This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Random Sound Clips At Random Times

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I ran ComboFix it said there was an update and asked me to update it.
I didn't update it, and did the scan anyway. Should I update it and re-do the scan?

Anyway here's the Log of it.

ComboFix 08-09-25.03 - Alex 2008-09-29 21:44:27.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.250 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Alex\Cookies\alex@cubics[1].txt
C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
C:\WINDOWS\Install.txt
C:\WINDOWS\system32\comsa32.sys
C:\WINDOWS\system32\Install.txt
C:\WINDOWS\system32\rtl60.bpl
C:\WINDOWS\system32\tpszxyd.sys

.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-29 )))))))))))))))))))))))))))))))
.

2008-09-27 20:46 . 2008-09-27 20:46 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-09-25 13:51 . 2008-09-25 15:27 d——– C:\Program Files\Daemons Ring Gunz
2008-09-25 08:57 . 2008-09-25 09:03 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-25 08:57 . 2008-09-25 08:57 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-25 08:57 . 2008-09-25 08:57 d——– C:\Documents and Settings\Alex\Application Data\Malwarebytes
2008-09-25 08:57 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-25 08:57 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-25 05:49 . 2008-09-28 13:33 d——– C:\Documents and Settings\Everyone Else\Contacts
2008-09-24 07:55 . 2008-07-18 22:09 25,800 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2008-09-24 06:59 . 2008-09-24 06:59 d——– C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-09-24 06:43 . 2008-09-24 06:43 d——– C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-09-22 18:11 . 2008-09-22 18:11 d——– C:\Documents and Settings\Everyone Else\Application Data\Ventrilo
2008-09-19 07:01 . 2008-09-19 07:15 d–h—– C:\Documents and Settings\Everyone Else\Application Data\ijjigame
2008-09-19 06:55 . 2008-09-19 07:18 d——– C:\Documents and Settings\Everyone Else\Application Data\AVGTOOLBAR
2008-09-19 06:48 . 2008-09-29 21:19 d——– C:\Documents and Settings\Everyone Else
2008-09-19 06:45 . 2008-09-19 06:45 d——– C:\Documents and Settings\Administrator
2008-09-18 03:32 . 2008-09-18 03:32 410,976 –a—— C:\WINDOWS\system32\deploytk.dll
2008-09-18 03:02 . 2008-09-18 03:02 d——– C:\Program Files\CCleaner
2008-09-18 02:40 . 2008-09-18 02:40 d——– C:\Program Files\Trend Micro
2008-09-17 20:44 . 2008-04-23 14:02 157,152 –a—— C:\WINDOWS\system32\PubPlugin.dll
2008-09-13 05:45 . 2008-09-13 04:46 41,117 –a—— C:\HackTasic.DLL.rar
2008-09-09 00:13 . 2008-09-09 00:13 7,680 –ahs—- C:\WINDOWS\Thumbs.db
2008-09-08 01:21 . 2008-09-19 06:58 d——– C:\Program Files\Saga
2008-09-07 23:38 . 2008-09-07 23:38 d——– C:\Program Files\Common Files\Blizzard Entertainment
2008-09-05 23:30 . 2008-09-05 23:30 241,704 —–c— C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-05 23:29 . 2008-09-05 23:29 917,032 —–c— C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-09-03 11:33 . 2008-09-03 11:33 d——– C:\WINDOWS\Sun
2008-09-01 00:01 . 2008-09-01 19:05 d——– C:\Documents and Settings\Alex\Application Data\GarageGames
2008-08-29 01:30 . 2008-08-29 01:30 25 –a—— C:\WINDOWS\TDH_Launcher.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-18 02:31 ——— d—–w C:\Program Files\Java
2008-09-18 01:58 ——— d—–w C:\Documents and Settings\Alex\Application Data\IGN_DLM
2008-09-16 01:03 ——— d–h–w C:\Documents and Settings\Alex\Application Data\ijjigame
2008-09-05 15:54 ——— d—–w C:\Program Files\TuneUp Utilities 2008
2008-09-01 06:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-30 00:33 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-27 18:33 ——— d—–w C:\Documents and Settings\Alex\Application Data\Trash
2008-08-25 07:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sony
2008-08-25 07:16 ——— d—–w C:\Documents and Settings\Alex\Application Data\Sony
2008-08-25 07:11 ——— d—–w C:\Program Files\Sony Ericsson
2008-08-25 07:11 ——— d—–w C:\Program Files\Sony
2008-08-25 07:11 ——— d—–w C:\Program Files\Common Files\Sony Shared
2008-08-25 07:07 ——— d—–w C:\Program Files\Apple Software Update
2008-08-25 07:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-25 07:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-25 07:00 ——— d—–w C:\Program Files\Sony Setup
2008-08-25 07:00 ——— d—–w C:\Documents and Settings\Alex\Application Data\Sony Setup
2008-08-23 23:37 ——— d—–w C:\Documents and Settings\Alex\Application Data\Ventrilo
2008-08-23 23:36 ——— d—–w C:\Program Files\Ventrilo
2008-08-23 23:36 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-21 19:31 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-21 19:29 ——— d—–w C:\Program Files\Windows Live
2008-08-21 18:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-21 02:05 ——— d—–w C:\Documents and Settings\Alex\Application Data\TigerPlayer
2008-08-21 02:02 ——— d—–w C:\Program Files\MpcStar
2008-08-21 01:24 ——— d—–w C:\Documents and Settings\Alex\Application Data\FrostWire
2008-08-20 17:06 ——— d—–w C:\Program Files\Common Files\Java
2008-08-20 16:33 ——— d—–w C:\Program Files\MSBuild
2008-08-20 16:32 ——— d—–w C:\Program Files\Reference Assemblies
2008-08-20 16:26 ——— d—–w C:\Program Files\MSXML 6.0
2008-08-19 06:19 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-15 06:18 355,584 —-a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-15 06:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-15 06:18 ——— d—–w C:\Documents and Settings\Alex\Application Data\TuneUp Software
2008-08-14 10:08 ——— d—–w C:\Documents and Settings\Alex\Application Data\MSNInstaller
2008-08-12 08:38 ——— d—–w C:\Program Files\Google
2008-08-12 06:46 ——— d—–w C:\Program Files\Common Files\INCA Shared
2008-08-12 06:43 ——— d—–w C:\Program Files\NHN USA
2008-08-12 06:00 ——— d—–w C:\Documents and Settings\Alex\Application Data\AVGTOOLBAR
2008-08-12 05:54 ——— d—–w C:\Program Files\BitComet
2008-08-12 05:07 ——— d—–w C:\Program Files\K-Lite Codec Pack
2008-08-12 04:43 76,040 —-a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-12 04:43 10,520 —-a-w C:\WINDOWS\system32\avgrsstx.dll
2008-08-12 04:43 ——— d—–w C:\Program Files\AVG
2008-08-12 04:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-08-12 03:32 ——— d—–w C:\Program Files\microsoft frontpage
2008-08-06 14:27 499,712 —-a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-31 09:41 68,616 —-a-w C:\WINDOWS\system32\XAPOFX1_1.dll
2008-07-31 09:41 238,088 —-a-w C:\WINDOWS\system32\xactengine3_2.dll
2008-07-31 09:40 509,448 —-a-w C:\WINDOWS\system32\XAudio2_2.dll
2008-07-25 08:34 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 —-a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-21 15:14 9,728 —-a-w C:\WINDOWS\system32\RtNicProp32.dll
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-12 07:18 467,984 —-a-w C:\WINDOWS\system32\d3dx10_39.dll
2008-07-12 07:18 3,851,784 —-a-w C:\WINDOWS\system32\D3DX9_39.dll
2008-07-12 07:18 1,493,528 —-a-w C:\WINDOWS\system32\D3DCompiler_39.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
.

((((((((((((((((((((((((((((( snapshot@2008-09-26_ 5.25.21.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-26 03:58:14 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-27 12:14:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-26 03:58:14 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-27 12:14:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-26 03:58:14 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-27 12:14:33 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-04-23 12:54:50 100,488 —-a-w C:\WINDOWS\system32\drivers\s115mgmt.sys
+ 2008-09-29 18:59:28 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_740.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-18 140696]
"QuickTime Task"="C:\Program Files\MpcStar\Codecs\QuickTime\qttask.exe" [2008-05-27 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"vidc.tscc"= C:\PROGRA~1\MpcStar\Codecs\tscc\tsccvid.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"solewxte"=2 (0x2)
"wsldoekd"=2 (0x2)
"tdydowkc"=2 (0x2)
"roytctm"=2 (0x2)
"noytcyr"=2 (0x2)
"afisicx"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"HijackThis startup scan"=C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\ijji\\ENGLISH\\u_gunz.exe"=
"C:\\ijji\\ENGLISH\\Gunz\\GunzLauncher.exe"=
"C:\\ijji\\ENGLISH\\Gunz\\Gunz.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"C:\\Program Files\\Daemons Ring Gunz\\DRGunZ.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19205:TCP"= 19205:TCP:BitComet 19205 TCP
"19205:UDP"= 19205:UDP:BitComet 19205 UDP
"8000:TCP"= 8000:TCP:Ijji Gunz 8000 TCP
"8000:UDP"= 8000:UDP:Ijji Gunz 8000 UDP
"7750:TCP"= 7750:TCP:Ijji Gunz 7750 TCP
"7750:UDP"= 7750:UDP:Ijji Gunz 7750 UDP

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-30 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-12 76040]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-09-18 152984]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R3 STAC97NA;SigmaTel 3D Environmental Audio;C:\WINDOWS\system32\drivers\stac97na.sys [2002-09-20 296179]
R3 STAC97NH;STAC97NH;C:\WINDOWS\system32\drivers\stac97nh.sys [2002-09-20 231983]
S0 ibnd;ibnd;C:\WINDOWS\system32\drivers\mmuacggp.sys [ ]
S3 dump_wmimmc;dump_wmimmc;C:\ijji\ENGLISH\Gunz\GameGuard\dump_wmimmc.sys [ ]
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\DOCUME~1\Alex\LOCALS~1\Temp\Rar$EX25.062\MoonLight Engine 1196.4\IlvMoney1215.sys [ ]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);C:\WINDOWS\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-15 355584]
S3 XDva092;XDva092;C:\WINDOWS\system32\XDva092.sys [ ]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\em6etqkv.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.com
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin2.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin3.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin4.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin5.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-29 21:48:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-09-29 21:51:40
ComboFix-quarantined-files.txt 2008-09-29 20:51:30
ComboFix2.txt 2008-09-26 04:26:00

Pre-Run: 97,230,274,560 bytes free
Post-Run: 97,435,439,104 bytes free

232
Here's the HJT Log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:55:11, on 29/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1801674531-1390067357-682003330-1016\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Everyone Else')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218518179171
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1218518268109
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.instantaction.com/download/iaplayer.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

–
End of file - 5638 bytes
I have no idea what this file is. I added it to the fix, but if you want to keep it, remove from the fix.
C:\HackTasic.DLL.rar


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\HackTasic.DLL.rar
C:\WINDOWS\system32\drivers\mmuacggp.sys

Driver::
mmuacggp

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"solewxte"=-
"wsldoekd"=-
"tdydowkc"=-
"roytctm"=-
"noytcyr"=-
"afisicx"=-

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
ComboFix 08-09-28.03 - Alex 2008-09-30 6:38:50.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.236 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Alex\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\HackTasic.DLL.rar
C:\WINDOWS\system32\drivers\mmuacggp.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
C:\HackTasic.DLL.rar

.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-30 )))))))))))))))))))))))))))))))
.

2008-09-30 04:53 . 2008-09-30 04:53 d——– C:\Program Files\Lavalys
2008-09-27 20:46 . 2008-09-27 20:46 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-09-25 13:51 . 2008-09-25 15:27 d——– C:\Program Files\Daemons Ring Gunz
2008-09-25 08:57 . 2008-09-25 09:03 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-25 08:57 . 2008-09-25 08:57 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-25 08:57 . 2008-09-25 08:57 d——– C:\Documents and Settings\Alex\Application Data\Malwarebytes
2008-09-25 08:57 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-25 08:57 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-25 05:49 . 2008-09-28 13:33 d——– C:\Documents and Settings\Everyone Else\Contacts
2008-09-24 07:55 . 2008-07-18 22:09 25,800 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2008-09-24 06:59 . 2008-09-24 06:59 d——– C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-09-24 06:43 . 2008-09-24 06:43 d——– C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-09-22 18:11 . 2008-09-22 18:11 d——– C:\Documents and Settings\Everyone Else\Application Data\Ventrilo
2008-09-19 07:01 . 2008-09-19 07:15 d–h—– C:\Documents and Settings\Everyone Else\Application Data\ijjigame
2008-09-19 06:55 . 2008-09-19 07:18 d——– C:\Documents and Settings\Everyone Else\Application Data\AVGTOOLBAR
2008-09-19 06:48 . 2008-09-29 21:19 d——– C:\Documents and Settings\Everyone Else
2008-09-19 06:45 . 2008-09-19 06:45 d——– C:\Documents and Settings\Administrator
2008-09-18 03:32 . 2008-09-18 03:32 410,976 –a—— C:\WINDOWS\system32\deploytk.dll
2008-09-18 03:02 . 2008-09-18 03:02 d——– C:\Program Files\CCleaner
2008-09-18 02:40 . 2008-09-18 02:40 d——– C:\Program Files\Trend Micro
2008-09-17 20:44 . 2008-04-23 14:02 157,152 –a—— C:\WINDOWS\system32\PubPlugin.dll
2008-09-09 00:13 . 2008-09-09 00:13 7,680 –ahs—- C:\WINDOWS\Thumbs.db
2008-09-08 01:21 . 2008-09-19 06:58 d——– C:\Program Files\Saga
2008-09-07 23:38 . 2008-09-07 23:38 d——– C:\Program Files\Common Files\Blizzard Entertainment
2008-09-05 23:30 . 2008-09-05 23:30 241,704 —–c— C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-05 23:29 . 2008-09-05 23:29 917,032 —–c— C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-09-03 11:33 . 2008-09-03 11:33 d——– C:\WINDOWS\Sun
2008-09-01 00:01 . 2008-09-01 19:05 d——– C:\Documents and Settings\Alex\Application Data\GarageGames
2008-08-29 01:30 . 2008-08-29 01:30 25 –a—— C:\WINDOWS\TDH_Launcher.ini
2008-08-28 23:55 . 2008-09-01 07:12 d——– C:\Mgame
2008-08-28 01:43 . 2004-08-04 00:56 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2008-08-28 01:43 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-08-28 01:43 . 2004-08-03 22:58 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-08-28 01:43 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2008-08-25 14:38 . 2008-08-25 14:38 d——– C:\Documents and Settings\Alex\WINDOWS
2008-08-25 14:38 . 1998-07-30 12:51 305,152 –a—— C:\WINDOWS\IsUninst.exe
2008-08-25 10:19 . 2008-08-27 19:33 d——– C:\Documents and Settings\Alex\Application Data\Trash
2008-08-25 08:16 . 2008-08-25 08:16 d——– C:\Documents and Settings\All Users\Application Data\Sony
2008-08-25 08:16 . 2008-08-25 08:16 d——– C:\Documents and Settings\Alex\Application Data\Sony
2008-08-25 08:11 . 2008-08-25 08:11 d——– C:\Program Files\Sony Ericsson
2008-08-25 08:11 . 2008-08-25 08:11 d——– C:\Program Files\Sony
2008-08-25 08:11 . 2008-08-25 08:11 d——– C:\Program Files\Common Files\Sony Shared
2008-08-25 08:07 . 2008-08-25 08:07 d——– C:\Program Files\Apple Software Update
2008-08-25 08:07 . 2008-08-25 08:07 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-08-25 08:06 . 2004-08-04 13:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-08-25 08:03 . 2008-08-25 08:03 d——– C:\WINDOWS\system32\LogFiles
2008-08-25 08:03 . 2008-08-25 08:04 d——– C:\WINDOWS\system32\drivers\UMDF
2008-08-25 08:00 . 2008-08-25 08:00 d——– C:\Program Files\Sony Setup
2008-08-25 08:00 . 2008-08-25 08:00 d——– C:\Documents and Settings\Alex\Application Data\Sony Setup
2008-08-24 00:37 . 2008-08-24 00:37 d——– C:\Documents and Settings\Alex\Application Data\Ventrilo
2008-08-24 00:36 . 2008-08-24 00:36 d——– C:\Program Files\Ventrilo
2008-08-21 21:17 . 2004-08-03 23:08 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-08-21 21:17 . 2004-08-03 23:08 31,616 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-08-21 19:23 . 2008-08-21 20:31 d——– C:\Program Files\Windows Live Toolbar
2008-08-21 03:41 . 2008-08-21 03:41 d——– C:\Documents and Settings\Alex\Limewire
2008-08-21 03:03 . 2008-08-21 03:05 d——– C:\Documents and Settings\Alex\Application Data\TigerPlayer
2008-08-21 03:00 . 2008-08-25 08:07 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-21 02:59 . 2008-08-21 03:02 d——– C:\Program Files\MpcStar
2008-08-20 18:18 . 2008-09-19 21:20 d–h—– C:\$AVG8.VAULT$
2008-08-20 18:08 . 2008-08-21 02:24 d——– C:\Documents and Settings\Alex\Incomplete
2008-08-20 18:07 . 2008-08-21 02:24 d——– C:\Documents and Settings\Alex\Application Data\FrostWire
2008-08-20 18:07 . 2008-09-18 03:32 73,728 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-08-20 18:06 . 2008-09-18 03:31 d——– C:\Program Files\Java
2008-08-20 18:06 . 2008-08-20 18:06 d——– C:\Program Files\Common Files\Java
2008-08-20 17:33 . 2008-08-20 17:33 d——– C:\WINDOWS\system32\XPSViewer
2008-08-20 17:33 . 2008-08-20 17:33 d——– C:\Program Files\MSBuild
2008-08-20 17:32 . 2008-08-20 17:32 d——– C:\Program Files\Reference Assemblies
2008-08-20 17:32 . 2006-06-29 13:07 14,048 ——— C:\WINDOWS\system32\spmsg2.dll
2008-08-20 17:26 . 2008-08-20 17:26 d——– C:\Program Files\MSXML 6.0
2008-08-20 17:17 . 2007-07-19 18:14 3,727,720 –a—— C:\WINDOWS\system32\d3dx9_35.dll
2008-08-20 17:11 . 2008-08-20 17:16 d–h—– C:\WINDOWS\msdownld.tmp
2008-08-20 17:10 . 2008-08-20 17:10 d——– C:\WINDOWS\Logs
2008-08-20 16:30 . 2008-06-23 17:57 6,066,176 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-08-20 16:30 . 2007-04-17 10:32 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-08-20 16:30 . 2007-03-08 06:10 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-08-20 16:30 . 2008-06-23 17:57 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-08-20 16:30 . 2008-06-23 17:57 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-08-20 16:30 . 2008-06-23 17:57 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-08-20 16:30 . 2008-06-23 17:57 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-08-20 16:30 . 2008-06-23 17:57 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-08-20 16:30 . 2008-06-23 10:20 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-20 16:29 . 2008-06-13 14:10 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-08-20 16:29 . 2008-06-13 14:10 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-20 14:27 . 2008-09-30 06:16 d——– C:\WINDOWS\system32\CatRoot_bak
2008-08-20 13:19 . 2008-08-06 15:27 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-08-20 11:04 . 2008-09-18 02:58 d——– C:\Documents and Settings\Alex\Application Data\IGN_DLM
2008-08-19 19:57 . 2008-08-19 19:57 0 –a—— C:\WINDOWS\nsreg.dat
2008-08-19 07:22 . 2008-09-14 23:11 d——– C:\Documents and Settings\Alex\Contacts
2008-08-19 07:19 . 2008-08-19 07:19 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-08-19 07:12 . 2008-08-19 07:19 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-19 07:11 . 2008-08-21 20:29 d——– C:\Program Files\Windows Live
2008-08-19 07:11 . 2008-08-21 19:21 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-15 07:18 . 2008-09-30 05:53 d——– C:\Program Files\TuneUp Utilities 2008
2008-08-15 07:18 . 2008-08-15 07:18 d——– C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-15 07:18 . 2008-08-15 07:18 d——– C:\Documents and Settings\Alex\Application Data\TuneUp Software
2008-08-15 07:18 . 2008-08-15 07:18 355,584 –a—— C:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-15 07:18 . 2008-05-29 09:28 28,416 –a—— C:\WINDOWS\system32\uxtuneup.dll
2008-08-15 07:16 . 2008-08-24 00:36 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-08-14 11:08 . 2008-08-14 11:08 d——– C:\Documents and Settings\Alex\Application Data\MSNInstaller
2008-08-14 04:38 . 2008-08-20 13:19 d——– C:\WINDOWS\system32\Adobe
2008-08-12 07:46 . 2008-08-12 07:46 d——– C:\Program Files\Common Files\INCA Shared
2008-08-12 07:46 . 2003-07-17 19:17 5,174 –a—— C:\WINDOWS\system32\nppt9x.vxd
2008-08-12 07:46 . 2005-01-01 10:43 4,682 –a—— C:\WINDOWS\system32\npptNT2.sys
2008-08-12 07:46 . 2008-09-29 22:21 32 –a—— C:\WINDOWS\GunzLauncher.INI
2008-08-12 07:44 . 2008-09-16 02:03 d–h—– C:\Documents and Settings\Alex\Application Data\ijjigame
2008-08-12 07:43 . 2008-08-12 07:43 d——– C:\Program Files\NHN USA
2008-08-12 07:43 . 2008-09-01 07:11 d–h—– C:\Program Files\InstallShield Installation Information
2008-08-12 07:43 . 2008-06-17 19:28 710,064 –a—— C:\WINDOWS\system32\ijjiSetup.exe
2008-08-12 07:43 . 2008-06-11 23:01 58,800 –a—— C:\WINDOWS\system32\ijjiPlugin2.dll
2008-08-12 07:41 . 2008-09-22 23:22 d——– C:\ijji
2008-08-12 06:54 . 2008-08-12 09:38 d——– C:\Program Files\Google
2008-08-12 06:53 . 2008-08-12 06:54 d——– C:\Program Files\BitComet
2008-08-12 06:53 . 2008-09-17 20:31 d—-c— C:\Downloads
2008-08-12 06:16 . 2008-07-18 22:10 45,768 –a—— C:\WINDOWS\system32\wups2.dll
2008-08-12 06:16 . 2008-07-18 22:10 33,992 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2008-08-12 06:16 . 2008-07-18 22:09 25,800 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-08-12 06:16 . 2006-10-16 16:10 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-08-12 06:16 . 2008-07-18 22:08 20,680 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2008-08-12 06:15 . 2008-09-24 08:07 d–h—– C:\WINDOWS\$hf_mig$
2008-08-12 06:07 . 2008-08-12 06:07 d——– C:\Program Files\K-Lite Codec Pack
2008-08-12 05:43 . 2008-09-30 04:50 d——– C:\WINDOWS\system32\drivers\Avg
2008-08-12 05:43 . 2008-08-12 05:43 d——– C:\Program Files\AVG
2008-08-12 05:43 . 2008-08-12 05:43 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-08-12 05:43 . 2008-08-12 07:00 d——– C:\Documents and Settings\Alex\Application Data\AVGTOOLBAR
2008-08-12 05:43 . 2008-08-30 01:33 97,928 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-12 03:32 ——— d—–w C:\Program Files\microsoft frontpage
2008-07-31 09:41 68,616 —-a-w C:\WINDOWS\system32\XAPOFX1_1.dll
2008-07-31 09:41 238,088 —-a-w C:\WINDOWS\system32\xactengine3_2.dll
2008-07-31 09:40 509,448 —-a-w C:\WINDOWS\system32\XAudio2_2.dll
2008-07-25 08:34 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-07-25 08:34 683,520 —-a-w C:\WINDOWS\system32\divx.dll
2008-07-23 16:50 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-21 15:14 9,728 —-a-w C:\WINDOWS\system32\RtNicProp32.dll
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-12 07:18 467,984 —-a-w C:\WINDOWS\system32\d3dx10_39.dll
2008-07-12 07:18 3,851,784 —-a-w C:\WINDOWS\system32\D3DX9_39.dll
2008-07-12 07:18 1,493,528 —-a-w C:\WINDOWS\system32\D3DCompiler_39.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-12 18:36 7,680 —-a-w C:\WINDOWS\system32\ff_vfw.dll
.

((((((((((((((((((((((((((((( snapshot@2008-09-26_ 5.25.21.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-10-23 09:37:28 241,664 —-a-w C:\WINDOWS\Downloaded Program Files\cpcScan.dll
- 2004-08-03 22:29:28 701,440 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\ati2mtag.sys
- 2004-08-04 12:00:00 100,352 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\6to4svc.dll
- 2004-08-03 21:39:38 142,464 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\aec.sys
- 2004-08-04 00:56:42 201,728 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\ati2dvag.dll
- 2004-08-04 00:56:42 1,888,992 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\ati3duag.dll
- 2004-08-04 00:56:42 516,768 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\ativvaxx.dll
- 2004-08-04 12:00:00 56,832 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\authz.dll
- 2004-08-04 12:00:00 229,888 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\catsrv.dll
- 2004-08-04 12:00:00 628,224 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\catsrvut.dll
- 2004-08-04 12:00:00 2,067,968 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\cdosys.dll
- 2004-08-04 12:00:00 110,080 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\clbcatex.dll
- 2004-08-04 12:00:00 501,248 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\clbcatq.dll
- 2004-08-04 12:00:00 62,464 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\colbact.dll
- 2004-08-04 12:00:00 195,584 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\comadmin.dll
- 2004-08-04 12:00:00 82,432 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\comrepl.dll
- 2004-08-04 12:00:00 1,251,840 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\comsvcs.dll
- 2004-08-04 12:00:00 540,160 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\comuid.dll
- 2004-08-04 12:00:00 148,480 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\dnsapi.dll
- 2004-08-04 12:00:00 243,200 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\es.dll
- 2004-08-04 12:00:00 1,082,368 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\esent.dll
- 2004-08-04 12:00:00 79,360 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\fontsub.dll
- 2004-08-04 12:00:00 10,752 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\hh.exe
- 2004-08-04 12:00:00 38,912 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\hhsetup.dll
- 2004-08-04 12:00:00 77,850 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\hlink.dll
- 2004-08-04 12:00:00 263,040 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\http.sys
- 2004-08-04 12:00:00 345,088 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\hypertrm.dll
- 2004-08-04 12:00:00 253,952 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\icm32.dll
- 2004-08-04 12:00:00 134,912 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\ipnat.sys
- 2004-08-04 12:00:00 143,872 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\itircl.dll
- 2004-08-04 12:00:00 134,144 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\itss.dll
- 2004-08-04 12:00:00 294,400 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\kerberos.dll
- 2004-08-03 22:07:50 171,776 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\kmixer.sys
- 2004-08-04 12:00:00 18,944 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\linkinfo.dll
- 2004-08-04 12:00:00 7,680 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\migregdb.exe
- 2004-08-04 12:00:00 451,456 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\mrxsmb.sys
- 2004-08-04 12:00:00 143,360 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\msadco.dll
- 2004-08-04 12:00:00 73,728 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\mscms.dll
- 2004-08-04 12:00:00 425,472 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\msdtcprx.dll
- 2004-08-04 12:00:00 949,248 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\msdtctm.dll
- 2004-08-04 12:00:00 161,280 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\msdtcuiu.dll
- 2004-08-04 00:06:34 1,667,584 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\msmsgs.exe
- 2004-08-04 12:00:00 66,560 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\mtxclu.dll
- 2004-08-04 12:00:00 90,112 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\mtxoci.dll
- 2004-08-04 12:00:00 198,144 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\netman.dll
- 2004-08-03 22:18:32 2,148,352 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\ntkrnlmp.exe
- 2004-08-04 12:00:00 2,056,832 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\ntkrnlpa.exe
- 2004-08-03 21:59:02 2,015,232 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\ntkrpamp.exe
- 2004-08-04 12:00:00 2,180,992 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\ntoskrnl.exe
- 2004-08-04 12:00:00 1,281,536 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\ole32.dll
- 2004-08-04 12:00:00 68,608 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\olecli32.dll
- 2004-08-04 12:00:00 34,304 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\olecnv32.dll
- 2004-08-04 12:00:00 1,435,648 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\query.dll
- 2004-08-04 12:00:00 8,192 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\rasadhlp.dll
- 2004-08-04 12:00:00 174,080 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\rasmans.dll
- 2004-08-04 12:00:00 176,512 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\rdbss.sys
- 2004-08-04 12:00:00 139,400 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\rdpwd.sys
- 2004-08-04 12:00:00 395,776 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\rpcss.dll
- 2004-08-04 12:00:00 8,384,000 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\shell32.dll
- 2004-08-04 12:00:00 473,600 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\shlwapi.dll
- 2004-08-04 12:00:00 57,856 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\spoolsv.exe
- 2004-08-04 12:00:00 336,256 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\srv.sys
- 2004-08-04 12:00:00 96,768 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\srvsvc.dll
- 2004-08-04 12:00:00 210,432 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\t2embed.dll
- 2004-08-04 12:00:00 246,272 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\tapisrv.dll
- 2004-08-04 12:00:00 75,264 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\telnet.exe
- 2004-08-04 12:00:00 101,376 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\txflog.dll
- 2004-08-04 12:00:00 118,272 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\umpnpmgr.dll
- 2004-08-04 12:00:00 577,024 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\user32.dll
- 2004-08-03 22:15:06 82,944 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\wdmaud.sys
- 2004-08-04 12:00:00 67,584 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\webclnt.dll
- 2004-08-04 12:00:00 1,835,904 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\win32k.sys
- 2004-08-04 12:00:00 290,816 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\winsrv.dll
- 2004-08-04 12:00:00 11,776 ——w C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\xolehlp.dll
- 2008-09-26 03:58:14 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-27 12:14:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-09-26 03:58:14 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-27 12:14:33 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-26 03:58:14 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-27 12:14:33 278,528 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-04-23 12:54:50 100,488 —-a-w C:\WINDOWS\system32\drivers\s115mgmt.sys
- 2008-08-20 16:34:08 67,676 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-09-30 04:16:21 67,560 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-20 16:34:08 433,164 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-09-30 04:16:21 432,856 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-09-30 05:20:27 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_73c.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-18 140696]
"QuickTime Task"="C:\Program Files\MpcStar\Codecs\QuickTime\qttask.exe" [2008-05-27 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"vidc.tscc"= C:\PROGRA~1\MpcStar\Codecs\tscc\tsccvid.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"HijackThis startup scan"=C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\ijji\\ENGLISH\\u_gunz.exe"=
"C:\\ijji\\ENGLISH\\Gunz\\GunzLauncher.exe"=
"C:\\ijji\\ENGLISH\\Gunz\\Gunz.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"C:\\Program Files\\Daemons Ring Gunz\\DRGunZ.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19205:TCP"= 19205:TCP:BitComet 19205 TCP
"19205:UDP"= 19205:UDP:BitComet 19205 UDP
"8000:TCP"= 8000:TCP:Ijji Gunz 8000 TCP
"8000:UDP"= 8000:UDP:Ijji Gunz 8000 UDP
"7750:TCP"= 7750:TCP:Ijji Gunz 7750 TCP
"7750:UDP"= 7750:UDP:Ijji Gunz 7750 UDP

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-30 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-30 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-30 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-12 76040]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-09-18 152984]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R3 STAC97NA;SigmaTel 3D Environmental Audio;C:\WINDOWS\system32\drivers\stac97na.sys [2002-09-20 296179]
R3 STAC97NH;STAC97NH;C:\WINDOWS\system32\drivers\stac97nh.sys [2002-09-20 231983]
S0 ibnd;ibnd;C:\WINDOWS\system32\drivers\mmuacggp.sys [ ]
S3 dump_wmimmc;dump_wmimmc;C:\ijji\ENGLISH\Gunz\GameGuard\dump_wmimmc.sys [ ]
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;C:\DOCUME~1\Alex\LOCALS~1\Temp\Rar$EX25.062\MoonLight Engine 1196.4\IlvMoney1215.sys [ ]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);C:\WINDOWS\system32\DRIVERS\s115bus.sys [2007-04-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s115mdfl.sys [2007-04-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s115mdm.sys [2007-04-23 108680]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s115mgmt.sys [2007-04-23 100488]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s115obex.sys [2007-04-23 98568]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-15 355584]
S3 XDva092;XDva092;C:\WINDOWS\system32\XDva092.sys [ ]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-30 06:41:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


C:\WINDOWS\TEMP\4f38b2cf-481e-477b-817b-98931fae5888.tmp

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2008-09-30 6:45:11
ComboFix-quarantined-files.txt 2008-09-30 05:45:07
ComboFix2.txt 2008-09-29 20:51:42
ComboFix3.txt 2008-09-26 04:26:00

Pre-Run: 96,728,313,856 bytes free
Post-Run: 96,763,211,776 bytes free

344
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:51:00, on 30/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218518179171
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1222748317656
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.orderingmemory.com/controls/cpcScanner.cab
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.instantaction.com/download/iaplayer.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

–
End of file - 5586 bytes
So far it seems to have worked. I haven't hear anything in a few days. If it has truly worked, I'mma donate. A little thank you for helping me. ^__^
Well I've just had to ReFormat my comp because my brother somehow messed up the Registry stopping us from booting Windows. You got rid of the Malware for me, so as promies I'll donate. Won't be much as I'm not made of money, but it's all good. :thumbup: Cheers dude.

Well I've just had to ReFormat my comp because my brother somehow messed up the Registry stopping us from booting Windows. You got rid of the Malware for me, so as promies I'll donate. Won't be much as I'm not made of money, but it's all good. :thumbup:

Cheers dude.

:pullhair:
You're more then welcome.

Thank You :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI