This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] incomplete removal

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok, this is for a relative's computer. When he gave it to me, "Spyware Guard 2008", "csrssc.exe", and a few other goodies made their way onto the machine.

I have been trying to resolve this myself, but ran into a wall.
SO, I'll include the original HJT log+description, as well as a current HJT log+description.

Also, Malwarebyte's Anti-Malware was installed by renaming mbam-setup.exe
When running mbam.exe, it will be listed in TaskManager and nothing else will occur.
I've tried renaming mbam.exe to several different filenames and have tried running in normal and safe-mode to no avail.
–I cannot figure out how to get mbam.exe to run. –

As a side note, Recovery Console is installed and I am comfortable working in the command line.

If it matters, this is the same machine as from this thread : http://forums.whatthetech.com/Baseline_t97909.html

Thanks in advance for the help :notworthy:

————————-
Initial State
————————-
Windows may or may not lock up during the login process.
Upon a successful login, "Spyware Guard 2008" will display a window. I am ignoring it as I'm suspiscious.
Windows Security Center also displays a window, mentioning that Auto-updates,along with virus protection is disabled.

regedit disabled

random browser popups
(or rather attempts,as this machine is now disconnected from the network. I'm using a usb flash drive for transfering files.)

In Windows Explorer, Tools–>Folder Options is hidden.

AVG Antivirus cannot connect to it's website to check for updated virus definitions.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:52:10 PM, on 1/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\explorer.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\Program Files\Lexmark 7100 Series\lxbxmon.exe
D:\Program Files\Lexmark 7100 Series\ezprint.exe
D:\WINDOWS\system32\lxbxcoms.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Documents and Settings\Owner\lsass.exe
D:\WINDOWS\System32\rs32net.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\System32\rs32net.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\HJT\HiJackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: D:\WINDOWS\system32\gseb37dkjgfgf.dll - {c5af42a3-94f3-42bd-f634-3604832c897d} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O2 - BHO: D:\WINDOWS\system32\rwhbfb873unjdfdg.dll - {c5bf49a2-94f3-42bd-f434-3604812c8955} - D:\WINDOWS\system32\rwhbfb873unjdfdg.dll
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "D:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "D:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "D:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LSA Shellu] D:\Documents and Settings\Owner\lsass.exe
O4 - HKLM\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogin.exe
O4 - HKLM\..\Run: [jsg8jfgfdfhfhf] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogun.exe
O4 - HKLM\..\Run: [Qgoqoxi] rundll32.exe "D:\WINDOWS\Inoyoxeb.dll",e
O4 - HKLM\..\Run: [spywareguard] D:\Program Files\Spyware Guard 2008\spywareguard.exe
O4 - HKLM\..\Run: [887407b3] rundll32.exe "D:\WINDOWS\system32\bfmlhpkf.dll",b
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogin.exe
O4 - HKCU\..\Run: [jsg8jfgfdfhfhf] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogun.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - HKUS\.DEFAULT\..\Run: [tezrtsjhfr84iusjfo84f] D:\WINDOWS\TEMP\csrssc.exe (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: knhwrj.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - Winlogon Notify: opnnnKax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: ieModule - {B36D696C-C331-4E30-AA93-4BE550E7C75A} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
O21 - SSODL: InternetConnection - {9BB113B3-2F6C-48D2-9AB7-75BEA0014FBD} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\rwhbfb873unjdfdg.dll
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - D:\WINDOWS\system32\lxbxcoms.exe

–
End of file - 6293 bytes


————————-
Current State
————————-
In Windows Explorer, Tools–>Folder Options is hidden.
AVG fails to auto-update.
Firefox fails to load www.avg.com
Other webpages are redirected.
mbam.exe still fails to load, even when renamed to something random.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:02:00 AM, on 1/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\wscntfy.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\Program Files\Lexmark 7100 Series\lxbxmon.exe
D:\Program Files\Lexmark 7100 Series\ezprint.exe
D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\lxbxcoms.exe
D:\HJT\HiJackThis(2).exe

O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "D:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "D:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "D:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - D:\WINDOWS\system32\lxbxcoms.exe

–
End of file - 3247 bytes
Hello mmadia

Welcome to the Whatthetech Malware Removal Forum,

All advice given by anyone volunteering here, is taken at your own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.


Sorry about the delay, but the amount of people posting with infected computers is through the roof and sometimes we can't get to logs as fast as we would like to. If you have not resolved your issue and still need assistance, post a new HJT log please as your system may have changed since your original post.


You have removed alot on your own, please do not remove anything else, do not run any other scans until directed to, this forum and myself will not be responsible if you remove entries and files on your own and bork your system.

Ken
Since creating the original post, that computer has been powered off, unplugged, and patiently awaiting a response. I promise you, nothing has changed. And thanks for the reply :)
Lets do this

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
I have disable AVG, windows firewall, (and windows update for the heck of it). This machine is not connected to the network. I am using a flash drive to transfer files back and forth. ComboFix.exe does not execute properly. double-clicking it will allow "ComboFix.exe" to display in Task Manager's Processes list, However, the CPU usage will remain at 0% and nothing will occur. I've attempted this in both normal and safe modes. I've tried re-naming ComboFix.exe to foobar.exe and the results are the same (well, foobar.exe displays in Task Manager instead of ComboFix.exe) :unsure: If you'd prefer, I'm currently logged into the irc channel as mmadia.
We just do our removal in the forums .

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.
While in safe mode, i needed to rename mbam-setup.exe to something random in order for Setup to load properly. During the installation, specifically "Finishing installation…" , mbam.exe will appear in TaskManager. At that point, installation halts. Mbam.exe never fully loads. Setup sits and does nothing.
This scan won't remove anything but I need to see the report

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
I ran it in Normal mode,

Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-01-13 22:26:02
Microsoft Windows XP Professional Service Pack 2
System drive D: has 171 GB (96%) free of 179 GB
Total RAM: 3007 MB (87% free)

HijackThis download failed

======Scheduled tasks folder======

D:\WINDOWS\tasks\bdmiqanb.job

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"=D:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-11-27 1261336]
"LXBXCATS"=rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll []
"lxbxmon.exe"=D:\Program Files\Lexmark 7100 Series\lxbxmon.exe [2005-01-18 196608]
"FaxCenterServer4_in_1"=D:\Program Files\Lexmark 7100 Series\fm3032.exe [2004-12-06 286720]
"EzPrint"=D:\Program Files\Lexmark 7100 Series\ezprint.exe [2004-09-17 61440]
"Adobe Reader Speed Launcher"=D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
D:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
D:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
D:\WINDOWS\system32\NvCpl.dll [2007-08-23 8478720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
D:\WINDOWS\system32\NvMcTray.dll [2007-08-23 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
D:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-09-14 102400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
D:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2006-11-13 561213]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3
"NVSvc"=2
"btwdins"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
D:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
D:\WINDOWS\system32\ssqPIBSK

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1tpxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8xpxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati1tpxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati8xpxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoFolderOptions"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\AVG\AVG8\avgemc.exe"="D:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"D:\Program Files\AVG\AVG8\avgupd.exe"="D:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"D:\WINDOWS\system32\mmc.exe"="D:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{27fb5c44-7a74-11dd-9e9a-001e68c6e09b}]
shell\Auto\command - F:\Start.exe
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe


======List of files/folders created in the last 2 months======

2009-01-13 22:26:02 —-D—- D:\rsit
2009-01-13 22:26:02 —-D—- D:\Program Files\trend micro
2009-01-13 22:00:57 —-D—- D:\Program Files\Malwarebytes' Anti-Malware
2009-01-08 00:30:13 —-A—- D:\WINDOWS\system32\fnnwuke.dll
2009-01-07 23:24:02 —-D—- D:\Program Files\gjhgfhfjh
2009-01-07 23:16:52 —-SHD—- D:\Config.Msi
2009-01-07 21:57:57 —-D—- D:\VundoFix Backups
2009-01-07 21:57:57 —-A—- D:\VundoFix.txt
2009-01-07 14:20:08 —-AH—- D:\matt.txt
2009-01-07 10:18:33 —-A—- D:\WINDOWS\system32\geBqQjgE.dll
2009-01-07 10:17:20 —-A—- D:\WINDOWS\vmreg.dll
2009-01-07 10:17:20 —-A—- D:\WINDOWS\sysexplorer.exe
2009-01-07 10:17:20 —-A—- D:\WINDOWS\syscert.exe
2009-01-07 10:17:20 —-A—- D:\WINDOWS\spoolsystem.exe
2009-01-07 10:17:20 —-A—- D:\WINDOWS\reged.exe
2009-01-06 21:30:53 —-A—- D:\WINDOWS\system32\byXPFutR.dll
2009-01-06 21:30:27 —-D—- D:\Program Files\Microsoft Common
2009-01-06 21:15:11 —-D—- D:\matt
2009-01-06 21:15:03 —-D—- D:\HJT
2009-01-06 21:12:50 —-A—- D:\WINDOWS\system32\knhwrj.dll
2009-01-06 21:12:48 —-A—- D:\WINDOWS\system32\vwqbklae.dll
2009-01-06 21:10:29 —-A—- D:\WINDOWS\system32\pmnlmLBs.dll
2009-01-06 21:10:20 —-SH—- D:\WINDOWS\system32\fkphlmfb.ini
2009-01-06 21:10:15 —-A—- D:\WINDOWS\system32\bfmlhpkf.dll
2009-01-06 15:16:24 —-ASH—- D:\WINDOWS\system32\KSBIPqss.ini2
2009-01-06 15:16:24 —-ASH—- D:\WINDOWS\system32\KSBIPqss.ini
2009-01-06 15:11:54 —-A—- D:\WINDOWS\system32\winscenter.exe
2009-01-06 15:11:53 —-A—- D:\WINDOWS\sys.com
2009-01-06 15:11:25 —-D—- D:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
2009-01-06 15:11:24 —-A—- D:\Documents and Settings\All Users\Application Data\svhost.exe
2009-01-06 15:11:01 —-A—- D:\WINDOWS\system32\cbXQiFya.dll
2009-01-06 15:11:00 —-A—- D:\WINDOWS\Inoyoxeb.dll
2009-01-06 15:10:53 —-A—- D:\WINDOWS\system32\rwhbfb873unjdfdg.dll
2009-01-06 15:10:51 —-A—- D:\WINDOWS\system32\rs32net.exe
2008-12-21 10:59:33 —-SHD—- D:\RECYCLER
2008-12-21 10:50:20 —-D—- D:\ComboFix
2008-12-21 10:36:39 —-A—- D:\ComboFix.txt
2008-12-19 17:35:44 —-HDC—- D:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-19 17:35:40 —-HDC—- D:\WINDOWS\$NtUninstallKB955839$
2008-12-19 17:33:59 —-HDC—- D:\WINDOWS\$NtUninstallKB954600$
2008-12-19 17:33:50 —-HDC—- D:\WINDOWS\$NtUninstallKB956802$
2008-12-19 14:05:45 —-D—- D:\WINDOWS\ERDNT
2008-12-19 09:26:04 —-A—- D:\avenger.txt
2008-12-19 09:12:14 —-D—- D:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-12-19 09:01:27 —-HD—- D:\WINDOWS\PIF
2008-12-19 08:53:12 —-D—- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-15 09:29:30 —-SHD—- D:\WINDOWS\CSC
2008-12-13 19:29:28 —-A—- D:\WINDOWS\system32\wmpns.dll
2008-12-13 18:34:56 —-A—- D:\WINDOWS\ntbtlog.txt
2008-12-13 18:33:20 —-D—- D:\WINDOWS\system32\DL5
2008-12-13 18:33:20 —-D—- D:\WINDOWS\system32\cap2
2008-12-13 18:33:20 —-D—- D:\WINDOWS\system32\ain
2008-12-13 18:15:50 —-D—- D:\WINDOWS\system32\whSLD02
2008-12-01 11:42:42 —-D—- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-11-19 15:34:39 —-D—- D:\Program Files\Citrix
2008-11-19 15:34:09 —-D—- D:\WINDOWS\Sun
2008-11-19 15:29:39 —-A—- D:\WINDOWS\system32\javaws.exe
2008-11-19 15:29:39 —-A—- D:\WINDOWS\system32\deploytk.dll
2008-11-19 15:29:38 —-A—- D:\WINDOWS\system32\javaw.exe
2008-11-19 15:29:38 —-A—- D:\WINDOWS\system32\java.exe
2008-11-19 15:29:25 —-D—- D:\Program Files\Java
2008-11-19 15:28:00 —-D—- D:\Documents and Settings\Owner\Application Data\Sun
2008-11-15 15:23:53 —-HDC—- D:\WINDOWS\$NtUninstallKB957097$
2008-11-15 15:23:43 —-HDC—- D:\WINDOWS\$NtUninstallKB955069$

======List of files/folders modified in the last 2 months======

2009-01-13 22:26:02 —-RD—- D:\Program Files
2009-01-13 22:25:53 —-D—- D:\WINDOWS\system32
2009-01-13 22:25:53 —-A—- D:\WINDOWS\system32\PerfStringBackup.INI
2009-01-13 22:25:27 —-D—- D:\WINDOWS\Temp
2009-01-13 22:01:00 —-D—- D:\WINDOWS\system32\drivers
2009-01-13 21:42:53 —-A—- D:\WINDOWS\SchedLgU.Txt
2009-01-08 01:13:13 —-D—- D:\Program Files\Mozilla Firefox
2009-01-08 00:40:54 —-D—- D:\WINDOWS\Prefetch
2009-01-08 00:39:11 —-RSHDC—- D:\WINDOWS\system32\dllcache
2009-01-08 00:39:03 —-D—- D:\WINDOWS\system32\CatRoot2
2009-01-08 00:39:02 —-A—- D:\WINDOWS\system32\svchost.exe
2009-01-07 23:16:52 —-SHD—- D:\WINDOWS\Installer
2009-01-07 11:50:23 —-D—- D:\Program Files\Adobe
2009-01-07 10:20:13 —-D—- D:\Documents and Settings\All Users\Application Data\avg8
2009-01-07 10:17:20 —-D—- D:\WINDOWS
2009-01-06 15:17:07 —-A—- D:\WINDOWS\system32\8357c3cd-.txt
2009-01-06 15:11:52 —-SD—- D:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-06 15:11:05 —-SD—- D:\WINDOWS\Tasks
2009-01-05 11:40:20 —-D—- D:\Program Files\Lx_cats
2008-12-22 16:15:42 —-HD—- D:\WINDOWS\inf
2008-12-21 13:22:44 —-SHD—- D:\System Volume Information
2008-12-21 13:22:44 —-D—- D:\WINDOWS\system32\Restore
2008-12-21 10:36:07 —-A—- D:\WINDOWS\system.ini
2008-12-21 10:35:43 —-D—- D:\WINDOWS\AppPatch
2008-12-21 10:35:43 —-D—- D:\Program Files\Common Files
2008-12-19 17:35:43 —-A—- D:\WINDOWS\imsins.BAK
2008-12-19 17:35:29 —-D—- D:\Program Files\Internet Explorer
2008-12-19 17:35:14 —-HD—- D:\WINDOWS\$hf_mig$
2008-12-19 17:24:56 —-SD—- D:\Documents and Settings\Owner\Application Data\Microsoft
2008-12-19 15:48:33 —-D—- D:\WINDOWS\system32\config
2008-12-13 19:29:36 —-A—- D:\WINDOWS\OEWABLog.txt
2008-12-13 19:28:19 —-D—- D:\Documents and Settings
2008-12-13 19:12:22 —-D—- D:\WINDOWS\Minidump
2008-12-13 18:39:21 —-D—- D:\temp
2008-12-13 01:40:02 —-A—- D:\WINDOWS\system32\mshtml.dll
2008-12-09 18:24:37 —-A—- D:\WINDOWS\system32\MRT.exe
2008-12-05 18:56:55 —-HD—- D:\$AVG8.VAULT$
2008-11-24 23:06:53 —-D—- D:\Program Files\MSN
2008-11-22 06:18:10 —-D—- D:\WINDOWS\Help
2008-11-16 18:57:23 —-D—- D:\WINDOWS\system32\QI02

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; D:\WINDOWS\System32\Drivers\avgldx86.sys [2008-10-04 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; D:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-10-04 26824]
R1 kbdhid;Keyboard HID Driver; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; D:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-03 8832]
R2 AvgTdiX;AVG Free8 Network Redirector; D:\WINDOWS\System32\Drivers\avgtdix.sys [2008-10-04 76040]
R2 mdmxsdk;mdmxsdk; D:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; D:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; D:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; D:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2007-03-21 37376]
R3 BTKRNL;Bluetooth Bus Enumerator; D:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-11-15 862922]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; D:\WINDOWS\System32\Drivers\btwusb.sys [2006-11-15 67672]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; D:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; D:\WINDOWS\system32\drivers\CHDAud.sys [2007-12-18 732160]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HpqRemHid;HP Remote Control HID Device; D:\WINDOWS\system32\DRIVERS\HpqRemHid.sys [2007-07-11 7168]
R3 HSF_DPV;HSF_DPV; D:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2007-11-01 989696]
R3 HSFHWAZL;HSFHWAZL; D:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2007-11-01 211456]
R3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-08-23 6844864]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; D:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2007-03-06 58752]
R3 nvnetbus;NVIDIA Network Bus Enumerator; D:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2007-03-06 19968]
R3 nvsmu;nvsmu; D:\WINDOWS\system32\DRIVERS\nvsmu.sys [2007-02-16 12032]
R3 pfc;Padus ASPI Shell; D:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
R3 sdbus;sdbus; D:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-04 67584]
R3 SynTP;Synaptics TouchPad Driver; D:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-09-14 213696]
R3 usbccgp;Microsoft USB Generic Parent Driver; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; D:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 USBSTOR;USB Mass Storage Driver; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbvideo;USB Video Device (WDM); D:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-03 78464]
R3 winachsf;winachsf; D:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2007-11-01 731520]
S1 streamm;streamm; D:\WINDOWS\System32\drivers\streamm.sys []
S3 AR5416;Atheros AR5008 Wireless Network Adapter Service; D:\WINDOWS\system32\DRIVERS\athw.sys [2008-05-18 1312576]
S3 CCDECODE;Closed Caption Decoder; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 HidUsb;Microsoft HID Class Driver; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HpqKbFiltr;HpqKbFilter Driver; D:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 TVICHW32;TVICHW32; \??\D:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 usbprint;Microsoft USB PRINTER Class; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 Wdf01000;Wdf01000; D:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service; D:\WINDOWS\system32\DRIVERS\ar5211.sys [2005-09-14 468768]
S3 WSTCODEC;World Standard Teletext Codec; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg8emc;AVG Free8 E-mail Scanner; D:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-04 875288]
R2 avg8wd;AVG Free8 WatchDog; D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-04 231704]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2008-11-19 152984]
R3 lxbx_device;lxbx_device; D:\WINDOWS\system32\lxbxcoms.exe [2005-01-06 462848]
S2 icf;ICF; D:\WINDOWS\system32\svchost.exe [2009-01-08 14336]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S4 btwdins;Bluetooth Service; D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-11-11 266295]
S4 FCI;FCI; D:\WINDOWS\system32\svchost.exe [2009-01-08 14336]
S4 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2007-08-23 155716]
S4 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

—————–EOF—————–

info.txt logfile of random's system information tool 1.05 2009-01-13 22:26:05

======Uninstall list======

–>D:\Program Files\Conexant\SmartAudio\SETUP.EXE -U -ISmartAudio -SM=SMAUDIO.EXE,1801
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 D:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 6.0 Sprint Plus–>MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
Acrobat.com–>D:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR–>D:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player Plugin–>D:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
ArcSoft Software Suite–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{EE7C3A14-1D20-49F6-B903-491561076F0F}\SETUP.EXE" -l0x9
AVG Free 8.0–>D:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Broadcom 802.11 Wireless LAN Adapter–>"D:\Program Files\Broadcom\Broadcom 802.11\Driver\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="D:\Program Files\Broadcom\Broadcom 802.11\Driver"
Conexant HD Audio–>D:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -I*.INF
Driver Genius Professional Edition 2007–>"D:\Program Files\Driver-Soft\DriverGenius\unins000.exe"
DriverAgent by TouchStone Software–>RunDll32.exe advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove
HDAUDIO Soft Data Fax Modem with SmartCP–>D:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_HERMOSA_HSF\UIU32m.exe -U -IHPQHER5m.inf
HijackThis 2.0.2–>"D:\HJT\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)–>"D:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"D:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Integrated Module with Bluetooth wireless technology–>MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
HP Integrated Wireless LAN W400-W500 Driver–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{5C3DA2A1-03B2-44BD-B5AA-A44BD6E0C0C1}\setup.exe" -l0x9
Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Lexmark 7100 Series Fax Solutions–>D:\PROGRA~1\COMMON~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /M{316A75E3-039D-4BF4-AC29-3FF91E8555CD} /l1033 /z/U
Lexmark 7100 Series–>D:\WINDOWS\system32\spool\drivers\w32x86\3\lxbxUNST.EXE -NOLICENSE
Malwarebytes' Anti-Malware–>"D:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0–>D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Internationalized Domain Names Mitigation APIs–>"D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5–>"D:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.5)–>D:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN–>D:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
NVIDIA Drivers–>D:\WINDOWS\system32\nvudisp.exe UninstallGUI
PC Wizard 2008.1.84–>"D:\Program Files\PC Wizard 2008\unins000.exe"
Realtek AC'97 Audio–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x9 -removeonly
RICOH R5C853 Driver WXP Ver.1.01.05–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x9 anything
Security Update for Windows Internet Explorer 7 (KB938127)–>"D:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127-v2)–>"D:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"D:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"D:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"D:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)–>"D:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB911564)–>"D:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"D:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 6.4 (KB925398)–>"D:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB936782)–>"D:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB890046)–>"D:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893756)–>"D:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)–>"D:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)–>"D:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896428)–>"D:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899587)–>"D:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899591)–>"D:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)–>"D:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)–>"D:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901214)–>"D:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)–>"D:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)–>"D:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)–>"D:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)–>"D:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911562)–>"D:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911927)–>"D:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Security Update for Windows XP (KB913580)–>"D:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914388)–>"D:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914389)–>"D:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918118)–>"D:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918439)–>"D:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920213)–>"D:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920670)–>"D:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920683)–>"D:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920685)–>"D:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923191)–>"D:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923414)–>"D:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>D:\WINDOWS\system32\MacroMed\Flash\genuinst.exe D:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB923980)–>"D:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924270)–>"D:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924667)–>"D:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925902)–>"D:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926255)–>"D:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926436)–>"D:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927779)–>"D:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927802)–>"D:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928255)–>"D:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928843)–>"D:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929123)–>"D:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Security Update for Windows XP (KB930178)–>"D:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931261)–>"D:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931784)–>"D:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Security Update for Windows XP (KB932168)–>"D:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933729)–>"D:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935839)–>"D:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935840)–>"D:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Security Update for Windows XP (KB936021)–>"D:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Security Update for Windows XP (KB937894)–>"D:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"D:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"D:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941693)–>"D:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943055)–>"D:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943460)–>"D:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943485)–>"D:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944338-v2)–>"D:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944653)–>"D:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB945553)–>"D:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946026)–>"D:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"D:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB948590)–>"D:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)–>"D:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"D:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"D:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"D:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"D:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"D:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"D:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"D:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)–>"D:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"D:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"D:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"D:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"D:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"D:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"D:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"D:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"D:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"D:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"D:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"D:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Spyware Guard 2008–>D:\Program Files\Spyware Guard 2008\uninstall.exe
Synaptics Pointing Device Driver–>rundll32.exe "D:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Texas Instruments PCIxx21/x515/xx12 drivers.–>D:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A} /l1033
Update for Windows XP (KB894391)–>"D:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Update for Windows XP (KB898461)–>"D:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB900485)–>"D:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Update for Windows XP (KB908531)–>"D:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)–>"D:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Update for Windows XP (KB911280)–>"D:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Update for Windows XP (KB916595)–>"D:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Update for Windows XP (KB920872)–>"D:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Update for Windows XP (KB922582)–>"D:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Update for Windows XP (KB927891)–>"D:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Update for Windows XP (KB930916)–>"D:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Update for Windows XP (KB932823-v3)–>"D:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Update for Windows XP (KB938828)–>"D:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"D:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"D:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)–>"D:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 7–>"D:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows XP Hotfix - KB873339–>D:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP Hotfix - KB885835–>D:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP Hotfix - KB885836–>D:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP Hotfix - KB886185–>D:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP Hotfix - KB887472–>D:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Windows XP Hotfix - KB888302–>D:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP Hotfix - KB890859–>"D:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP Hotfix - KB891781–>D:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe

=====HijackThis Backups=====

O4 - HKLM\..\Run: [Qgoqoxi] rundll32.exe "D:\WINDOWS\Inoyoxeb.dll",e
O4 - HKCU\..\Run: [jsg8jfgfdfhfhf] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogun.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogin.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O4 - HKUS\.DEFAULT\..\Run: [tezrtsjhfr84iusjfo84f] D:\WINDOWS\TEMP\csrssc.exe (User 'Default user')
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogin.exe
O4 - HKLM\..\Run: [jsg8jfgfdfhfhf] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogun.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - HKLM\..\Run: [spywareguard] D:\Program Files\Spyware Guard 2008\spywareguard.exe
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - AppInit_DLLs: knhwrj.dll
O20 - Winlogon Notify: opnnnKax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\rwhbfb873unjdfdg.dll
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {c5bf49a2-94f3-42bd-f434-3604812c8955} - (no file)
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {c5af42a3-94f3-42bd-f634-3604832c897d} - (no file)
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O4 - HKLM\..\Run: [887407b3] rundll32.exe "D:\WINDOWS\system32\bfmlhpkf.dll",b
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O21 - SSODL: InternetConnection - {9BB113B3-2F6C-48D2-9AB7-75BEA0014FBD} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: ieModule - {B36D696C-C331-4E30-AA93-4BE550E7C75A} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O4 - HKLM\..\Run: [LSA Shellu] D:\Documents and Settings\Owner\lsass.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O4 - HKLM\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: InternetConnection - {31697D4A-AEC7-4BCE-8BF0-3FEAEC5C8FE2} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O2 - BHO: D:\WINDOWS\system32\gseb37dkjgfgf.dll - {c5af42a3-94f3-42bd-f634-3604832c897d} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O2 - BHO: (no name) - {C6403D33-965C-452D-A8F3-2FA92C6446B9} - D:\WINDOWS\system32\ssqPIBSK.dll
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O21 - SSODL: InternetConnection - {EEED702B-2A45-4F66-8076-6FAE05CF126B} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: InternetConnection - {EEED702B-2A45-4F66-8076-6FAE05CF126B} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O2 - BHO: (no name) - {C6403D33-965C-452D-A8F3-2FA92C6446B9} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - (no file)
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {E66D37F9-1D81-4C9C-ABDE-EE4407A17CC0} - D:\WINDOWS\system32\ssqPIBSK.dll
O20 - Winlogon Notify: opnnnKax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O2 - BHO: (no name) - {cfdf0f20-4944-48a6-9370-d8075facae40} - D:\WINDOWS\system32\ssqPIBSK.dll (file missing)
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O20 - Winlogon Notify: fnnwuke - fnnwuke32.dll (file missing)
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrssc.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke.dll
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://bontrafic.org/s/in.cgi?3&key;=door
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: FCI - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke.dll
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe

======Security center information======

AV: AVG Anti-Virus Free (outdated)

System event log

Computer Name: OWNER-FC0C2179D
Event Code: 7035
Message: The Fast User Switching Compatibility service was successfully sent a start control.

Record Number: 12115
Source Name: Service Control Manager
Time Written: 20081224103840.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM

Computer Name: OWNER-FC0C2179D
Event Code: 7036
Message: The Terminal Services service entered the running state.

Record Number: 12114
Source Name: Service Control Manager
Time Written: 20081224103840.000000-300
Event Type: information
User:

Computer Name: OWNER-FC0C2179D
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
ohci1394

Record Number: 12113
Source Name: Service Control Manager
Time Written: 20081224103836.000000-300
Event Type: error
User:

Computer Name: OWNER-FC0C2179D
Event Code: 4201
Message: The system detected that network adapter HP WLAN 802.11a/b/g W500 - Packet Scheduler Miniport was connected to the network,
and has initiated normal operation over the network adapter.

Record Number: 12112
Source Name: Tcpip
Time Written: 20081224103812.000000-300
Event Type: information
User:

Computer Name: OWNER-FC0C2179D
Event Code: 26
Message: Application popup: : Machine Check: Regs

Record Number: 12111
Source Name: Application Popup
Time Written: 20081224103812.000000-300
Event Type: information
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 104 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=6802
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–
Hi,



REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=-

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00


Copy the entire contents inside the Quote box and Paste it into Notepad ( this will only work with Notepad ) name the file Regfix.reg and in the drop down box, save it as All Files. Save it to your desktop. Then Rightclick on the Regfix.reg file and click on Merge, when it asks you to merge with the Registry, say yes.

If you saved the file correctly it should look like this [external image: Posted Image]







Please download the OTMoveIt3 by OldTimer.

  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Files
D:\WINDOWS\system32\ssqPIBSK
D:\WINDOWS\system32\fnnwuke.dll
D:\WINDOWS\system32\geBqQjgE.dll
D:\WINDOWS\vmreg.dll
D:\WINDOWS\sysexplorer.exe
D:\WINDOWS\syscert.exe
D:\WINDOWS\spoolsystem.exe
D:\WINDOWS\reged.exe
D:\WINDOWS\system32\knhwrj.dll
D:\WINDOWS\system32\vwqbklae.dll
D:\WINDOWS\system32\pmnlmLBs.dll
D:\WINDOWS\system32\fkphlmfb.ini
D:\WINDOWS\system32\bfmlhpkf.dll
D:\WINDOWS\system32\KSBIPqss.ini2
D:\WINDOWS\system32\KSBIPqss.ini
D:\WINDOWS\system32\winscenter.exe
D:\Documents and Settings\All Users\Application Data\svhost.exe
D:\WINDOWS\system32\cbXQiFya.dll
D:\WINDOWS\Inoyoxeb.dll
D:\WINDOWS\system32\rwhbfb873unjdfdg.dll
D:\WINDOWS\system32\rs32net.exe
D:\WINDOWS\sys.com

:Folders
D:\Program Files\gjhgfhfjh

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Now try running Malwarebytes or Combofix or both if you can

Post a new HJT log
After running MoveIt,
I ran ComboFix in SafeMode.
Upon Completion, Mbam was run in Normal mode.
Followed up by HJT.

——————–
MoveIt Log
———————
========== FILES ==========
File/Folder D:\WINDOWS\system32\ssqPIBSK not found.
DllUnregisterServer procedure not found in D:\WINDOWS\system32\fnnwuke.dll
D:\WINDOWS\system32\fnnwuke.dll NOT unregistered.
D:\WINDOWS\system32\fnnwuke.dll moved successfully.
DllUnregisterServer procedure not found in D:\WINDOWS\system32\geBqQjgE.dll
D:\WINDOWS\system32\geBqQjgE.dll NOT unregistered.
D:\WINDOWS\system32\geBqQjgE.dll moved successfully.
LoadLibrary failed for D:\WINDOWS\vmreg.dll
D:\WINDOWS\vmreg.dll NOT unregistered.
D:\WINDOWS\vmreg.dll moved successfully.
D:\WINDOWS\sysexplorer.exe moved successfully.
D:\WINDOWS\syscert.exe moved successfully.
D:\WINDOWS\spoolsystem.exe moved successfully.
D:\WINDOWS\reged.exe moved successfully.
DllUnregisterServer procedure not found in D:\WINDOWS\system32\knhwrj.dll
D:\WINDOWS\system32\knhwrj.dll NOT unregistered.
D:\WINDOWS\system32\knhwrj.dll moved successfully.
DllUnregisterServer procedure not found in D:\WINDOWS\system32\vwqbklae.dll
D:\WINDOWS\system32\vwqbklae.dll NOT unregistered.
D:\WINDOWS\system32\vwqbklae.dll moved successfully.
DllUnregisterServer procedure not found in D:\WINDOWS\system32\pmnlmLBs.dll
D:\WINDOWS\system32\pmnlmLBs.dll NOT unregistered.
D:\WINDOWS\system32\pmnlmLBs.dll moved successfully.
D:\WINDOWS\system32\fkphlmfb.ini moved successfully.
DllUnregisterServer procedure not found in D:\WINDOWS\system32\bfmlhpkf.dll
D:\WINDOWS\system32\bfmlhpkf.dll NOT unregistered.
D:\WINDOWS\system32\bfmlhpkf.dll moved successfully.
D:\WINDOWS\system32\KSBIPqss.ini2 moved successfully.
D:\WINDOWS\system32\KSBIPqss.ini moved successfully.
D:\WINDOWS\system32\winscenter.exe moved successfully.
D:\Documents and Settings\All Users\Application Data\svhost.exe moved successfully.
DllUnregisterServer procedure not found in D:\WINDOWS\system32\cbXQiFya.dll
D:\WINDOWS\system32\cbXQiFya.dll NOT unregistered.
D:\WINDOWS\system32\cbXQiFya.dll moved successfully.
DllUnregisterServer procedure not found in D:\WINDOWS\Inoyoxeb.dll
D:\WINDOWS\Inoyoxeb.dll NOT unregistered.
D:\WINDOWS\Inoyoxeb.dll moved successfully.
LoadLibrary failed for D:\WINDOWS\system32\rwhbfb873unjdfdg.dll
D:\WINDOWS\system32\rwhbfb873unjdfdg.dll NOT unregistered.
D:\WINDOWS\system32\rwhbfb873unjdfdg.dll moved successfully.
D:\WINDOWS\system32\rs32net.exe moved successfully.
D:\WINDOWS\sys.com moved successfully.
Error: Unable to interpret <:Folders> in the current context!
Error: Unable to interpret in the current context!

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01142009_104447



——————-
ComboFix Log
——————
ComboFix 09-01-13.03 - Owner 2009-01-14 11:09:23.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3007.2646 [GMT -5:00]
Running from: d:\documents and settings\[removed]\Desktop\ComdsfboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
.
ADS - svchost.exe: deleted 32256 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\documents and settings\All Users\Application Data\CrucialSoft Ltd
d:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
d:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
d:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll
d:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
d:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
d:\documents and settings\All Users\Application Data\Microsoft\Protect\svhost.exe
d:\documents and settings\Owner\lsass.exe
d:\program files\Microsoft Common
d:\program files\Microsoft Common\svchost.exe
d:\windows\system32\byXPFutR.dll
d:\windows\system32\drivers\ati1tpxx.sys
d:\windows\system32\drivers\TDSSpqlt.sys
d:\windows\system32\pac.txt
d:\windows\system32\TDSScfum.dll
d:\windows\system32\TDSSlxwp.dll
d:\windows\system32\TDSSnmxh.log
d:\windows\system32\TDSSnrsr.dll
d:\windows\system32\TDSSofxh.dll
d:\windows\system32\TDSSosvd.dat
d:\windows\system32\TDSSrhym.log
d:\windows\system32\TDSSriqp.dll
d:\windows\system32\TDSSsihc.dll
d:\windows\system32\TDSStkdv.log
F:\autorun.inf

—– BITS: Possible infected sites —–

hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_TDSSserv.sys
——-\Legacy_TDSSserv.sys
——-\Legacy_ati1tpxx
——-\Legacy_FCI
——-\Legacy_ICF
——-\Service_ati1tpxx
——-\Service_FCI
——-\Service_icf


((((((((((((((((((((((((( Files Created from 2008-12-14 to 2009-01-14 )))))))))))))))))))))))))))))))
.

2009-01-14 10:44 . 2009-01-14 10:44 d——– D:\_OTMoveIt
2009-01-13 22:26 . 2009-01-13 22:26 d——– D:\rsit
2009-01-13 22:26 . 2009-01-13 22:26 d——– d:\program files\trend micro
2009-01-13 22:00 . 2009-01-14 10:59 d——– d:\program files\Malwarebytes' Anti-Malware
2009-01-07 23:24 . 2009-01-08 00:03 d——– d:\program files\gjhgfhfjh
2009-01-07 23:24 . 2009-01-04 18:39 38,496 –a—— d:\windows\system32\drivers\mbamswissarmy.sys
2009-01-07 23:24 . 2009-01-04 18:39 15,504 –a—— d:\windows\system32\drivers\mbam.sys
2009-01-07 21:57 . 2009-01-07 21:57 d——– D:\VundoFix Backups
2009-01-07 10:19 . 2009-01-14 11:16 100,588 –a—— d:\windows\system32\drivers\df32559.sys
2009-01-06 21:15 . 2009-01-08 00:23 d——– D:\matt
2009-01-06 21:15 . 2009-01-08 01:01 d——– D:\HJT
2009-01-06 21:11 . 2009-01-14 11:15 100,588 –a—— d:\windows\system32\drivers\19954aae.sys
2009-01-06 15:11 . 2009-01-14 11:15 100,588 –a—— d:\windows\system32\drivers\ea8ac7b6.sys
2008-12-21 10:50 . 2009-01-14 10:48 d——– D:\ComboFix
2008-12-19 09:12 . 2008-12-19 09:12 d——– d:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-19 09:01 . 2008-12-19 09:01 d–h—– d:\windows\PIF
2008-12-19 08:53 . 2008-12-19 08:53 d——– d:\documents and settings\All Users\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 15:20 ——— d—–w d:\documents and settings\All Users\Application Data\avg8
2009-01-05 16:40 ——— d—–w d:\program files\Lx_cats
2008-12-14 00:30 ——— d—–w d:\documents and settings\Administrator\Application Data\7100Series
2008-11-19 20:34 60,744 —-a-w d:\documents and settings\Owner\g2mdlhlpx.exe
2008-11-19 20:34 ——— d—–w d:\program files\Citrix
2008-11-19 20:29 ——— d—–w d:\program files\Java
2008-11-11 22:49 2,663 —-a-w d:\documents and settings\Owner\index.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="d:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"LXBXCATS"="d:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-11-02 69632]
"lxbxmon.exe"="d:\program files\Lexmark 7100 Series\lxbxmon.exe" [2005-01-18 196608]
"FaxCenterServer4_in_1"="d:\program files\Lexmark 7100 Series\fm3032.exe" [2004-12-06 286720]
"EzPrint"="d:\program files\Lexmark 7100 Series\ezprint.exe" [2004-09-17 61440]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=d:\windows\pss\Bluetooth.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 15:00 15360 d:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 11:24 1694208 d:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-08-23 17:15 8478720 d:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-08-23 17:15 81920 d:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
–a—— 2007-09-14 18:29 102400 d:\program files\Synaptics\SynTP\SynTPStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-08-23 17:15 1626112 d:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"btwdins"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"d:\\WINDOWS\\system32\\mmc.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;d:\windows\system32\drivers\avgldx86.sys [2008-10-04 97928]
R4 avg8emc;AVG Free8 E-mail Scanner;d:\progra~1\AVG\AVG8\avgemc.exe [2008-10-04 875288]
R4 avg8wd;AVG Free8 WatchDog;d:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-04 231704]
R4 AvgTdiX;AVG Free8 Network Redirector;d:\windows\system32\drivers\avgtdix.sys [2008-10-04 76040]
S1 streamm;streamm;d:\windows\system32\drivers\streamm.sys –> d:\windows\system32\drivers\streamm.sys [?]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;d:\windows\system32\drivers\ar5211.sys [2008-08-31 468768]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{27fb5c44-7a74-11dd-9e9a-001e68c6e09b}]
\Shell\Auto\command - F:\Start.exe
\Shell\AutoRun\command - d:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
Contents of the 'Scheduled Tasks' folder

2009-01-08 d:\windows\Tasks\bdmiqanb.job
- d:\windows\system32\rundll32.exe [2004-08-04 15:00]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-ati8xpxx.sys


.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - d:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - d:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vuyfwylj.default\
FF - component: d:\program files\AVG\AVG8\Firefox\components\avgssff.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-14 11:15:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBXCATS = rundll32 d:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\controlset005\Services\19954aae]
"ImagePath"="\SystemRoot\System32\drivers\19954aae.sys"
–

[HKEY_LOCAL_MACHINE\System\controlset005\Services\df32559]
"ImagePath"="\SystemRoot\System32\drivers\df32559.sys"
–

[HKEY_LOCAL_MACHINE\System\controlset005\Services\ea8ac7b6]
"ImagePath"="\SystemRoot\System32\drivers\ea8ac7b6.sys"
.
———————— Other Running Processes ————————
.
d:\program files\Java\jre6\bin\jqs.exe
d:\progra~1\AVG\AVG8\avgrsx.exe
d:\windows\system32\wscntfy.exe
d:\windows\system32\lxbxcoms.exe
.
**************************************************************************
.
Completion time: 2009-01-14 11:17:02 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2009-01-14 16:17:00
ComboFix2.txt 2008-12-21 15:36:39

Pre-Run: 179,134,500,864 bytes free
Post-Run: 179,085,131,776 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
177 — E O F — 2008-12-19 22:35:47

—————–
Mbam Log
—————-
Malwarebytes' Anti-Malware 1.32
Database version: 1616
Windows 5.1.2600 Service Pack 2

1/14/2009 11:36:53 AM
mbam-log-2009-01-14 (11-36-48).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 73883
Time elapsed: 10 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 15

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Spyware Guard 2008 (Rogue.SpywareGuard) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Qoobox\Quarantine\D\Program Files\Microsoft Common\svchost.exe.vir (Trojan.Agent) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSnrsr.dll.vir (Trojan.TDSS) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSofxh.dll.vir (Trojan.TDSS) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSriqp.dll.vir (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP3\A0000260.dll (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP3\A0000261.dll (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP3\A0000262.dll (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP3\A0000284.exe (Trojan.Agent) -> No action taken.
D:\WINDOWS\system32\drivers\19954aae.sys (Rootkit.Agent) -> No action taken.
D:\WINDOWS\system32\drivers\df32559.sys (Rootkit.Agent) -> No action taken.
D:\WINDOWS\system32\drivers\ea8ac7b6.sys (Rootkit.Agent) -> No action taken.
D:\_OTMoveIt\MovedFiles\01142009_104447\WINDOWS\system32\winscenter.exe (Trojan.FakeAlert) -> No action taken.
D:\Documents and Settings\All Users\Application Data\Microsoft\Protect\track.sys (Trojan.FakeAlert) -> No action taken.
D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll (Trojan.FakeAlert) -> No action taken.
D:\Documents and Settings\Owner\Desktop\services.txt (Heuristics.Reserved.Word.Exploit) -> No action taken.


—————–
HJT Log
—————–
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:45:17 AM, on 1/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Lexmark 7100 Series\lxbxmon.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\lxbxcoms.exe
D:\WINDOWS\explorer.exe
D:\HJT\HiJackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "D:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "D:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "D:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - D:\WINDOWS\system32\lxbxcoms.exe

–
End of file - 3373 bytes
If you look over your combofix log Service_TDSSserv.sys, this was a Rootkit infection that prevented you from running any programs.

You also had Malwarebytes set to Take No Action and I especially stated in the instructions to Select it All and Remove selected, if you have not done so you need to rerun Malwarebytes and remove those bad entries.

How are things running now?
Sorry about that.
windows explorer's Tools–>Folder Options is now visible
AVG is able to autoupdate.
no sign of browser redirects yet.
nothing malicious is catching my attention.

Here are the updated logs:

Malwarebytes' Anti-Malware 1.32
Database version: 1616
Windows 5.1.2600 Service Pack 2

1/14/2009 1:05:58 PM
mbam-log-2009-01-14 (13-05-58).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 74045
Time elapsed: 11 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 15

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Spyware Guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Qoobox\Quarantine\D\Program Files\Microsoft Common\svchost.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSnrsr.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSofxh.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSriqp.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP3\A0000260.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP3\A0000261.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP3\A0000262.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP3\A0000284.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\drivers\19954aae.sys (Rootkit.Agent) -> Delete on reboot.
D:\WINDOWS\system32\drivers\df32559.sys (Rootkit.Agent) -> Delete on reboot.
D:\WINDOWS\system32\drivers\ea8ac7b6.sys (Rootkit.Agent) -> Delete on reboot.
D:\_OTMoveIt\MovedFiles\01142009_104447\WINDOWS\system32\winscenter.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
D:\Documents and Settings\All Users\Application Data\Microsoft\Protect\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
D:\Documents and Settings\Owner\Desktop\services.txt (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

——————–
——————-
——————-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:09:56 PM, on 1/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\wscntfy.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\Program Files\Lexmark 7100 Series\lxbxmon.exe
D:\Program Files\Lexmark 7100 Series\ezprint.exe
D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\lxbxcoms.exe
D:\WINDOWS\system32\wuauclt.exe
D:\HJT\HiJackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "D:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "D:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "D:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - D:\WINDOWS\system32\lxbxcoms.exe

–
End of file - 3545 bytes
Hi,

Looking good :thumbup: You have AVG AV installed, check for updates and run the scan, it will find and remove some leftover garbage I am sure.

Forgot to add that you need to run Windows Updates , your Operating System is out of date, you need to install all critical updates including Service Pack 3 (SP3)

ATF Cleaner <– Yours to keep, run it now and then to clean out the clutter.

Malwarebytes <– Yours to keep also, check for updates and run a scan now and then.

Hijackthis <—Your call, hopefully you won't need it again, if you do you can redownload it

Combofix <—Is not a general cleaning tool, just run it with supervision or you can bork your system

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


    • [external image: Posted Image]

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


  • How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports


Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster, you can still install Spybot Search and Destroy but do not enable the TeaTimer in Spybot.


Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.6
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI