 76040]
R3 Dot4Usb HPH09;Dot4Usb HPH09;C:\WINDOWS\system32\drivers\hphius09.sys [2001-10-25 18864]
S1 bthportt;bthportt;C:\WINDOWS\system32\drivers\bthportt.sys [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{90dd7b50-1ae5-11dd-8bf2-0015f21d3e1c}]
\Shell\Auto\command - J:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

BHO-{0076C234-2AE1-43E0-BE7F-12C145C36700} - C:\WINDOWS\system32\jkkHBTJc.dll
BHO-{3CB3AD6C-464E-45B6-95EB-CCE9130CBC6E} - C:\WINDOWS\system32\mlJYolij.dll
BHO-{5BAA70E7-E291-4431-B5AB-DC10A2535619} - C:\WINDOWS\system32\opnmLdcY.dll
BHO-{d8a247e6-a353-4e6d-8d9d-36196053d785} - C:\WINDOWS\system32\uyezmi.dll
BHO-{E6E8BEE5-3075-4DF1-993D-BEF6343024B0} - C:\WINDOWS\system32\efcBtSli.dll
HKLM-Run-33b0b847 - C:\WINDOWS\system32\scklgqbd.dll
HKLM-Run-BM30838bdb - C:\WINDOWS\system32\qebmfuwg.dll
HKLM-Run-PCDrProfiler - (no file)
ShellExecuteHooks-{0076C234-2AE1-43E0-BE7F-12C145C36700} - C:\WINDOWS\system32\jkkHBTJc.dll
ShellExecuteHooks-{E6E8BEE5-3075-4DF1-993D-BEF6343024B0} - C:\WINDOWS\system32\efcBtSli.dll
Notify-efcBtSli - efcBtSli.dll
Notify-jkkHBTJc - jkkHBTJc.dll


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-Internet Settings,ProxyServer = ftp=63.199.37.11:3128;http=63.199.37.11:3128;https=63.199.37.11:3128;socks=63.19
9.37.11:3128
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
.
——- File Associations (Beta) ——-
.
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-11 11:12:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\system32\hphipm09.exe
.
**************************************************************************
.
Completion time: 2008-09-11 11:25:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-11 18:25:14

Pre-Run: 49,161,555,968 bytes free
Post-Run: 50,697,998,336 bytes free

287 — E O F — 2008-08-28 19:18:08
Logfile of HijackThis v1.99.1
Scan saved at 11:30:00 AM, on 9/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\hphmon03.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\ALCWZRD.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\HPHipm09.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\HP_Owner\My Documents\HJT\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=63.199.37.11:3128;http=63.199.37.11:3128;https=63.199.37.11:3128;socks=63.19
9.37.11:3128
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: agadoo browser enhancer - {77fb3526-e39b-5361-88f1-32849b15ec12} - C:\WINDOWS\system32\ohklkzsvqr.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1192644168390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1192644151343
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll uyezmi.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe

uninstall list:

ACDSee
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.5 Language Support
Adobe Reader 7.0.9
Agere Systems PCI Soft Modem
AT&T Yahoo! Applications
AVG 8.0
Barnyard Invasion from Hewlett-Packard Desktops (remove only)
Bejeweled 2 Deluxe from Hewlett-Packard Desktops (remove only)
Big Kahuna Reef from Hewlett-Packard Desktops (remove only)
Blackhawk Striker 2 from Hewlett-Packard Desktops (remove only)
Blasterball 2 from Hewlett-Packard Desktops (remove only)
Blasterball 2 Holidays from Hewlett-Packard Desktops (remove only)
Boggle Supreme from Hewlett-Packard Desktops (remove only)
Bookworm Deluxe from Hewlett-Packard Desktops (remove only)
Bounce Symphony from Hewlett-Packard Desktops (remove only)
Browser Extension Tool Agadoo
Compatibility Pack for the 2007 Office system
Crystal Maze from Hewlett-Packard Desktops (remove only)
Digby's Donuts from Hewlett-Packard Desktops (remove only)
DING!
Easy Internet Sign-up
FATE Demo from Hewlett-Packard Desktops (remove only)
Flip Words from Hewlett-Packard Desktops (remove only)
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB888111
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HP Boot Optimizer
HP Deskjet Printer Preload
HP Document Viewer 5.3
HP Game Console and games
HP Image Zone 5.3
HP Imaging Device Functions 5.3
HP Organize
HP Photo Imaging Software
HP Photo Printing Software
hp photosmart 1115 series
HP Photosmart 330,380,420,470,7800,8000,8200 Series
HP Photosmart Cameras 5.0
hp photosmart printer series (Remove only)
HP PSC & OfficeJet 5.3.B
HP Share-to-Web
HP Solution Center & Imaging Support Tools 5.3
Insaniquarium Deluxe from Hewlett-Packard Desktops (remove only)
Intel® Graphics Media Accelerator Driver
IntelliMover Data Transfer Demo
iTunes
J2SE Runtime Environment 5.0
J2SE Runtime Environment 5.0 Update 11
Java™ 6 Update 2
Java™ 6 Update 5
Java™ SE Runtime Environment 6 Update 1
Jewel Quest from Hewlett-Packard Desktops (remove only)
Macromedia Contribute 3.11
Macromedia Dreamweaver 8
Macromedia Extension Manager
Macromedia Fireworks 8
Macromedia Flash 8
Macromedia Flash 8 Video Encoder
Macromedia Flash Player 8
Macromedia Flash Player 8 Plugin
Mah Jong Quest from Hewlett-Packard Desktops (remove only)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2005
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSN
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
PC-Doctor 5 for Windows
Picasa 2
Polar Bowler from Hewlett-Packard Desktops (remove only)
Polar Golfer from Hewlett-Packard Desktops (remove only)
Puzzle Express from Hewlett-Packard Desktops (remove only)
QuickTime
RealPlayer
Realtek High Definition Audio Driver
Remove WeatherBug Installer
Ricochet Lost Worlds from Hewlett-Packard Desktops (remove only)
SCRABBLE Blast from Hewlett-Packard Desktops (remove only)
SCRABBLE from Hewlett-Packard Desktops (remove only)
SCRABBLE Rack Attack from Hewlett-Packard Desktops (remove only)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Shrek 2 Ogre Bowler from Hewlett-Packard Desktops (remove only)
Slingo Deluxe from Hewlett-Packard Desktops (remove only)
Slyder from Hewlett-Packard Desktops (remove only)
Sonic Express Labeler
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Super Granny from Hewlett-Packard Desktops (remove only)
Swarm from Hewlett-Packard Desktops (remove only)
Update for Windows XP (KB951072-v2)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
WildTangent Web Driver
Windows Communication Foundation
Windows Defender
Windows Imaging Component
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
Hi

To complete the uninstall of Symantec/Norton, click here:
http://service1.symantec.com/SUPPORT/tsgen…005033108162039
and follow the instructions for Download and run the Norton Removal Tool
You will download a tool and run it from your Desktop, and this will clean up the Norton installation.


Viewpoint Manager is often installed without the users permission. If you didn't install it, or if you did but you no longer use it, I recommend you get rid of it. Instructions to remove it are below, along with other programs I recommend you uninstall.

If you do not use WildTangent yourself, then I recommend you get rid of this as well (uninstall as with below instructions). More info on this can be found here:
http://www.pchell.com./support/wildtangent.shtml


Theres a few programs on your machine that I recommend you uninstall.

Please click Start >> Control Panel >> Add or Remove Programs.
Find each of the below items on the list and click remove on each one.
Browser Extension Tool Agadoo
J2SE Runtime Environment 5.0
J2SE Runtime Environment 5.0 Update 11
Java™ 6 Update 2
Java™ 6 Update 5
Java™ SE Runtime Environment 6 Update 1
Remove WeatherBug Installer
Viewpoint Manager (Remove Only)
Viewpoint Media Player
WildTangent Web Driver

Note: We will be installing the latest version of Java later on so you can remove all versions present now.


1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\ohklkzsvqr.dll
C:\WINDOWS\system32\etsqajea.dll
C:\WINDOWS\system32\pxgkefadpjmupfflk.exe

Folder::
C:\Program Files\rhcnetj0e1sq
C:\WINDOWS\system32\wTR02
C:\WINDOWS\system32\towl
C:\WINDOWS\system32\sec
C:\WINDOWS\system32\drives
C:\Temp
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Program Files\Common Files\Symantec Shared

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{77fb3526-e39b-5361-88f1-32849b15ec12}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{90dd7b50-1ae5-11dd-8bf2-0015f21d3e1c}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt.
Installing Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 7.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 7, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.

  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop.
  • Close any programs you may have running - especially any web browsers.
  • From your desktop double-click on jre-6u7-windowsi586.exe to install the newest version.
Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post the results of the Kaspersky scan in your next reply, along with a fresh HijackThis log. Also, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems.

Thanks.
Okay, hopefully I followed your directions correctly. Had trouble with the Kapersky part and the scan took forever (mostly MY fault). Here are the logs:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, September 18, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, September 17, 2008 19:12:25
Records in database: 1246182
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
K:\

Scan statistics:
Files scanned: 98507
Threat name: 6
Infected objects: 11
Suspicious objects: 0
Duration of the scan: 05:33:36


File name / Threat name / Threats count
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\autodown.exe Infected: Backdoor.Win32.Agobot.pnu 1
C:\Program Files\Online Services\AOL\United States\AOL90\comps\toolbar\toolbr.EXE Infected: not-a-virus:AdWare.Win32.SearchIt.t 1
C:\QooBox\Quarantine\C\WINDOWS\system32\izvjah.dll.vir Infected: Trojan.Win32.Monder.men 1
C:\QooBox\Quarantine\C\WINDOWS\system32\nwdvxw.dll.vir Infected: Trojan.Win32.Monder.mew 1
C:\QooBox\Quarantine\C\WINDOWS\system32\rhvckwos.dll.vir Infected: Trojan.Win32.Monder.men 1
C:\QooBox\Quarantine\C\WINDOWS\system32\rjrnvqra.dll.vir Infected: Trojan.Win32.Monder.mew 1
C:\QooBox\Quarantine\C\WINDOWS\system32\slapvmdo.dll.vir Infected: Trojan.Win32.Monder.mem 1
C:\QooBox\Quarantine\C\WINDOWS\system32\xobqkace.dll.vir Infected: Trojan.Win32.Monder.mew 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ypbwcnvs.dll.vir Infected: Trojan.Win32.Monder.mem 1
C:\QooBox\Quarantine\C\WINDOWS\system32\yxekun.dll.vir Infected: Trojan.Win32.Monder.mew 1
D:\I386\Apps\APP31758\src\HPSummer2005.exe Infected: not-a-virus:AdWare.Win32.MyWay.j 1

The selected area was scanned.

HIJACKTHIS LOG:
Logfile of HijackThis v1.99.1
Scan saved at 9:13:04 AM, on 9/18/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\hphmon03.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\WINDOWS\system32\HPHipm09.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\HP_Owner\My Documents\HJT\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=63.199.37.11:3128;http=63.199.37.11:3128;https=63.199.37.11:3128;socks=63.19
9.37.11:3128
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1192644168390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1192644151343
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll uyezmi.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
OH! I'm sorry! Here is the ComboFix log.

ComboFix 08-09-10.04 - HP_Owner 2008-09-15 12:15:39.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Owner\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\HP_Owner\Cookies\[removed][2].txt
C:\Program Files\Common Files\Symantec Shared
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
C:\Program Files\rhcnetj0e1sq
C:\Program Files\rhcnetj0e1sq\database.dat
C:\Program Files\rhcnetj0e1sq\license.txt
C:\Program Files\rhcnetj0e1sq\MFC71.dll
C:\Program Files\rhcnetj0e1sq\MFC71ENU.DLL
C:\Program Files\rhcnetj0e1sq\msvcp71.dll
C:\Program Files\rhcnetj0e1sq\msvcr71.dll
C:\Program Files\rhcnetj0e1sq\rhcnetj0e1sq.exe.local
C:\Temp
C:\Temp\dax41\A3G.log
C:\WINDOWS\system32\drives
C:\WINDOWS\system32\etsqajea.dll
C:\WINDOWS\system32\sec
C:\WINDOWS\system32\towl
C:\WINDOWS\system32\wTR02

.
((((((((((((((((((((((((( Files Created from 2008-08-15 to 2008-09-15 )))))))))))))))))))))))))))))))
.

2008-09-15 10:20 . 2008-09-15 10:20 d——– C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-08-29 12:01 . 2008-09-11 19:12 d–h—– C:\$AVG8.VAULT$
2008-08-29 11:55 . 2008-08-29 11:55 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-29 11:55 . 2008-08-29 11:55 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-29 11:55 . 2008-08-29 11:55 12,936 –a—— C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-08-29 11:55 . 2008-08-29 11:55 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-08-29 11:54 . 2008-09-15 08:59 d——– C:\WINDOWS\system32\drivers\Avg
2008-08-29 11:54 . 2008-08-29 11:54 d——– C:\Program Files\AVG
2008-08-29 11:54 . 2008-09-03 11:00 d——– C:\Documents and Settings\HP_Owner\Application Data\AVGTOOLBAR
2008-08-29 11:54 . 2008-08-29 11:54 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-08-28 11:42 . 2008-08-28 11:42 d——– C:\WINDOWS\system32\scripting
2008-08-28 11:42 . 2008-08-28 11:42 d——– C:\WINDOWS\system32\en
2008-08-28 11:42 . 2008-08-28 11:42 d——– C:\WINDOWS\system32\bits
2008-08-28 11:42 . 2008-08-28 11:42 d——– C:\WINDOWS\l2schemas
2008-08-28 11:40 . 2008-08-28 11:42 d——– C:\WINDOWS\ServicePackFiles
2008-08-28 11:31 . 2008-08-28 11:31 d——– C:\WINDOWS\EHome
2008-08-25 09:47 . 2004-08-03 22:41 404,990 ——— C:\WINDOWS\system32\drivers\slntamr.sys
2008-08-25 09:46 . 2008-04-13 17:12 4,274,816 ——— C:\WINDOWS\system32\nv4_disp.dll
2008-08-25 09:45 . 2008-04-13 17:11 397,312 ——— C:\WINDOWS\system32\mmcex.dll
2008-08-25 09:45 . 2008-04-13 17:11 184,320 ——— C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-25 09:45 . 2008-04-13 17:11 106,496 ——— C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-25 09:45 . 2008-04-13 17:11 86,016 ——— C:\WINDOWS\system32\mdmxsdk.dll
2008-08-25 09:45 . 2008-04-13 17:12 33,792 ——— C:\WINDOWS\system32\mmcperf.exe
2008-08-25 09:45 . 2004-08-03 22:41 11,868 ——— C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-08-25 09:44 . 2008-04-13 17:11 61,440 ——— C:\WINDOWS\system32\kmsvc.dll
2008-08-25 09:44 . 2008-04-13 17:11 37,376 ——— C:\WINDOWS\system32\l2gpstore.dll
2008-08-25 09:44 . 2008-04-13 17:09 6,144 ——— C:\WINDOWS\system32\kbdpash.dll
2008-08-25 09:44 . 2008-04-13 17:09 6,144 ——— C:\WINDOWS\system32\kbdnepr.dll
2008-08-25 09:44 . 2008-04-13 17:09 6,144 ——— C:\WINDOWS\system32\kbdiultn.dll
2008-08-25 09:44 . 2008-04-13 17:09 6,144 ——— C:\WINDOWS\system32\kbdbhc.dll
2008-08-25 09:43 . 2004-08-03 22:41 1,041,536 ——— C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-08-25 09:43 . 2004-08-03 22:41 685,056 ——— C:\WINDOWS\system32\drivers\hsfcxts2.sys
2008-08-25 09:43 . 2004-08-03 22:41 220,032 ——— C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2008-08-25 09:43 . 2008-04-13 11:36 46,464 ——— C:\WINDOWS\system32\drivers\gagp30kx.sys
2008-08-25 09:43 . 2008-04-13 17:11 32,285 ——— C:\WINDOWS\system32\hsfcisp2.dll
2008-08-25 09:43 . 2008-04-13 11:46 25,600 ——— C:\WINDOWS\system32\drivers\hidbth.sys
2008-08-25 09:43 . 2008-04-13 11:45 19,200 ——— C:\WINDOWS\system32\drivers\hidir.sys
2008-08-25 09:43 . 2007-09-17 01:48 1,261 ——— C:\WINDOWS\system32\pid.inf
2008-08-25 09:41 . 2008-04-13 17:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-08-19 09:35 . 2008-07-18 22:07 270,880 –a—— C:\WINDOWS\system32\mucltui.dll
2008-08-18 10:18 . 2008-06-13 04:05 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-08-18 10:18 . 2008-06-13 04:05 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-18 10:16 . 2008-05-08 07:02 203,136 ——— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-08-18 10:15 . 2008-04-11 12:04 691,712 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-18 10:03 . 2008-07-18 22:07 29,728 –a—— C:\WINDOWS\system32\mucltui.dll.mui

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 18:29 ——— d—–w C:\Program Files\Viewpoint
2008-09-15 18:23 ——— d—–w C:\Program Files\Yahoo!
2008-09-15 18:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\WildTangent
2008-09-15 18:20 ——— d—–w C:\Program Files\WildTangent
2008-09-15 18:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-15 18:13 ——— d—–w C:\Program Files\Java
2006-08-23 19:07 426 —-a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
2004-08-04 12:00 94,784 –sh–w C:\WINDOWS\twain.dll
2008-04-14 00:12 50,688 –sh–w C:\WINDOWS\twain_32.dll
2004-07-30 15:04 1,216 –sh–w C:\WINDOWS\Twunk_16.dll
2004-07-30 15:04 1,216 –sh–w C:\WINDOWS\Twunk_32.dll
2006-01-06 16:47 22 –sha-w C:\WINDOWS\SMINST\HPCD.sys
2008-04-14 00:11 1,028,096 –sha-w C:\WINDOWS\system32\mfc42.dll
2008-04-14 00:12 57,344 –sh–w C:\WINDOWS\system32\msvcirt.dll
2008-04-14 00:12 413,696 –sha-w C:\WINDOWS\system32\msvcp60.dll
2008-04-14 00:12 343,040 –sha-w C:\WINDOWS\system32\msvcrt.dll
2008-04-14 00:12 551,936 –sh–w C:\WINDOWS\system32\oleaut32.dll
2008-04-14 00:12 84,992 –sh–w C:\WINDOWS\system32\olepro32.dll
2008-04-14 00:12 11,776 –sh–w C:\WINDOWS\system32\regsvr32.exe
.

((((((((((((((((((((((((((((( snapshot@2008-09-11_11.24.39.75 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-09-15 05:45:58 16,901,168 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\MSO.DLL
+ 2007-08-29 08:19:24 1,654,648 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6215\OGL.DLL
- 2008-08-19 21:57:41 593,920 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-09-12 01:44:29 593,920 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-08-19 21:57:41 12,288 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-09-12 01:44:29 12,288 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-08-19 21:57:42 86,016 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-09-12 01:44:29 86,016 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-08-19 21:57:41 135,168 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-09-12 01:44:29 135,168 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-08-19 21:57:42 11,264 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-09-12 01:44:29 11,264 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-08-19 21:57:42 27,136 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-09-12 01:44:30 27,136 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-08-19 21:57:42 4,096 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-09-12 01:44:30 4,096 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-08-19 21:57:42 794,624 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-09-12 01:44:30 794,624 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-08-19 21:57:41 249,856 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-09-12 01:44:29 249,856 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-08-19 21:57:41 61,440 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-09-12 01:44:29 61,440 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-08-19 21:57:42 23,040 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-09-12 01:44:30 23,040 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-08-19 21:57:41 286,720 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-09-12 01:44:29 286,720 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-08-19 21:57:41 409,600 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-09-12 01:44:28 409,600 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-08-19 21:55:44 38,240 —-a-r C:\WINDOWS\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2008-09-12 01:45:09 38,240 —-a-r C:\WINDOWS\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2008-04-14 00:12:15 139,264 —-a-w C:\WINDOWS\system32\cscript.exe
+ 2008-05-07 09:07:23 135,168 —-a-w C:\WINDOWS\system32\cscript.exe
+ 2008-05-07 09:07:23 135,168 ——w C:\WINDOWS\system32\dllcache\cscript.exe
+ 2008-05-09 10:53:39 512,000 ——w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2008-05-09 10:53:39 180,224 ——w C:\WINDOWS\system32\dllcache\scrobj.dll
+ 2008-05-09 10:53:40 172,032 ——w C:\WINDOWS\system32\dllcache\scrrun.dll
+ 2008-05-09 10:53:40 430,080 ——w C:\WINDOWS\system32\dllcache\vbscript.dll
+ 2008-05-08 11:24:44 155,648 ——w C:\WINDOWS\system32\dllcache\wscript.exe
+ 2008-05-09 10:53:40 90,112 ——w C:\WINDOWS\system32\dllcache\wshext.dll
- 2008-04-14 00:11:56 512,000 —-a-w C:\WINDOWS\system32\jscript.dll
+ 2008-05-09 10:53:39 512,000 —-a-w C:\WINDOWS\system32\jscript.dll
- 2008-08-05 18:11:02 15,888,504 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-08-26 20:28:12 16,208,504 —-a-w C:\WINDOWS\system32\MRT.exe
- 2008-04-14 00:12:05 180,224 —-a-w C:\WINDOWS\system32\scrobj.dll
+ 2008-05-09 10:53:39 180,224 —-a-w C:\WINDOWS\system32\scrobj.dll
- 2008-04-14 00:12:05 172,032 —-a-w C:\WINDOWS\system32\scrrun.dll
+ 2008-05-09 10:53:40 172,032 —-a-w C:\WINDOWS\system32\scrrun.dll
- 2008-04-14 00:12:08 434,176 —-a-w C:\WINDOWS\system32\vbscript.dll
+ 2008-05-09 10:53:40 430,080 —-a-w C:\WINDOWS\system32\vbscript.dll
- 2006-10-19 05:47:20 295,936 ——w C:\WINDOWS\system32\wmpeffects.dll
+ 2008-06-25 01:12:58 295,936 ——w C:\WINDOWS\system32\wmpeffects.dll
- 2008-04-14 00:12:41 155,648 —-a-w C:\WINDOWS\system32\wscript.exe
+ 2008-05-08 11:24:44 155,648 —-a-w C:\WINDOWS\system32\wscript.exe
- 2008-04-14 00:12:10 90,112 —-a-w C:\WINDOWS\system32\wshext.dll
+ 2008-05-09 10:53:40 90,112 —-a-w C:\WINDOWS\system32\wshext.dll
+ 2008-04-15 17:47:33 1,724,416 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-03 68856]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-25 443968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-08 114688]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-15 180269]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-25 196608]
"HPHmon03"="C:\WINDOWS\system32\hphmon03.exe" [2001-10-25 311296]
"CXMon"="C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe" [2001-09-19 45056]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-15 98304]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-29 1235736]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-09-21 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-09-21 C:\WINDOWS\ALCWZRD.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
DING!.lnk - C:\Program Files\Southwest Airlines\Ding\Ding.exe [2006-06-22 462848]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll uyezmi.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-08-29 12936]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-29 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-29 76040]
R3 Dot4Usb HPH09;Dot4Usb HPH09;C:\WINDOWS\system32\drivers\hphius09.sys [2001-10-25 18864]
S1 bthportt;bthportt;C:\WINDOWS\system32\drivers\bthportt.sys [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 12:22:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-09-15 12:27:40
ComboFix-quarantined-files.txt 2008-09-15 19:27:34
ComboFix2.txt 2008-09-11 18:25:28

Pre-Run: 51,899,744,256 bytes free
Post-Run: 51,937,996,800 bytes free

245 — E O F — 2008-09-12 01:48:56
Hi

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
File::
D:\I386\Apps\APP31758\src\HPSummer2005.exe

Folder::
C:\Program Files\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\Cmdmapping]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"="avgrsstx.dll"

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\autodown.exe

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.

5. Please repeat steps 2-4 for the following files:
C:\Program Files\Online Services\AOL\United States\AOL90\comps\toolbar\toolbr.EXE

Did you have CA eTrust AntiVirus at any point? Have you removed the program? Please also let me know if you decided to Uninstall WildTangent.

Also, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems.

Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI