This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antivirus 2008..and more?

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I seemed to have fixed everything, but Internet explorer still won't startup and maybe some files were left from the virus.

Here's my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:11:33 PM, on 9/13/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\WINDOWS\System32\Cpl32ver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\drwtsn32.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.249.72.240:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Cpl32ver] C:\WINDOWS\System32\Cpl32ver.exe
O4 - HKLM\..\Run: [BM89636401] Rundll32.exe "C:\WINDOWS\system32\jexwceyo.dll",s
O4 - HKLM\..\Run: [8a50579d] rundll32.exe "C:\WINDOWS\system32\xchtdspb.dll",b
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [RegistryCleanerProMFCT] C:\Program Files\RegistryCleanerPro\RegistryCleanerPro.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: SnapDetect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O20 - AppInit_DLLs: hjiafo.dll goqyyp.dll
O22 - SharedTaskScheduler: lksdfj98w3rmsekfnaui3rgfdgf - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\gjm86akm34.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - C:\WINDOWS\system32\msinet.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 10685 bytes
Welcome MikeJones23

I will be helping you under the guidance of one of our expert coaches.
Please give me a little time to get back to you with instructions.

In the meantime please note the following:
  • Any recommendations made are for your computer problems only and should NOT be used on any other computer.
  • Please DO NOT run any scans/tools or other fixes unless I ask you to. This is very important for several reasons. Here are just two of them:
    1. The tools that we use are very powerful and can cause >>irreparable damage<< to your computer if not used correctly.
    2. Commercial scanners, for the most part can not completely remove some of the more "resistant" infections. This makes it much more difficult to get rid of completely.
  • If you get stuck or are unsure of something please ask for a further explanation, do not guess.
  • Continue to respond to this thread until I give you the All Clean!
Please Note: My instructions to you are checked by an expert prior to posting. This may cause a small delay between posts.
Thanks

Rename HiJackThis
  • Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to: C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
  • Right-click on HijackThis.exe & select Rename to
  • Rename to something like MikeJones.exe
  • Right click on MikeJones.exe & from the list click Create Shortcut then close the Explorer
  • Delete the old HijackThis shortcut
  • Double click the MikeJones.exe shortcut on your desktop to run the program then post back a new Hijackthis log.

Create an Uninstall List
  • Start HijackThis
  • Click on the Config button
  • Click on the Misc Tools button
  • Click on the Open Uninstall Manager button
  • Click on the Save list… button and specify where you would like to save this file
  • When you press the Save button a notepad will open with the contents of that file
  • Copy and paste the contents of that notepad here in your next reply
thanks for the help,

heres my logs:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:19 AM, on 9/14/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\Cpl32ver.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Trend Micro\HijackThis\MikeJones.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {47836122-9D2E-476C-9763-B1D366F704E1} - C:\WINDOWS\system32\urqPjHwT.dll
O2 - BHO: (no name) - {724D3DDA-5922-400B-992F-E10768EBC611} - (no file)
O2 - BHO: C:\WINDOWS\system32\gjm86akm34.dll - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\gjm86akm34.dll
O2 - BHO: (no name) - {EB9A278F-1DBC-4F39-84AF-7DF3610F6E15} - C:\WINDOWS\system32\vtUlIxWP.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Cpl32ver] C:\WINDOWS\System32\Cpl32ver.exe
O4 - HKLM\..\Run: [8a50579d] rundll32.exe "C:\WINDOWS\system32\xchtdspb.dll",b
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [BM89636401] Rundll32.exe "C:\WINDOWS\system32\jexwceyo.dll",s
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [RegistryCleanerProMFCT] C:\Program Files\RegistryCleanerPro\RegistryCleanerPro.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: SnapDetect.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O20 - AppInit_DLLs: hjiafo.dll goqyyp.dll
O20 - Winlogon Notify: urqPjHwT - C:\WINDOWS\SYSTEM32\urqPjHwT.dll
O22 - SharedTaskScheduler: lksdfj98w3rmsekfnaui3rgfdgf - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\gjm86akm34.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - C:\WINDOWS\system32\msinet.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 11844 bytes






2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
Activation Assistant for the 2007 Microsoft Office suites
Ad-Aware
Adobe Flash Player ActiveX
Adobe Reader 8
Adobe Shockwave Player 11
Apple Mobile Device Support
Apple Software Update
AudibleManager
AVG Anti-Spyware 7.5
AVS Video Converter 6
AVS4YOU Software Navigator 1.2
Battlefield 1942
Battlefield 1942: Secret Weapons of WWII
Battlefield 1942: The Road To Rome
Battlefield Vietnam™
Battlefield Vietnam: WW2 Mod
Blaze Media Pro
Blaze Media Pro
Bonjour
Browser Address Error Redirector
Command & Conquer Generals
Command & Conquer Red Alert 2
Command & Conquer Renegade
Command && Conquer Red Alert 2 - Yuri's Revenge
Command and ConquerTM Generals Zero Hour
Creative System Information
Creative ZEN
Diablo II
DivxToDVD 0.5.2b
eMachines Connect
eMachines Game Console
Express Burn
Ezonics Greeting Cam Deluxe
EZPhoto Browser
EZPhoto Tools
EZShowtime MMS
EZSuite For Video Chat Kit
EZVideo Chat 2.0
EZVideo Mail
Free WMA to MP3 Converter 1.16
Gamevance
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Updater
GTA2
Hamachi 1.0.2.5
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Intel® Graphics Media Accelerator Driver
iTunes
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Kaspersky Online Scanner
LimeWire 4.16.6
Macromedia Flash Player 8
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Microsoft WSE 2.0 SP3 Runtime
MSXML 4.0 SP2 (KB936181)
Musicmatch® Jukebox
neroxml
Open Video Converter version 3.22
OpenOffice.org Installer 1.0
Power2Go 5.0
PowerDVD
PunkBuster for Battlefield 1942
PunkBuster for Battlefield Vietnam
Quake 3 Arena Demo
QuickTime
REALTEK GbE & FE Ethernet PCI NIC Driver
Realtek High Definition Audio Driver
River Past Crazi Video
Security Update for 2007 Microsoft Office System (KB951596)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for Microsoft Office Excel 2007 (KB951546)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office system 2007 (KB951808)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office Word 2007 (KB950113)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Visio 2007 (KB947590)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
ShoqBox Buddy version 1.0
Soft Data Fax Modem with SmartCP
Spybot - Search & Destroy
Starcraft
Uniblue RegistryBooster 2009
Uniblue RegistryBooster 2009
Update for Office 2007 (KB946691)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
USB PC Camera
VCRedistSetup
Ventrilo Client
Viewpoint Media Player
VSO CopyToDVD 4
Westwood Shared Internet Components
Windows Backup Utility
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
Wolfenstein - Enemy Territory
Xilisoft AVI to DVD Converter
Xvid 1.1.3 final uninstall
ZENcast Organizer



Also one thing i've never seen before is the drwtsn32 running for every explorer I try to open, it's almost as if they're all there but drwtsns preventing me from seeing them. whatever it is, is also not allowing me to use automatic updates either, but every other internet-based program/process seems to run just fine.
WhattheTech P2P Policy
IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

LimeWire 4.16.6

I'd like you to read the WTT We Do Not Support Policy.
Go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

Disabling Programs That May Interfere With The Fix
You have one (or more) of these programs running on your machine. While this is a good thing, they may interfere with the next part of the fix for your problem.

AdAware
Spybot S&D (TeaTimer option)

But prior to doing the fix below with HijackThis they need to be turned off. A guide to do this can be found here
You can turn them back on once your machine is clean.

Fix HiJackThis Entries
  • Open HiJackThis
  • Click on do a system scan only
  • Place a checkmark next to these lines(if still present):

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {47836122-9D2E-476C-9763-B1D366F704E1} - C:\WINDOWS\system32\urqPjHwT.dll
O2 - BHO: (no name) - {724D3DDA-5922-400B-992F-E10768EBC611} - (no file)
O2 - BHO: C:\WINDOWS\system32\gjm86akm34.dll - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\gjm86akm34.dll
O2 - BHO: (no name) - {EB9A278F-1DBC-4F39-84AF-7DF3610F6E15} - C:\WINDOWS\system32\vtUlIxWP.dll
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Cpl32ver] C:\WINDOWS\System32\Cpl32ver.exe
O4 - HKLM\..\Run: [8a50579d] rundll32.exe "C:\WINDOWS\system32\xchtdspb.dll",b
O4 - HKLM\..\Run: [BM89636401] Rundll32.exe "C:\WINDOWS\system32\jexwceyo.dll",s
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - Global Startup: SnapDetect.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O20 - AppInit_DLLs: hjiafo.dll goqyyp.dll
O20 - Winlogon Notify: urqPjHwT - C:\WINDOWS\SYSTEM32\urqPjHwT.dll
O22 - SharedTaskScheduler: lksdfj98w3rmsekfnaui3rgfdgf - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\gjm86akm34.dll
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - C:\WINDOWS\system32\msinet.exe


  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

ATF Cleaner
Download ATF Cleaner here by Atribune.
Double-click ATF-Cleaner.exe to run the program
Under Main choose: Select All
Click the Empty Selected button
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button
NOTE: If you would like to keep your saved passwords, please click No at the prompt
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button
NOTE: If you would like to keep your saved passwords, please click No at the prompt
Click Exit on the Main menu to close the program.

ComboFix
Please visit this webpage for download links, and instructions for running the tool:
How To Use Combofix

Please ensure you read this guide carefully and install the Recovery Console first.
The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
Once installed, you should see a blue screen prompt that says: The Recovery Console was successfully installed.

Continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix
A guide to do this can be found here.
The ones that need to be closed/disabled are:
AVG 7.5 | Adaware | Spybot TeaTimer

  • Click Yes to allow ComboFix to continue scanning for malware
  • When the tool is finished, it will produce a report for you
Include the following reports for further review so we may continue cleaning the system:
C:\ComboFix.txt
New HijackThis log.

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall
Here's the logs:

Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:31:31 PM, on 9/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\MikeJones.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: C:\WINDOWS\system32\gjm86akm34.dll - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\gjm86akm34.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O22 - SharedTaskScheduler: lksdfj98w3rmsekfnaui3rgfdgf - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\gjm86akm34.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8079 bytes







ComboFix 08-09-15.01 - Owner 2008-09-15 17:07:04.1 - NTFSx86
Running from: F:\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Owner\Application Data\inst.exe
C:\Documents and Settings\Owner\Application Data\rhc3kbj0e166
C:\Program Files\Internet Explorer\setupapi.dll
C:\WINDOWS\ampkfst.dll
C:\WINDOWS\BM89636401.txt
C:\WINDOWS\BM89636401.xml
C:\WINDOWS\faceback.exe
C:\WINDOWS\foxflpd.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\actskn43.ocx
C:\WINDOWS\system32\atngnnms.dll
C:\WINDOWS\system32\bdlwaydc.ini
C:\WINDOWS\system32\bpsdthcx.ini
C:\WINDOWS\system32\cdyawldb.dll
C:\WINDOWS\system32\Cpl32ver.exe
C:\WINDOWS\system32\drivers\Oty38.sys
C:\WINDOWS\system32\eqxyyrec.dll
C:\WINDOWS\system32\gbiakhqs.dll
C:\WINDOWS\system32\goqyyp.dll
C:\WINDOWS\system32\hjiafo.dll
C:\WINDOWS\system32\ibhvahbb.dll
C:\WINDOWS\system32\iueetb.dll
C:\WINDOWS\system32\jexwceyo.dll
C:\WINDOWS\system32\Memman.vxd
C:\WINDOWS\system32\msinet.exe
C:\WINDOWS\system32\MSVolume.dll
C:\WINDOWS\system32\PWxIlUtv.ini
C:\WINDOWS\system32\PWxIlUtv.ini2
C:\WINDOWS\system32\scgikwkv.ini
C:\WINDOWS\system32\scmjwiak.dll
C:\WINDOWS\system32\skinboxer43.dll
C:\WINDOWS\system32\urqPjHwT.dll
C:\WINDOWS\system32\vkwkigcs.dll
C:\WINDOWS\system32\vlzemy.dll
C:\WINDOWS\system32\vtUlIxWP.dll
C:\WINDOWS\system32\winjjq32.dll
C:\WINDOWS\system32\xchtdspb.dll
C:\WINDOWS\system32\yayYqpoL.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_MSUPDATE
——-\Legacy_OTY38
——-\Service_msupdate
——-\Service_Oty38


((((((((((((((((((((((((( Files Created from 2008-08-15 to 2008-09-15 )))))))))))))))))))))))))))))))
.

2008-09-13 19:55 . 2008-09-13 19:55 14,336 –a—— C:\WINDOWS\system32\svchost.exe
2008-09-13 19:55 . 2008-09-13 19:55 14,336 –a–c— C:\WINDOWS\system32\dllcache\svchost.exe
2008-09-13 16:44 . 2008-09-13 20:15 d——– C:\Program Files\File Recover
2008-09-13 16:44 . 2008-08-05 18:58 44,544 –a—— C:\WINDOWS\system32\msxml4a.dll
2008-09-13 15:06 . 2008-09-13 15:25 d——– C:\Program Files\RegistryCleanerPro
2008-09-13 09:07 . 2008-09-13 09:07 d——– C:\Program Files\Mjcore
2008-09-13 09:03 . 2008-09-13 09:03 d——– C:\100120bf
2008-09-13 09:03 . 2008-09-13 09:03 133,248 –a—— C:\WINDOWS\system32\drivers\ethygqrv.sys
2008-09-13 09:02 . 2008-09-13 09:02 10,000 –a—— C:\WINDOWS\system32\gjm86akm34.dll
2008-09-13 08:02 . 2008-09-13 08:32 d——– C:\Program Files\SAV
2008-09-13 08:02 . 2008-09-05 19:32 165,888 –a—— C:\WINDOWS\system32\sav.cpl
2008-09-11 18:39 . 2008-09-11 18:39 d——– C:\Program Files\River Past
2008-09-11 18:39 . 2008-09-11 18:39 d——– C:\Program Files\Common Files\River Past
2008-09-11 18:39 . 2008-09-11 22:17 d——– C:\Documents and Settings\Owner\Application Data\River Past G5
2008-09-11 18:39 . 2008-09-11 22:17 d——– C:\Documents and Settings\All Users\Application Data\River Past G5
2008-09-11 18:39 . 2008-09-11 18:40 164,872 –a—— C:\WINDOWS\Crazi Video Uninstaller.exe
2008-09-10 16:32 . 2008-02-05 15:28 148,840 –a—— C:\WINDOWS\system32\DSKernel2.dll
2008-09-10 16:23 . 2008-09-10 16:23 d——– C:\WINDOWS\system32\windows media
2008-09-10 05:51 . 2008-09-10 05:51 118 –a—— C:\WINDOWS\system32\MRT.INI
2008-09-09 21:02 . 2008-09-09 21:02 d——– C:\Program Files\VideoConverter
2008-09-09 19:49 . 2008-09-09 19:50 d——– C:\Program Files\Blaze Media Pro
2008-09-09 19:49 . 2008-09-09 19:49 d–h-c— C:\Documents and Settings\All Users\Application Data\{436FF568-C03A-41B5-B97A-23CADCB7E6C9}
2008-09-08 21:34 . 2008-09-08 21:42 d——– C:\Documents and Settings\Owner\Application Data\Creative
2008-09-08 21:30 . 2000-05-21 20:58 647,872 –a—— C:\WINDOWS\system32\Mscomct2.ocx
2008-09-08 21:30 . 2006-10-05 18:17 53,248 ——— C:\WINDOWS\Ctregrun.exe
2008-09-08 21:29 . 2008-09-08 21:29 417,792 –a—— C:\WINDOWS\system32\awrdscdc.ax
2008-09-08 21:28 . 2008-09-08 21:29 d——– C:\Program Files\Audible
2008-09-08 21:27 . 2008-09-08 21:38 d——– C:\Documents and Settings\All Users\Application Data\Creative
2008-09-08 21:26 . 2008-09-08 21:26 d–h—– C:\Program Files\Creative Installation Information
2008-09-08 21:26 . 2008-09-08 21:30 d——– C:\Program Files\Creative
2008-09-08 21:26 . 2008-09-08 21:26 d——– C:\Program Files\Common Files\Creative
2008-09-08 21:26 . 1999-12-12 13:01 44,032 –a—— C:\WINDOWS\system32\CTSVCCDA.EXE
2008-09-08 21:26 . 1999-11-17 13:00 25,088 –a—— C:\WINDOWS\system32\CTSVCCTL.EXE
2008-08-25 20:13 . 2008-08-25 20:13 d——– C:\Documents and Settings\All Users\Application Data\VSO
2008-08-25 18:14 . 2008-08-25 18:14 45,056 –a—— C:\WINDOWS\system32\yaok.dll
2008-08-25 18:13 . 2008-08-25 18:13 45,056 –a—— C:\WINDOWS\system32\dwl32i.dll
2008-08-25 18:12 . 2008-08-25 18:12 45,056 –a—— C:\WINDOWS\system32\zwv32i.dll
2008-08-25 18:11 . 2008-08-25 18:11 45,056 –a—— C:\WINDOWS\system32\zav32i.dll
2008-08-25 18:11 . 2008-08-25 18:11 45,056 –a—— C:\WINDOWS\system32\zal32i.dll
2008-08-25 18:10 . 2008-08-25 18:10 45,056 –a—— C:\WINDOWS\system32\dro2.dll
2008-08-25 18:03 . 2008-08-25 18:03 d——– C:\Program Files\Xilisoft
2008-08-25 17:38 . 2008-08-25 18:03 d——– C:\Program Files\VSO
2008-08-25 17:38 . 2008-08-25 20:13 d——– C:\Documents and Settings\Owner\Application Data\Vso
2008-08-25 17:38 . 2008-08-25 17:38 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2008-08-25 17:38 . 2008-08-25 17:38 47,360 –a—— C:\Documents and Settings\Owner\Application Data\pcouffin.sys
2008-08-25 17:27 . 2008-08-25 17:27 d——– C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-08-25 17:27 . 2008-08-25 17:27 d——– C:\Documents and Settings\All Users\Application Data\NCH Software
2008-08-25 17:25 . 2008-08-25 17:25 d——– C:\Program Files\NCH Swift Sound
2008-08-19 02:03 . 2008-08-19 02:03 d——– C:\Documents and Settings\Owner\Application Data\AVS4YOU
2008-08-19 02:03 . 2008-08-19 02:03 d——– C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-08-19 02:02 . 2008-08-19 02:03 d——– C:\Program Files\Common Files\AVSMedia
2008-08-19 02:02 . 2008-08-25 17:43 d——– C:\Program Files\AVS4YOU
2008-08-19 02:02 . 2007-02-27 19:36 974,848 –a—— C:\WINDOWS\system32\mfc70.dll
2008-08-18 23:27 . 2008-08-18 23:27 d——– C:\Program Files\Xvid
2008-08-18 23:27 . 2007-06-28 18:52 765,952 –a—— C:\WINDOWS\system32\xvidcore.dll
2008-08-18 23:27 . 2007-06-28 18:54 180,224 –a—— C:\WINDOWS\system32\xvidvfw.dll
2008-08-18 23:27 . 2007-06-28 18:55 77,824 –a—— C:\WINDOWS\system32\xvid.ax
2008-08-18 23:23 . 2008-08-18 23:31 d——– C:\Program Files\SmartSoftVideoConverterPro
2008-08-18 23:18 . 2008-08-18 23:18 d——– C:\boilsoft_tmp
2008-08-18 23:16 . 2008-08-18 23:16 67 –a—— C:\WINDOWS\AVIConverter.INI
2008-08-17 14:31 . 2008-08-17 14:31 d——– C:\WINDOWS\system32\scripting
2008-08-17 14:31 . 2008-08-17 14:31 d——– C:\WINDOWS\system32\en
2008-08-17 14:31 . 2008-08-17 14:31 d——– C:\WINDOWS\system32\bits
2008-08-17 14:31 . 2008-08-17 14:31 d——– C:\WINDOWS\l2schemas
2008-08-17 14:29 . 2008-08-17 14:32 d——– C:\WINDOWS\ServicePackFiles
2008-08-17 14:23 . 2008-08-17 14:23 d——– C:\WINDOWS\EHome
2008-08-17 14:16 . 2008-04-13 20:11 1,888,992 –a—— C:\WINDOWS\system32\ati3duag.dll
2008-08-16 17:04 . 2008-08-16 17:04 d——– C:\Program Files\Gamevance
2008-08-15 03:01 . 2008-09-10 05:48 1,374 –a—— C:\WINDOWS\imsins.BAK

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.

2008-09-15 19:30 ——— d—–w C:\Documents and Settings\Owner\Application Data\Hamachi
2008-09-15 13:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-09-13 21:42 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-13 13:45 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-09-13 05:56 137,472 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-09-10 20:32 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-10 09:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-10 00:34 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-09-06 00:59 ——— d—–w C:\Program Files\Warcraft III
2008-08-19 15:02 ——— d—–w C:\Documents and Settings\Owner\Application Data\CyberLink
2008-08-19 05:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-08-12 17:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-12 17:07 ——— d—–w C:\Program Files\Lavasoft
2008-08-12 17:06 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-12 06:05 ——— d—–w C:\Program Files\Rockstar Games
2008-08-12 06:05 ——— d—–w C:\Program Files\directx
2008-08-12 02:34 ——— d—–w C:\Program Files\Wolfenstein - Enemy Territory
2008-08-11 20:51 ——— d—–w C:\Program Files\Hamachi
2008-08-11 20:49 25,280 —-a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-08-11 19:30 ——— d—–w C:\Program Files\Google
2008-08-10 18:13 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-10 10:27 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-08-08 07:39 ——— d—–w C:\Program Files\Common Files\Nero
2008-08-08 07:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-08-08 06:56 ——— d—–w C:\Documents and Settings\Owner\Application Data\Nero
2008-08-08 00:10 ——— d—–w C:\Program Files\EA GAMES
2008-08-07 22:47 ——— d—–w C:\Program Files\Burn CD
2008-08-06 22:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-06 11:58 ——— d—–w C:\Program Files\DAEMON Tools Lite
2008-08-06 11:54 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-08-06 11:54 ——— d—–w C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-08-05 19:51 ——— d—–w C:\Program Files\Diablo II
2008-08-05 03:12 ——— d—–w C:\Program Files\Sun
2008-08-05 03:12 ——— d—–w C:\Program Files\Java
2008-07-31 08:40 ——— d—–w C:\Program Files\Command and Conquer Renegade
2008-06-29 01:56 94,208 —-a-w C:\WINDOWS\DIIUnin.exe
2008-06-29 01:56 2,829 —-a-w C:\WINDOWS\DIIUnin.pif
2007-08-10 02:27 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
2007-12-25 14:17 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012007122520071226\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5BF49A2-94F3-42BD-F434-3604812C897D}]
2008-09-13 09:02 10000 –a—— C:\WINDOWS\system32\gjm86akm34.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-11 39408]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-01-20 2321600]
"Jnskdfmf9eldfd"="C:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe" [2008-09-15 22025]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-06 114688]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 94208]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-11-29 58928]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2005-05-10 11776]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-05-10 110592]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 C:\WINDOWS\RTHDCPL.exe]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2008-08-11 624416]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFolderOptions"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{C5BF49A2-94F3-42BD-F434-3604812C897D}"= "C:\WINDOWS\system32\gjm86akm34.dll" [2008-09-13 10000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"VIDC.NSVI"= nsvideo.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"RegistryCleanerProMFCT"=C:\Program Files\RegistryCleanerPro\RegistryCleanerPro.exe
"Uniblue RegistryBooster 2009"=C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Q3Ademo\\quake3.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield Vietnam\\bfvietnam.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Westwood\\RA2\\game.exe"=
"C:\\Westwood\\RA2\\gamemd.exe"=
"C:\\Westwood\\RA2\\Ra2.exe"=
"C:\\Westwood\\Renegade\\Game.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\EA GAMES\\Command and Conquer Generals\\game.dat"=
"C:\\Program Files\\EA GAMES\\Command and Conquer Generals\\patchget.dat"=
"C:\\Program Files\\EA GAMES\\Command & Conquer Generals Zero Hour\\game.dat"=
"C:\\Program Files\\EA GAMES\\Command and Conquer Generals\\generals.exe"=
"C:\\Program Files\\EA GAMES\\Command and Conquer Generals\\WorldBuilder.exe"=
"C:\\Program Files\\DAEMON Tools Lite\\daemon.exe"=
"C:\\Program Files\\Hamachi\\hamachi.exe"=
"C:\\Program Files\\Rockstar Games\\GTA2\\gta2.exe"=
"C:\\Program Files\\Rockstar Games\\GTA2\\gta2 manager.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\River Past\\Crazi Video\\CraziVideo.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S0 tclondrv;tclondrv;C:\WINDOWS\system32\DRIVERS\tclondrv.sys [ ]
S1 ethygqrv;ethygqrv;C:\WINDOWS\system32\drivers\ethygqrv.sys [2008-09-13 133248]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;C:\WINDOWS\system32\DRIVERS\el575nd5.sys [2001-08-17 69692]
S3 restore;restore;C:\WINDOWS\system32\drivers\restore.sys [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{abcdc963-46e0-11dc-9731-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df53717d-4af7-11dc-831d-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKLM-Run-BigFix - c:\program files\Bigfix\bigfix.exe
HKLM-Run-NBKeyScan - C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
HKLM-Run-NeroFilterCheck - C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
HKLM-Run-UnlockerAssistant - C:\Program Files\Unlocker\UnlockerAssistant.exe
HKLM-Run-BM89636401 - C:\WINDOWS\system32\atngnnms.dll
HKLM-Run-8a50579d - C:\WINDOWS\system32\vkwkigcs.dll
ShellExecuteHooks-{47836122-9D2E-476C-9763-B1D366F704E1} - C:\WINDOWS\system32\urqPjHwT.dll


.
——- Supplementary Scan ——-
.
R1 -: HKCU-Internet Settings,ProxyOverride =
O8 -: E&xport to Microsoft Excel
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 17:15:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-15 17:19:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-15 21:19:25

Pre-Run: 23,180,943,360 bytes free
Post-Run: 23,456,460,800 bytes free

307 — E O F — 2008-09-11 10:23:42


It looks like it fixed pretty much all the problems i was having.

see anything else?
Hello MikeJones 23
Your logs are looking better however we still have some work to do. Your machine was a lot more infected than you may have thought. Bare in mind that a lack of symptons does not mean your pc is clean.

You have not installed the Recovery Console. The Recovery Console is essential should something go wrong & we need to repair your system. The instructions below are the easiest way to install the Recovery Console. Please do so now.

Make sure Combofix.exe is on your desktop
Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System

[external image: Posted Image]

Download the file & save it as it's originally named, next to ComboFix.exe.

[external image: Posted Image]

Now close all open windows and programs, including all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Drag the setup package onto ComboFix.exe and drop it.
  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.
  • At the next prompt, click No to exit.
    [external image: Posted Image]

CFScript
Close any open browsers.
Open notepad and copy/paste the text in the code box below into it:

File::
C:\WINDOWS\system32\gjm86akm34.dll
C:\WINDOWS\system32\sav.cpl
C:\WINDOWS\system32\yaok.dll
C:\WINDOWS\system32\dwl32i.dll
C:\WINDOWS\system32\zwv32i.dll
C:\WINDOWS\system32\zav32i.dll
C:\WINDOWS\system32\zal32i.dll
C:\WINDOWS\system32\dro2.dll
C:\WINDOWS\imsins.BAK
C:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
C:\WINDOWS\system32\drivers\ethygqrv.sys

Folder::
C:\Program Files\Mjcore
C:\100120bf
C:\Program Files\SAV
C:\Documents and Settings\All Users\Application Data\{436FF568-C03A-41B5-B97A-23CADCB7E6C9}

Driver::
ethygqrv

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5BF49A2-94F3-42BD-F434-3604812C897D}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Jnskdfmf9eldfd"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFolderOptions"=dword:00000000
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{C5BF49A2-94F3-42BD-F434-3604812C897D}"=-
Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Fix HiJackThis Entries
  • Open HiJackThis
  • Click on do a system scan only
  • Place a checkmark next to these lines(if still present):

O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

To post in next reply:
Combofix log
New HijackThis log
hey sorry for the extra trouble :( , but yesterday my computer constantly kept restarting and eventually made it to my desktop, and there it only showed the wallpaper and disabled any form of navigation through my computer (windows task manager, cds/usbs, etc) and I didn't feel like going through anything complicated so I decided to do a partial system recovery. anyways I knew this wasn't going to fix the problem, so obviously i'm still going to need your help.

Here's the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:29:34 AM, on 9/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Spare Backup\SpareBackup.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…DTP&M=W3622
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M=W3622
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…DTP&M=W3622
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [inrhc3kbj0e166] C:\WINDOWS\Temp\.tt3A.tmp.exe /CR=43125078F4C989AE533E84C6C62B1F51B588EDF10AF59D524AA980DBF6771C6117DAFB5E88FC9
B46B7B521BC52FD08B06C60239A6C5851E34B6FC1FBE0181D64E32FC939677C8C472EDA03F6D9620
B
3E2C0582
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [\YUR1A.exe] C:\Windows\system32\YUR1A.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR1B.exe] C:\Windows\system32\YUR1B.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR1C.exe] C:\Windows\system32\YUR1C.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR1D.exe] C:\Windows\system32\YUR1D.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [\YUR1E.exe] C:\Windows\system32\YUR1E.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [\YUR1A.exe] C:\Windows\system32\YUR1A.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 4862 bytes

as of now I have to click system restore to load my desktop (which i'm pretty sure is from the YURs) and half the places I go on the net is redirected to a different website. don't worry about disabling ad-aware, i dsiabled it incase I have to use combofix again.

also thanks for the help so far, I appreciate it.
Hello MikeJones23
Yes you have picked up some other junk. I don't see your Anti-virus (AVG 7.5) in your last HijackThis log. I think we need to re-enable it. I will let you know when to turn it off again.
Until your computer is clean & before we go any further I need to stress the importance of not downloading anything unless I ask you to, don't install anything, don't surf the net & follow my instructions otherwise we'll be chasing our tail.
Did you run the CFScript before this latest infection? If so I need to see the most recent Combofix log.
To open the ComboFix log, go to Start > Run > type Notepad C:\combofix.txt
In Notepad, click Edit > Select All then Edit > Copy
Paste (Ctrl+V) the content with your next reply.
well I reinstalled newest version of avg (it said v7.5 was no longer avialable) and spybot s&d, but with teamtimer, etc. disabled. since I did the semi-recovery (aka w/ backup). It made me redownload some of the programs i had before. this versions alot different, so i'm assuming I should just disable all of the components when you tell me to disable it again. oh and no I didn't run the script, I saw the post after I had already done the recovery, so I wasn't too sure if I still should've done it.

here's a more recent hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:44:15 AM, on 9/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Spare Backup\SpareBackup.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…DTP&M=W3622
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M=W3622
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…DTP&M=W3622
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: duplex - duplex.dll (file missing)
O20 - Winlogon Notify: imod3 - C:\WINDOWS\SYSTEM32\imod3.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 5124 bytes

so what should I do now, get a recent combofix log?
Hello MikeJones23
We'll leave the CFScript for now but I'll get you to run Combofix again using the instructions set out below:
  • Temporarily disable AVG & Ad-Aware
  • Click Start>Run, type Combofix /F3M into the Run box then click OK
  • This will allow Combofix to run in a limited capacity
  • When finished it will produce a log at C:\Combofix.txt
  • Copy & paste the contents of Combofix.txt in to your next reply along with a new HijackThis log
Here you go:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:51:55 AM, on 9/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Spare Backup\SpareBackup.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M=W3622
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: imod3 - C:\WINDOWS\SYSTEM32\imod3.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 4625 bytes













ComboFix 08-09-19.02 - Owner 2008-09-20 4:38:00.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: /f3m
.
((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.

2008-09-19 10:33 . 2008-09-19 10:33 154 –a—— C:\WINDOWS\wininit.ini
2008-09-19 09:23 . 2008-09-19 09:25 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-19 09:23 . 2008-09-19 10:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-19 08:23 . 2008-09-19 09:23 d–h—– C:\$AVG8.VAULT$
2008-09-19 08:13 . 2008-09-19 08:24 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\AVGTOOLBAR
2008-09-19 08:11 . 2008-09-20 04:06 d——– C:\WINDOWS\system32\drivers\Avg
2008-09-19 08:11 . 2008-09-19 08:11 d——– C:\Program Files\AVG
2008-09-19 08:11 . 2008-09-19 09:15 d——– C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-09-19 08:11 . 2008-09-19 11:13 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-09-19 08:11 . 2008-09-19 08:11 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-19 08:11 . 2008-09-19 08:11 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-19 08:11 . 2008-09-19 08:11 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-09-19 07:44 . 2008-09-19 07:44 0 –a—— C:\WINDOWS\nsreg.dat
2008-09-18 10:28 . 2008-09-18 10:28 18,432 –a—— C:\WINDOWS\system32\00setup.exe
2008-09-18 10:28 . 2008-09-18 10:28 5,136 –a—— C:\WINDOWS\system32\imod3.dll
2008-09-17 15:33 . 2008-09-17 15:33 d——– C:\Program Files\Microsoft Silverlight
2008-09-17 15:19 . 2008-09-17 15:19 d——– C:\Program Files\Windows Media Components
2008-09-17 15:14 . 2008-09-17 15:15 d——– C:\Documents and Settings\Owner\Application Data\Ventrilo
2008-09-17 15:14 . 2008-09-19 09:05 d——– C:\Documents and Settings\Owner\Application Data\Hamachi
2008-09-17 15:06 . 2008-09-17 15:06 d——– C:\Program Files\Xilisoft
2008-09-17 15:06 . 2008-09-17 15:06 d——– C:\Program Files\Trend Micro
2008-09-17 15:04 . 2008-09-17 15:05 d——– C:\Program Files\Warcraft III
2008-09-17 14:25 . 2008-09-17 15:35 d——– C:\Program Files\Beston
2008-09-17 14:20 . 2008-09-17 14:35 137,472 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-09-17 14:20 . 2008-09-17 14:35 111,928 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2008-09-17 14:19 . 2008-09-17 14:19 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Program Files\Lavasoft
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-17 10:30 . 2008-09-17 10:30 d——– C:\Documents and Settings\Owner\Application Data\AdwareAlert
2008-09-17 09:54 . 2008-09-16 18:34 372,736 –a—— C:\WINDOWS\vmgspntbqvm.dll
2008-09-17 09:54 . 2008-09-16 18:34 135,168 –a—— C:\WINDOWS\exsv.exe
2008-09-17 09:18 . 2008-09-19 09:13 7 –a—— C:\WINDOWS\system32\nxg.bin
2008-09-17 08:57 . 2008-09-17 08:57 199,168 –a—— C:\WINDOWS\system32\71.tmp
2008-09-17 08:57 . 2008-09-17 08:57 73,728 –a—— C:\WINDOWS\system32\72.tmp
2008-09-17 08:57 . 2008-09-17 08:57 36,452 –a—— C:\WINDOWS\system32\70.tmp
2008-09-17 08:57 . 2008-09-17 08:57 132 –a—— C:\WINDOWS\system32\6F.tmp
2008-09-17 08:57 . 2008-09-17 08:57 0 –a—— C:\WINDOWS\system32\73.tmp
2008-09-17 08:56 . 2008-09-17 14:11 d——– C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-09-17 08:55 . 2008-04-17 13:12 107,368 –a—— C:\WINDOWS\system32\GEARAspi.dll
2008-09-17 08:55 . 2008-04-17 13:12 15,464 –a—— C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-09-17 08:54 . 2008-09-17 15:42 d——– C:\Program Files\iTunes
2008-09-17 08:54 . 2008-09-17 14:28 d——– C:\Program Files\iPod
2008-09-17 08:54 . 2008-09-17 08:55 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-17 08:53 . 2008-09-17 08:53 d——– C:\Program Files\Bonjour
2008-09-17 08:51 . 2008-09-17 08:53 d——– C:\Program Files\QuickTime
2008-09-17 08:51 . 2008-09-17 08:54 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-17 08:50 . 2008-09-17 08:50 d——– C:\Program Files\Apple Software Update
2008-09-17 08:49 . 2008-09-17 08:52 d——– C:\Program Files\Common Files\Apple
2008-09-17 08:48 . 2008-09-17 08:48 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-09-17 08:44 . 2008-09-19 11:35 53,285 –a—— C:\WINDOWS\system32\tdssinit.dll
2008-09-17 08:44 . 2008-09-17 08:44 32,768 –a—— C:\WINDOWS\system32\tdssadw.dll
2008-09-17 08:44 . 2008-09-17 08:44 17,920 –a—— C:\WINDOWS\system32\tdssl.dll
2008-09-17 08:44 . 2008-09-17 08:44 12,288 –a—— C:\WINDOWS\system32\tdssserf.dll
2008-09-17 08:44 . 2008-09-17 08:44 11,264 –a—— C:\WINDOWS\system32\tdsslog.dll
2008-09-17 08:44 . 2008-09-17 08:44 10,240 –a—— C:\WINDOWS\system32\tdssmain.dll
2008-09-17 08:44 . 2008-09-17 08:44 254 –a—— C:\WINDOWS\system32\tdssservers.dat
2008-09-17 08:39 . 2008-09-17 08:39 8,592 –a—— C:\WINDOWS\system32\dplx.sys
2008-09-17 08:39 . 2008-09-17 08:39 132 –a—— C:\WINDOWS\system32\12.tmp
2008-09-17 08:39 . 2008-09-17 08:39 18 –a—— C:\WINDOWS\system32\16.tmp
2008-09-17 08:39 . 2008-09-19 11:34 7 –a—— C:\WINDOWS\system32\k86.bin
2008-09-17 08:38 . 2008-09-17 08:38 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-17 08:36 . 2008-09-17 08:36 d——– C:\Program Files\River Past
2008-09-17 08:36 . 2008-09-17 08:36 d——– C:\Program Files\Common Files\River Past
2008-09-17 08:36 . 2008-09-17 09:44 d——– C:\Documents and Settings\Owner\Application Data\River Past G5
2008-09-17 08:36 . 2008-09-17 09:44 d——– C:\Documents and Settings\All Users\Application Data\River Past G5
2008-09-17 08:36 . 2008-09-17 08:36 164,872 –a—— C:\WINDOWS\Crazi Video Uninstaller.exe
2008-09-17 08:29 . 2008-09-17 10:05 d——– C:\Documents and Settings\Owner\Incomplete
2008-09-17 03:00 . 2008-09-17 03:00 d——– C:\Program Files\MSXML 4.0
2008-09-16 01:30 . 2008-09-17 10:05 d——– C:\Documents and Settings\Owner\Shared
2008-09-16 01:27 . 2008-09-16 11:29 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-16 01:27 . 2008-06-13 09:10 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-09-16 01:27 . 2008-06-13 09:10 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-16 01:26 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-16 01:26 . 2008-06-23 12:57 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-09-16 01:23 . 2004-08-04 15:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-09-16 01:22 . 2006-07-01 01:30 d——– C:\WINDOWS\system32\config\systemprofile\WINDOWS
2008-09-16 01:22 . 2008-09-16 00:59 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\Spare Backup
2008-09-16 01:22 . 2008-09-16 00:56 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
2008-09-16 01:22 . 2006-07-01 01:30 d——– C:\Documents and Settings\Default User\WINDOWS
2008-09-16 01:03 . 2008-09-16 01:03 8,192 –a—— C:\WINDOWS\REGLOCS.OLD
2008-09-16 00:59 . 2008-09-16 00:59 333 –a—— C:\WINDOWS\system32\$ncsp$.inf
2008-09-16 00:59 . 2008-09-16 00:59 0 –a—— C:\WINDOWS\system32\Gateway_W3622_3.1_0000.MRK
2008-09-16 00:58 . 2008-09-16 00:58 940,794 –a—— C:\WINDOWS\system32\LoopyMusic.wav
2008-09-16 00:58 . 2008-09-16 00:58 146,650 –a—— C:\WINDOWS\system32\BuzzingBee.wav
2008-09-16 00:57 . 2006-10-06 00:09 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2008-09-16 00:56 . 2008-09-16 00:56 d——– C:\Documents and Settings\Owner\Application Data\SampleView
2008-09-16 00:54 . 2006-12-19 17:52 8,453,632 –a–c— C:\WINDOWS\system32\dllcache\shell32.dll
2008-09-16 00:54 . 2006-12-19 17:52 134,656 –a–c— C:\WINDOWS\system32\dllcache\shsvcs.dll
2008-09-16 00:52 . 2006-11-27 10:54 539,136 –a–c— C:\WINDOWS\system32\dllcache\msftedit.dll
2008-09-16 00:52 . 2006-11-27 10:54 433,152 –a–c— C:\WINDOWS\system32\dllcache\riched20.dll
2008-09-16 00:51 . 2006-08-21 05:14 128,896 –a–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-09-16 00:51 . 2006-08-21 05:14 30,720 –a–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-09-16 00:51 . 2006-08-21 08:21 16,896 –a–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-09-16 00:50 . 2006-06-22 01:06 1,435,648 –a–c— C:\WINDOWS\system32\dllcache\query.dll
2008-09-16 00:50 . 2008-05-08 08:28 202,752 –a–c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-16 00:50 . 2006-06-22 01:06 69,120 –a–c— C:\WINDOWS\system32\dllcache\ciodm.dll
2008-09-16 00:49 . 2006-04-21 02:12 332,800 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-09-16 00:49 . 2006-06-22 06:47 181,248 –a–c— C:\WINDOWS\system32\dllcache\rasmans.dll
2008-09-16 00:49 . 2008-06-20 13:41 148,992 –a–c— C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-09-16 00:49 . 2006-05-19 08:59 111,616 –a–c— C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
2008-09-16 00:49 . 2006-05-19 08:59 94,720 –a–c— C:\WINDOWS\system32\dllcache\iphlpapi.dll
2008-09-16 00:48 . 2004-09-03 19:07 28,672 –a—— C:\WINDOWS\system32\Marker32.exe
2008-09-16 00:47 . 2008-09-16 00:47 d——– C:\Program Files\Spare Backup
2008-09-16 00:47 . 2008-09-16 00:47 d——– C:\Program Files\Microsoft WSE
2008-09-16 00:47 . 2008-09-20 04:36 d——– C:\Documents and Settings\Owner\Application Data\Spare Backup
2008-09-16 00:46 . 2008-09-16 00:46 d——– C:\McAfee
2008-09-16 00:46 . 2007-04-23 06:14 364,160 –a–c— C:\WINDOWS\system32\dllcache\update.sys
2008-09-16 00:44 . 2007-02-28 05:55 2,182,144 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-09-16 00:44 . 2007-02-28 05:53 2,137,600 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-09-16 00:44 . 2007-02-28 05:15 2,017,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-09-16 00:44 . 2007-03-17 09:43 292,864 –a–c— C:\WINDOWS\system32\dllcache\winsrv.dll
2008-09-16 00:44 . 2007-02-05 16:17 185,344 –a–c— C:\WINDOWS\system32\dllcache\upnphost.dll
2008-09-16 00:44 . 2007-03-09 09:58 57,344 –a–c— C:\WINDOWS\system32\dllcache\agentdpv.dll
2008-09-16 00:43 . 2008-09-16 01:34 d——– C:\Program Files\BigFix
2008-09-16 00:43 . 2007-03-08 09:47 1,843,584 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-09-16 00:43 . 2007-03-08 11:36 577,536 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-09-16 00:43 . 2007-03-08 11:36 281,600 –a–c— C:\WINDOWS\system32\dllcache\gdi32.dll
2008-09-16 00:43 . 2007-03-08 11:36 40,960 –a–c— C:\WINDOWS\system32\dllcache\mf3216.dll
2008-09-16 00:43 . 2006-11-16 19:05 11,816 –a—— C:\WINDOWS\BigFixClientOverride.dll
2008-09-16 00:42 . 2008-09-16 11:18 d——– C:\Program Files\eMachines Games
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Program Files\NetZero
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 07:54 ——— d—–w C:\Program Files\Diablo II
2008-09-17 19:15 ——— d—–w C:\Program Files\Ventrilo
2008-09-17 18:55 ——— d—–w C:\Program Files\Q3Ademo
2008-09-17 18:20 ——— d—–w C:\Program Files\Wolfenstein - Enemy Territory
2008-09-15 23:05 ——— d—–w C:\Program Files\Starcraft
2008-08-12 06:05 ——— d—–w C:\Program Files\Rockstar Games
2008-08-08 00:10 ——— d—–w C:\Program Files\EA GAMES
.

——- Sigcheck ——-

2004-08-04 15:00 1039872 6beed988649566e49c3fb63dec564c3c C:\WINDOWS\explorer.exe
2008-04-13 20:12 1041408 6ce19208891e9dc85b46ec32ea3fa3e9 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe

2008-04-13 20:12 23040 7994d694ec2fb339baff2e50925e62cf C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 15:00 23040 8f95a0995a14394008f0415fa5aceaac C:\WINDOWS\system32\ctfmon.exe

2008-04-13 20:12 33792 66f69cf680ee53f7751ab7bd8490c797 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 15:00 32256 72eadc55ba014923295f84aba5361d50 C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23040]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 1675264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 106496]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 102400]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 221184]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 65120]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-11-29 58928]
"Spare Backup"="C:\Program Files\Spare Backup\SpareBackup.exe" [2007-07-13 5252936]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 421888]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2005-09-27 177664]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-19 1235736]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 C:\WINDOWS\RTHDCPL.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\imod3]
2008-09-18 10:28 5136 C:\WINDOWS\system32\imod3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
"LoadAppInit_DLLs"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dplx.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\River Past\\Crazi Video\\CraziVideo.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;C:\WINDOWS\system32\DRIVERS\el575nd5.sys [2001-08-17 22:10]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-09-19 08:11]
S1 dplx;PCI Express DMA;C:\WINDOWS\system32\dplx.sys [2008-09-17 08:39]
S2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-19 08:11]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-19 08:11]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-09-19 08:11]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de930ff0-84c0-11dd-8deb-001bb9a216cd}]
\Shell\AutoRun\command - F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe
\Shell\open\command - F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe
.
Contents of the 'Scheduled Tasks' folder

2008-09-20 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
- C:\Program Files\AdwareAlert\AdwareAlert.exe []

2008-09-20 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
- C:\Program Files\AdwareAlert []

2008-09-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-09-16 C:\WINDOWS\Tasks\ISP signup reminder 2.job
- C:\WINDOWS\system32\OOBE\oobebaln.exe [2004-08-04 15:00]

2008-09-16 C:\WINDOWS\Tasks\ISP signup reminder 3.job
- C:\WINDOWS\system32\OOBE\oobebaln.exe [2004-08-04 15:00]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-BigFix - c:\program files\Bigfix\bigfix.exe
Notify-duplex - duplex.dll
MSConfigStartUp-AdwareAlert - C:\Program Files\AdwareAlert\AdwareAlert.exe
MSConfigStartUp-lphc7kbj0e166 - C:\WINDOWS\system32\lphc7kbj0e166.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8fldi60q.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 04:38:07
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDSSserv]
"imagepath"="\systemroot\system32\drivers\TDSSserv.sys"
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\imod3.dll
.
Completion time: 2008-09-20 4:40:33
ComboFix-quarantined-files.txt 2008-09-20 08:40:30

Post-Run: 39,045,623,808 bytes free

244 — E O F — 2008-09-17 07:00:22
Hello MikeJones
Please do the following:

CFScript
Close any open browsers.
Open notepad and copy/paste the text in the code box below into it:

SysRst::

File::
C:\WINDOWS\wininit.ini
C:\WINDOWS\system32\00setup.exe
C:\WINDOWS\system32\imod3.dll
C:\WINDOWS\vmgspntbqvm.dll
C:\WINDOWS\exsv.exe
C:\WINDOWS\system32\nxg.bin
C:\WINDOWS\system32\71.tmp
C:\WINDOWS\system32\72.tmp
C:\WINDOWS\system32\70.tmp
C:\WINDOWS\system32\6F.tmp
C:\WINDOWS\system32\73.tmp
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdssserf.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\system32\dplx.sys
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\system32\k86.bin
C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job

Rootkit::
C:\WINDOWS\system32\drivers\TDSSserv.sys

Folder::
C:\Documents and Settings\Owner\Application Data\AdwareAlert
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

Driver::
dplx
TDSSserv

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\imod3]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dplx.sys]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDSSserv]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de930ff0-84c0-11dd-8deb-001bb9a216cd}]
Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Flash_Disinfector
  • Download Flash_Disinfector here and save it to your desktop.
  • Double click to run it
  • You will be prompted to plug in your USB drive. Plug it in
  • Flash_Disinfector will start disinfecting your flash and hard drives. This takes a few seconds. Your desktop will disappear in the meantime
  • When done, a message box will appear. Click OK. Your desktop should now appear. If it doesn't, press Ctrl + Shift + Esc to open Task Manager
  • Click on File > New Task (Run…). Type in explorer.exe and press Enter. Your desktop should now appear
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

To post in next reply:
Combofix log
New HijackThis log
Well I ran the CFscript and went off to work, and when I come back I have no internet connection. It was sending out packets but wouldn't recieve any, so I went on another computer and looked online for solution, and none of them seemed to work out for my comptuer..my guess is that it could've been combofix since it occured right after the CFscript or just quinicdental. I have everything set to "obtain automatically" and all the settings are set the same as this one so I really don't know. also when I try to repiar it , it comes back with "cannot renew IP"


heres the logs:

Logfile of Trend Micro HijackThis v2.0.2Scan saved at 9:42:31 PM, on 9/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Spybot - Search & Destroy\SDFiles.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M=W3622
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 4307 bytes






ComboFix 08-09-19.13 - Owner 2008-09-20 12:21:24.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFscript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\exsv.exe
C:\WINDOWS\system32\00setup.exe
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\system32\6F.tmp
C:\WINDOWS\system32\70.tmp
C:\WINDOWS\system32\71.tmp
C:\WINDOWS\system32\72.tmp
C:\WINDOWS\system32\73.tmp
C:\WINDOWS\system32\dplx.sys
C:\WINDOWS\system32\imod3.dll
C:\WINDOWS\system32\k86.bin
C:\WINDOWS\system32\nxg.bin
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssserf.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
C:\WINDOWS\vmgspntbqvm.dll
C:\WINDOWS\wininit.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DIFxAPI.dll
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\GEARAspiWDM.inf
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\gearaspiwdmx86.cat
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspi.dll
C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspiWDM.sys
C:\Documents and Settings\Owner\Application Data\AdwareAlert
C:\Documents and Settings\Owner\Application Data\AdwareAlert\Log\2008 Sep 17 - 10_30_38 AM_796.log
C:\Documents and Settings\Owner\Application Data\AdwareAlert\rs.dat
C:\Documents and Settings\Owner\Application Data\AdwareAlert\Settings\ScanResults.pie
C:\WINDOWS\exsv.exe
C:\WINDOWS\system32\00setup.exe
C:\WINDOWS\system32\12.tmp
C:\WINDOWS\system32\16.tmp
C:\WINDOWS\system32\6F.tmp
C:\WINDOWS\system32\71.tmp
C:\WINDOWS\system32\73.tmp
C:\WINDOWS\system32\dwave.sys
C:\WINDOWS\system32\imod3.dll
C:\WINDOWS\system32\k86.bin
C:\WINDOWS\system32\nxg.bin
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
C:\WINDOWS\vmgspntbqvm.dll
C:\WINDOWS\wininit.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_DPLX
——-\Legacy_TDSSSERV
——-\Service_dplx
——-\Service_TDSSserv


((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.

2008-09-19 09:23 . 2008-09-19 09:25 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-19 09:23 . 2008-09-19 10:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-19 08:23 . 2008-09-20 05:33 d–h—– C:\$AVG8.VAULT$
2008-09-19 08:13 . 2008-09-19 08:24 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\AVGTOOLBAR
2008-09-19 08:11 . 2008-09-20 04:06 d——– C:\WINDOWS\system32\drivers\Avg
2008-09-19 08:11 . 2008-09-19 08:11 d——– C:\Program Files\AVG
2008-09-19 08:11 . 2008-09-19 09:15 d——– C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-09-19 08:11 . 2008-09-19 11:13 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-09-19 08:11 . 2008-09-19 08:11 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-19 08:11 . 2008-09-19 08:11 76,040 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-19 08:11 . 2008-09-19 08:11 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-09-19 07:44 . 2008-09-19 07:44 0 –a—— C:\WINDOWS\nsreg.dat
2008-09-17 15:33 . 2008-09-17 15:33 d——– C:\Program Files\Microsoft Silverlight
2008-09-17 15:19 . 2008-09-17 15:19 d——– C:\Program Files\Windows Media Components
2008-09-17 15:14 . 2008-09-17 15:15 d——– C:\Documents and Settings\Owner\Application Data\Ventrilo
2008-09-17 15:14 . 2008-09-19 09:05 d——– C:\Documents and Settings\Owner\Application Data\Hamachi
2008-09-17 15:06 . 2008-09-17 15:06 d——– C:\Program Files\Xilisoft
2008-09-17 15:06 . 2008-09-17 15:06 d——– C:\Program Files\Trend Micro
2008-09-17 15:04 . 2008-09-17 15:05 d——– C:\Program Files\Warcraft III
2008-09-17 14:25 . 2008-09-17 15:35 d——– C:\Program Files\Beston
2008-09-17 14:20 . 2008-09-17 14:35 137,472 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-09-17 14:20 . 2008-09-17 14:35 111,928 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2008-09-17 14:19 . 2008-09-17 14:19 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Program Files\Lavasoft
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-09-17 12:40 . 2008-09-17 12:40 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-17 08:56 . 2008-09-17 14:11 d——– C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-09-17 08:55 . 2008-04-17 13:12 107,368 –a—— C:\WINDOWS\system32\GEARAspi.dll
2008-09-17 08:55 . 2008-04-17 13:12 15,464 –a—— C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-09-17 08:54 . 2008-09-17 15:42 d——– C:\Program Files\iTunes
2008-09-17 08:54 . 2008-09-17 14:28 d——– C:\Program Files\iPod
2008-09-17 08:53 . 2008-09-17 08:53 d——– C:\Program Files\Bonjour
2008-09-17 08:51 . 2008-09-17 08:53 d——– C:\Program Files\QuickTime
2008-09-17 08:51 . 2008-09-17 08:54 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-17 08:50 . 2008-09-17 08:50 d——– C:\Program Files\Apple Software Update
2008-09-17 08:49 . 2008-09-17 08:52 d——– C:\Program Files\Common Files\Apple
2008-09-17 08:48 . 2008-09-17 08:48 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-09-17 08:38 . 2008-09-17 08:38 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-17 08:36 . 2008-09-17 08:36 d——– C:\Program Files\River Past
2008-09-17 08:36 . 2008-09-17 08:36 d——– C:\Program Files\Common Files\River Past
2008-09-17 08:36 . 2008-09-17 09:44 d——– C:\Documents and Settings\Owner\Application Data\River Past G5
2008-09-17 08:36 . 2008-09-17 09:44 d——– C:\Documents and Settings\All Users\Application Data\River Past G5
2008-09-17 08:36 . 2008-09-17 08:36 164,872 –a—— C:\WINDOWS\Crazi Video Uninstaller.exe
2008-09-17 08:29 . 2008-09-17 10:05 d——– C:\Documents and Settings\Owner\Incomplete
2008-09-17 08:28 . 2008-09-17 10:05 d——– C:\Program Files\LimeWire
2008-09-17 08:28 . 2008-09-17 10:16 d——– C:\Documents and Settings\Owner\Application Data\LimeWire
2008-09-17 03:00 . 2008-09-17 03:00 d——– C:\Program Files\MSXML 4.0
2008-09-16 01:30 . 2008-09-20 04:07 d——– C:\Documents and Settings\Owner\Shared
2008-09-16 01:27 . 2008-09-16 11:29 d——– C:\WINDOWS\system32\CatRoot_bak
2008-09-16 01:27 . 2008-06-13 09:10 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-09-16 01:27 . 2008-06-13 09:10 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-16 01:26 . 2008-05-01 10:30 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-16 01:26 . 2008-06-23 12:57 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-09-16 01:23 . 2004-08-04 15:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-09-16 01:22 . 2006-07-01 01:30 d——– C:\WINDOWS\system32\config\systemprofile\WINDOWS
2008-09-16 01:22 . 2008-09-16 00:59 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\Spare Backup
2008-09-16 01:22 . 2008-09-16 00:56 d——– C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
2008-09-16 01:22 . 2006-07-01 01:30 d——– C:\Documents and Settings\Default User\WINDOWS
2008-09-16 01:03 . 2008-09-16 01:03 8,192 –a—— C:\WINDOWS\REGLOCS.OLD
2008-09-16 00:59 . 2008-09-16 00:59 333 –a—— C:\WINDOWS\system32\$ncsp$.inf
2008-09-16 00:59 . 2008-09-16 00:59 0 –a—— C:\WINDOWS\system32\Gateway_W3622_3.1_0000.MRK
2008-09-16 00:58 . 2008-09-16 00:58 940,794 –a—— C:\WINDOWS\system32\LoopyMusic.wav
2008-09-16 00:58 . 2008-09-16 00:58 146,650 –a—— C:\WINDOWS\system32\BuzzingBee.wav
2008-09-16 00:57 . 2006-10-06 00:09 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2008-09-16 00:56 . 2008-09-16 00:56 d——– C:\Documents and Settings\Owner\Application Data\SampleView
2008-09-16 00:54 . 2006-12-19 17:52 8,453,632 –a–c— C:\WINDOWS\system32\dllcache\shell32.dll
2008-09-16 00:54 . 2006-12-19 17:52 134,656 –a–c— C:\WINDOWS\system32\dllcache\shsvcs.dll
2008-09-16 00:52 . 2006-11-27 10:54 539,136 –a–c— C:\WINDOWS\system32\dllcache\msftedit.dll
2008-09-16 00:52 . 2006-11-27 10:54 433,152 –a–c— C:\WINDOWS\system32\dllcache\riched20.dll
2008-09-16 00:51 . 2006-08-21 05:14 128,896 –a–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-09-16 00:51 . 2006-08-21 05:14 30,720 –a–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2008-09-16 00:51 . 2006-08-21 08:21 16,896 –a–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-09-16 00:50 . 2006-06-22 01:06 1,435,648 –a–c— C:\WINDOWS\system32\dllcache\query.dll
2008-09-16 00:50 . 2008-05-08 08:28 202,752 –a–c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-16 00:50 . 2006-06-22 01:06 69,120 –a–c— C:\WINDOWS\system32\dllcache\ciodm.dll
2008-09-16 00:49 . 2006-04-21 02:12 332,800 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-09-16 00:49 . 2006-06-22 06:47 181,248 –a–c— C:\WINDOWS\system32\dllcache\rasmans.dll
2008-09-16 00:49 . 2008-06-20 13:41 148,992 –a–c— C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-09-16 00:49 . 2006-05-19 08:59 111,616 –a–c— C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
2008-09-16 00:49 . 2006-05-19 08:59 94,720 –a–c— C:\WINDOWS\system32\dllcache\iphlpapi.dll
2008-09-16 00:48 . 2004-09-03 19:07 28,672 –a—— C:\WINDOWS\system32\Marker32.exe
2008-09-16 00:47 . 2008-09-16 00:47 d——– C:\Program Files\Spare Backup
2008-09-16 00:47 . 2008-09-16 00:47 d——– C:\Program Files\Microsoft WSE
2008-09-16 00:47 . 2008-09-20 04:36 d——– C:\Documents and Settings\Owner\Application Data\Spare Backup
2008-09-16 00:46 . 2008-09-16 00:46 d——– C:\McAfee
2008-09-16 00:46 . 2007-04-23 06:14 364,160 –a–c— C:\WINDOWS\system32\dllcache\update.sys
2008-09-16 00:44 . 2007-02-28 05:55 2,182,144 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-09-16 00:44 . 2007-02-28 05:53 2,137,600 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-09-16 00:44 . 2007-02-28 05:15 2,017,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-09-16 00:44 . 2007-03-17 09:43 292,864 –a–c— C:\WINDOWS\system32\dllcache\winsrv.dll
2008-09-16 00:44 . 2007-02-05 16:17 185,344 –a–c— C:\WINDOWS\system32\dllcache\upnphost.dll
2008-09-16 00:44 . 2007-03-09 09:58 57,344 –a–c— C:\WINDOWS\system32\dllcache\agentdpv.dll
2008-09-16 00:43 . 2008-09-16 01:34 d——– C:\Program Files\BigFix
2008-09-16 00:43 . 2007-03-08 09:47 1,843,584 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-09-16 00:43 . 2007-03-08 11:36 577,536 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-09-16 00:43 . 2007-03-08 11:36 281,600 –a–c— C:\WINDOWS\system32\dllcache\gdi32.dll
2008-09-16 00:43 . 2007-03-08 11:36 40,960 –a–c— C:\WINDOWS\system32\dllcache\mf3216.dll
2008-09-16 00:43 . 2006-11-16 19:05 11,816 –a—— C:\WINDOWS\BigFixClientOverride.dll
2008-09-16 00:42 . 2008-09-16 11:18 d——– C:\Program Files\eMachines Games
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Program Files\NetZero
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\google
2008-09-16 00:41 . 2008-09-16 00:41 d——– C:\Documents and Settings\All Users\Application Data\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2008-09-16 00:41 . 2006-02-01 06:54 94,208 –a—— C:\WINDOWS\system32\BAE.dll
2008-09-16 00:39 . 2008-09-16 11:19 d——– C:\Program Files\Java
2008-09-16 00:39 . 2008-09-16 11:44 d——– C:\Program Files\Google
2008-09-16 00:39 . 2008-09-16 00:39 d——– C:\Program Files\Common Files\Java
2008-09-16 00:39 . 2008-06-10 02:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-09-16 00:39 . 2008-09-16 00:39 0 –a—— C:\WINDOWS\system32\drivers\Gateway_W3622_3.1_0000.MRK
2008-09-16 00:38 . 2008-09-16 00:38 d–h—– C:\WINDOWS\msdownld.tmp
2008-09-16 00:38 . 2006-10-26 22:56 32,592 –a—— C:\WINDOWS\system32\msonpmon.dll
2008-09-16 00:37 . 2008-09-16 00:37 d——– C:\Program Files\Microsoft.NET
2008-09-16 00:37 . 2008-09-16 00:40 d——– C:\Program Files\Microsoft Works
2008-09-16 00:36 . 2008-09-16 00:36 d——– C:\WINDOWS\SHELLNEW
2008-09-16 00:35 . 2008-09-16 00:35 dr-h—– C:\MSOCache
2008-09-16 00:35 . 2008-09-16 00:38 d——– C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-16 00:34 . 2001-03-08 21:30 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2008-09-16 00:33 . 2008-09-16 00:34 d——– C:\Program Files\CyberLink
2008-09-16 00:33 . 2003-03-18 23:14 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-09-16 00:33 . 2003-02-21 07:42 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-09-16 00:32 . 2008-09-16 00:33 d——– C:\Program Files\Common Files\Adobe
2008-09-16 00:31 . 2008-09-17 15:19 d——– C:\Program Files\Windows Media Connect 2
2008-09-16 00:31 . 2006-10-04 10:06 1,197,294 –a–c— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-09-16 00:31 . 2006-10-04 10:06 764,868 –a–c— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-09-16 00:31 . 2006-10-04 10:06 217,118 –a–c— C:\WINDOWS\system32\dllcache\apphelp.sdb

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 07:54 ——— d—–w C:\Program Files\Diablo II
2008-09-17 19:15 ——— d—–w C:\Program Files\Ventrilo
2008-09-17 18:55 ——— d—–w C:\Program Files\Q3Ademo
2008-09-17 18:20 ——— d—–w C:\Program Files\Wolfenstein - Enemy Territory
2008-09-15 23:05 ——— d—–w C:\Program Files\Starcraft
2008-08-12 06:05 ——— d—–w C:\Program Files\Rockstar Games
2008-08-08 00:10 ——— d—–w C:\Program Files\EA GAMES
.

——- Sigcheck ——-

2004-08-04 15:00 1039872 6beed988649566e49c3fb63dec564c3c C:\WINDOWS\explorer.exe
2008-04-13 20:12 1041408 6ce19208891e9dc85b46ec32ea3fa3e9 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe

2008-04-13 20:12 23040 7994d694ec2fb339baff2e50925e62cf C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 15:00 23040 8f95a0995a14394008f0415fa5aceaac C:\WINDOWS\system32\ctfmon.exe

2008-04-13 20:12 33792 66f69cf680ee53f7751ab7bd8490c797 C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 15:00 32256 72eadc55ba014923295f84aba5361d50 C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2008-09-20_ 4.40.07.89 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 00:02:28 174,592 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-09-20 08:33:53 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-20 16:30:13 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-20 08:33:53 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-20 16:30:13 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-20 08:33:53 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-20 16:30:13 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DIFxAPI.dll
2008-04-17 13:12 319456 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002161.dll

C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
2008-07-04 13:35 54632 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002162.exe

C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspi.dll
2008-04-17 13:12 107368 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002165.dll

C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspiWDM.sys
2008-04-17 13:12 15464 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002166.sys

2008-09-16 00:30 57344 C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{15377C3E-9655-400F-B441-E69F0A6BEAFE}\NewShortcut3_15377C3E9655400FB441E69F0A6BEAFE.EXE
2008-09-16 00:30 57344 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002208.EXE

2007-01-08 18:46 656984 C:\McAfee\Install.exe
2007-01-08 18:46 656984 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002278.exe

2008-09-19 08:11 540440 C:\Program Files\AVG\AVG8\aAvgApi.exe
2008-09-19 08:11 540440 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002062.exe

2008-09-19 08:11 875288 C:\Program Files\AVG\AVG8\avgemc.exe
2008-09-19 08:11 875288 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002181.exe

2008-09-19 08:11 287000 C:\Program Files\AVG\AVG8\avgrsx.exe
2008-09-19 08:11 287000 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002180.exe

2008-09-19 08:11 2813720 C:\Program Files\AVG\AVG8\avgui.exe
2008-09-19 08:11 2813720 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002206.exe

2008-09-19 08:11 641304 C:\Program Files\AVG\AVG8\avgupd.exe
2008-09-19 08:11 641304 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002056.exe

2008-09-19 08:11 222488 C:\Program Files\AVG\AVG8\fixcfg.exe
2008-09-19 08:11 222488 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002057.exe

2008-09-19 08:11 2546968 C:\Program Files\AVG\AVG8\setup.exe
2008-09-19 08:11 2546968 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002234.exe

2003-07-23 14:32 2347008 C:\Program Files\Beston\EZPhoto Browser 2.1\EZPhotoBrowser2.exe
2003-07-23 14:32 2347008 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002235.exe

2003-06-26 03:46 4497408 C:\Program Files\Beston\EZPhoto Tools 2.1\EZPhotoTools2.exe
2003-06-26 03:46 4497408 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002236.exe

2003-07-07 13:39 1953792 C:\Program Files\Beston\EZShowtime MMS 1.1\Showtime1.exe
2003-07-07 13:39 1953792 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002237.exe

2003-06-21 00:28 266240 C:\Program Files\Beston\EZSuite For Video Chat Kit\EZSuite-VideoChatKit.exe
2003-06-21 00:28 266240 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002238.exe

2001-05-11 05:17 200704 C:\Program Files\Beston\EZSuite For Video Chat Kit\OnlineReg.exe
2001-05-11 05:17 200704 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002239.exe

2002-03-11 04:08 484100 C:\Program Files\Beston\EZVideo Mail 2.1\demo.exe
2002-03-11 04:08 484100 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002240.exe

2003-07-07 13:26 1273856 C:\Program Files\Beston\EZVideo Mail 2.1\EZVMail2.exe
2003-07-07 13:26 1273856 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002241.exe

2004-08-04 15:00 47616 C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe
2004-08-04 15:00 47616 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002230.exe

2005-06-14 23:42 65536 C:\Program Files\CyberLink\Power2Go\CLDMA.exe
2005-06-14 23:42 65536 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002245.exe

2006-11-13 22:49 360448 C:\Program Files\CyberLink\Power2Go\OLRSubmission\OLRSubmission.exe
2006-11-13 22:49 360448 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002242.exe

2006-11-23 00:45 2129920 C:\Program Files\CyberLink\Power2Go\Power2Go.exe
2006-11-23 00:45 2129920 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002243.exe

2006-11-23 00:42 2478080 C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
2006-11-23 00:42 2478080 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002244.exe

2008-05-27 21:44 192512 C:\Program Files\Diablo II\D2VidTst.exe
2008-05-27 21:44 192512 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002246.exe

2008-06-28 22:14 45056 C:\Program Files\Diablo II\Diablo II.exe
2008-06-28 22:14 45056 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002203.exe

2004-10-19 15:04 5656576 C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe
2004-10-19 15:04 5656576 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002247.exe

2004-01-22 12:36 376832 C:\Program Files\EA GAMES\Battlefield 1942\DedicatedServer.exe
2004-01-22 12:36 376832 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002250.exe

2002-07-17 16:28 790528 C:\Program Files\EA GAMES\Battlefield 1942\eReg\Battlefield 1942_eReg.exe
2002-07-17 16:28 790528 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002249.exe

2003-09-11 11:35 634880 C:\Program Files\EA GAMES\Battlefield 1942\eReg\Battlefield 1942_EZ.exe
2003-09-11 11:35 634880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002248.exe

2002-12-13 04:35 790528 C:\Program Files\EA GAMES\Battlefield 1942\Mods\XPack1\eReg\Battlefield 1942 The Road to Rome_eReg.exe
2002-12-13 04:35 790528 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002254.exe

2003-09-11 11:35 634880 C:\Program Files\EA GAMES\Battlefield 1942\Mods\XPack1\eReg\Battlefield 1942 The Road to Rome_EZ.exe
2003-09-11 11:35 634880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002253.exe

2003-07-02 16:52 450560 C:\Program Files\EA GAMES\Battlefield 1942\Mods\XPack2\eReg\Battlefield 1942 Secret Weapons of WWII_eReg.exe
2003-07-02 16:52 450560 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002252.exe

2003-07-02 16:55 634880 C:\Program Files\EA GAMES\Battlefield 1942\Mods\XPack2\eReg\Battlefield 1942 Secret Weapons of WWII_EZ.exe
2003-07-02 16:55 634880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002251.exe

2004-09-23 12:24 9696256 C:\Program Files\EA GAMES\Battlefield Vietnam\bfvietnam.exe
2004-09-23 12:24 9696256 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002255.exe

2004-09-06 12:25 3809280 C:\Program Files\EA GAMES\Battlefield Vietnam\DedicatedServer.exe
2004-09-06 12:25 3809280 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002258.exe

2004-02-13 11:49 634880 C:\Program Files\EA GAMES\Battlefield Vietnam\eReg\Battlefield Vietnam TM_EZ.exe
2004-02-13 11:49 634880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002256.exe

2003-10-29 13:51 450560 C:\Program Files\EA GAMES\Battlefield Vietnam\eReg\Battlefield Vietnam_eReg.exe
2003-10-29 13:51 450560 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002257.exe

2003-08-30 20:16 450560 C:\Program Files\EA GAMES\Command & Conquer Generals Zero Hour\support\Command and Conquer Generals Zero Hour_eReg.exe
2003-08-30 20:16 450560 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002263.exe

2003-08-30 20:16 77824 C:\Program Files\EA GAMES\Command & Conquer Generals Zero Hour\support\go_ez.exe
2003-08-30 20:16 77824 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002262.exe

2003-01-12 17:15 790528 C:\Program Files\EA GAMES\Command and Conquer Generals\support\Generals_eReg.exe
2003-01-12 17:15 790528 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002261.exe

2003-01-12 14:13 77824 C:\Program Files\EA GAMES\Command and Conquer Generals\support\go_ez.exe
2003-01-12 14:13 77824 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002260.exe

2007-06-26 18:48 1394464 C:\Program Files\eMachines Games\eMachines Game Console\GameConsole.exe
2007-06-26 18:48 1394464 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002264.exe

2008-06-23 05:20 633344 C:\Program Files\Internet Explorer\iexplore.exe
2008-06-23 05:20 633344 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002060.exe

2008-05-14 15:17 2682216 C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
2008-05-14 15:17 2682216 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002274.exe

2008-04-29 12:26 1238880 C:\Program Files\Lavasoft\Ad-Aware\lsupdatemanager.exe
2008-04-29 12:26 1238880 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002275.exe

2008-05-12 13:45 468312 C:\Program Files\Lavasoft\Ad-Aware\threatwork.exe
2008-05-12 13:45 468312 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002276.exe

2004-08-04 15:00 3563008 C:\Program Files\Movie Maker\moviemk.exe
2004-08-04 15:00 3563008 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002218.exe

2008-07-02 21:52 307712 C:\Program Files\Mozilla Firefox\firefox.exe
2008-07-02 21:52 307712 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002061.exe
2008-07-02 21:52 307712 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002205.exe

2004-08-04 15:00 50257 C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe
2004-08-04 15:00 50257 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002265.exe

2004-08-04 15:00 50255 C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe
2004-08-04 15:00 50255 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002266.exe

2004-08-04 15:00 50253 C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe
2004-08-04 15:00 50253 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002267.exe

2004-08-04 15:00 50254 C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe
2004-08-04 15:00 50254 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002268.exe

2004-08-04 15:00 50253 C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe
2004-08-04 15:00 50253 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002269.exe

2004-08-04 15:00 68096 C:\Program Files\Outlook Express\msimn.exe
2004-08-04 15:00 68096 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002160.exe

1999-11-29 16:47 872505 C:\Program Files\Q3Ademo\quake3.exe
1999-11-29 16:47 872505 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002201.exe

2008-09-06 15:09 7685424 C:\Program Files\QuickTime\QuickTimePlayer.exe
2008-09-06 15:09 7685424 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002070.exe

2008-08-29 19:55 339968 C:\Program Files\River Past\Crazi Video\CraziVideo.exe
2008-08-29 19:55 339968 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002289.exe

2006-01-29 11:48 623616 C:\Program Files\ShoqBox Buddy\ShoqBox Buddy.exe
2006-01-29 11:48 623616 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002291.exe

2008-07-07 09:37 966656 C:\Program Files\Spybot - Search & Destroy\SDShred.exe
2008-07-07 09:37 966656 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002295.exe

2008-07-07 09:42 1429840 C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe
2008-07-07 09:42 1429840 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002297.exe

2008-07-07 09:42 4891472 C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
2008-07-07 09:42 4891472 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002200.exe

2008-09-19 09:23 696200 C:\Program Files\Spybot - Search & Destroy\unins000.exe
2008-09-19 09:23 696200 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002296.exe

2008-01-10 16:23 1228800 C:\Program Files\Starcraft\StarCraft.exe
2008-01-10 16:23 1228800 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002298.exe

2008-01-10 16:23 1024000 C:\Program Files\Starcraft\StarEdit.exe
2008-01-10 16:23 1024000 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002299.exe

2008-09-17 15:06 404480 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
2008-09-17 15:06 404480 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002202.exe

2007-11-17 15:58 1396736 C:\Program Files\Ventrilo\Ventrilo.exe
2007-11-17 15:58 1396736 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002199.exe

2006-10-19 00:46 71680 C:\Program Files\Windows Media Player\wmplayer.exe
2006-10-19 00:46 71680 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002071.exe

2004-08-04 15:00 222208 C:\Program Files\Windows NT\Accessories\wordpad.exe
2004-08-04 15:00 222208 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002222.exe

2004-08-04 15:00 35840 C:\Program Files\Windows NT\hypertrm.exe
2004-08-04 15:00 35840 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002224.exe

2004-08-04 15:00 288768 C:\Program Files\Windows NT\Pinball\PINBALL.EXE
2004-08-04 15:00 288768 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002271.EXE

2003-05-27 15:44 1405000 C:\Program Files\Wolfenstein - Enemy Territory\ET.exe
2003-05-27 15:44 1405000 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002196.exe

2008-09-03 22:21 61440 C:\Program Files\Xilisoft\AVI to DVD Converter\AVI to DVD Converter.exe
2008-09-03 22:21 61440 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002195.exe

2008-09-17 15:06 68334 C:\Program Files\Xilisoft\AVI to DVD Converter\Uninstall.exe
2008-09-17 15:06 68334 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002209.exe

2008-09-17 08:36 164872 C:\WINDOWS\Crazi Video Uninstaller.exe
2008-09-17 08:36 164872 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002290.exe

2004-08-04 15:00 1039872 C:\WINDOWS\explorer.exe
2004-08-04 15:00 1039872 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002186.exe

C:\WINDOWS\exsv.exe
2008-09-16 18:34 135168 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002168.exe

2008-09-17 08:50 27136 C:\WINDOWS\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
2008-09-17 08:50 27136 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002212.exe

2008-09-16 00:40 73728 C:\WINDOWS\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_630CEEA9B210_4765_A2B1_FC24596048D7.exe
2008-09-16 00:40 73728 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002286.exe

2008-09-16 00:40 192512 C:\WINDOWS\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_9FA356B1395F_4530_8CB3_946ED0B3291E.exe
2008-09-16 00:40 192512 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002287.exe

2008-09-16 00:40 73728 C:\WINDOWS\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_B8B1511D9331_467C_9B1B_E8204012E95B.exe
2008-09-16 00:40 73728 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002288.exe

2008-09-16 00:40 17534 C:\WINDOWS\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\gtngstrtd.exe
2008-09-16 00:40 17534 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002285.exe

2008-09-16 00:38 20240 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
2008-09-16 00:38 20240 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002283.exe

2008-09-16 00:38 184080 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
2008-09-16 00:38 184080 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002280.exe

2008-09-16 00:38 217864 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
2008-09-16 00:38 217864 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002282.exe

2008-09-16 00:38 35088 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
2008-09-16 00:38 35088 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002284.exe

2008-09-16 00:38 922384 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
2008-09-16 00:38 922384 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002281.exe

2008-09-16 00:38 888080 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
2008-09-16 00:38 888080 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002259.exe

2008-09-16 00:38 1172240 C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
2008-09-16 00:38 1172240 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002279.exe

2008-09-16 00:47 65536 C:\WINDOWS\Installer\{A57C6094-FC5A-4DEC-B1E0-1B2F48EEE8F4}\SpareBackup.exe_A57C6094FC5A4DECB1E01B2F48EEE8F4.exe
2008-09-16 00:47 65536 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002292.exe

2008-09-16 00:47 2238 C:\WINDOWS\Installer\{A57C6094-FC5A-4DEC-B1E0-1B2F48EEE8F4}\Sparebackup.url_A57C6094FC5A4DECB1E01B2F48EEE8F4.exe
2008-09-16 00:47 2238 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002294.exe

2008-09-16 00:47 2238 C:\WINDOWS\Installer\{A57C6094-FC5A-4DEC-B1E0-1B2F48EEE8F4}\WebAccess.url_A57C6094FC5A4DECB1E01B2F48EEE8F4.exe
2008-09-16 00:47 2238 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002293.exe

2008-09-16 00:33 295606 C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A80000000002}\SC_Reader.exe
2008-09-16 00:33 295606 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002300.exe

2003-02-21 17:24 57344 C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
2003-02-21 17:24 57344 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002233.exe

2005-09-27 03:34 177664 C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
2005-09-27 03:34 177664 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002213.exe

2004-08-04 15:00 154112 C:\WINDOWS\regedit.exe
2004-08-04 15:00 154112 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002120.exe

2006-07-21 19:14 94208 C:\WINDOWS\SoundMan.exe
2006-07-21 19:14 94208 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002117.exe

C:\WINDOWS\system32\00setup.exe
2008-09-18 10:28 18432 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002067.exe

2004-08-04 15:00 191488 C:\WINDOWS\system32\accwiz.exe
2004-08-04 15:00 191488 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002223.exe

2004-08-04 15:00 18944 C:\WINDOWS\system32\attrib.exe
2004-08-04 15:00 18944 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002078.exe

2004-08-04 15:00 122368 C:\WINDOWS\system32\calc.exe
2004-08-04 15:00 122368 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002221.exe

2004-08-04 15:00 71680 C:\WINDOWS\system32\cleanmgr.exe
2004-08-04 15:00 71680 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002229.exe

2004-08-04 15:00 396288 C:\WINDOWS\system32\cmd.exe
2004-08-04 15:00 396288 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002076.exe
2004-08-04 15:00 396288 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002189.exe

2004-08-04 15:00 21504 C:\WINDOWS\system32\convert.exe
2004-08-04 15:00 21504 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002068.exe

2004-08-04 15:00 16896 C:\WINDOWS\system32\find.exe
2004-08-04 15:00 16896 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002077.exe

2004-08-04 15:00 34816 C:\WINDOWS\system32\findstr.exe
2004-08-04 15:00 34816 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002079.exe
2004-08-04 15:00 34816 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002190.exe

2004-08-04 15:00 47104 C:\WINDOWS\system32\grpconv.exe
2004-08-04 15:00 47104 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002074.exe

2006-10-06 00:10 102400 C:\WINDOWS\system32\igfxpers.exe
2006-10-06 00:10 102400 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002210.exe

C:\WINDOWS\system32\imod3.dll
2008-09-18 10:28 5136 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002169.dll

2006-10-17 14:56 53248 C:\WINDOWS\system32\mshta.exe
2006-10-17 14:56 53248 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002065.exe

2005-03-22 01:00 86528 C:\WINDOWS\system32\msiexec.exe
2005-03-22 01:00 86528 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002277.exe

2004-08-04 15:00 415232 C:\WINDOWS\system32\mstsc.exe
2004-08-04 15:00 415232 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002225.exe

2004-08-04 15:00 76800 C:\WINDOWS\system32\notepad.exe
2004-08-04 15:00 76800 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002066.exe

2001-08-18 08:36 1143296 C:\WINDOWS\system32\ntbackup.exe
2001-08-18 08:36 1143296 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002228.exe

2007-02-28 04:15 2059392 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 04:15 2059392 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002301.exe

2007-02-28 05:55 2182144 C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 05:55 2182144 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002159.exe
2007-02-28 05:55 2182144 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002302.exe

2004-08-04 15:00 40960 C:\WINDOWS\system32\odbcad32.exe
2004-08-04 15:00 40960 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002232.exe

2004-08-04 15:00 25600 C:\WINDOWS\system32\ping.exe
2004-08-04 15:00 25600 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002080.exe

2004-08-04 15:00 388096 C:\WINDOWS\system32\Restore\rstrui.exe
2004-08-04 15:00 388096 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002231.exe

2004-08-04 15:00 27648 C:\WINDOWS\system32\route.exe
2004-08-04 15:00 27648 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002124.exe

2004-08-04 15:00 40960 C:\WINDOWS\system32\rundll32.exe
2004-08-04 15:00 40960 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002072.exe
2004-08-04 15:00 40960 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002187.exe

2004-08-04 15:00 22016 C:\WINDOWS\system32\runonce.exe
2004-08-04 15:00 22016 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002073.exe

2004-08-04 15:00 139264 C:\WINDOWS\system32\sndrec32.exe
2004-08-04 15:00 139264 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002226.exe

2004-08-04 15:00 146432 C:\WINDOWS\system32\sndvol32.exe
2004-08-04 15:00 146432 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002227.exe

2004-08-04 15:00 64512 C:\WINDOWS\system32\sol.exe
2004-08-04 15:00 64512 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002272.exe

2004-08-04 15:00 31232 C:\WINDOWS\system32\sort.exe
2004-08-04 15:00 31232 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002081.exe
2004-08-04 15:00 31232 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002191.exe

2004-08-04 15:00 546304 C:\WINDOWS\system32\spider.exe
2004-08-04 15:00 546304 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002273.exe

C:\WINDOWS\system32\tdssinit.dll
2008-09-19 11:35 53285 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002167.dll

2004-08-04 15:00 32256 C:\WINDOWS\system32\userinit.exe
2004-08-04 15:00 32256 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002185.exe

2006-03-17 03:38 36352 C:\WINDOWS\system32\verclsid.exe
2006-03-17 03:38 36352 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002075.exe
2006-03-17 03:38 36352 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002207.exe

2004-08-04 15:00 225792 C:\WINDOWS\system32\wbem\wmiprvse.exe
2004-08-04 15:00 225792 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002183.exe

2004-08-04 15:00 127488 C:\WINDOWS\system32\winmine.exe
2004-08-04 15:00 127488 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002270.exe

2008-07-18 22:10 53448 C:\WINDOWS\system32\wuauclt.exe
2008-07-18 22:10 53448 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002182.exe

2004-08-04 15:00 39936 C:\WINDOWS\system32\wupdmgr.exe
2004-08-04 15:00 39936 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002211.exe

C:\WINDOWS\vmgspntbqvm.dll
2008-09-16 18:34 372736 {39C571A2-5C6A-433B-8AC6-DBD815F09639}\RP9\A0002170.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\River Past\\Crazi Video\\CraziVideo.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;C:\WINDOWS\system32\DRIVERS\el575nd5.sys [2001-08-17 22:10]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-09-19 08:11]
S2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-19 08:11]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-19 08:11]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-09-19 08:11]

.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 12:37:29
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-20 12:41:09 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-09-20 16:41:06
ComboFix2.txt 2008-09-20 08:40:34

Pre-Run: 39,181,025,280 bytes free
Post-Run: 39,014,985,728 bytes free

569 — E O F — 2008-09-17 07:00:22
Normally, re-booting the computer after running Combofix is enough to re-establish the Internet connection. Did you try rebooting? if not please do so now.
Also check to make sure none of your security programs are blocking access. Let me know if you still cannot connect to the Internet.

I notice there is still signs of P2P programs on your computer - Limewire. May I remind you of What the Tech's policy on P2P programs: WTT We Do Not Support Policy.
Go to Control Panel > Add/Remove Programs and uninstall Limewire.
Then delete the following folders (if still present):
C:\Documents and Settings\Owner\Incomplete
C:\Program Files\LimeWire
C:\Documents and Settings\Owner\Application Data\LimeWire
Once done post a New Uninstall List & HijackThis log.
well I asked on a different website about the internet problem to try and save you some time and what they told me was to go to cmd and type in these commands: netsh winsock reset catalog and netsh int ip reset reset.log then reboot and now it's recieving packets and created a gateway but still no connection. I did try rebooting yesterday and nothing changed.I checked my security programs too, and nothing seems to be blocking access. I'll add a before/after log below of the IPConfig from the cmd prompt, not sure if that'll help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:22:02 AM, on 9/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M=W3622
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 4404 bytes




Before the commands:

Host Name . . . . . . . . . . . . : MikeJones
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8139/810x Family Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-1B-B9-A2-16-CD
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Autoconfiguration IP Address. . . : 192.168.1.5
Subnet Mask . . . . . . . . . . . : 255.255.0.0
Default Gateway . . . . . . . . . :





After I did the commands:

Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\Owner>IPconfig/all

Windows IP Configuration

Host Name . . . . . . . . . . . . : MikeJones
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : home

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : home
Description . . . . . . . . . . . : Realtek RTL8139/810x Family Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-1B-B9-A2-16-CD
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.5
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1
Lease Obtained. . . . . . . . . . : Sunday, September 21, 2008 9:10:53 A
M
Lease Expires . . . . . . . . . . : Monday, September 22, 2008 9:10:52 A
M

but don't worry about it, you can go ahead and continue getting rid of the virus, I don't want to give you too many things to fix at a time.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI