This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Unwanted Popups - HijackThis Log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. Looking to rid my system of some unwanted popups. I had some nasty malware/spyware/adware on here, and i ran Malwarebytes, spybot, Adaware, and AVG virus scan and got rid of most of it. I'm still encountering random popup ads that IE is not catching. Can someone please examine my hijackthis log and let me know where to begin? Thank you very much for your help.

ybstuk



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:29:44 PM, on 10/20/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Apoint\HidFind.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\dlbtcoms.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: {8840c3a7-d16c-56ea-5654-d07e70823407} - {70432807-e70d-4565-ae65-c61d7a3c0488} - C:\WINDOWS\system32\jfbotz.dll
O3 - Toolbar: olnmraew - {B57C06B1-B493-4579-840D-0ED09B8BDDF6} - (no file)
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.mpix.com/customer/uploading/act…geUploader5.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll jfbotz.dll
O21 - SSODL: qmafxprs - {5D90CB84-2A6D-437B-87C2-91D6258B91E2} - (no file)
O21 - SSODL: lfstbwvd - {D305DCC9-92A6-4258-BDA0-5EAD51D480F5} - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: Privacy Protection - (no file)

–
End of file - 5648 bytes
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Please post the log from MalwareBytes' AntiMalware, you can find it here:
C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt


Let's get some more information then we'll clean you up.
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Thanks.
Thank you for your reply! sorry it took me a while to get back to you. i have done what you requested, and below are the logs. please let me know what steps you'd like me to take next. Thank you!!!




Malwarebytes' Anti-Malware 1.28
Database version: 1134
Windows 5.1.2600 Service Pack 3

10/23/2008 9:26:50 PM
mbam-log-2008-10-23 (21-26-50).txt

Scan type: Full Scan (C:\|)
Objects scanned: 107894
Time elapsed: 39 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)









Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-23 21:29:08
Microsoft Windows XP Professional Service Pack 3
System drive C: has 98 GB (86%) free of 114 GB
Total RAM: 1023 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:29:15 PM, on 10/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Hartmann\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Hartmann.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: {8840c3a7-d16c-56ea-5654-d07e70823407} - {70432807-e70d-4565-ae65-c61d7a3c0488} - C:\WINDOWS\system32\jfbotz.dll
O3 - Toolbar: olnmraew - {B57C06B1-B493-4579-840D-0ED09B8BDDF6} - (no file)
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.mpix.com/customer/uploading/act…geUploader5.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll jfbotz.dll
O21 - SSODL: qmafxprs - {5D90CB84-2A6D-437B-87C2-91D6258B91E2} - (no file)
O21 - SSODL: lfstbwvd - {D305DCC9-92A6-4258-BDA0-5EAD51D480F5} - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: Privacy Protection - (no file)

–
End of file - 5666 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70432807-e70d-4565-ae65-c61d7a3c0488}]
C:\WINDOWS\system32\jfbotz.dll [2008-10-11 108544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B57C06B1-B493-4579-840D-0ED09B8BDDF6} - []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2007-02-21 819200]
"IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2007-02-21 970752]
"Apoint"=C:\Program Files\Apoint\Apoint.exe [2005-10-07 176128]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-10-02 1234712]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"DLBTCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll []
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-10-10 413696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll jfbotz.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-08-03 46080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
qmafxprs - {5D90CB84-2A6D-437B-87C2-91D6258B91E2}
lfstbwvd - {D305DCC9-92A6-4258-BDA0-5EAD51D480F5}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{903C377B-E501-4A35-A6B2-1E3994711EA1}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSserv.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDSSserv.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"NoDispCPL"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoStartMenuMorePrograms"=0
"StartMenuLogOff"=0
"NoToolbarCustomize"=0
"NoSetFolders"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2008-10-23 21:29:08 —-D—- C:\rsit
2008-10-22 15:54:38 —-D—- C:\Documents and Settings\Hartmann\Application Data\Canon
2008-10-22 15:50:33 —-A—- C:\WINDOWS\system32\ptpusb.dll
2008-10-22 15:50:32 —-A—- C:\WINDOWS\system32\ptpusd.dll
2008-10-22 15:43:46 —-D—- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-10-22 15:41:05 —-D—- C:\Program Files\Canon
2008-10-22 15:38:56 —-RSD—- C:\WINDOWS\assembly
2008-10-22 15:38:22 —-D—- C:\WINDOWS\Microsoft.NET
2008-10-22 15:30:15 —-D—- C:\Program Files\Common Files\Canon
2008-10-20 21:29:24 —-D—- C:\Program Files\Trend Micro
2008-10-15 20:34:38 —-D—- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-10-15 20:23:05 —-D—- C:\Program Files\Bonjour
2008-10-15 20:16:47 —-D—- C:\Program Files\Common Files\Macrovision Shared
2008-10-14 13:12:14 —-D—- C:\Program Files\My Photo Calendars and Cards
2008-10-13 20:07:42 —-D—- C:\Program Files\Lavasoft
2008-10-13 20:07:40 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-13 20:06:16 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-12 09:45:34 —-D—- C:\WINDOWS\CSC
2008-10-12 09:39:59 —-D—- C:\Documents and Settings\All Users\Application Data\jctiborg
2008-10-12 09:38:44 —-D—- C:\Documents and Settings\Hartmann\Application Data\TmpRecentIcons
2008-10-12 09:37:26 —-A—- C:\WINDOWS\vortsgbqpvo.dll
2008-10-12 09:34:38 —-D—- C:\Documents and Settings\Hartmann\Application Data\sp2
2008-10-11 09:00:23 —-D—- C:\Program Files\ToniArts
2008-10-11 08:58:30 —-A—- C:\WINDOWS\ntbtlog.txt
2008-10-11 08:56:59 —-D—- C:\Documents and Settings\All Users\Application Data\exgfebmr
2008-10-11 08:47:32 —-D—- C:\WINDOWS\system32\LogFiles
2008-10-11 08:35:47 —-A—- C:\WINDOWS\system32\jfbotz.dll
2008-10-11 08:35:46 —-A—- C:\WINDOWS\system32\ashowkfe.dll
2008-10-11 08:35:17 —-A—- C:\WINDOWS\system32\b364fc5e-.txt
2008-10-11 08:27:06 —-D—- C:\Documents and Settings\All Users\Application Data\xghatopy
2008-10-11 08:26:58 —-D—- C:\Documents and Settings\Hartmann\Application Data\Malwarebytes
2008-10-11 08:26:48 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-11 08:26:48 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-11 08:25:27 —-D—- C:\Documents and Settings\Hartmann\Application Data\Rapid Antivirus
2008-10-11 08:25:18 —-D—- C:\Documents and Settings\Hartmann\Application Data\0000005738
2008-10-10 23:05:10 —-HD—- C:\$AVG8.VAULT$
2008-10-10 08:07:31 —-D—- C:\Program Files\Common Files\Apple
2008-10-10 08:07:24 —-D—- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-10-10 08:07:08 —-D—- C:\Program Files\Apple Software Update
2008-10-10 08:07:08 —-D—- C:\Documents and Settings\All Users\Application Data\Apple
2008-10-10 08:02:16 —-D—- C:\Program Files\QuickTime
2008-10-09 20:49:19 —-D—- C:\Program Files\uTorrent
2008-10-09 20:49:11 —-D—- C:\Documents and Settings\Hartmann\Application Data\uTorrent
2008-10-09 20:26:31 —-D—- C:\Program Files\Dl_cats
2008-10-09 20:26:18 —-A—- C:\WINDOWS\dellstat.ini
2008-10-09 20:25:03 —-A—- C:\WINDOWS\system32\dlbtpmui.dll
2008-10-09 20:25:03 —-A—- C:\WINDOWS\system32\dlbtinsb.dll
2008-10-09 20:25:03 —-A—- C:\WINDOWS\system32\dlbtcub.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtvs.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtusb1.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtserv.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtprox.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtpplc.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtlmpm.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtinsr.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtins.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtih.exe
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbthbn1.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtcoms.exe
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtcomm.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtcomc.dll
2008-10-09 20:25:02 —-A—- C:\WINDOWS\system32\dlbtcfg.exe
2008-10-09 20:25:01 —-A—- C:\WINDOWS\system32\dlbtcur.dll
2008-10-09 20:25:01 —-A—- C:\WINDOWS\system32\dlbtcu.dll
2008-10-09 20:25:00 —-A—- C:\WINDOWS\system32\dlbtjswr.dll
2008-10-09 20:24:57 —-A—- C:\WINDOWS\system32\dlbtutil.dll
2008-10-09 20:24:57 —-A—- C:\WINDOWS\system32\dlbtgf.dll
2008-10-09 20:24:56 —-D—- C:\Program Files\Dell Photo AIO Printer 922
2008-10-09 20:24:50 —-D—- C:\Temp
2008-10-09 20:24:37 —-D—- C:\Dell922
2008-10-09 15:57:27 —-A—- C:\WINDOWS\system32\wiafbdrv.dll
2008-10-02 21:21:18 —-D—- C:\Program Files\NCH Swift Sound
2008-10-02 21:21:18 —-D—- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-09-26 13:26:50 —-D—- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-26 13:26:44 —-D—- C:\Program Files\Yahoo!
2008-09-25 20:26:04 —-D—- C:\Documents and Settings\Hartmann\Application Data\OfficeUpdate12
2008-09-25 20:24:04 —-D—- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-09-25 20:19:11 —-A—- C:\WINDOWS\ODBC.INI
2008-09-25 20:19:07 —-A—- C:\WINDOWS\system32\mdimon.dll
2008-09-25 20:18:30 —-D—- C:\Program Files\Microsoft.NET
2008-09-25 20:18:27 —-D—- C:\Program Files\Microsoft ActiveSync
2008-09-25 20:18:11 —-D—- C:\Program Files\Common Files\DESIGNER
2008-09-25 20:17:56 —-D—- C:\WINDOWS\SHELLNEW
2008-09-25 20:15:27 —-D—- C:\Program Files\Microsoft Office
2008-09-25 20:12:48 —-RHD—- C:\MSOCache

======List of files/folders modified in the last 1 months======

2008-10-23 21:29:10 —-D—- C:\WINDOWS\Temp
2008-10-23 21:18:15 —-D—- C:\WINDOWS\system32
2008-10-23 21:15:25 —-D—- C:\WINDOWS
2008-10-23 20:24:09 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-22 17:39:14 —-D—- C:\WINDOWS\Prefetch
2008-10-22 16:05:53 —-SD—- C:\Documents and Settings\Hartmann\Application Data\Microsoft
2008-10-22 15:46:37 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-22 15:41:05 —-RD—- C:\Program Files
2008-10-22 15:40:51 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-22 15:39:22 —-SHD—- C:\WINDOWS\Installer
2008-10-22 15:38:59 —-D—- C:\WINDOWS\WinSxS
2008-10-22 15:38:39 —-HD—- C:\WINDOWS\inf
2008-10-22 15:38:29 —-D—- C:\Program Files\Internet Explorer
2008-10-22 15:30:15 —-D—- C:\Program Files\Common Files
2008-10-16 18:28:12 —-D—- C:\Documents and Settings\Hartmann\Application Data\Adobe
2008-10-16 08:28:57 —-A—- C:\WINDOWS\win.ini
2008-10-15 20:24:16 —-D—- C:\Program Files\Adobe
2008-10-15 20:22:50 —-D—- C:\Program Files\Common Files\Adobe
2008-10-15 20:21:16 —-RSD—- C:\WINDOWS\Fonts
2008-10-13 20:07:42 —-D—- C:\WINDOWS\system32\drivers
2008-10-12 09:39:55 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-10-11 09:00:21 —-HD—- C:\Program Files\InstallShield Installation Information
2008-10-11 08:58:15 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-10 08:02:18 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-10-09 15:57:33 —-D—- C:\WINDOWS\twain_32
2008-09-25 20:58:51 —-D—- C:\Program Files\Common Files\Microsoft Shared
2008-09-25 20:17:58 —-D—- C:\Program Files\Common Files\System
2008-09-25 20:15:27 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-09-25 20:14:41 —-D—- C:\WINDOWS\msapps
2008-09-25 20:14:40 —-D—- C:\WINDOWS\system
2008-09-25 20:14:40 —-D—- C:\Program Files\microsoft frontpage
2008-09-24 06:33:16 —-D—- C:\Program Files\NOS
2008-09-24 06:33:16 —-D—- C:\Documents and Settings\All Users\Application Data\NOS

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-09-22 97928]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-09-22 26824]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.6.0.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-09-20 21425]
R2 AvgTdiX;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-09-22 76040]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-02-21 12416]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2005-09-28 113847]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-03 1273344]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2004-05-26 44928]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.SYS [2005-05-03 1033728]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2005-05-03 208384]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 sffdisk;SFF Storage Class Driver; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2008-04-13 11904]
R3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2008-04-13 11008]
R3 STAC97;SigmaTel C-Major Audio; C:\WINDOWS\system32\drivers\STAC97.sys [2005-03-10 273168]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 w29n51;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2007-02-08 2209408]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-05-03 705408]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 UIUSys;Conexant Setup API; C:\WINDOWS\system32\drivers\UIUSys.sys []
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-13 611664]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-03 380928]
R2 avg8emc;AVG8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-22 875288]
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-22 231704]
R2 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2007-01-31 96370]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-02-21 643072]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-02-21 327680]
R2 S24EventMonitor;Intel® PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2007-02-21 983040]
R2 WLANKEEPER;Intel® PROSet/Wireless SSO Service; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [2007-02-21 294912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 dlbt_device;dlbt_device; C:\WINDOWS\system32\dlbtcoms.exe [2005-03-03 466944]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-10-15 654848]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

—————–EOF—————–








info.txt logfile of random's system information tool 1.04 2008-10-23 21:29:16

======Uninstall list======

–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Ad-Aware–>MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Anchor Service CS3–>MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3–>MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3–>MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting–>MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0–>MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps–>MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific–>MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings–>MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Extra Settings–>MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings–>MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings–>MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Default Language CS3–>MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3–>MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2–>MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Fonts All–>MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3–>MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3–>MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files–>MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3–>C:\Program Files\Common Files\Adobe\Installers\2ac78060bc5856b0c1cf873bb919b58\Setup.exe
Adobe Photoshop CS3–>MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Adobe Setup–>MsiExec.exe /I{D1BB4446-AE9C-4256-9A7F-4D46604D2462}
Adobe Stock Photos CS3–>MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support–>MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3–>MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client–>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin–>MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3–>MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
ALPS Touch Pad Driver–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}\setup.exe" UNINSTALL
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ATI - Software Uninstall Utility–>C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AusLogics Disk Defrag–>"C:\Program Files\Auslogics\AusLogics Disk Defrag\unins000.exe"
AVG Free 8.0–>C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Broadcom 440x 10/100 Integrated Controller–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{52504CE6-E909-4113-B232-4AFEC6543A61} /l1033
Canon Camera Access Library–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CAL\Uninst.ini"
Canon Camera Support Core Library–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CSCLIB\Uninst.ini"
CANON iMAGE GATEWAY Task for ZoomBrowser EX–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\CRWUnInstall.ini"
Canon Internet Library for ZoomBrowser EX–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\CIGUnInstall.ini"
Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC\Uninst.ini"
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC6\Uninst.ini"
Canon Utilities CameraWindow–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowLauncher\Uninst.ini"
Canon Utilities Digital Photo Professional 3.5–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\Digital Photo Professional\Uninst.ini"
Canon Utilities EOS Utility–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\EOS Utility\Uninst.ini"
Canon Utilities MyCamera–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\MyCamera\Uninst.ini"
Canon Utilities Original Data Security Tools–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\Original Data Security Tools\Uninst.ini"
Canon Utilities PhotoStitch–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\PhotoStitch\Uninst.ini"
Canon Utilities Picture Style Editor–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\Picture Style Editor\Uninst.ini"
Canon Utilities RemoteCapture Task for ZoomBrowser EX–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureTask DC\Uninst.ini"
Canon Utilities WFT-E1/E2/E3 Utility–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\WFT Utility\Uninst.ini"
Canon Utilities ZoomBrowser EX–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\Uninst.ini"
Canon ZoomBrowser EX Memory Card Utility–>"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX MCU\Uninst.ini"
C-Major Audio–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
Conexant D110 MDC V.92 Modem–>C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV;_24x6&SUBSYS;_542214F1\HXFSETUP.EXE -U -Idel5422k.inf
Dell Photo AIO Printer 922–>C:\WINDOWS\system32\spool\drivers\w32x86\3\DLBTUNST.EXE -NOLICENSE
EasyCleaner–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly
Express Scribe Uninstall–>C:\Program Files\NCH Swift Sound\Scribe\uninst.exe
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Intel® PROSet/Wireless Software–>C:\WINDOWS\Installer\iProInst.exe
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
mCore–>MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
mDriver–>MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
mDrWiFi–>MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
mHlpDell–>MsiExec.exe /I{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}
Microsoft .NET Framework 2.0–>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
mIWA–>MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
mLogView–>MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
mMHouse–>MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
mPfMgr–>MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
mPfWiz–>MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
mProSafe–>MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
mSCfg–>MsiExec.exe /I{829CD169-E692-48E8-9BDE-A3E8D8B65538}
mSSO–>MsiExec.exe /I{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}
MSXML 6.0 Parser–>MsiExec.exe /I{AEB9948B-4FF2-47C9-990E-47014492A0FE}
mWlsSafe–>MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
mWMI–>MsiExec.exe /I{63DB9CCD-2B56-4217-9A3D-507AC78320CA}
My Photo Calendars and Cards–>MsiExec.exe /I{E285C3A0-C883-4B42-849D-8BA71768EE64}
mZConfig–>MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
PDF Settings–>MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
QuickTime–>MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
Security Update for Windows Internet Explorer 7 (KB938127-v2)–>"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)–>"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Windows Internet Explorer 7–>"C:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Yahoo! Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

======Hosts File======

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

======Security center information======

AV: AVG Anti-Virus Free

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 8, GenuineIntel
"PROCESSOR_REVISION"=0d08
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

—————–EOF—————–
Hi.

Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Please open the AVG Control Center program -> double-click on the "AVG Resident Shield" component (looks like this: [external image: Posted Image]) -> deselect the "Turn on AVG Resident Shield" checkmark and save the setting.
When you need to enable the AVG Resident Shield, ( I'll let you know when) just open the AVG Control Center program -> double-click on the "AVG Resident Shield" component -> select the "Turn on AVG Resident Shield" checkmark and save the setting.

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks.
OK - below is the combofix log as well as the HJT log below that… please let me know what you think, and what steps i might need to take next. thanks!!



ComboFix 08-10-28.01 - Hartmann 2008-10-28 17:59:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.596 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Hartmann\Application Data\Adobe\Player.exe.bak
C:\Documents and Settings\Hartmann\Application Data\Rapid Antivirus
C:\Documents and Settings\Hartmann\Application Data\Rapid Antivirus\base.dat
C:\Documents and Settings\Hartmann\Application Data\Rapid Antivirus\base2.dat
C:\Documents and Settings\Hartmann\Application Data\Rapid Antivirus\Desc.dat
C:\Documents and Settings\Hartmann\Application Data\Rapid Antivirus\Rapid Antivirus.ini
C:\Documents and Settings\Hartmann\Application Data\Rapid Antivirus\spline.dat
C:\WINDOWS\system32\ashowkfe.dll
C:\WINDOWS\system32\jfbotz.dll
C:\WINDOWS\system32\TDSSerrors.log
C:\WINDOWS\vortsgbqpvo.dll

—– BITS: Possible infected sites —–

hxxp://78.157.143.198
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV
——-\Service_TDSSserv


((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 )))))))))))))))))))))))))))))))
.

2008-10-23 21:29 . 2008-10-23 21:29 d——– C:\rsit
2008-10-22 15:54 . 2008-10-22 15:54 d——– C:\Documents and Settings\Hartmann\Application Data\Canon
2008-10-22 15:50 . 2008-04-13 19:12 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2008-10-22 15:50 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2008-10-22 15:43 . 2008-10-22 15:43 d——– C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-10-22 15:41 . 2008-10-22 15:45 d——– C:\Program Files\Canon
2008-10-22 15:30 . 2008-10-22 15:30 d——– C:\Program Files\Common Files\Canon
2008-10-20 21:29 . 2008-10-20 21:29 d——– C:\Program Files\Trend Micro
2008-10-15 20:34 . 2008-10-15 20:34 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-10-15 20:23 . 2008-10-20 21:45 d——– C:\Program Files\Bonjour
2008-10-15 20:16 . 2008-10-15 20:16 d——– C:\Program Files\Common Files\Macrovision Shared
2008-10-14 13:13 . 2008-10-14 13:13 d——– C:\Documents and Settings\Hartmann\.Calendar
2008-10-14 13:12 . 2008-10-14 13:21 d——– C:\Program Files\My Photo Calendars and Cards
2008-10-13 20:07 . 2008-10-13 20:07 d——– C:\Program Files\Lavasoft
2008-10-13 20:07 . 2008-10-13 20:07 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-13 20:06 . 2008-10-13 20:06 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-10-12 09:39 . 2008-10-12 10:05 d——– C:\Documents and Settings\All Users\Application Data\jctiborg
2008-10-12 09:34 . 2008-10-12 10:05 d——– C:\Documents and Settings\Hartmann\Application Data\sp2
2008-10-11 09:00 . 2008-10-11 09:00 d——– C:\Program Files\ToniArts
2008-10-11 08:56 . 2008-10-12 12:23 d——– C:\Documents and Settings\All Users\Application Data\exgfebmr
2008-10-11 08:47 . 2008-10-11 08:47 d——– C:\WINDOWS\system32\LogFiles
2008-10-11 08:27 . 2008-10-12 12:23 d——– C:\Documents and Settings\All Users\Application Data\xghatopy
2008-10-11 08:26 . 2008-10-11 08:26 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-11 08:26 . 2008-10-11 08:26 d——– C:\Documents and Settings\Hartmann\Application Data\Malwarebytes
2008-10-11 08:26 . 2008-10-11 08:26 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-11 08:26 . 2008-09-10 00:04 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-11 08:26 . 2008-09-10 00:03 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-11 08:25 . 2008-10-11 08:25 d——– C:\Documents and Settings\Hartmann\Application Data\0000005738
2008-10-10 23:05 . 2008-10-25 13:10 d–h—– C:\$AVG8.VAULT$
2008-10-10 08:07 . 2008-10-10 08:07 d——– C:\Program Files\Common Files\Apple
2008-10-10 08:07 . 2008-10-10 08:07 d——– C:\Program Files\Apple Software Update
2008-10-10 08:07 . 2008-10-10 08:07 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-10-10 08:07 . 2008-10-10 08:07 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-10-10 08:02 . 2008-10-10 08:07 d——– C:\Program Files\QuickTime
2008-10-09 20:49 . 2008-10-09 20:49 d——– C:\Program Files\uTorrent
2008-10-09 20:49 . 2008-10-10 21:53 d——– C:\Documents and Settings\Hartmann\Application Data\uTorrent
2008-10-09 20:26 . 2008-10-19 12:56 d——– C:\Program Files\Dl_cats
2008-10-09 20:26 . 2008-10-19 12:56 828 –a—— C:\WINDOWS\dellstat.ini
2008-10-09 20:24 . 2008-10-11 08:28 d——– C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2008-10-09 20:24 . 2008-10-20 20:11 d——– C:\Temp
2008-10-09 20:24 . 2008-10-09 20:24 d——– C:\Program Files\Dell Photo AIO Printer 922
2008-10-09 20:24 . 2008-10-09 20:24 d——– C:\Dell922
2008-10-09 20:24 . 2005-02-23 16:55 983,101 –a—— C:\WINDOWS\system32\dlbtgf.dll
2008-10-09 20:24 . 2005-04-15 00:42 397,312 –a—— C:\WINDOWS\system32\dlbtutil.dll
2008-10-09 15:57 . 2001-08-17 22:36 87,040 –a—— C:\WINDOWS\system32\wiafbdrv.dll
2008-10-09 15:57 . 2001-08-17 22:36 87,040 –a–c— C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2008-10-09 15:57 . 2008-04-13 13:45 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-10-09 15:57 . 2008-04-13 13:45 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-10-02 21:21 . 2008-10-02 21:21 d——– C:\Program Files\NCH Swift Sound
2008-10-02 21:21 . 2008-10-02 21:21 d——– C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-10-02 16:25 . 2008-04-13 13:45 32,128 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-02 16:25 . 2008-04-13 13:45 32,128 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-10-02 16:25 . 2008-04-13 13:47 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-10-02 16:25 . 2008-04-13 13:47 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2008-10-02 16:25 . 2008-04-13 13:45 10,368 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-10-02 16:25 . 2008-04-13 13:45 10,368 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-16 01:22 ——— d—–w C:\Program Files\Common Files\Adobe
2008-10-12 14:39 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-10-11 14:00 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-26 18:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-26 18:26 ——— d—–w C:\Program Files\Yahoo!
2008-09-26 02:24 ——— d—–w C:\Documents and Settings\Hartmann\Application Data\OfficeUpdate12
2008-09-26 01:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-09-26 01:18 ——— d—–w C:\Program Files\Microsoft.NET
2008-09-26 01:18 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-09-26 01:14 ——— d—–w C:\Program Files\microsoft frontpage
2008-09-24 11:33 ——— d—–w C:\Program Files\NOS
2008-09-24 11:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\NOS
2008-09-23 02:47 ——— d—–w C:\Program Files\Common Files\Adobe AIR
2008-09-23 01:10 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-23 01:10 76,040 —-a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-21 03:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-21 02:43 ——— d—–w C:\Documents and Settings\Hartmann\Application Data\Auslogics
2008-09-21 02:35 ——— d—–w C:\Program Files\AVG
2008-09-21 02:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-09-21 02:34 ——— d—–w C:\Program Files\Auslogics
2008-09-20 21:51 ——— d—–w C:\Program Files\Broadcom
2008-09-20 21:50 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-09-20 21:45 ——— d—–w C:\Program Files\Apoint
2008-09-20 21:44 ——— d—–w C:\Program Files\ATI Technologies
2008-09-20 21:43 ——— d—–w C:\Program Files\CONEXANT
2008-09-20 21:41 ——— d—–w C:\Program Files\SigmaTel
2008-09-20 20:00 21,425 —-a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-09-20 20:00 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
2008-09-20 20:00 ——— d—–w C:\Program Files\Intel
2008-09-20 20:00 ——— d—–w C:\Documents and Settings\NetworkService\Application Data\Intel
2008-09-20 20:00 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Intel
2008-09-20 20:00 ——— d—–w C:\Documents and Settings\Hartmann\Application Data\Intel
2008-09-20 20:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intel
2008-08-25 19:31 524,288 —-a-w C:\WINDOWS\opuc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 176128]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-02 1234712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"DLBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-09 69632]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-10-10 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll jfbotz.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-22 97928]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-22 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-22 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-22 76040]
.
- - - - ORPHANS REMOVED - - - -

BHO-{70432807-e70d-4565-ae65-c61d7a3c0488} - C:\WINDOWS\system32\jfbotz.dll
ShellExecuteHooks-{903C377B-E501-4A35-A6B2-1E3994711EA1} - (no file)
SSODL-qmafxprs-{5D90CB84-2A6D-437B-87C2-91D6258B91E2} - (no file)
SSODL-lfstbwvd-{D305DCC9-92A6-4258-BDA0-5EAD51D480F5} - (no file)


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O16 -: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.mpix.com/customer/uploading/activex/ImageUploader5.cab
C:\WINDOWS\Downloaded Program Files\ImageUploader5.inf
C:\WINDOWS\system32\unicows.dll
C:\WINDOWS\Downloaded Program Files\ImageUploader5.ocx
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 18:03:10
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Apoint\hidfind.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-10-28 18:06:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-28 23:06:20

Pre-Run: 101,999,321,088 bytes free
Post-Run: 102,348,324,864 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

212 — E O F — 2008-09-23 01:39:18












Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:10:11 PM, on 10/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Apoint\Apoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.mpix.com/customer/uploading/act…geUploader5.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll jfbotz.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: Privacy Protection - (no file)

–
End of file - 5126 bytes
Hi.

Please disable AVG as before.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

DirLook::
C:\Documents and Settings\All Users\Application Data\jctiborg
C:\Documents and Settings\Hartmann\Application Data\sp2
C:\Documents and Settings\All Users\Application Data\exgfebmr
C:\Documents and Settings\All Users\Application Data\xghatopy
C:\Documents and Settings\Hartmann\Application Data\0000005738

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"="avgrsstx.dll"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\WINDOWS\system32\blank.htm"
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Also, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems.

Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI