Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

trojan vundo infection


  • This topic is locked This topic is locked
10 replies to this topic

#1 daz1

daz1

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:10:37 AM

Posted 04 November 2008 - 04:42 PM

Hi,

My avg security detected a trojan called vundo al. a couple of days ago and after running the various scans recommended in the forum (other than bit defender as it kept saying cannot update virus definitions and wouldnt run) avg is no longer detecting it. However, my pc remains very sluggish so im wondering if there could still be a problem that avg isnt detecting. When i boot up and the desktop first appears the icons are all white then slowly get their various pictures whereas before this was instant. Also web pages are loading more slowly. Here is the hijackthis log for anyone who maybe able to help me thanks.
Sorry in advance if i havent followed site etiquette properly and thanks in advance for any help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:27:04, on 04/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
G:\WINDOWS\system32\spoolsv.exe
G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
G:\PROGRA~1\AVG\AVG8\avgfws8.exe
G:\WINDOWS\system32\IoctlSvc.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\SearchIndexer.exe
G:\WINDOWS\Explorer.EXE
G:\PROGRA~1\AVG\AVG8\avgam.exe
G:\PROGRA~1\AVG\AVG8\avgrsx.exe
G:\PROGRA~1\AVG\AVG8\avgnsx.exe
G:\PROGRA~1\AVG\AVG8\avgtray.exe
G:\WINDOWS\system32\igfxtray.exe
G:\PROGRA~1\AVG\AVG8\avgemc.exe
G:\WINDOWS\system32\hkcmd.exe
G:\WINDOWS\system32\igfxpers.exe
G:\WINDOWS\system32\igfxsrvc.exe
G:\WINDOWS\RTHDCPL.EXE
G:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
G:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
G:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
G:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDCountdown.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
G:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
G:\Program Files\TomTom HOME 2\HOMERunner.exe
G:\Program Files\Windows Desktop Search\WindowsSearch.exe
G:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
G:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
G:\Program Files\Internet Explorer\iexplore.exe
G:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
G:\Program Files\Pool Sharks\Starter.exe
G:\Program Files\Trend Micro\HijackThis\HijackThis.exe
G:\WINDOWS\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - G:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] G:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [IgfxTray] G:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] G:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] G:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] "G:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "G:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "G:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "G:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] G:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] G:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "G:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Search.lnk = G:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1224410992031
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - G:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: fccaArQk - G:\WINDOWS\
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: NBService - Nero AG - G:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - G:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - G:\WINDOWS\system32\IoctlSvc.exe

--
End of file - 7420 bytes

BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:37 AM

Posted 05 November 2008 - 10:52 AM

Hello daz1,

Posted Image

I notice that you have Spybot's TeaTimer running. While this is normally a wonderful tool to protect against hijackers, it can also interfere with the fixes. So please disable TeaTimer by doing the following:
1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts

You can reenable TeaTimer once your system is clean.

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 daz1

daz1
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:10:37 AM

Posted 05 November 2008 - 02:15 PM

hi tea thanks for your attention here are the logs you requested for combofix and hijackthis

ComboFix 08-11-04.02 - darren 2008-11-05 19:04:14.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1510 [GMT 0:00]
Running from: g:\documents and settings\darren\Desktop\ComboFix.exe
* Resident AV is active

.

((((((((((((((((((((((((( Files Created from 2008-10-05 to 2008-11-05 )))))))))))))))))))))))))))))))
.

2008-11-04 22:42 . 2008-11-04 22:42 <DIR> d-------- g:\windows\ERUNT
2008-11-04 22:39 . 2008-11-04 22:46 <DIR> d-------- G:\SDFix
2008-11-04 21:14 . 2008-11-04 21:19 <DIR> d-------- g:\windows\BDOSCAN8
2008-11-04 20:47 . 2008-11-04 20:47 <DIR> d-------- g:\program files\Panda Security
2008-11-04 20:47 . 2008-06-19 17:24 28,544 --a------ g:\windows\system32\drivers\pavboot.sys
2008-11-04 20:04 . 2008-11-04 20:42 <DIR> d-------- g:\documents and settings\darren\.housecall6.6
2008-11-04 18:31 . 2008-11-04 18:31 <DIR> d-------- G:\VundoFix Backups
2008-11-03 19:22 . 2008-11-03 19:22 <DIR> d-------- g:\program files\Trend Micro
2008-11-01 16:23 . 2008-11-01 16:23 <DIR> d-------- g:\documents and settings\darren\LocalLow
2008-11-01 13:39 . 2008-11-01 13:39 <DIR> d-------- g:\program files\Support Tools
2008-10-31 18:23 . 2004-03-09 00:00 1,081,616 --a------ g:\windows\system32\MSCOMCTL.OCX
2008-10-31 18:19 . 2008-10-31 18:19 <DIR> d-------- g:\documents and settings\darren\Application Data\Serif
2008-10-31 18:17 . 2008-10-31 18:17 <DIR> d-------- g:\program files\Serif
2008-10-30 21:28 . 2008-10-30 21:28 <DIR> d-------- g:\program files\TomTom HOME 2
2008-10-30 21:28 . 2008-10-30 21:28 <DIR> d-------- g:\documents and settings\darren\Application Data\TomTom
2008-10-30 21:11 . 2008-10-30 21:28 <DIR> d-------- g:\program files\TomTom HOME
2008-10-29 22:43 . 2008-05-14 08:34 1,000,744 --a------ g:\windows\system32\ShellManager10E2D762.dll
2008-10-29 22:43 . 2008-04-10 18:52 648,192 --a------ g:\windows\system32\NEROINSTAEC43759.DB
2008-10-28 22:22 . 2008-01-22 12:28 148,776 --a------ g:\windows\system32\ImageDrive.cpl
2008-10-27 19:50 . 2008-10-27 19:52 <DIR> d-------- g:\program files\Enigma Software Group
2008-10-26 20:26 . 2008-11-04 20:44 <DIR> d-------- g:\program files\a-squared Free
2008-10-26 10:58 . 2008-10-26 10:58 <DIR> d-------- g:\documents and settings\darren\Application Data\Canon
2008-10-25 17:07 . 2008-11-04 22:49 <DIR> d-a------ g:\documents and settings\All Users\Application Data\TEMP
2008-10-25 16:07 . 2008-10-25 16:09 <DIR> d-------- g:\documents and settings\darren\Application Data\Simply Super Software
2008-10-25 16:07 . 2006-05-25 14:52 162,304 --a------ g:\windows\system32\ztvunrar36.dll
2008-10-25 16:07 . 2003-02-02 19:06 153,088 --a------ g:\windows\system32\unrar3.dll
2008-10-25 16:07 . 2005-08-26 00:50 77,312 --a------ g:\windows\system32\ztvunace26.dll
2008-10-25 16:07 . 2002-03-06 00:00 75,264 --a------ g:\windows\system32\unacev2.dll
2008-10-25 16:07 . 2006-06-19 12:01 69,632 --a------ g:\windows\system32\ztvcabinet.dll
2008-10-24 19:42 . 2008-10-24 19:42 2,600,220 --a------ g:\windows\system32\SetupAnyDVD6457.exe
2008-10-24 18:03 . 2008-10-24 18:05 24 --ahs---- g:\windows\SA238F1C3.tmp
2008-10-24 17:44 . 2008-10-24 17:44 <DIR> d-------- g:\program files\7-Zip
2008-10-24 17:03 . 2008-10-24 17:03 <DIR> d-------- g:\windows\Sun
2008-10-23 18:55 . 2008-10-26 11:54 <DIR> d-------- g:\program files\ASUS
2008-10-23 18:55 . 2006-01-10 08:50 24,576 -ra------ g:\windows\system32\AsIO.dll
2008-10-23 18:55 . 2006-10-18 19:12 12,664 -ra------ g:\windows\system32\drivers\AsIO.sys
2008-10-23 18:55 . 2008-10-23 19:02 666 --a------ g:\windows\setup.iss
2008-10-23 18:29 . 2008-11-04 20:27 <DIR> d--h----- G:\$AVG8.VAULT$
2008-10-22 18:08 . 2008-10-22 18:08 <DIR> d-------- g:\documents and settings\All Users\Application Data\Ahead
2008-10-22 18:07 . 2008-10-22 18:07 <DIR> d-------- g:\documents and settings\All Users\Application Data\Nero
2008-10-20 21:43 . 2008-10-20 21:43 <DIR> d-------- g:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-20 19:38 . 2008-10-20 19:38 <DIR> d-------- g:\documents and settings\LocalService\Application Data\Ahead
2008-10-20 17:22 . 2007-07-30 18:19 271,224 --a------ g:\windows\system32\mucltui.dll
2008-10-20 17:22 . 2007-07-30 18:19 30,072 --a------ g:\windows\system32\mucltui.dll.mui
2008-10-19 23:07 . 2008-10-19 23:08 <DIR> d-------- g:\program files\Windows Live Safety Center
2008-10-19 22:57 . 2008-10-19 22:57 <DIR> d-------- g:\program files\Messenger Plus! Live
2008-10-19 22:53 . 2008-10-25 14:07 <DIR> d-------- g:\documents and settings\darren\Contacts
2008-10-19 19:21 . 2008-11-01 00:41 116 --a------ g:\windows\NeroDigital.ini
2008-10-19 18:54 . 2008-10-19 18:54 <DIR> d-------- g:\program files\Runtime Software
2008-10-19 16:15 . 2008-10-19 16:15 <DIR> d-------- g:\documents and settings\All Users\Application Data\SlySoft
2008-10-19 15:58 . 2008-10-19 15:58 <DIR> d-------- g:\program files\AskBarDis
2008-10-19 15:58 . 2008-11-02 17:48 <DIR> d-------- g:\documents and settings\darren\Application Data\Azureus
2008-10-19 15:58 . 2008-10-19 15:58 <DIR> d-------- g:\documents and settings\All Users\Application Data\Azureus
2008-10-19 15:57 . 2008-11-02 17:48 <DIR> d-------- g:\program files\Vuze
2008-10-19 15:50 . 2008-11-05 18:53 <DIR> d-------- g:\program files\Spybot - Search & Destroy
2008-10-19 15:50 . 2008-10-19 16:10 <DIR> d-------- g:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-19 15:48 . 2008-10-19 15:48 <DIR> d-------- g:\program files\Lavasoft
2008-10-19 15:48 . 2008-10-19 15:48 <DIR> d-------- g:\documents and settings\All Users\Application Data\Lavasoft
2008-10-19 15:47 . 2008-10-19 15:47 <DIR> d-------- g:\program files\Common Files\Wise Installation Wizard
2008-10-19 14:54 . 2008-10-19 14:54 <DIR> d-------- g:\documents and settings\darren\Application Data\Windows Search
2008-10-19 14:41 . 2008-10-19 14:41 <DIR> d-------- g:\program files\MSXML 4.0
2008-10-19 14:41 . 2008-10-19 14:41 <DIR> d-------- g:\program files\Microsoft CAPICOM 2.1.0.2
2008-10-19 14:37 . 2008-10-19 14:37 <DIR> d-------- g:\documents and settings\darren\Application Data\Simple Star
2008-10-19 14:37 . 2006-05-18 19:20 319,488 --a------ g:\windows\Nero PhotoShow.scr
2008-10-19 14:37 . 2006-03-14 01:49 106,496 --a------ g:\windows\system32\TwnLib20.dll
2008-10-19 14:37 . 2006-03-14 01:49 38,912 --a------ g:\windows\system32\picn20.dll
2008-10-19 14:35 . 2008-10-19 14:35 <DIR> d-------- g:\program files\Common Files\Simple Star Shared
2008-10-19 14:35 . 2008-11-02 19:58 <DIR> d-------- g:\documents and settings\darren\Application Data\Nero
2008-10-19 14:16 . 2008-10-19 14:18 <DIR> d--hsc--- g:\program files\Common Files\WindowsLiveInstaller
2008-10-19 14:15 . 2008-10-19 22:52 <DIR> d-------- g:\program files\Windows Live
2008-10-19 14:15 . 2008-10-19 22:47 <DIR> d-------- g:\documents and settings\All Users\Application Data\WLInstaller
2008-10-19 14:00 . 2008-10-19 14:00 <DIR> d-------- g:\documents and settings\darren\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-10-19 13:59 . 2008-06-10 01:32 73,728 --a------ g:\windows\system32\javacpl.cpl
2008-10-19 13:58 . 2008-10-19 13:59 <DIR> d-------- g:\program files\Java
2008-10-19 13:57 . 2008-10-19 13:57 <DIR> d-------- g:\program files\Common Files\Java
2008-10-19 13:54 . 2008-11-04 20:52 <DIR> d-------- g:\program files\Pool Sharks
2008-10-19 13:49 . 2008-10-19 13:49 <DIR> d-------- g:\windows\system32\Adobe
2008-10-19 13:48 . 2008-10-19 13:48 <DIR> d-------- g:\program files\Common Files\Adobe AIR
2008-10-19 13:47 . 2008-10-19 13:47 <DIR> d-------- g:\program files\Common Files\Adobe
2008-10-19 13:46 . 2008-10-19 15:33 <DIR> d-------- g:\program files\NOS
2008-10-19 13:46 . 2008-10-19 15:33 <DIR> d-------- g:\documents and settings\All Users\Application Data\NOS
2008-10-19 13:41 . 2008-10-19 13:41 <DIR> d-------- g:\program files\Logitech
2008-10-19 13:41 . 2008-10-19 13:41 <DIR> d-------- g:\program files\Common Files\Logitech
2008-10-19 13:30 . 2008-04-13 23:17 25,856 --a------ g:\windows\system32\drivers\usbprint.sys
2008-10-19 13:30 . 2008-04-13 23:17 25,856 --a--c--- g:\windows\system32\dllcache\usbprint.sys
2008-10-19 13:29 . 2008-04-13 23:15 15,104 --a------ g:\windows\system32\drivers\usbscan.sys
2008-10-19 13:29 . 2008-04-13 23:15 15,104 --a--c--- g:\windows\system32\dllcache\usbscan.sys
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\program files\ScanSoft
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\program files\Common Files\ScanSoft Shared
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\documents and settings\darren\Application Data\ScanSoft
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\documents and settings\All Users\Application Data\ScanSoft
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\documents and settings\All Users\Application Data\InstallShield
2008-10-19 13:28 . 2008-10-19 13:28 412 --a------ g:\windows\MAXLINK.INI
2008-10-19 13:25 . 2008-10-19 13:25 <DIR> d--h----- g:\windows\system32\CanonIJ Uninstaller Information
2008-10-19 13:25 . 2008-10-19 13:25 <DIR> d--h----- g:\program files\CanonBJ
2008-10-19 13:25 . 2008-10-19 13:25 <DIR> d--h----- g:\documents and settings\All Users\Application Data\CanonBJ
2008-10-19 13:25 . 2006-11-10 02:00 1,314,816 --a------ g:\windows\system32\CNCC140.DLL
2008-10-19 13:25 . 2006-12-25 20:00 198,656 --a------ g:\windows\system32\CNMLM8R.DLL
2008-10-19 13:25 . 2006-05-26 01:54 135,168 --a------ g:\windows\system32\CNCL140.DLL
2008-10-19 13:25 . 2006-06-29 05:29 106,496 --a------ g:\windows\system32\cnco140.dll
2008-10-19 13:25 . 2006-11-10 01:59 57,344 --a------ g:\windows\system32\CNCI140.DLL
2008-10-19 13:24 . 2008-10-19 13:30 <DIR> d-------- g:\program files\Canon
2008-10-19 13:15 . 2008-10-19 19:08 <DIR> d-------- g:\documents and settings\darren\Application Data\Ahead
2008-10-19 13:13 . 2008-10-22 17:41 <DIR> d-------- g:\program files\Nero
2008-10-19 13:13 . 2008-10-22 18:07 <DIR> d-------- g:\program files\Common Files\Ahead
2008-10-19 10:14 . 2008-10-19 10:14 0 --a------ g:\windows\nsreg.dat
2008-10-19 10:11 . 2008-10-20 17:30 <DIR> d-------- g:\program files\Microsoft Silverlight
2008-10-19 09:47 . 2008-10-19 09:47 <DIR> d-------- g:\windows\system32\GroupPolicy
2008-10-19 09:47 . 2008-10-19 09:47 <DIR> d-------- g:\program files\Windows Desktop Search
2008-10-19 09:47 . 2008-10-19 09:47 <DIR> d-------- g:\documents and settings\darren\Application Data\Windows Desktop Search
2008-10-19 09:46 . 2008-10-19 09:46 <DIR> d-------- g:\program files\Windows Media Connect 2
2008-10-19 09:45 . 2008-10-19 09:45 <DIR> d-------- g:\windows\system32\LogFiles
2008-10-19 09:45 . 2008-10-19 18:42 <DIR> d-------- g:\windows\system32\drivers\UMDF
2008-10-19 09:43 . 2008-10-19 09:43 <DIR> d-------- g:\windows\system32\URTTemp
2008-10-19 09:32 . 2008-10-23 19:04 <DIR> d-------- g:\program files\Marvell
2008-10-19 09:32 . 2008-10-19 09:32 940,794 --a------ g:\windows\system32\LoopyMusic.wav
2008-10-19 09:32 . 2008-10-19 09:32 146,650 --a------ g:\windows\system32\BuzzingBee.wav
2008-10-19 09:30 . 2008-10-19 09:30 <DIR> d-------- g:\windows\system32\RTCOM
2008-10-19 09:30 . 2007-01-30 10:54 16,116,224 -r------- g:\windows\RTHDCPL.exe
2008-10-19 09:30 . 2006-05-04 08:35 9,709,568 -r------- g:\windows\RTLCPL.exe
2008-10-19 09:30 . 2007-01-30 10:57 4,474,368 -r------- g:\windows\system32\drivers\RtkHDAud.sys
2008-10-19 09:30 . 2006-05-16 10:04 2,879,488 -r------- g:\windows\SkyTel.exe
2008-10-19 09:30 . 2007-01-02 05:32 1,191,936 -r------- g:\windows\RtlUpd.exe
2008-10-19 09:30 . 2006-08-17 22:58 282,624 -r------- g:\windows\system32\RTSndMgr.cpl
2008-10-19 09:30 . 2006-07-21 08:14 86,016 -r------- g:\windows\SoundMan.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 18:17 --------- d--h--w g:\program files\InstallShield Installation Information
2008-10-23 18:55 --------- d-----w g:\program files\Common Files\InstallShield
2008-10-19 08:32 21,035 ----a-w g:\windows\system32\drivers\AegisP.sys
2008-10-19 08:31 --------- d-----w g:\program files\NETGEAR
2008-10-19 08:01 --------- d-----w g:\program files\microsoft frontpage
2008-09-15 12:12 1,846,400 ----a-w g:\windows\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w g:\windows\system32\drivers\srv.sys
2008-08-26 07:24 826,368 ----a-w g:\windows\system32\wininet.dll
2008-08-14 10:09 2,145,280 ----a-w g:\windows\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 ----a-w g:\windows\system32\ntkrnlpa.exe
2006-06-23 06:48 32,768 ----a-r g:\windows\inf\UpdateUSB.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "g:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-02 325000]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "g:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-02 325000]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="g:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="g:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"Nero PhotoShow Media Manager"="g:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-05-10 249856]
"TomTomHOME.exe"="g:\program files\TomTom HOME 2\HOMERunner.exe" [2008-09-26 206184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="g:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-23 1235736]
"IgfxTray"="g:\windows\system32\igfxtray.exe" [2007-04-20 142104]
"HotKeysCmds"="g:\windows\system32\hkcmd.exe" [2007-04-20 162584]
"Persistence"="g:\windows\system32\igfxpers.exe" [2007-04-20 138008]
"SSBkgdUpdate"="g:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="g:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Launch LCDMon"="g:\program files\Common Files\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 774168]
"Adobe Reader Speed Launcher"="g:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="g:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NeroFilterCheck"="g:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 g:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 g:\windows\SkyTel.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="g:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

g:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - g:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "g:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccaArQk]
[BU]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"g:\\Program Files\\Messenger\\msmsgs.exe"=
"g:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"g:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 AvgRkx86;avgrkx86.sys;g:\windows\system32\Drivers\avgrkx86.sys [2008-10-19 12936]
R0 pavboot;pavboot;g:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
R1 AvgLdx86;AVG AVI Loader Driver x86;g:\windows\system32\Drivers\avgldx86.sys [2008-10-29 98440]
R1 AvgTdiX;AVG8 Network Redirector;g:\windows\system32\Drivers\avgtdix.sys [2008-11-05 90632]
R2 avg8emc;AVG8 E-mail Scanner;g:\progra~1\AVG\AVG8\avgemc.exe [2008-10-23 874776]
R2 avg8wd;AVG8 WatchDog;g:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-19 231704]
R2 avgfws8;AVG8 Firewall;g:\progra~1\AVG\AVG8\avgfws8.exe [2008-11-05 1212184]
R3 Avgfwdx;Avgfwdx;g:\windows\system32\DRIVERS\avgfwdx.sys [2008-11-05 29208]
S3 ADM8511;%ADM8511.Service.DispName%;g:\windows\system32\DRIVERS\ADM8511.SYS [2001-08-17 20160]
S3 Avgfwfd;AVG network filter service;g:\windows\system32\DRIVERS\avgfwdx.sys [2008-11-05 29208]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;g:\windows\system32\DRIVERS\wg111v2.sys [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc6d6fd7-a6c8-11dd-8b52-001fc669679d}]
\Shell\AutoRun\command - C:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2008-10-19 g:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- g:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-07-07 08:42]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - g:\documents and settings\darren\Application Data\Mozilla\Firefox\Profiles\lazsmmlg.default\
FF -: plugin - g:\documents and settings\darren\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\octoprogram-L03-NMS0810164_SUA_900\npoctoshape.dll
FF -: plugin - g:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - g:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-05 19:05:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-05 19:05:31
ComboFix-quarantined-files.txt 2008-11-05 19:05:29
ComboFix2.txt 2008-11-05 19:01:09
ComboFix3.txt 2008-11-03 22:29:17
ComboFix4.txt 2008-11-02 17:52:37
ComboFix5.txt 2008-11-05 19:03:56

Pre-Run: 483,686,715,392 bytes free
Post-Run: 483,674,460,160 bytes free

240 --- E O F --- 2008-10-23 17:41:06


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:08:40, on 05/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
G:\WINDOWS\system32\spoolsv.exe
G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
G:\PROGRA~1\AVG\AVG8\avgfws8.exe
G:\WINDOWS\system32\IoctlSvc.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\igfxtray.exe
G:\WINDOWS\system32\hkcmd.exe
G:\WINDOWS\system32\igfxpers.exe
G:\WINDOWS\RTHDCPL.EXE
G:\WINDOWS\system32\igfxsrvc.exe
G:\PROGRA~1\AVG\AVG8\avgam.exe
G:\PROGRA~1\AVG\AVG8\avgrsx.exe
G:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
G:\WINDOWS\system32\SearchIndexer.exe
G:\PROGRA~1\AVG\AVG8\avgnsx.exe
G:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
G:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
G:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDCountdown.exe
G:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
G:\PROGRA~1\AVG\AVG8\avgemc.exe
G:\Program Files\TomTom HOME 2\HOMERunner.exe
G:\Program Files\Windows Desktop Search\WindowsSearch.exe
G:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
G:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
G:\WINDOWS\explorer.exe
G:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - G:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] G:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [IgfxTray] G:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] G:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] G:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] "G:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "G:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "G:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "G:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] G:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] G:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "G:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Search.lnk = G:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1224410992031
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - G:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: fccaArQk - G:\WINDOWS\
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: NBService - Nero AG - G:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - G:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - G:\WINDOWS\system32\IoctlSvc.exe

--
End of file - 7021 bytes

once again thanks in advance

#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:37 AM

Posted 05 November 2008 - 02:40 PM

Hello,

You're welcome. :thumbsup: One more scanner/cleaner, please. This one is good for getting leftovers in the registry.

Please download Malwarebytes' Anti-Malware from one of these places:
http://www.majorgeeks.com/Malwarebytes_Ant...ware_d5756.html
http://www.besttechie.net/tools/mbam-setup.exe

Double Click mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy&Paste the entire report in your next reply along with a fresh HijackThis log.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

Please also let me know how it's running. :)

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 daz1

daz1
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:10:37 AM

Posted 05 November 2008 - 04:03 PM

hello again tea

i have done as instructed and it seems to be running as it was before here are the log files requested

Malwarebytes' Anti-Malware 1.30
Database version: 1368
Windows 5.1.2600 Service Pack 3

05/11/2008 20:51:31
mbam-log-2008-11-05 (20-51-31).txt

Scan type: Quick Scan
Objects scanned: 44045
Time elapsed: 1 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
G:\WINDOWS\explorer.scf.vir (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:53:19, on 05/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
G:\WINDOWS\system32\spoolsv.exe
G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
G:\PROGRA~1\AVG\AVG8\avgfws8.exe
G:\WINDOWS\system32\IoctlSvc.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\SearchIndexer.exe
G:\WINDOWS\Explorer.EXE
G:\PROGRA~1\AVG\AVG8\avgam.exe
G:\PROGRA~1\AVG\AVG8\avgrsx.exe
G:\PROGRA~1\AVG\AVG8\avgnsx.exe
G:\PROGRA~1\AVG\AVG8\avgemc.exe
G:\PROGRA~1\AVG\AVG8\avgtray.exe
G:\WINDOWS\system32\igfxtray.exe
G:\WINDOWS\system32\hkcmd.exe
G:\WINDOWS\system32\igfxpers.exe
G:\WINDOWS\RTHDCPL.EXE
G:\WINDOWS\system32\igfxsrvc.exe
G:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
G:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
G:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDCountdown.exe
G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
G:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
G:\Program Files\TomTom HOME 2\HOMERunner.exe
G:\Program Files\Windows Desktop Search\WindowsSearch.exe
G:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
G:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
G:\Program Files\Mozilla Firefox\firefox.exe
G:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - G:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] G:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [IgfxTray] G:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] G:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] G:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] "G:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "G:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "G:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "G:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] G:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] G:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] G:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "G:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Search.lnk = G:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1224410992031
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - G:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: fccaArQk - G:\WINDOWS\
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: NBService - Nero AG - G:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - G:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - G:\WINDOWS\system32\IoctlSvc.exe

--
End of file - 7378 bytes


many thanks for your help and i will be donating, great site!

#6 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:37 AM

Posted 05 November 2008 - 04:49 PM

Hello,

You're most welcome. :) Still a bit to do :

If you don't use it, please uninstall the Ask Toolbar. It usually gets bundles with other programs and you don't realize it's even there. :thumbsup:

Please run HijackThis! and click "Scan." Place checks next to the following entries, if present:

O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - G:\Program Files\AskBarDis\bar\bin\askBar.dll <----if you uninstalled
O4 - HKLM\..\Run: [Persistence] G:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "G:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "G:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "G:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] G:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O20 - Winlogon Notify: fccaArQk - G:\WINDOWS\


Close all browsers and other windows except for HijackThis!, and click "Fix checked".

Reboot your computer.


* Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the quote box below into notepad:

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccaArQk]

Folder::
G:\VundoFix Backups
G:\SDFix


Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again.

After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#7 daz1

daz1
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:10:37 AM

Posted 05 November 2008 - 06:33 PM

hi again ok done all that here are the log files

ComboFix 08-11-04.02 - darren 2008-11-05 23:23:40.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1506 [GMT 0:00]
Running from: g:\documents and settings\darren\Desktop\ComboFix.exe
Command switches used :: g:\documents and settings\darren\My Documents\CFScript.txt
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

G:\SDFix
g:\sdfix\Add_DBFix_RunOnce_key.inf
g:\sdfix\apps\assosfix.reg
g:\sdfix\apps\Cghtme.exe
g:\sdfix\apps\cliptext.exe
g:\sdfix\apps\DBFix.inf
g:\sdfix\apps\download.exe
g:\sdfix\apps\dummy.sys
g:\sdfix\apps\Enable_Command_Prompt.inf
g:\sdfix\apps\Enable_Command_Prompt.reg
g:\sdfix\apps\ERDNT.E_E
g:\sdfix\apps\ERDNTDOS.LOC
g:\sdfix\apps\ERDNTWIN.LOC
g:\sdfix\apps\ERUNT.EXE
g:\sdfix\apps\ERUNT.LOC
g:\sdfix\apps\fix.reg
g:\sdfix\apps\FixBeep.reg
g:\sdfix\apps\FixBH.reg
g:\sdfix\apps\FixComponents.reg
g:\sdfix\apps\FIXCU.reg
g:\sdfix\apps\FIXLM.reg
g:\sdfix\apps\FixPath.exe
g:\sdfix\apps\FixRedir.reg
g:\sdfix\apps\FixSchedule.reg
g:\sdfix\apps\FixWebCheck.reg
g:\sdfix\apps\fixXP.reg
g:\sdfix\apps\FixXPsp2.reg
g:\sdfix\apps\grep.exe
g:\sdfix\apps\HaxdFix.reg
g:\sdfix\apps\HPFix.reg
g:\sdfix\apps\HPFix2.reg
g:\sdfix\apps\HPFix3.reg
g:\sdfix\apps\HPFix4.reg
g:\sdfix\apps\HPFix5.reg
g:\sdfix\apps\HPFix6.reg
g:\sdfix\apps\HPFix7.reg
g:\sdfix\apps\HPFix8.reg
g:\sdfix\apps\HPFix9.reg
g:\sdfix\apps\Installed.txt
g:\sdfix\apps\isadmin.exe
g:\sdfix\apps\leg2.txt
g:\sdfix\apps\legacy.txt
g:\sdfix\apps\legacybk.txt
g:\sdfix\apps\locate.com
g:\sdfix\apps\LS.exe
g:\sdfix\apps\MD5File.exe
g:\sdfix\apps\moveex.exe
g:\sdfix\apps\MyGcpvFix.reg
g:\sdfix\apps\MyGkFix2.reg
g:\sdfix\apps\Process.exe
g:\sdfix\apps\procs.exe
g:\sdfix\apps\psservice.exe
g:\sdfix\apps\Rem.txt
g:\sdfix\apps\Rem2.txt
g:\sdfix\apps\Replace\regedit.exe
g:\sdfix\apps\Replace\w2k\AUTOEXEC.NT
g:\sdfix\apps\Replace\w2k\beep.sys
g:\sdfix\apps\Replace\w2k\command.com
g:\sdfix\apps\Replace\w2k\command.PIF
g:\sdfix\apps\Replace\w2k\CONFIG.NT
g:\sdfix\apps\Replace\w2k\null.sys
g:\sdfix\apps\Replace\xp\AUTOEXEC.NT
g:\sdfix\apps\Replace\xp\beep.sys
g:\sdfix\apps\Replace\xp\command.com
g:\sdfix\apps\Replace\xp\command.PIF
g:\sdfix\apps\Replace\xp\CONFIG.NT
g:\sdfix\apps\Replace\xp\null.sys
g:\sdfix\apps\Reset_AppInit_DLLs.reg
g:\sdfix\apps\RestartIt!.exe
g:\sdfix\apps\Restore_SafeBoot_Windows2000.reg
g:\sdfix\apps\Restore_SafeBoot_WindowsXP.reg
g:\sdfix\apps\Restore_SafeBoot_WindowsXP_SP2.reg
g:\sdfix\apps\Restore_SafeBoot_WindowsXP_SP3.reg
g:\sdfix\apps\Restore_SecurityCenter.reg
g:\sdfix\apps\Restore_SharedAccess.reg
g:\sdfix\apps\sc.exe
g:\sdfix\apps\sed.exe
g:\sdfix\apps\SF.exe
g:\sdfix\apps\shutdown.exe
g:\sdfix\apps\srv2.txt
g:\sdfix\apps\srv2bk.txt
g:\sdfix\apps\svc.txt
g:\sdfix\apps\svcbk.txt
g:\sdfix\apps\Swreg.exe
g:\sdfix\apps\swsc.exe
g:\sdfix\apps\UnRAR.exe
g:\sdfix\apps\unzip.exe
g:\sdfix\apps\vfind.exe
g:\sdfix\apps\WINMSG.EXE
g:\sdfix\apps\winsec.reg
g:\sdfix\apps\zip.exe
g:\sdfix\backups\backupreg.zip
g:\sdfix\backups\catchme.log
g:\sdfix\backups\HOSTS
g:\sdfix\catchme.exe
g:\sdfix\DBFix.bat
g:\sdfix\dummy.sys
g:\sdfix\Report.txt
g:\sdfix\RunThis.bat
g:\sdfix\SDFIX_ReadMe_Online.url
g:\sdfix\W2K_VirusAlert_Repair.inf
g:\sdfix\XP_VirusAlert_Repair.inf
G:\VundoFix Backups

.
((((((((((((((((((((((((( Files Created from 2008-10-05 to 2008-11-05 )))))))))))))))))))))))))))))))
.

2008-11-05 20:45 . 2008-11-05 20:45 <DIR> d-------- g:\program files\Malwarebytes' Anti-Malware
2008-11-05 20:45 . 2008-11-05 20:45 <DIR> d-------- g:\documents and settings\darren\Application Data\Malwarebytes
2008-11-05 20:45 . 2008-11-05 20:45 <DIR> d-------- g:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-05 20:45 . 2008-10-22 16:28 38,496 --a------ g:\windows\system32\drivers\mbamswissarmy.sys
2008-11-05 20:45 . 2008-10-22 16:28 15,504 --a------ g:\windows\system32\drivers\mbam.sys
2008-11-04 22:42 . 2008-11-04 22:42 <DIR> d-------- g:\windows\ERUNT
2008-11-04 21:14 . 2008-11-04 21:19 <DIR> d-------- g:\windows\BDOSCAN8
2008-11-04 20:47 . 2008-11-04 20:47 <DIR> d-------- g:\program files\Panda Security
2008-11-04 20:47 . 2008-06-19 17:24 28,544 --a------ g:\windows\system32\drivers\pavboot.sys
2008-11-04 20:04 . 2008-11-04 20:42 <DIR> d-------- g:\documents and settings\darren\.housecall6.6
2008-11-03 19:22 . 2008-11-03 19:22 <DIR> d-------- g:\program files\Trend Micro
2008-11-01 16:23 . 2008-11-01 16:23 <DIR> d-------- g:\documents and settings\darren\LocalLow
2008-11-01 13:39 . 2008-11-01 13:39 <DIR> d-------- g:\program files\Support Tools
2008-10-31 18:23 . 2004-03-09 00:00 1,081,616 --a------ g:\windows\system32\MSCOMCTL.OCX
2008-10-31 18:19 . 2008-10-31 18:19 <DIR> d-------- g:\documents and settings\darren\Application Data\Serif
2008-10-31 18:17 . 2008-10-31 18:17 <DIR> d-------- g:\program files\Serif
2008-10-30 21:28 . 2008-10-30 21:28 <DIR> d-------- g:\program files\TomTom HOME 2
2008-10-30 21:28 . 2008-10-30 21:28 <DIR> d-------- g:\documents and settings\darren\Application Data\TomTom
2008-10-30 21:11 . 2008-10-30 21:28 <DIR> d-------- g:\program files\TomTom HOME
2008-10-29 22:43 . 2008-05-14 08:34 1,000,744 --a------ g:\windows\system32\ShellManager10E2D762.dll
2008-10-29 22:43 . 2008-04-10 18:52 648,192 --a------ g:\windows\system32\NEROINSTAEC43759.DB
2008-10-28 22:22 . 2008-01-22 12:28 148,776 --a------ g:\windows\system32\ImageDrive.cpl
2008-10-27 19:50 . 2008-10-27 19:52 <DIR> d-------- g:\program files\Enigma Software Group
2008-10-26 20:26 . 2008-11-04 20:44 <DIR> d-------- g:\program files\a-squared Free
2008-10-26 10:58 . 2008-10-26 10:58 <DIR> d-------- g:\documents and settings\darren\Application Data\Canon
2008-10-25 17:07 . 2008-11-04 22:49 <DIR> d-a------ g:\documents and settings\All Users\Application Data\TEMP
2008-10-25 16:07 . 2008-10-25 16:09 <DIR> d-------- g:\documents and settings\darren\Application Data\Simply Super Software
2008-10-25 16:07 . 2006-05-25 14:52 162,304 --a------ g:\windows\system32\ztvunrar36.dll
2008-10-25 16:07 . 2003-02-02 19:06 153,088 --a------ g:\windows\system32\unrar3.dll
2008-10-25 16:07 . 2005-08-26 00:50 77,312 --a------ g:\windows\system32\ztvunace26.dll
2008-10-25 16:07 . 2002-03-06 00:00 75,264 --a------ g:\windows\system32\unacev2.dll
2008-10-25 16:07 . 2006-06-19 12:01 69,632 --a------ g:\windows\system32\ztvcabinet.dll
2008-10-24 19:42 . 2008-10-24 19:42 2,600,220 --a------ g:\windows\system32\SetupAnyDVD6457.exe
2008-10-24 18:03 . 2008-10-24 18:05 24 --ahs---- g:\windows\SA238F1C3.tmp
2008-10-24 17:44 . 2008-10-24 17:44 <DIR> d-------- g:\program files\7-Zip
2008-10-24 17:03 . 2008-10-24 17:03 <DIR> d-------- g:\windows\Sun
2008-10-23 18:55 . 2008-10-26 11:54 <DIR> d-------- g:\program files\ASUS
2008-10-23 18:55 . 2006-01-10 08:50 24,576 -ra------ g:\windows\system32\AsIO.dll
2008-10-23 18:55 . 2006-10-18 19:12 12,664 -ra------ g:\windows\system32\drivers\AsIO.sys
2008-10-23 18:55 . 2008-10-23 19:02 666 --a------ g:\windows\setup.iss
2008-10-23 18:29 . 2008-11-05 21:32 <DIR> d--h----- G:\$AVG8.VAULT$
2008-10-22 18:08 . 2008-10-22 18:08 <DIR> d-------- g:\documents and settings\All Users\Application Data\Ahead
2008-10-22 18:07 . 2008-10-22 18:07 <DIR> d-------- g:\documents and settings\All Users\Application Data\Nero
2008-10-20 21:43 . 2008-10-20 21:43 <DIR> d-------- g:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-20 19:38 . 2008-10-20 19:38 <DIR> d-------- g:\documents and settings\LocalService\Application Data\Ahead
2008-10-20 17:22 . 2007-07-30 18:19 271,224 --a------ g:\windows\system32\mucltui.dll
2008-10-20 17:22 . 2007-07-30 18:19 30,072 --a------ g:\windows\system32\mucltui.dll.mui
2008-10-19 23:07 . 2008-10-19 23:08 <DIR> d-------- g:\program files\Windows Live Safety Center
2008-10-19 22:57 . 2008-10-19 22:57 <DIR> d-------- g:\program files\Messenger Plus! Live
2008-10-19 22:53 . 2008-10-25 14:07 <DIR> d-------- g:\documents and settings\darren\Contacts
2008-10-19 19:21 . 2008-11-01 00:41 116 --a------ g:\windows\NeroDigital.ini
2008-10-19 18:54 . 2008-10-19 18:54 <DIR> d-------- g:\program files\Runtime Software
2008-10-19 16:15 . 2008-10-19 16:15 <DIR> d-------- g:\documents and settings\All Users\Application Data\SlySoft
2008-10-19 15:58 . 2008-11-02 17:48 <DIR> d-------- g:\documents and settings\darren\Application Data\Azureus
2008-10-19 15:58 . 2008-10-19 15:58 <DIR> d-------- g:\documents and settings\All Users\Application Data\Azureus
2008-10-19 15:57 . 2008-11-02 17:48 <DIR> d-------- g:\program files\Vuze
2008-10-19 15:50 . 2008-11-05 18:53 <DIR> d-------- g:\program files\Spybot - Search & Destroy
2008-10-19 15:50 . 2008-10-19 16:10 <DIR> d-------- g:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-19 15:48 . 2008-10-19 15:48 <DIR> d-------- g:\program files\Lavasoft
2008-10-19 15:48 . 2008-10-19 15:48 <DIR> d-------- g:\documents and settings\All Users\Application Data\Lavasoft
2008-10-19 15:47 . 2008-10-19 15:47 <DIR> d-------- g:\program files\Common Files\Wise Installation Wizard
2008-10-19 14:54 . 2008-10-19 14:54 <DIR> d-------- g:\documents and settings\darren\Application Data\Windows Search
2008-10-19 14:41 . 2008-10-19 14:41 <DIR> d-------- g:\program files\MSXML 4.0
2008-10-19 14:41 . 2008-10-19 14:41 <DIR> d-------- g:\program files\Microsoft CAPICOM 2.1.0.2
2008-10-19 14:37 . 2008-10-19 14:37 <DIR> d-------- g:\documents and settings\darren\Application Data\Simple Star
2008-10-19 14:37 . 2006-05-18 19:20 319,488 --a------ g:\windows\Nero PhotoShow.scr
2008-10-19 14:37 . 2006-03-14 01:49 106,496 --a------ g:\windows\system32\TwnLib20.dll
2008-10-19 14:37 . 2006-03-14 01:49 38,912 --a------ g:\windows\system32\picn20.dll
2008-10-19 14:35 . 2008-10-19 14:35 <DIR> d-------- g:\program files\Common Files\Simple Star Shared
2008-10-19 14:35 . 2008-11-02 19:58 <DIR> d-------- g:\documents and settings\darren\Application Data\Nero
2008-10-19 14:16 . 2008-10-19 14:18 <DIR> d--hsc--- g:\program files\Common Files\WindowsLiveInstaller
2008-10-19 14:15 . 2008-10-19 22:52 <DIR> d-------- g:\program files\Windows Live
2008-10-19 14:15 . 2008-10-19 22:47 <DIR> d-------- g:\documents and settings\All Users\Application Data\WLInstaller
2008-10-19 14:00 . 2008-10-19 14:00 <DIR> d-------- g:\documents and settings\darren\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-10-19 13:59 . 2008-06-10 01:32 73,728 --a------ g:\windows\system32\javacpl.cpl
2008-10-19 13:58 . 2008-10-19 13:59 <DIR> d-------- g:\program files\Java
2008-10-19 13:57 . 2008-10-19 13:57 <DIR> d-------- g:\program files\Common Files\Java
2008-10-19 13:54 . 2008-11-05 22:34 <DIR> d-------- g:\program files\Pool Sharks
2008-10-19 13:49 . 2008-10-19 13:49 <DIR> d-------- g:\windows\system32\Adobe
2008-10-19 13:48 . 2008-10-19 13:48 <DIR> d-------- g:\program files\Common Files\Adobe AIR
2008-10-19 13:47 . 2008-10-19 13:47 <DIR> d-------- g:\program files\Common Files\Adobe
2008-10-19 13:46 . 2008-10-19 15:33 <DIR> d-------- g:\program files\NOS
2008-10-19 13:46 . 2008-10-19 15:33 <DIR> d-------- g:\documents and settings\All Users\Application Data\NOS
2008-10-19 13:41 . 2008-10-19 13:41 <DIR> d-------- g:\program files\Logitech
2008-10-19 13:41 . 2008-10-19 13:41 <DIR> d-------- g:\program files\Common Files\Logitech
2008-10-19 13:30 . 2008-04-13 23:17 25,856 --a------ g:\windows\system32\drivers\usbprint.sys
2008-10-19 13:30 . 2008-04-13 23:17 25,856 --a--c--- g:\windows\system32\dllcache\usbprint.sys
2008-10-19 13:29 . 2008-04-13 23:15 15,104 --a------ g:\windows\system32\drivers\usbscan.sys
2008-10-19 13:29 . 2008-04-13 23:15 15,104 --a--c--- g:\windows\system32\dllcache\usbscan.sys
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\program files\ScanSoft
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\program files\Common Files\ScanSoft Shared
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\documents and settings\darren\Application Data\ScanSoft
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\documents and settings\All Users\Application Data\ScanSoft
2008-10-19 13:28 . 2008-10-19 13:28 <DIR> d-------- g:\documents and settings\All Users\Application Data\InstallShield
2008-10-19 13:28 . 2008-10-19 13:28 412 --a------ g:\windows\MAXLINK.INI
2008-10-19 13:25 . 2008-10-19 13:25 <DIR> d--h----- g:\windows\system32\CanonIJ Uninstaller Information
2008-10-19 13:25 . 2008-10-19 13:25 <DIR> d--h----- g:\program files\CanonBJ
2008-10-19 13:25 . 2008-10-19 13:25 <DIR> d--h----- g:\documents and settings\All Users\Application Data\CanonBJ
2008-10-19 13:25 . 2006-11-10 02:00 1,314,816 --a------ g:\windows\system32\CNCC140.DLL
2008-10-19 13:25 . 2006-12-25 20:00 198,656 --a------ g:\windows\system32\CNMLM8R.DLL
2008-10-19 13:25 . 2006-05-26 01:54 135,168 --a------ g:\windows\system32\CNCL140.DLL
2008-10-19 13:25 . 2006-06-29 05:29 106,496 --a------ g:\windows\system32\cnco140.dll
2008-10-19 13:25 . 2006-11-10 01:59 57,344 --a------ g:\windows\system32\CNCI140.DLL
2008-10-19 13:24 . 2008-10-19 13:30 <DIR> d-------- g:\program files\Canon
2008-10-19 13:15 . 2008-10-19 19:08 <DIR> d-------- g:\documents and settings\darren\Application Data\Ahead
2008-10-19 13:13 . 2008-10-22 17:41 <DIR> d-------- g:\program files\Nero
2008-10-19 13:13 . 2008-10-22 18:07 <DIR> d-------- g:\program files\Common Files\Ahead
2008-10-19 10:14 . 2008-10-19 10:14 0 --a------ g:\windows\nsreg.dat
2008-10-19 10:11 . 2008-10-20 17:30 <DIR> d-------- g:\program files\Microsoft Silverlight
2008-10-19 09:47 . 2008-10-19 09:47 <DIR> d-------- g:\windows\system32\GroupPolicy
2008-10-19 09:47 . 2008-10-19 09:47 <DIR> d-------- g:\program files\Windows Desktop Search
2008-10-19 09:47 . 2008-10-19 09:47 <DIR> d-------- g:\documents and settings\darren\Application Data\Windows Desktop Search
2008-10-19 09:46 . 2008-10-19 09:46 <DIR> d-------- g:\program files\Windows Media Connect 2
2008-10-19 09:45 . 2008-10-19 09:45 <DIR> d-------- g:\windows\system32\LogFiles
2008-10-19 09:45 . 2008-10-19 18:42 <DIR> d-------- g:\windows\system32\drivers\UMDF
2008-10-19 09:43 . 2008-10-19 09:43 <DIR> d-------- g:\windows\system32\URTTemp
2008-10-19 09:32 . 2008-10-23 19:04 <DIR> d-------- g:\program files\Marvell
2008-10-19 09:32 . 2008-10-19 09:32 940,794 --a------ g:\windows\system32\LoopyMusic.wav
2008-10-19 09:32 . 2008-10-19 09:32 146,650 --a------ g:\windows\system32\BuzzingBee.wav
2008-10-19 09:30 . 2008-10-19 09:30 <DIR> d-------- g:\windows\system32\RTCOM
2008-10-19 09:30 . 2007-01-30 10:54 16,116,224 -r------- g:\windows\RTHDCPL.exe
2008-10-19 09:30 . 2006-05-04 08:35 9,709,568 -r------- g:\windows\RTLCPL.exe
2008-10-19 09:30 . 2007-01-30 10:57 4,474,368 -r------- g:\windows\system32\drivers\RtkHDAud.sys
2008-10-19 09:30 . 2006-05-16 10:04 2,879,488 -r------- g:\windows\SkyTel.exe
2008-10-19 09:30 . 2007-01-02 05:32 1,191,936 -r------- g:\windows\RtlUpd.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 18:17 --------- d--h--w g:\program files\InstallShield Installation Information
2008-10-23 18:55 --------- d-----w g:\program files\Common Files\InstallShield
2008-10-19 08:32 21,035 ----a-w g:\windows\system32\drivers\AegisP.sys
2008-10-19 08:31 --------- d-----w g:\program files\NETGEAR
2008-10-19 08:01 --------- d-----w g:\program files\microsoft frontpage
2008-09-15 12:12 1,846,400 ----a-w g:\windows\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w g:\windows\system32\drivers\srv.sys
2008-08-26 07:24 826,368 ----a-w g:\windows\system32\wininet.dll
2008-08-14 10:09 2,145,280 ----a-w g:\windows\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 ----a-w g:\windows\system32\ntkrnlpa.exe
2006-06-23 06:48 32,768 ----a-r g:\windows\inf\UpdateUSB.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="g:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="g:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"TomTomHOME.exe"="g:\program files\TomTom HOME 2\HOMERunner.exe" [2008-09-26 206184]
"SpybotSD TeaTimer"="g:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="g:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-23 1235736]
"IgfxTray"="g:\windows\system32\igfxtray.exe" [2007-04-20 142104]
"HotKeysCmds"="g:\windows\system32\hkcmd.exe" [2007-04-20 162584]
"OpwareSE4"="g:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Launch LCDMon"="g:\program files\Common Files\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 774168]
"NeroFilterCheck"="g:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 g:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 g:\windows\SkyTel.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="g:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

g:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - g:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "g:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"g:\\Program Files\\Messenger\\msmsgs.exe"=
"g:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"g:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 AvgRkx86;avgrkx86.sys;g:\windows\system32\Drivers\avgrkx86.sys [2008-10-19 12936]
R0 pavboot;pavboot;g:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
R1 AvgLdx86;AVG AVI Loader Driver x86;g:\windows\system32\Drivers\avgldx86.sys [2008-10-29 98440]
R1 AvgTdiX;AVG8 Network Redirector;g:\windows\system32\Drivers\avgtdix.sys [2008-11-05 90632]
R2 avg8emc;AVG8 E-mail Scanner;g:\progra~1\AVG\AVG8\avgemc.exe [2008-10-23 874776]
R2 avg8wd;AVG8 WatchDog;g:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-19 231704]
R2 avgfws8;AVG8 Firewall;g:\progra~1\AVG\AVG8\avgfws8.exe [2008-11-05 1212184]
R3 Avgfwdx;Avgfwdx;g:\windows\system32\DRIVERS\avgfwdx.sys [2008-11-05 29208]
S3 ADM8511;%ADM8511.Service.DispName%;g:\windows\system32\DRIVERS\ADM8511.SYS [2001-08-17 20160]
S3 Avgfwfd;AVG network filter service;g:\windows\system32\DRIVERS\avgfwdx.sys [2008-11-05 29208]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;g:\windows\system32\DRIVERS\wg111v2.sys [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc6d6fd7-a6c8-11dd-8b52-001fc669679d}]
\Shell\AutoRun\command - C:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2008-10-19 g:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- g:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-07-07 08:42]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-05 23:24:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-05 23:25:21
ComboFix-quarantined-files.txt 2008-11-05 23:25:18
ComboFix2.txt 2008-11-05 19:05:32
ComboFix3.txt 2008-11-05 19:01:09
ComboFix4.txt 2008-11-03 22:29:17
ComboFix5.txt 2008-11-05 23:22:58

Pre-Run: 483,621,818,368 bytes free
Post-Run: 483,605,725,184 bytes free

328 --- E O F --- 2008-10-23 17:41:06


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:28:27, on 05/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
G:\WINDOWS\system32\spoolsv.exe
G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
G:\PROGRA~1\AVG\AVG8\avgfws8.exe
G:\WINDOWS\system32\IoctlSvc.exe
G:\WINDOWS\system32\svchost.exe
G:\PROGRA~1\AVG\AVG8\avgam.exe
G:\PROGRA~1\AVG\AVG8\avgrsx.exe
G:\PROGRA~1\AVG\AVG8\avgnsx.exe
G:\WINDOWS\system32\SearchIndexer.exe
G:\PROGRA~1\AVG\AVG8\avgemc.exe
G:\PROGRA~1\AVG\AVG8\avgtray.exe
G:\WINDOWS\system32\igfxtray.exe
G:\WINDOWS\system32\hkcmd.exe
G:\WINDOWS\RTHDCPL.EXE
G:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
G:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
G:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
G:\Program Files\TomTom HOME 2\HOMERunner.exe
G:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDCountdown.exe
G:\Program Files\Windows Desktop Search\WindowsSearch.exe
G:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
G:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
G:\WINDOWS\explorer.exe
G:\Program Files\Mozilla Firefox\firefox.exe
G:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVG8_TRAY] G:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [IgfxTray] G:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] G:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [OpwareSE4] "G:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "G:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] G:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "G:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [TomTomHOME.exe] "G:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Search.lnk = G:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - G:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1224410992031
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - G:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - G:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: NBService - Nero AG - G:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - G:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - G:\WINDOWS\system32\IoctlSvc.exe

--
End of file - 6427 bytes

thanks again

#8 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:37 AM

Posted 05 November 2008 - 06:41 PM

Hello,

Looks good. :thumbsup: Still running all right?

Please delete ComboFix and its accompanying folder C:\Qoobox. Empty your Recycle bin and reboot your computer.

You have some good protection in place, so the only other thing I would recommend id a firewall. Some good free firewalls are Kerio, or Outpost. I use Comodo on my own system and really like it. http://comodo.com
A tutorial on understanding and using firewalls may be found here.

If you need anything else, please let me know. Otherwise I think we're done! :)

Take care!
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#9 daz1

daz1
  • Topic Starter

  • Members
  • 29 posts
  • OFFLINE
  •  
  • Local time:10:37 AM

Posted 06 November 2008 - 01:34 PM

yep seems to be running fine, i do have avg firewall as i bought a 2 year license its not the free version, does this mean its not configured right?

many thanks once again for the help i have made a donation and i'll recommend the site to anyone who needs help.

#10 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:37 AM

Posted 06 November 2008 - 01:48 PM

Bah....you're right! :) It's unusual to see AVG's firewall in ANY log. It's fine. :)

Thank you, and you are most welcome. :thumbsup:

Best,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#11 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:37 AM

Posted 02 December 2008 - 05:37 AM

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users