This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected, possible rootkit?

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A relative's laptop is yet again infected.

Access to Regedit.exe was originally disabled, has since been restored.
Windows Explorer's Tools–>Folder Options is not visible
mbam.exe will not run in safe mode, even with renaming the file
ComboFix will not run in safe mode, even with renaming the file.

I am using a USB drive to transfer files. The USB stick becomes infected with system.exe, a Trojan horse Crypt.CGE accorind to AVG's resident shield on another computer.

This laptop has been serviced through this website twice before.
http://forums.whatthetech.com/Baseline_t97909.html
http://forums.whatthetech.com/incomplete_removal_t98760.html

I'm starting to get a good idea of what should and should not be listed in HiJackThis for this particular machine. So, I've removed the most obvious elements.

I'll provide The original HiJackThis Log, the current log (not much better), and a current log.txt and info.txt from random's system information tool (RSIT). The RSIT log is being included as it was requested in the previous removal. Hopefully this will aid whomever assists me.

Lastly, I would like to thank the contributors to What The Tech for assisting myself and countless others. Your efforts are greatly appreciated.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:40:15 PM, on 2/1/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Safe mode

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\taskmgr.exe
D:\WINDOWS\explorer.exe
D:\HJT\HiJackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\pmnnmjgE.dll
O2 - BHO: D:\WINDOWS\system32\hgdfeeeh4fdg.dll - {c5bf49a2-94f3-42bd-f434-3604812c8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O2 - BHO: (no name) - {E16A746C-A14B-4903-9F3B-C3659B35B39E} - D:\WINDOWS\system32\nnnnNEut.dll
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "D:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "D:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "D:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LSA Shellu] D:\Documents and Settings\Owner\lsass.exe
O4 - HKLM\..\Run: [Microsoft Windows Installer] D:\Documents and Settings\Owner\Application Data\msiexec.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [Qgoqoxi] rundll32.exe "D:\WINDOWS\Inoyoxeb.dll",e
O4 - HKLM\..\Run: [Pzoni] rundll32.exe "D:\WINDOWS\oyuqoseje.dll",e
O4 - HKLM\..\Run: [887407b3] rundll32.exe "D:\WINDOWS\system32\lgjkpabb.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlognn.exe
O4 - HKCU\..\Run: [ttool] D:\WINDOWS\9129837.exe
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [svschost.exe] D:\WINDOWS\system32\svschost.exe -check
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth; Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: rolwnd.dll cillvg.dll tjtwbp.dll
O20 - Winlogon Notify: pmnnmjgE - D:\WINDOWS\SYSTEM32\pmnnmjgE.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - D:\WINDOWS\system32\lxbxcoms.exe

–
End of file - 4823 bytes

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:01:02 PM, on 2/1/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Safe mode

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\taskmgr.exe
D:\WINDOWS\explorer.exe
D:\HJT\HiJackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\pmnnmjgE.dll
O2 - BHO: D:\WINDOWS\system32\hgdfeeeh4fdg.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O2 - BHO: (no name) - {E16A746C-A14B-4903-9F3B-C3659B35B39E} - D:\WINDOWS\system32\nnnnNEut.dll
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "D:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "D:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "D:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth; Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: pmnnmjgE - D:\WINDOWS\SYSTEM32\pmnnmjgE.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - D:\WINDOWS\system32\lxbxcoms.exe

–
End of file - 3437 bytes

info.txt logfile of random's system information tool 1.05 2009-02-01 20:01:38

======Uninstall list======

–>D:\Program Files\Conexant\SmartAudio\SETUP.EXE -U -ISmartAudio -SM=SMAUDIO.EXE,1801
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 D:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 6.0 Sprint Plus–>MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
Acrobat.com–>D:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR–>D:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player Plugin–>D:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
ArcSoft Software Suite–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{EE7C3A14-1D20-49F6-B903-491561076F0F}\SETUP.EXE" -l0x9
AVG Free 8.0–>D:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Broadcom 802.11 Wireless LAN Adapter–>"D:\Program Files\Broadcom\Broadcom 802.11\Driver\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="D:\Program Files\Broadcom\Broadcom 802.11\Driver"
Conexant HD Audio–>D:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -I*.INF
Driver Genius Professional Edition 2007–>"D:\Program Files\Driver-Soft\DriverGenius\unins000.exe"
DriverAgent by TouchStone Software–>RunDll32.exe advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove
HDAUDIO Soft Data Fax Modem with SmartCP–>D:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_HERMOSA_HSF\UIU32m.exe -U -IHPQHER5m.inf
HijackThis 2.0.2–>"D:\HJT\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)–>"D:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Integrated Module with Bluetooth wireless technology–>MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
HP Integrated Wireless LAN W400-W500 Driver–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{5C3DA2A1-03B2-44BD-B5AA-A44BD6E0C0C1}\setup.exe" -l0x9
Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Lexmark 7100 Series Fax Solutions–>D:\PROGRA~1\COMMON~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /M{316A75E3-039D-4BF4-AC29-3FF91E8555CD} /l1033 /z/U
Lexmark 7100 Series–>D:\WINDOWS\system32\spool\drivers\w32x86\3\lxbxUNST.EXE -NOLICENSE
Malwarebytes' Anti-Malware–>"D:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Internationalized Domain Names Mitigation APIs–>"D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5–>"D:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.5)–>D:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN–>D:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
NVIDIA Drivers–>D:\WINDOWS\system32\nvudisp.exe UninstallGUI
PC Wizard 2008.1.84–>"D:\Program Files\PC Wizard 2008\unins000.exe"
Realtek AC'97 Audio–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x9 -removeonly
RICOH R5C853 Driver WXP Ver.1.01.05–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x9 anything
Security Update for Windows Internet Explorer 7 (KB938127)–>"D:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127-v2)–>"D:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"D:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"D:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"D:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)–>"D:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"D:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>D:\WINDOWS\system32\MacroMed\Flash\genuinst.exe D:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"D:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"D:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"D:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"D:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"D:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"D:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"D:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"D:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"D:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"D:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)–>"D:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"D:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"D:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)–>"D:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"D:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"D:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"D:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"D:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"D:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"D:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"D:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"D:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"D:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)–>"D:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Synaptics Pointing Device Driver–>rundll32.exe "D:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Texas Instruments PCIxx21/x515/xx12 drivers.–>D:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A} /l1033
Update for Windows XP (KB951072-v2)–>"D:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"D:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"D:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"D:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

=====HijackThis Backups=====

O4 - HKLM\..\Run: [Qgoqoxi] rundll32.exe "D:\WINDOWS\Inoyoxeb.dll",e
O4 - HKCU\..\Run: [jsg8jfgfdfhfhf] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogun.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogin.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O4 - HKUS\.DEFAULT\..\Run: [tezrtsjhfr84iusjfo84f] D:\WINDOWS\TEMP\csrssc.exe (User 'Default user')
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogin.exe
O4 - HKLM\..\Run: [jsg8jfgfdfhfhf] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogun.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - HKLM\..\Run: [spywareguard] D:\Program Files\Spyware Guard 2008\spywareguard.exe
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - AppInit_DLLs: knhwrj.dll
O20 - Winlogon Notify: opnnnKax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\rwhbfb873unjdfdg.dll
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {c5bf49a2-94f3-42bd-f434-3604812c8955} - (no file)
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {c5af42a3-94f3-42bd-f634-3604832c897d} - (no file)
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O4 - HKLM\..\Run: [887407b3] rundll32.exe "D:\WINDOWS\system32\bfmlhpkf.dll",b
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O21 - SSODL: InternetConnection - {9BB113B3-2F6C-48D2-9AB7-75BEA0014FBD} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: ieModule - {B36D696C-C331-4E30-AA93-4BE550E7C75A} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O4 - HKLM\..\Run: [LSA Shellu] D:\Documents and Settings\Owner\lsass.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O4 - HKLM\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: InternetConnection - {31697D4A-AEC7-4BCE-8BF0-3FEAEC5C8FE2} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O2 - BHO: D:\WINDOWS\system32\gseb37dkjgfgf.dll - {c5af42a3-94f3-42bd-f634-3604832c897d} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O2 - BHO: (no name) - {C6403D33-965C-452D-A8F3-2FA92C6446B9} - D:\WINDOWS\system32\ssqPIBSK.dll
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O21 - SSODL: InternetConnection - {EEED702B-2A45-4F66-8076-6FAE05CF126B} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: InternetConnection - {EEED702B-2A45-4F66-8076-6FAE05CF126B} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O2 - BHO: (no name) - {C6403D33-965C-452D-A8F3-2FA92C6446B9} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - (no file)
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {E66D37F9-1D81-4C9C-ABDE-EE4407A17CC0} - D:\WINDOWS\system32\ssqPIBSK.dll
O20 - Winlogon Notify: opnnnKax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O2 - BHO: (no name) - {cfdf0f20-4944-48a6-9370-d8075facae40} - D:\WINDOWS\system32\ssqPIBSK.dll (file missing)
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O20 - Winlogon Notify: fnnwuke - fnnwuke32.dll (file missing)
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrssc.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke.dll
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://bontrafic.org/s/in.cgi?3&key;=door
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: FCI - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke.dll
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O4 - HKLM\..\Run: [Microsoft Windows Installer] D:\Documents and Settings\Owner\Application Data\msiexec.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O4 - HKLM\..\Run: [887407b3] rundll32.exe "D:\WINDOWS\system32\lgjkpabb.dll",b
O4 - HKLM\..\Run: [Pzoni] rundll32.exe "D:\WINDOWS\oyuqoseje.dll",e
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - HKLM\..\Run: [LSA Shellu] D:\Documents and Settings\Owner\lsass.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\pmnnmjgE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O4 - HKCU\..\Run: [svschost.exe] D:\WINDOWS\system32\svschost.exe -check
O4 - HKLM\..\Run: [Qgoqoxi] rundll32.exe "D:\WINDOWS\Inoyoxeb.dll",e
O4 - HKCU\..\Run: [ttool] D:\WINDOWS\9129837.exe
O2 - BHO: (no name) - {E16A746C-A14B-4903-9F3B-C3659B35B39E} - D:\WINDOWS\system32\nnnnNEut.dll
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlognn.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O2 - BHO: D:\WINDOWS\system32\hgdfeeeh4fdg.dll - {c5bf49a2-94f3-42bd-f434-3604812c8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O20 - AppInit_DLLs: rolwnd.dll cillvg.dll tjtwbp.dll
O20 - Winlogon Notify: pmnnmjgE - D:\WINDOWS\SYSTEM32\pmnnmjgE.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O20 - Winlogon Notify: pmnnmjgE - D:\WINDOWS\SYSTEM32\pmnnmjgE.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\pmnnmjgE.dll
O2 - BHO: (no name) - {E16A746C-A14B-4903-9F3B-C3659B35B39E} - D:\WINDOWS\system32\nnnnNEut.dll
O20 - Winlogon Notify: pmnnmjgE - D:\WINDOWS\SYSTEM32\pmnnmjgE.dll
O2 - BHO: (no name) - {E16A746C-A14B-4903-9F3B-C3659B35B39E} - D:\WINDOWS\system32\nnnnNEut.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\pmnnmjgE.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O20 - Winlogon Notify: pmnnmjgE - D:\WINDOWS\SYSTEM32\pmnnmjgE.dll
O2 - BHO: D:\WINDOWS\system32\hgdfeeeh4fdg.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab

======Security center information======

AV: AVG Anti-Virus Free (outdated)

System event log

Computer Name: OWNER-FC0C2179D
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
AFD
AvgLdx86
AvgMfx86
Fips
IPSec
MRxSmb
NetBIOS
NetBT
Processor
RasAcd
Rdbss
Tcpip

Record Number: 13276
Source Name: Service Control Manager
Time Written: 20090107104706.000000-300
Event Type: error
User:

Computer Name: OWNER-FC0C2179D
Event Code: 7001
Message: The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
A device attached to the system is not functioning.


Record Number: 13275
Source Name: Service Control Manager
Time Written: 20090107104706.000000-300
Event Type: error
User:

Computer Name: OWNER-FC0C2179D
Event Code: 7001
Message: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
A device attached to the system is not functioning.


Record Number: 13274
Source Name: Service Control Manager
Time Written: 20090107104706.000000-300
Event Type: error
User:

Computer Name: OWNER-FC0C2179D
Event Code: 7001
Message: The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
A device attached to the system is not functioning.


Record Number: 13273
Source Name: Service Control Manager
Time Written: 20090107104706.000000-300
Event Type: error
User:

Computer Name: OWNER-FC0C2179D
Event Code: 7001
Message: The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:
A device attached to the system is not functioning.


Record Number: 13272
Source Name: Service Control Manager
Time Written: 20090107104706.000000-300
Event Type: error
User:

Application event log

Computer Name: OWNER-FC0C2179D
Event Code: 1001
Message: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.
The Record Data contains the new values of the system Last Counter and
Last Help registry entries.

Record Number: 1486
Source Name: LoadPerf
Time Written: 20090106213335.000000-300
Event Type: information
User:

Computer Name: OWNER-FC0C2179D
Event Code: 1
Message:
Record Number: 1485
Source Name: avg8emc
Time Written: 20090106212927.000000-300
Event Type: information
User:

Computer Name: OWNER-FC0C2179D
Event Code: 1800
Message: The Windows Security Center Service has started.

Record Number: 1484
Source Name: SecurityCenter
Time Written: 20090106212924.000000-300
Event Type: information
User:

Computer Name: OWNER-FC0C2179D
Event Code: 1000
Message: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.

Record Number: 1483
Source Name: LoadPerf
Time Written: 20090106211353.000000-300
Event Type: information
User:

Computer Name: OWNER-FC0C2179D
Event Code: 1001
Message: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.
The Record Data contains the new values of the system Last Counter and
Last Help registry entries.

Record Number: 1482
Source Name: LoadPerf
Time Written: 20090106211353.000000-300
Event Type: information
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 104 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=6802
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"SAFEBOOT_OPTION"=MINIMAL

—————–EOF—————–

Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-02-01 20:01:37
Microsoft Windows XP Professional Service Pack 3
System drive D: has 171 GB (96%) free of 179 GB
Total RAM: 3007 MB (92% free)

HijackThis download failed

======Scheduled tasks folder======

D:\WINDOWS\tasks\bdmiqanb.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
D:\WINDOWS\system32\pmnnmjgE.dll [2009-01-25 47616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5BF49A2-94F3-42BD-F434-3604812C8955}]
D:\WINDOWS\system32\hgdfeeeh4fdg.dll - D:\WINDOWS\system32\hgdfeeeh4fdg.dll [2009-01-25 15000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E16A746C-A14B-4903-9F3B-C3659B35B39E}]
D:\WINDOWS\system32\nnnnNEut.dll [2009-01-25 297472]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"=D:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-11-27 1261336]
"LXBXCATS"=rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll []
"lxbxmon.exe"=D:\Program Files\Lexmark 7100 Series\lxbxmon.exe [2005-01-18 196608]
"FaxCenterServer4_in_1"=D:\Program Files\Lexmark 7100 Series\fm3032.exe [2004-12-06 286720]
"EzPrint"=D:\Program Files\Lexmark 7100 Series\ezprint.exe [2004-09-17 61440]
"Adobe Reader Speed Launcher"=D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
D:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
D:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
D:\WINDOWS\system32\NvCpl.dll [2007-08-23 8478720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
D:\WINDOWS\system32\NvMcTray.dll [2007-08-23 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
D:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-09-14 102400]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
D:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2006-11-13 561213]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3
"NVSvc"=2
"btwdins"=2

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnnmjgE]
D:\WINDOWS\system32\pmnnmjgE.dll [2009-01-25 47616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
D:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll [2009-01-25 15000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=D:\WINDOWS\system32\pmnnmjgE.dll [2009-01-25 47616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
D:\WINDOWS\system32\nnnnNEut

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoFolderOptions"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\AVG\AVG8\avgemc.exe"="D:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"D:\Program Files\AVG\AVG8\avgupd.exe"="D:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"D:\WINDOWS\system32\mmc.exe"="D:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{27fb5c44-7a74-11dd-9e9a-001e68c6e09b}]
shell\auto\command - F:\Start.exe
shell\autorun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe


======List of files/folders created in the last 3 months======

2009-02-01 19:27:18 —-D—- D:\Documents and Settings\Owner\Application Data\uTorrent
2009-01-26 21:25:53 —-A—- D:\WINDOWS\system32\khfGyWoM.dll
2009-01-26 21:25:27 —-A—- D:\WINDOWS\system32\tjtwbp.dll
2009-01-26 21:25:26 —-A—- D:\WINDOWS\system32\blswwvhl.dll
2009-01-26 21:22:43 —-SH—- D:\WINDOWS\system32\bbapkjgl.ini
2009-01-26 21:22:38 —-A—- D:\WINDOWS\system32\lgjkpabb.dll
2009-01-26 21:12:14 —-SH—- D:\WINDOWS\system32\apdxsybk.ini
2009-01-26 21:12:11 —-A—- D:\WINDOWS\system32\kbysxdpa.dll
2009-01-26 21:09:29 —-A—- D:\WINDOWS\system32\cillvg.dll
2009-01-26 21:09:28 —-A—- D:\WINDOWS\system32\iavdktpe.dll
2009-01-25 21:00:55 —-D—- D:\WINDOWS\system32\LogFiles
2009-01-25 20:33:35 —-A—- D:\WINDOWS\oyuqoseje.dll
2009-01-25 20:31:26 —-A—- D:\WINDOWS\system32\rolwnd.dll
2009-01-25 20:31:25 —-A—- D:\WINDOWS\system32\mlcxtorm.dll
2009-01-25 20:30:39 —-ASH—- D:\WINDOWS\system32\tuENnnnn.ini2
2009-01-25 20:30:38 —-ASH—- D:\WINDOWS\system32\tuENnnnn.ini
2009-01-25 20:30:35 —-A—- D:\WINDOWS\system32\nnnnNEut.dll
2009-01-25 20:24:10 —-A—- D:\WINDOWS\system32\svschost.exe
2009-01-25 20:24:10 —-A—- D:\WINDOWS\system32\svñshost.exe
2009-01-25 20:21:45 —-D—- D:\Program Files\Microsoft Common
2009-01-25 20:21:27 —-A—- D:\WINDOWS\system32\nvaux32.dll
2009-01-25 20:21:27 —-A—- D:\WINDOWS\Inoyoxeb.dll
2009-01-25 20:21:25 —-A—- D:\WINDOWS\9129837.exe
2009-01-25 20:21:22 —-A—- D:\WINDOWS\system32\hgdfeeeh4fdg.dll
2009-01-25 20:21:22 —-A—- D:\Documents and Settings\Owner\Application Data\msiexec.exe
2009-01-25 20:21:14 —-D—- D:\WINDOWS\system32\m3V02
2009-01-25 20:21:11 —-A—- D:\WINDOWS\system32\pmnnmjgE.dll
2009-01-15 14:06:18 —-SHD—- D:\RECYCLER
2009-01-14 14:14:24 —-HDC—- D:\WINDOWS\$NtUninstallKB958687$
2009-01-14 14:14:11 —-HDC—- D:\WINDOWS\$NtUninstallKB954459$
2009-01-14 14:11:45 —-HDC—- D:\WINDOWS\$NtUninstallKB951978$
2009-01-14 13:59:10 —-D—- D:\WINDOWS\Prefetch
2009-01-14 13:48:21 —-HDC—- D:\WINDOWS\$NtUninstallKB958644$
2009-01-14 13:48:15 —-HDC—- D:\WINDOWS\$NtUninstallKB957097$
2009-01-14 13:48:09 —-HDC—- D:\WINDOWS\$NtUninstallKB957095$
2009-01-14 13:48:01 —-HDC—- D:\WINDOWS\$NtUninstallKB956841$
2009-01-14 13:47:55 —-HDC—- D:\WINDOWS\$NtUninstallKB956803$
2009-01-14 13:47:47 —-HDC—- D:\WINDOWS\$NtUninstallKB956802$
2009-01-14 13:47:36 —-HDC—- D:\WINDOWS\$NtUninstallKB955069$
2009-01-14 13:47:29 —-HDC—- D:\WINDOWS\$NtUninstallKB954600$
2009-01-14 13:47:22 —-HDC—- D:\WINDOWS\$NtUninstallKB954211$
2009-01-14 13:47:10 —-HDC—- D:\WINDOWS\$NtUninstallKB952954$
2009-01-14 13:47:04 —-HDC—- D:\WINDOWS\$NtUninstallKB952287$
2009-01-14 13:46:57 —-HDC—- D:\WINDOWS\$NtUninstallKB951748$
2009-01-14 13:46:51 —-HDC—- D:\WINDOWS\$NtUninstallKB951698$
2009-01-14 13:46:45 —-HDC—- D:\WINDOWS\$NtUninstallKB951376-v2$
2009-01-14 13:46:35 —-HDC—- D:\WINDOWS\$NtUninstallKB951066$
2009-01-14 13:46:29 —-HDC—- D:\WINDOWS\$NtUninstallKB950974$
2009-01-14 13:46:22 —-HDC—- D:\WINDOWS\$NtUninstallKB950762$
2009-01-14 13:46:16 —-HDC—- D:\WINDOWS\$NtUninstallKB946648$
2009-01-14 13:46:10 —-HDC—- D:\WINDOWS\$NtUninstallKB938464$
2009-01-14 13:43:06 —-D—- D:\WINDOWS\system32\scripting
2009-01-14 13:43:06 —-D—- D:\WINDOWS\l2schemas
2009-01-14 13:43:05 —-D—- D:\WINDOWS\system32\en
2009-01-14 13:43:05 —-D—- D:\WINDOWS\system32\bits
2009-01-14 13:40:48 —-D—- D:\WINDOWS\ServicePackFiles
2009-01-14 13:38:49 —-D—- D:\WINDOWS\network diagnostic
2009-01-14 13:35:30 —-HDC—- D:\WINDOWS\$NtServicePackUninstall$
2009-01-14 11:17:03 —-A—- D:\ComboFix.txt
2009-01-14 11:00:33 —-D—- D:\ComdsfboFix
2009-01-13 22:26:02 —-D—- D:\rsit
2009-01-13 22:26:02 —-D—- D:\Program Files\trend micro
2009-01-13 22:00:57 —-D—- D:\Program Files\Malwarebytes' Anti-Malware
2009-01-07 23:24:02 —-D—- D:\Program Files\gjhgfhfjh
2009-01-07 23:16:52 —-SHD—- D:\Config.Msi
2009-01-07 21:57:57 —-A—- D:\VundoFix.txt
2009-01-07 14:20:08 —-AH—- D:\matt.txt
2009-01-06 21:15:11 —-D—- D:\matt
2009-01-06 21:15:03 —-D—- D:\HJT
2008-12-19 17:35:44 —-HDC—- D:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-19 17:35:40 —-HDC—- D:\WINDOWS\$NtUninstallKB955839$
2008-12-19 17:33:59 —-HDC—- D:\WINDOWS\$NtUninstallKB954600_0$
2008-12-19 17:33:50 —-HDC—- D:\WINDOWS\$NtUninstallKB956802_0$
2008-12-19 14:05:45 —-D—- D:\WINDOWS\ERDNT
2008-12-19 09:12:14 —-D—- D:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-12-19 09:01:27 —-HD—- D:\WINDOWS\PIF
2008-12-19 08:53:12 —-D—- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-15 09:29:30 —-SHD—- D:\WINDOWS\CSC
2008-12-13 19:29:28 —-A—- D:\WINDOWS\system32\wmpns.dll
2008-12-13 18:34:56 —-A—- D:\WINDOWS\ntbtlog.txt
2008-12-13 18:33:20 —-D—- D:\WINDOWS\system32\DL5
2008-12-13 18:33:20 —-D—- D:\WINDOWS\system32\cap2
2008-12-13 18:33:20 —-D—- D:\WINDOWS\system32\ain
2008-12-13 18:15:50 —-D—- D:\WINDOWS\system32\whSLD02
2008-12-01 11:42:42 —-D—- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-11-19 15:34:39 —-D—- D:\Program Files\Citrix
2008-11-19 15:34:09 —-D—- D:\WINDOWS\Sun
2008-11-19 15:29:39 —-A—- D:\WINDOWS\system32\javaws.exe
2008-11-19 15:29:39 —-A—- D:\WINDOWS\system32\deploytk.dll
2008-11-19 15:29:38 —-A—- D:\WINDOWS\system32\javaw.exe
2008-11-19 15:29:38 —-A—- D:\WINDOWS\system32\java.exe
2008-11-19 15:29:25 —-D—- D:\Program Files\Java
2008-11-19 15:28:00 —-D—- D:\Documents and Settings\Owner\Application Data\Sun
2008-11-15 15:23:53 —-HDC—- D:\WINDOWS\$NtUninstallKB957097_0$
2008-11-15 15:23:43 —-HDC—- D:\WINDOWS\$NtUninstallKB955069_0$
2008-11-12 13:45:03 —-D—- D:\WINDOWS\Minidump
2008-11-09 17:00:40 —-HDC—- D:\WINDOWS\$NtUninstallKB958644_0$

======List of files/folders modified in the last 3 months======

2009-02-01 19:51:03 —-D—- D:\WINDOWS\Temp
2009-02-01 19:50:33 —-SD—- D:\WINDOWS\Downloaded Program Files
2009-02-01 19:38:32 —-D—- D:\WINDOWS\system32
2009-02-01 19:38:32 —-A—- D:\WINDOWS\system32\PerfStringBackup.INI
2009-02-01 19:28:13 —-A—- D:\WINDOWS\SchedLgU.Txt
2009-02-01 19:26:31 —-D—- D:\Program Files\Mozilla Firefox
2009-01-26 21:28:12 —-D—- D:\WINDOWS
2009-01-26 21:27:09 —-D—- D:\WINDOWS\system32\drivers
2009-01-26 21:14:44 —-A—- D:\WINDOWS\system32\8357c3cd-.txt
2009-01-25 20:21:45 —-RD—- D:\Program Files
2009-01-25 20:21:28 —-RSHDC—- D:\WINDOWS\system32\dllcache
2009-01-15 13:40:22 —-HD—- D:\WINDOWS\inf
2009-01-15 13:39:52 —-D—- D:\WINDOWS\system32\CatRoot2
2009-01-14 19:54:55 —-SHD—- D:\System Volume Information
2009-01-14 19:54:55 —-D—- D:\WINDOWS\system32\Restore
2009-01-14 14:32:30 —-RSD—- D:\WINDOWS\assembly
2009-01-14 14:32:30 —-D—- D:\WINDOWS\Microsoft.NET
2009-01-14 14:14:23 —-HD—- D:\WINDOWS\$hf_mig$
2009-01-14 14:14:19 —-D—- D:\WINDOWS\system32\CatRoot
2009-01-14 14:14:15 —-A—- D:\WINDOWS\imsins.BAK
2009-01-14 14:13:54 —-SHD—- D:\WINDOWS\Installer
2009-01-14 14:13:30 —-D—- D:\WINDOWS\WinSxS
2009-01-14 14:13:01 —-D—- D:\Program Files\Internet Explorer
2009-01-14 14:00:14 —-A—- D:\WINDOWS\OEWABLog.txt
2009-01-14 13:59:14 —-A—- D:\WINDOWS\setuplog.txt
2009-01-14 13:58:36 —-D—- D:\WINDOWS\system32\Setup
2009-01-14 13:58:36 —-D—- D:\WINDOWS\AppPatch
2009-01-14 13:58:35 —-D—- D:\WINDOWS\system32\wbem
2009-01-14 13:58:34 —-RSD—- D:\WINDOWS\Fonts
2009-01-14 13:57:44 —-D—- D:\WINDOWS\security
2009-01-14 13:46:18 —-D—- D:\Program Files\Messenger
2009-01-14 13:43:30 —-D—- D:\Program Files\Windows Media Player
2009-01-14 13:43:17 —-D—- D:\WINDOWS\system32\inetsrv
2009-01-14 13:43:16 —-D—- D:\WINDOWS\ime
2009-01-14 13:43:16 —-D—- D:\WINDOWS\Help
2009-01-14 13:43:06 —-D—- D:\WINDOWS\system32\usmt
2009-01-14 13:43:06 —-D—- D:\WINDOWS\system32\en-US
2009-01-14 13:43:05 —-D—- D:\WINDOWS\PeerNet
2009-01-14 13:43:05 —-D—- D:\Program Files\Movie Maker
2009-01-14 13:40:39 —-D—- D:\WINDOWS\system32\npp
2009-01-14 13:40:39 —-D—- D:\WINDOWS\mui
2009-01-14 13:40:38 —-D—- D:\WINDOWS\msagent
2009-01-14 13:40:37 —-D—- D:\WINDOWS\srchasst
2009-01-14 13:40:36 —-D—- D:\Program Files\NetMeeting
2009-01-14 13:40:35 —-D—- D:\WINDOWS\system32\Com
2009-01-14 13:40:32 —-D—- D:\Program Files\Windows NT
2009-01-14 13:40:32 —-D—- D:\Program Files\Outlook Express
2009-01-14 13:40:29 —-D—- D:\Program Files\Common Files\System
2009-01-14 13:40:11 —-D—- D:\WINDOWS\system32\oobe
2009-01-14 13:40:09 —-D—- D:\WINDOWS\system
2009-01-14 13:35:28 —-D—- D:\WINDOWS\ehome
2009-01-14 11:15:53 —-A—- D:\WINDOWS\system.ini
2009-01-14 11:11:08 —-D—- D:\WINDOWS\system32\config
2009-01-14 11:10:22 —-D—- D:\Program Files\Common Files
2009-01-09 20:35:28 —-A—- D:\WINDOWS\system32\MRT.exe
2009-01-07 11:50:23 —-D—- D:\Program Files\Adobe
2009-01-07 10:20:13 —-D—- D:\Documents and Settings\All Users\Application Data\avg8
2009-01-06 15:11:52 —-SD—- D:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-06 15:11:05 —-SD—- D:\WINDOWS\Tasks
2009-01-05 11:40:20 —-D—- D:\Program Files\Lx_cats
2008-12-19 17:24:56 —-SD—- D:\Documents and Settings\Owner\Application Data\Microsoft
2008-12-13 19:28:19 —-D—- D:\Documents and Settings
2008-12-13 18:39:21 —-D—- D:\temp
2008-12-13 01:40:02 —-A—- D:\WINDOWS\system32\mshtml.dll
2008-12-05 18:56:55 —-HD—- D:\$AVG8.VAULT$
2008-11-24 23:06:53 —-D—- D:\Program Files\MSN
2008-11-16 18:57:23 —-D—- D:\WINDOWS\system32\QI02
2008-11-07 16:45:32 —-A—- D:\WINDOWS\system32\WMVCore.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 kbdhid;Keyboard HID Driver; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; D:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 rimmptsk;rimmptsk; D:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; D:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; D:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2007-03-21 37376]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HpqRemHid;HP Remote Control HID Device; D:\WINDOWS\system32\DRIVERS\HpqRemHid.sys [2007-07-11 7168]
R3 nvsmu;nvsmu; D:\WINDOWS\system32\DRIVERS\nvsmu.sys [2007-02-16 12032]
R3 pfc;Padus ASPI Shell; D:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
R3 SynTP;Synaptics TouchPad Driver; D:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-03-28 224672]
R3 usbccgp;Microsoft USB Generic Parent Driver; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; D:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 USBSTOR;USB Mass Storage Driver; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S1 19954aae;19954aae; D:\WINDOWS\System32\drivers\19954aae.sys []
S1 25a59eb3;25a59eb3; D:\WINDOWS\System32\drivers\25a59eb3.sys [2009-02-01 93420]
S1 AmdPPM;AMD HwPState Processor Driver; D:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
S1 AvgLdx86;AVG Free AVI Loader Driver x86; D:\WINDOWS\System32\Drivers\avgldx86.sys [2008-10-04 97928]
S1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; D:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-10-04 26824]
S1 c907d39;c907d39; D:\WINDOWS\System32\drivers\c907d39.sys [2009-02-01 93420]
S1 df32559;df32559; D:\WINDOWS\System32\drivers\df32559.sys []
S1 ea8ac7b6;ea8ac7b6; D:\WINDOWS\System32\drivers\ea8ac7b6.sys []
S1 streamm;streamm; D:\WINDOWS\System32\drivers\streamm.sys []
S2 AvgTdiX;AVG Free8 Network Redirector; D:\WINDOWS\System32\Drivers\avgtdix.sys [2008-10-04 76040]
S2 mdmxsdk;mdmxsdk; D:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
S3 AR5416;Atheros AR5008 Wireless Network Adapter Service; D:\WINDOWS\system32\DRIVERS\athw.sys [2008-05-18 1312576]
S3 BTKRNL;Bluetooth Bus Enumerator; D:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-11-15 862922]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; D:\WINDOWS\System32\Drivers\btwusb.sys [2006-11-15 67672]
S3 CCDECODE;Closed Caption Decoder; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; D:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; D:\WINDOWS\system32\drivers\CHDAud.sys [2007-12-18 732160]
S3 HidUsb;Microsoft HID Class Driver; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 HpqKbFiltr;HpqKbFilter Driver; D:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
S3 HSF_DPV;HSF_DPV; D:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2007-11-01 989696]
S3 HSFHWAZL;HSFHWAZL; D:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2007-11-01 211456]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 new_drv;!!!!; \??\D:\WINDOWS\new_drv.sys []
S3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-08-23 6844864]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; D:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2007-03-06 58752]
S3 nvnetbus;NVIDIA Network Bus Enumerator; D:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2007-03-06 19968]
S3 sdbus;sdbus; D:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TVICHW32;TVICHW32; \??\D:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 usbprint;Microsoft USB PRINTER Class; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbvideo;USB Video Device (WDM); D:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 Wdf01000;Wdf01000; D:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 winachsf;winachsf; D:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2007-11-01 731520]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service; D:\WINDOWS\system32\DRIVERS\ar5211.sys [2005-09-14 468768]
S3 WSTCODEC;World Standard Teletext Codec; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 avg8emc;AVG Free8 E-mail Scanner; D:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-04 875288]
S2 avg8wd;AVG Free8 WatchDog; D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-04 231704]
S2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2008-11-19 152984]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 lxbx_device;lxbx_device; D:\WINDOWS\system32\lxbxcoms.exe [2005-01-06 462848]
S4 btwdins;Bluetooth Service; D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-11-11 266295]
S4 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

—————–EOF—————–
Hello and Welcome to the forum.

Run this for your USB drive first:

Download & run this file
http://www.techsupportforum.com/sectools/s…Disinfector.exe

Be sure to insert any flash drives or USB devices that you use.


Dowload this file to your USB drive and copy it to the infected PC.

Unable to access websites


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

NOTE: worksnow is actually Combofix renamed so user is able download and run Combofix

Download worksnow from HERE:


* IMPORTANT !!! Save worksnow to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on worksnow & follow the prompts.

    Note: worksnow will run without the Recovery Console installed.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, combofix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Windows Explorer's Tools –> Folder options is now visible.
In the limited contact with the machine, i've noticed browser pop-up attempts
(as the machine is and will continue to be offline, until you give the go-ahead).

Ran Worksnow (FKA ComboFix), worked :)
It's log is attached along with one from HJT.

ComboFix 09-02-01.01 - Owner 2009-02-02 20:47:27.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3007.2639 [GMT -5:00]

Running from: D:\worksnow.exe
Command switches used :: worksnow.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\c.cgm
d:\documents and settings\Owner\lsass.exe
d:\program files\Microsoft Common
d:\program files\Microsoft Common\svchost.exe
d:\program files\Mozilla Firefox\setupapi.dll
d:\windows\9129837.exe
d:\windows\new_drv.sys
d:\windows\system32\apdxsybk.ini
d:\windows\system32\bbapkjgl.ini
d:\windows\system32\blswwvhl.dll
d:\windows\system32\cillvg.dll
d:\windows\system32\drivers\TDSSmaxt.sys
d:\windows\system32\iavdktpe.dll
d:\windows\system32\kbysxdpa.dll
d:\windows\system32\lgjkpabb.dll
d:\windows\system32\mlcxtorm.dll
d:\windows\system32\nnnnNEut.dll
d:\windows\system32\nvaux32.dll
d:\windows\system32\pac.txt
d:\windows\system32\rolwnd.dll
d:\windows\system32\svschost.exe
d:\windows\system32\TDSScfum.dll
d:\windows\system32\TDSSlxwp.dll
d:\windows\system32\TDSSnmxh.log
d:\windows\system32\TDSSnrsr.dll
d:\windows\system32\TDSSofxh.dll
d:\windows\system32\TDSSosvd.dat
d:\windows\system32\TDSSrhym.log
d:\windows\system32\TDSSriqp.dll
d:\windows\system32\TDSSsihl.dll
d:\windows\system32\TDSStkdv.log
d:\windows\system32\tjtwbp.dll
d:\windows\system32\tuENnnnn.ini
d:\windows\system32\tuENnnnn.ini2
d:\windows\Tasks\bdmiqanb.job
F:\autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_TDSSserv.sys
——-\Legacy_TDSSserv.sys
——-\Legacy_new_drv
——-\Service_new_drv


((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.

2009-02-02 20:40 . 2009-02-02 20:27 3,307,596 -ra—— D:\worksnow.exe
2009-02-01 19:27 . 2009-02-01 19:27 d——– d:\documents and settings\Owner\Application Data\uTorrent
2009-01-26 21:27 . 2009-02-02 20:53 93,420 –a—— d:\windows\system32\drivers\25a59eb3.sys
2009-01-26 21:25 . 2009-01-26 21:25 53,248 –a—— d:\windows\system32\khfGyWoM.dll
2009-01-25 21:00 . 2009-01-25 21:00 d——– d:\windows\system32\LogFiles
2009-01-25 20:33 . 2009-01-25 20:33 134,144 –a—— d:\windows\oyuqoseje.dll
2009-01-25 20:24 . 2009-01-25 20:24 88,576 –a—— d:\windows\system32\svñshost.exe
2009-01-25 20:22 . 2009-02-02 20:53 93,420 –a—— d:\windows\system32\drivers\c907d39.sys
2009-01-25 20:22 . 2009-01-25 20:22 0 –a—— d:\windows\mqcd.dbt
2009-01-25 20:21 . 2009-01-26 21:25 d——– d:\windows\system32\m3V02
2009-01-25 20:21 . 2009-01-25 20:21 578,560 –a–c— d:\windows\system32\dllcache\user32.dll
2009-01-25 20:21 . 2009-01-25 20:21 376,832 –a—— d:\documents and settings\Owner\Application Data\msiexec.exe
2009-01-25 20:21 . 2009-01-25 20:21 143,360 –a—— d:\windows\system32\azton.mt
2009-01-25 20:21 . 2009-01-25 20:21 77,312 –a—— d:\windows\system32\f3g.e
2009-01-25 20:21 . 2009-01-25 20:21 47,616 –a—— d:\windows\system32\pmnnmjgE.dll
2009-01-25 20:21 . 2009-01-25 20:21 41,984 –a—— d:\windows\Inoyoxeb.dll
2009-01-25 20:21 . 2009-01-25 20:21 32,768 –a—— d:\windows\system32\zd.zag
2009-01-25 20:21 . 2009-01-25 20:21 32,768 –a—— d:\windows\system32\f2djq.as
2009-01-25 20:21 . 2009-01-25 20:21 28,672 –a—— d:\windows\system32\do8d.sr
2009-01-25 20:21 . 2009-01-25 20:21 28,672 –a—— d:\windows\system32\dedwf.lp
2009-01-25 20:21 . 2009-01-25 20:21 15,000 –a—— d:\windows\system32\hgdfeeeh4fdg.dll
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\system32\scripting
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\system32\en
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\system32\bits
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\l2schemas
2009-01-14 13:40 . 2009-01-14 13:40 d——– d:\windows\ServicePackFiles
2009-01-14 11:00 . 2009-01-14 11:17 d——– D:\ComdsfboFix
2009-01-13 22:26 . 2009-02-01 20:01 d——– D:\rsit
2009-01-13 22:26 . 2009-01-13 22:26 d——– d:\program files\trend micro
2009-01-13 22:00 . 2009-02-01 19:39 d——– d:\program files\Malwarebytes' Anti-Malware
2009-01-07 23:24 . 2009-01-08 00:03 d——– d:\program files\gjhgfhfjh
2009-01-07 23:24 . 2009-01-04 18:39 38,496 –a—— d:\windows\system32\drivers\mbamswissarmy.sys
2009-01-07 23:24 . 2009-01-04 18:39 15,504 –a—— d:\windows\system32\drivers\mbam.sys
2009-01-06 21:15 . 2009-02-01 19:47 d——– D:\matt
2009-01-06 21:15 . 2009-02-01 20:01 d——– D:\HJT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 15:20 ——— d—–w d:\documents and settings\All Users\Application Data\avg8
2009-01-05 16:40 ——— d—–w d:\program files\Lx_cats
2008-12-19 14:12 ——— d—–w d:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-19 13:53 ——— d—–w d:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-14 00:30 ——— d—–w d:\documents and settings\Administrator\Application Data\7100Series
2008-12-11 10:57 333,952 —-a-w d:\windows\system32\drivers\srv.sys
2008-11-19 20:34 60,744 —-a-w d:\documents and settings\Owner\g2mdlhlpx.exe
2008-11-11 22:49 2,663 —-a-w d:\documents and settings\Owner\index.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}]
2009-01-25 20:21 47616 –a—— d:\windows\system32\pmnnmjgE.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5bf49a2-94f3-42bd-f434-3604812c8955}]
2009-01-25 20:21 15000 –a—— d:\windows\system32\hgdfeeeh4fdg.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="d:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"LXBXCATS"="d:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-11-02 69632]
"lxbxmon.exe"="d:\program files\Lexmark 7100 Series\lxbxmon.exe" [2005-01-18 196608]
"FaxCenterServer4_in_1"="d:\program files\Lexmark 7100 Series\fm3032.exe" [2004-12-06 286720]
"EzPrint"="d:\program files\Lexmark 7100 Series\ezprint.exe" [2004-09-17 61440]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{C5BF49A2-94F3-42BD-F434-3604812C8955}"= "d:\windows\system32\hgdfeeeh4fdg.dll" [2009-01-25 15000]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= "d:\windows\system32\pmnnmjgE.dll" [2009-01-25 47616]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnmjgE]
2009-01-25 20:21 47616 d:\windows\system32\pmnnmjgE.dll

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=d:\windows\pss\Bluetooth.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 19:12 15360 d:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-13 19:12 1695232 d:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-08-23 17:15 8478720 d:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-08-23 17:15 81920 d:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
–a—— 2007-09-14 18:29 102400 d:\program files\Synaptics\SynTP\SynTPStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-08-23 17:15 1626112 d:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"btwdins"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"d:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;d:\windows\system32\drivers\avgldx86.sys [2008-10-04 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;d:\progra~1\AVG\AVG8\avgemc.exe [2008-10-04 875288]
R2 avg8wd;AVG Free8 WatchDog;d:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-04 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;d:\windows\system32\drivers\avgtdix.sys [2008-10-04 76040]
S1 19954aae;19954aae;d:\windows\system32\drivers\19954aae.sys –> d:\windows\system32\drivers\19954aae.sys [?]
S1 df32559;df32559;d:\windows\system32\drivers\df32559.sys –> d:\windows\system32\drivers\df32559.sys [?]
S1 ea8ac7b6;ea8ac7b6;d:\windows\system32\drivers\ea8ac7b6.sys –> d:\windows\system32\drivers\ea8ac7b6.sys [?]
S1 streamm;streamm;d:\windows\system32\drivers\streamm.sys –> d:\windows\system32\drivers\streamm.sys [?]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;d:\windows\system32\drivers\ar5211.sys [2008-08-31 468768]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{27fb5c44-7a74-11dd-9e9a-001e68c6e09b}]
\shell\auto\command - F:\Start.exe
\shell\autorun\command - d:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - d:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - d:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vuyfwylj.default\
FF - component: d:\program files\AVG\AVG8\Firefox\components\avgssff.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-02 20:53:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBXCATS = rundll32 d:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\controlset005\Services\25a59eb3]
"ImagePath"="\SystemRoot\System32\drivers\25a59eb3.sys"
–

[HKEY_LOCAL_MACHINE\System\controlset005\Services\c907d39]
"ImagePath"="\SystemRoot\System32\drivers\c907d39.sys"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(408)
d:\windows\system32\pmnnmjgE.dll
.
———————— Other Running Processes ————————
.
d:\program files\Java\jre6\bin\jqs.exe
d:\progra~1\AVG\AVG8\avgrsx.exe
d:\windows\system32\wscntfy.exe
d:\windows\system32\lxbxcoms.exe
.
**************************************************************************
.
Completion time: 2009-02-02 20:55:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-03 01:55:12
ComboFix2.txt 2009-01-14 16:17:03

Pre-Run: 178,865,377,280 bytes free
Post-Run: 178,833,739,776 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=3 Sets=1,2,3,4,5,6
208 — E O F — 2008-12-19 22:35:47

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:01:44 PM, on 2/2/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\WINDOWS\system32\wscntfy.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\Program Files\Lexmark 7100 Series\lxbxmon.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\lxbxcoms.exe
D:\WINDOWS\explorer.exe
D:\Program Files\AVG\AVG8\avgui.exe
D:\HJT\HiJackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\pmnnmjgE.dll
O2 - BHO: D:\WINDOWS\system32\hgdfeeeh4fdg.dll - {c5bf49a2-94f3-42bd-f434-3604812c8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "D:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "D:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "D:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: pmnnmjgE - D:\WINDOWS\SYSTEM32\pmnnmjgE.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\hgdfeeeh4fdg.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - D:\WINDOWS\system32\lxbxcoms.exe

–
End of file - 3731 bytes
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
d:\windows\system32\drivers\25a59eb3.sys
d:\windows\system32\khfGyWoM.dll
d:\windows\oyuqoseje.dll
d:\windows\system32\svñshost.exe
d:\windows\system32\drivers\c907d39.sys
d:\windows\mqcd.dbt
d:\windows\system32\azton.mt
d:\windows\system32\f3g.e
d:\windows\system32\pmnnmjgE.dll
d:\windows\Inoyoxeb.dll
d:\windows\system32\zd.zag
d:\windows\system32\f2djq.as
d:\windows\system32\do8d.sr
d:\windows\system32\dedwf.lp
d:\windows\system32\hgdfeeeh4fdg.dll
d:\windows\system32\drivers\19954aae.sys
d:\windows\system32\drivers\df32559.sys
d:\windows\system32\drivers\ea8ac7b6.sys 
d:\windows\system32\drivers\streamm.sys
F:\Start.exe
D:\Start.exe

Folder::
d:\program files\gjhgfhfjh

Driver::
25a59eb3
c907d39
19954aae
df32559
ea8ac7b6
streamm

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5bf49a2-94f3-42bd-f434-3604812c8955}]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{C5BF49A2-94F3-42BD-F434-3604812C8955}"=-
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnmjgE]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{27fb5c44-7a74-11dd-9e9a-001e68c6e09b}]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Here's the log files, ComboFix's log, then HJT

Also, I wasn't sure if you wanted me to run MalwareByte's Anti-Malware.
So, I only performed a scan with it. Here's that log too.

I'm still keeping the machine disconnected from my network.
Though I haven't seen any browser pop-up attempts.

ComboFix 09-02-01.01 - Owner 2009-02-03 10:31:55.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3007.2637 [GMT -5:00]
Running from: D:\worksnow.exe
Command switches used :: D:\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated)
* Created a new restore point

FILE ::
D:\Start.exe
d:\windows\Inoyoxeb.dll
d:\windows\mqcd.dbt
d:\windows\oyuqoseje.dll
d:\windows\system32\azton.mt
d:\windows\system32\dedwf.lp
d:\windows\system32\do8d.sr
d:\windows\system32\drivers\19954aae.sys
d:\windows\system32\drivers\25a59eb3.sys
d:\windows\system32\drivers\c907d39.sys
d:\windows\system32\drivers\df32559.sys
d:\windows\system32\drivers\ea8ac7b6.sys
d:\windows\system32\drivers\streamm.sys
d:\windows\system32\f2djq.as
d:\windows\system32\f3g.e
d:\windows\system32\hgdfeeeh4fdg.dll
d:\windows\system32\khfGyWoM.dll
d:\windows\system32\pmnnmjgE.dll
d:\windows\system32\svñshost.exe
d:\windows\system32\zd.zag
F:\Start.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\program files\gjhgfhfjh
d:\program files\gjhgfhfjh\changes.rtf
d:\program files\gjhgfhfjh\is-AECEQ.tmp
d:\program files\gjhgfhfjh\Languages\albanian.lng
d:\program files\gjhgfhfjh\Languages\bulgarian.lng
d:\program files\gjhgfhfjh\Languages\catalan.lng
d:\program files\gjhgfhfjh\Languages\chineseSI.lng
d:\program files\gjhgfhfjh\Languages\chineseTR.lng
d:\program files\gjhgfhfjh\Languages\croatian.lng
d:\program files\gjhgfhfjh\Languages\czech.lng
d:\program files\gjhgfhfjh\Languages\danish.lng
d:\program files\gjhgfhfjh\Languages\dutch.lng
d:\program files\gjhgfhfjh\Languages\english.lng
d:\program files\gjhgfhfjh\Languages\finnish.lng
d:\program files\gjhgfhfjh\Languages\french.lng
d:\program files\gjhgfhfjh\Languages\german.lng
d:\program files\gjhgfhfjh\Languages\greek.lng
d:\program files\gjhgfhfjh\Languages\hungarian.lng
d:\program files\gjhgfhfjh\Languages\italian.lng
d:\program files\gjhgfhfjh\Languages\latvian.lng
d:\program files\gjhgfhfjh\Languages\macedonian.lng
d:\program files\gjhgfhfjh\Languages\norwegian.lng
d:\program files\gjhgfhfjh\Languages\polish.lng
d:\program files\gjhgfhfjh\Languages\portugueseBR.lng
d:\program files\gjhgfhfjh\Languages\portuguesePT.lng
d:\program files\gjhgfhfjh\Languages\romanian.lng
d:\program files\gjhgfhfjh\Languages\russian.lng
d:\program files\gjhgfhfjh\Languages\serbian.lng
d:\program files\gjhgfhfjh\Languages\slovak.lng
d:\program files\gjhgfhfjh\Languages\slovenian.lng
d:\program files\gjhgfhfjh\Languages\spanish.lng
d:\program files\gjhgfhfjh\Languages\swedish.lng
d:\program files\gjhgfhfjh\Languages\turkish.lng
d:\program files\gjhgfhfjh\Languages\ukrainian.lng
d:\program files\gjhgfhfjh\license.txt
d:\program files\gjhgfhfjh\mbam-dor.exe
d:\program files\gjhgfhfjh\mbam.chm
d:\program files\gjhgfhfjh\mbam.dll
d:\program files\gjhgfhfjh\mbamext.dll
d:\program files\gjhgfhfjh\mbamgui.exe
d:\program files\gjhgfhfjh\mbamservice.exe
d:\program files\gjhgfhfjh\somethingrandom.exe
d:\program files\gjhgfhfjh\ssubtmr6.dll
d:\program files\gjhgfhfjh\unins000.dat
d:\program files\gjhgfhfjh\unins000.exe
d:\program files\gjhgfhfjh\unins000.msg
d:\program files\gjhgfhfjh\vbalsgrid6.ocx
d:\program files\gjhgfhfjh\zlib.dll
d:\windows\Inoyoxeb.dll
d:\windows\mqcd.dbt
d:\windows\oyuqoseje.dll
d:\windows\system32\azton.mt
d:\windows\system32\dedwf.lp
d:\windows\system32\do8d.sr
d:\windows\system32\drivers\25a59eb3.sys
d:\windows\system32\drivers\c907d39.sys
d:\windows\system32\f2djq.as
d:\windows\system32\f3g.e
d:\windows\system32\hgdfeeeh4fdg.dll
d:\windows\system32\khfGyWoM.dll
d:\windows\system32\pmnnmjgE.dll
d:\windows\system32\svñshost.exe
d:\windows\system32\zd.zag

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_streamm
——-\Service_19954aae
——-\Service_25a59eb3
——-\Service_c907d39
——-\Service_df32559
——-\Service_ea8ac7b6
——-\Service_streamm


((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.

2009-02-02 20:40 . 2009-02-02 20:27 3,307,596 -ra—— D:\worksnow.exe
2009-02-01 19:27 . 2009-02-01 19:27 d——– d:\documents and settings\Owner\Application Data\uTorrent
2009-01-25 21:00 . 2009-01-25 21:00 d——– d:\windows\system32\LogFiles
2009-01-25 20:21 . 2009-01-26 21:25 d——– d:\windows\system32\m3V02
2009-01-25 20:21 . 2009-01-25 20:21 578,560 –a–c— d:\windows\system32\dllcache\user32.dll
2009-01-25 20:21 . 2009-01-25 20:21 376,832 –a—— d:\documents and settings\Owner\Application Data\msiexec.exe
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\system32\scripting
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\system32\en
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\system32\bits
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\l2schemas
2009-01-14 13:40 . 2009-01-14 13:40 d——– d:\windows\ServicePackFiles
2009-01-14 11:00 . 2009-01-14 11:17 d——– D:\ComdsfboFix
2009-01-13 22:26 . 2009-02-01 20:01 d——– D:\rsit
2009-01-13 22:26 . 2009-01-13 22:26 d——– d:\program files\trend micro
2009-01-13 22:00 . 2009-02-01 19:39 d——– d:\program files\Malwarebytes' Anti-Malware
2009-01-07 23:24 . 2009-01-04 18:39 38,496 –a—— d:\windows\system32\drivers\mbamswissarmy.sys
2009-01-07 23:24 . 2009-01-04 18:39 15,504 –a—— d:\windows\system32\drivers\mbam.sys
2009-01-06 21:15 . 2009-02-01 19:47 d——– D:\matt
2009-01-06 21:15 . 2009-02-02 21:02 d——– D:\HJT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 15:20 ——— d—–w d:\documents and settings\All Users\Application Data\avg8
2009-01-05 16:40 ——— d—–w d:\program files\Lx_cats
2008-12-19 14:12 ——— d—–w d:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-19 13:53 ——— d—–w d:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-14 00:30 ——— d—–w d:\documents and settings\Administrator\Application Data\7100Series
2008-12-11 10:57 333,952 —-a-w d:\windows\system32\drivers\srv.sys
2008-11-19 20:34 60,744 —-a-w d:\documents and settings\Owner\g2mdlhlpx.exe
2008-11-11 22:49 2,663 —-a-w d:\documents and settings\Owner\index.exe
.

((((((((((((((((((((((((((((( snapshot@2009-02-02_20.54.32.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-03 01:50:44 61,020 —-a-w d:\windows\system32\perfc009.dat
+ 2009-02-03 15:39:31 61,020 —-a-w d:\windows\system32\perfc009.dat
- 2009-02-03 01:50:44 400,940 —-a-w d:\windows\system32\perfh009.dat
+ 2009-02-03 15:39:31 400,940 —-a-w d:\windows\system32\perfh009.dat
+ 2009-02-03 15:35:27 16,384 —-atw d:\windows\Temp\Perflib_Perfdata_440.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="d:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"LXBXCATS"="d:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-11-02 69632]
"lxbxmon.exe"="d:\program files\Lexmark 7100 Series\lxbxmon.exe" [2005-01-18 196608]
"FaxCenterServer4_in_1"="d:\program files\Lexmark 7100 Series\fm3032.exe" [2004-12-06 286720]
"EzPrint"="d:\program files\Lexmark 7100 Series\ezprint.exe" [2004-09-17 61440]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=d:\windows\pss\Bluetooth.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 19:12 15360 d:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-13 19:12 1695232 d:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-08-23 17:15 8478720 d:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-08-23 17:15 81920 d:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
–a—— 2007-09-14 18:29 102400 d:\program files\Synaptics\SynTP\SynTPStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-08-23 17:15 1626112 d:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"btwdins"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"d:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;d:\windows\system32\drivers\avgldx86.sys [2008-10-04 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;d:\progra~1\AVG\AVG8\avgemc.exe [2008-10-04 875288]
R2 avg8wd;AVG Free8 WatchDog;d:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-04 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;d:\windows\system32\drivers\avgtdix.sys [2008-10-04 76040]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;d:\windows\system32\drivers\ar5211.sys [2008-08-31 468768]
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - d:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - d:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vuyfwylj.default\
FF - component: d:\program files\AVG\AVG8\Firefox\components\avgssff.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-03 10:40:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBXCATS = rundll32 d:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
d:\program files\Java\jre6\bin\jqs.exe
d:\progra~1\AVG\AVG8\avgrsx.exe
d:\windows\system32\wscntfy.exe
d:\windows\system32\lxbxcoms.exe
.
**************************************************************************
.
Completion time: 2009-02-03 10:42:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-03 15:42:16
ComboFix2.txt 2009-02-03 01:55:17
ComboFix3.txt 2009-01-14 16:17:03

Pre-Run: 178,849,300,480 bytes free
Post-Run: 178,824,462,336 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=3 Sets=1,2,3,4,5,6
228 — E O F — 2008-12-19 22:35:47


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:57:48 AM, on 2/3/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\WINDOWS\system32\wscntfy.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\Program Files\Lexmark 7100 Series\lxbxmon.exe
D:\WINDOWS\system32\lxbxcoms.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\notepad.exe
D:\HJT\HiJackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "D:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "D:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "D:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - D:\WINDOWS\system32\lxbxcoms.exe

–
End of file - 3306 bytes



Malwarebytes' Anti-Malware 1.32
Database version: 1616
Windows 5.1.2600 Service Pack 3

2/3/2009 11:32:15 AM
mbam-log-2009-02-03 (11-29-03).txt


Scan type: Full Scan (C:\|D:\|)
Objects scanned: 76457
Time elapsed: 12 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Documents and Settings\Owner\Application Data\msiexec.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\new_drv.sys.vir (Rootkit.Agent) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002207.sys (Rootkit.Agent) -> No action taken.
D:\Qoobox\Quarantine\D\Program Files\Mozilla Firefox\setupapi.dll.vir (Spyware.Passwords) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002205.dll (Spyware.Passwords) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSnrsr.dll.vir (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002185.dll (Trojan.TDSS) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSofxh.dll.vir (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002184.dll (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002186.dll (Trojan.TDSS) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSriqp.dll.vir (Trojan.TDSS) -> No action taken.
C:\bkha.exe (Trojan.TinyDownloader705) -> No action taken.
C:\asyoclq.exe (Trojan.TinyDownloader705) -> No action taken.
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\asyoclq.exe
C:\bkha.exe
D:\Documents and Settings\Owner\Application Data\msiexec.exe

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Re worksnow /combofix with you new cfscript, log attached
HJT log attached.
mbam's "scan only" log attached.

out of curiousity, is there any reason why you're not having me use mbam to remove the detected infections?

ComboFix 09-02-01.01 - Owner 2009-02-03 17:23:24.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3007.2598 [GMT -5:00]
Running from: D:\worksnow.exe
Command switches used :: D:\CFScript-2.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated)
* Created a new restore point


FILE ::
C:\asyoclq.exe
C:\bkha.exe
d:\documents and settings\Owner\Application Data\msiexec.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\asyoclq.exe
C:\bkha.exe
d:\documents and settings\Owner\Application Data\msiexec.exe

.
((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.

2009-02-02 20:40 . 2009-02-02 20:27 3,307,596 -ra—— D:\worksnow.exe
2009-02-01 19:27 . 2009-02-01 19:27 d——– d:\documents and settings\Owner\Application Data\uTorrent
2009-01-25 21:00 . 2009-01-25 21:00 d——– d:\windows\system32\LogFiles
2009-01-25 20:21 . 2009-01-26 21:25 d——– d:\windows\system32\m3V02
2009-01-25 20:21 . 2009-01-25 20:21 578,560 –a–c— d:\windows\system32\dllcache\user32.dll
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\system32\scripting
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\system32\en
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\system32\bits
2009-01-14 13:43 . 2009-01-14 13:43 d——– d:\windows\l2schemas
2009-01-14 13:40 . 2009-01-14 13:40 d——– d:\windows\ServicePackFiles
2009-01-14 11:00 . 2009-01-14 11:17 d——– D:\ComdsfboFix
2009-01-13 22:26 . 2009-02-01 20:01 d——– D:\rsit
2009-01-13 22:26 . 2009-01-13 22:26 d——– d:\program files\trend micro
2009-01-13 22:00 . 2009-02-01 19:39 d——– d:\program files\Malwarebytes' Anti-Malware
2009-01-07 23:24 . 2009-01-04 18:39 38,496 –a—— d:\windows\system32\drivers\mbamswissarmy.sys
2009-01-07 23:24 . 2009-01-04 18:39 15,504 –a—— d:\windows\system32\drivers\mbam.sys
2009-01-06 21:15 . 2009-02-01 19:47 d——– D:\matt
2009-01-06 21:15 . 2009-02-03 10:57 d——– D:\HJT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 15:20 ——— d—–w d:\documents and settings\All Users\Application Data\avg8
2009-01-05 16:40 ——— d—–w d:\program files\Lx_cats
2008-12-19 14:12 ——— d—–w d:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-19 13:53 ——— d—–w d:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-14 00:30 ——— d—–w d:\documents and settings\Administrator\Application Data\7100Series
2008-12-11 10:57 333,952 —-a-w d:\windows\system32\drivers\srv.sys
2008-11-19 20:34 60,744 —-a-w d:\documents and settings\Owner\g2mdlhlpx.exe
2008-11-19 20:29 410,976 —-a-w d:\windows\system32\deploytk.dll
2008-11-11 22:49 2,663 —-a-w d:\documents and settings\Owner\index.exe
.

((((((((((((((((((((((((((((( snapshot@2009-02-02_20.54.32.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-03 01:50:44 61,020 —-a-w d:\windows\system32\perfc009.dat
+ 2009-02-03 16:13:27 61,020 —-a-w d:\windows\system32\perfc009.dat
- 2009-02-03 01:50:44 400,940 —-a-w d:\windows\system32\perfh009.dat
+ 2009-02-03 16:13:27 400,940 —-a-w d:\windows\system32\perfh009.dat
+ 2009-02-03 22:21:49 16,384 —-atw d:\windows\Temp\Perflib_Perfdata_454.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="d:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"LXBXCATS"="d:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-11-02 69632]
"lxbxmon.exe"="d:\program files\Lexmark 7100 Series\lxbxmon.exe" [2005-01-18 196608]
"FaxCenterServer4_in_1"="d:\program files\Lexmark 7100 Series\fm3032.exe" [2004-12-06 286720]
"EzPrint"="d:\program files\Lexmark 7100 Series\ezprint.exe" [2004-09-17 61440]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=d:\windows\pss\Bluetooth.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 19:12 15360 d:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-13 19:12 1695232 d:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-08-23 17:15 8478720 d:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-08-23 17:15 81920 d:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
–a—— 2007-09-14 18:29 102400 d:\program files\Synaptics\SynTP\SynTPStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-08-23 17:15 1626112 d:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"btwdins"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"d:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;d:\windows\system32\drivers\avgldx86.sys [2008-10-04 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;d:\progra~1\AVG\AVG8\avgemc.exe [2008-10-04 875288]
R2 avg8wd;AVG Free8 WatchDog;d:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-04 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;d:\windows\system32\drivers\avgtdix.sys [2008-10-04 76040]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;d:\windows\system32\drivers\ar5211.sys [2008-08-31 468768]
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - d:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - d:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\vuyfwylj.default\
FF - component: d:\program files\AVG\AVG8\Firefox\components\avgssff.dll

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-03 17:24:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBXCATS = rundll32 d:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-03 17:25:25
ComboFix-quarantined-files.txt 2009-02-03 22:25:23
ComboFix2.txt 2009-02-03 15:42:20
ComboFix3.txt 2009-02-03 01:55:17
ComboFix4.txt 2009-01-14 16:17:03

Pre-Run: 178,817,138,688 bytes free
Post-Run: 178,797,961,216 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=3 Sets=1,2,3,4,5,6
133 — E O F — 2008-12-19 22:35:47

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:27:29 PM, on 2/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal


Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\svchost.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
D:\Program Files\Lexmark 7100 Series\lxbxmon.exe
D:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\lxbxcoms.exe
D:\WINDOWS\system32\imapi.exe
D:\WINDOWS\explorer.exe
D:\HJT\HiJackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "D:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "D:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "D:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - D:\WINDOWS\system32\lxbxcoms.exe

–
End of file - 3303 bytes

Malwarebytes' Anti-Malware 1.32
Database version: 1616
Windows 5.1.2600 Service Pack 3


2/3/2009 5:41:23 PM
mbam-log-pass3

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 76441
Time elapsed: 11 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP4\A0002411.exe (Trojan.TinyDownloader705) -> No action taken.
C:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP4\A0002412.exe (Trojan.TinyDownloader705) -> No action taken.
D:\Qoobox\Quarantine\C\asyoclq.exe.vir (Trojan.TinyDownloader705) -> No action taken.
D:\Qoobox\Quarantine\C\bkha.exe.vir (Trojan.TinyDownloader705) -> No action taken.
D:\Qoobox\Quarantine\D\Program Files\Mozilla Firefox\setupapi.dll.vir (Spyware.Passwords) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\new_drv.sys.vir (Rootkit.Agent) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSnrsr.dll.vir (Trojan.TDSS) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSofxh.dll.vir (Trojan.TDSS) -> No action taken.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSriqp.dll.vir (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002184.dll (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002185.dll (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002186.dll (Trojan.TDSS) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002205.dll (Spyware.Passwords) -> No action taken.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002207.sys (Rootkit.Agent) -> No action taken.
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type D:\worksnow /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

Now run MBAM

Be sure that everything is checked, and click Remove Selected .

Post the results
Seems I misplaced the log files of mbam for the file-removal scan.
Suffice it to say, the files were deleted. After rebooting, I ran a full scan, which found no infected files.

I updated AVG 8's virus definitions and performed a fullscan, which found and auto-healed some files.
After a reboot, I did another scan with AVG8 for paranoia's sake, which came back clean :)

I've since purchased a license key for SpywareBlaster and enabled all of it's security features.

Thanks for helping me once again! :notworthy:


Just found the mbam-log:

Malwarebytes' Anti-Malware 1.32
Database version: 1616
Windows 5.1.2600 Service Pack 3


2/3/2009 6:12:28 PM
mbam-log-2009-02-03 (18-12-28).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 76460
Time elapsed: 11 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP4\A0002411.exe (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP4\A0002412.exe (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\C\asyoclq.exe.vir (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\C\bkha.exe.vir (Trojan.TinyDownloader705) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\D\Program Files\Mozilla Firefox\setupapi.dll.vir (Spyware.Passwords) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\D\WINDOWS\new_drv.sys.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSnrsr.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSofxh.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\Qoobox\Quarantine\D\WINDOWS\system32\TDSSriqp.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002184.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002185.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002186.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002205.dll (Spyware.Passwords) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{36195952-3AE4-4A82-8564-84856B106AEC}\RP2\A0002207.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
You can remove these files and folders if listed:
C:\ComboFix
D:\Qoobox
C:\combofix.txt
C:\combofix-quarantine-files.txt

Be sure to check the D: drive as well for these.


Note: This will remove all previous Restore Points

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI