1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved " Invalid image " warning.

Discussion in 'Malware and Virus Removal Archive' started by scouse71, 2010/02/08.

  1. 2010/02/08
    scouse71

    scouse71 Inactive Thread Starter

    Joined:
    2010/01/29
    Messages:
    10
    Likes Received:
    0
    [Resolved] " Invalid image " warning.

    http://www.WindowsBBS.com/windows-xp/90948-invalid-image-warning.html

    Hi, when i start my computer up i have to click away at warnings that come up for nearly everything that is starting on my system. Then when it`s fully booted & i start an application i get the same warning which say`s, " The application or DLL C;\WINDOWS\system32\app_dll.dll is not a valid Windows image. Please check this against your diskette ". A few weeks back i had a trojan and somehow damaged my computer internals when i finally got it removed. I bought the computer 2nd hand and wasn`t given any discs with it. Apart from these warnings the computer runs ok.
    I`m pretty new to all this so any help or advice would be appreciated. Thanks.:confused:
    P.S I`m running Windows XP



    DDS (Ver_09-12-01.01) - NTFSx86
    Run by user at 9:54:19.90 on 08/02/2010
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.511.59 [GMT 0:00]

    AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\WinPcap\rpcapd.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Virgin Broadband Wireless\ndis_events.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\user\Start Menu\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    uDefault_Page_URL = hxxp://www.msn.com
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [Wireless Manager] "c:\program files\virgin broadband wireless\Wireless Manager.exe" startup
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
    StartupFolder: c:\documents and settings\user\start menu\programs\startup\CCC.lnk.disabled
    dPolicies-system: DisableRegistryTools = 1 (0x1)
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: avgrsstarter - avgrsstx.dll
    AppInit_DLLs: app_dll.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    Hosts: 127.0.0.1 www.spywareinfo.com

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\a7qdwyy7.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:eek:fficial
    FF - prefs.js: keyword.URL - hxxp://www.google.com/search?&q=
    FF - prefs.js: network.proxy.http - 66.63.165.11
    FF - prefs.js: network.proxy.http_port - 3128
    FF - prefs.js: network.proxy.type - 4
    FF - plugin: c:\documents and settings\user\application data\facebook\npfbplugin_1_0_1.dll
    FF - plugin: c:\documents and settings\user\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
    FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: browser.cache.memory.capacity - 16000
    FF - user.js: browser.chrome.favicons - false
    FF - user.js: browser.display.show_image_placeholders - true
    FF - user.js: browser.turbo.enabled - true
    FF - user.js: browser.urlbar.autocomplete.enabled - true
    FF - user.js: browser.urlbar.autofill - true
    FF - user.js: content.max.tokenizing.time - 3000000
    FF - user.js: content.maxtextrun - 4095
    FF - user.js: content.notify.backoffcount - 5
    FF - user.js: content.notify.interval - 1000000
    FF - user.js: content.notify.ontimer - true
    FF - user.js: content.switch.threshold - 1000000
    FF - user.js: dom.disable_window_status_change - true
    FF - user.js: network.http.max-connections - 48
    FF - user.js: network.http.max-connections-per-server - 16
    FF - user.js: network.http.max-persistent-connections-per-proxy - 16
    FF - user.js: network.http.max-persistent-connections-per-server - 8
    FF - user.js: network.http.pipelining - true
    FF - user.js: network.http.pipelining.firstrequest - true
    FF - user.js: network.http.pipelining.maxrequests - 8
    FF - user.js: network.http.proxy.pipelining - true
    FF - user.js: network.http.request.max-start-delay - 0
    FF - user.js: nglayout.initialpaint.delay - 1000
    FF - user.js: plugin.expose_full_path - true
    FF - user.js: ui.submenuDelay - 0
    FF - user.js: yahoo.homepage.dontask - true
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_popup_windows ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.enable_click_image_resizing ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "accessibility.browsewithcaret_shortcut.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.high_water_mark ", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.gc_frequency ", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.trackpoint_hack.enabled ", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.debug ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.agedWeight ", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.bucketSize ", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.maxTimeGroupings ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.timeGroupingSize ", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.boundaryWeight ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.prefixWeight ", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "html5.enable ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl3.rsa_seed_sha ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.download.backgroundInterval ", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.url.manual ", "http://www.firefox.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-ja ", "mozff ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add ", "addons.mozilla.org ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add.36 ", "getpersonas.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "lightweightThemes.update.enabled ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.allTabs.previews ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.hide_infobar_for_outdated_plugin ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "toolbar.customization.usesheet ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.enable ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.max ", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.cachetime ", 20);

    ============= SERVICES / DRIVERS ===============

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-12-8 12552]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-12-8 335240]
    R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-12-8 27784]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-12-8 108552]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-12-8 297752]
    R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-12-8 32512]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-12-27 19160]
    S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\user\locals~1\temp\sas_selfextract\sasdifsv.sys --> c:\docume~1\user\locals~1\temp\sas_selfextract\SASDIFSV.SYS [?]
    S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\user\locals~1\temp\sas_selfextract\saskutil.sys --> c:\docume~1\user\locals~1\temp\sas_selfextract\SASKUTIL.sys [?]
    S2 FlexService;Remote Connections Service; "c:\program files\rapidbit\cisvc.exe" --> c:\program files\rapidbit\cisvc.exe [?]
    S2 gupdate1c9e7712253ae80;Google Update Service (gupdate1c9e7712253ae80);c:\program files\google\update\GoogleUpdate.exe [2009-6-7 133104]
    S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [2004-11-8 2825088]
    S3 ADASPROT;SYSTWEAKASO;\??\c:\program files\advanced system optimizer 3\adasprot32.sys --> c:\program files\advanced system optimizer 3\adasprot32.sys [?]
    S3 DrmRAudio;DrmRAudio;c:\windows\system32\drivers\DrmRAudio.sys [2009-7-23 23096]
    S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-6-17 12648]
    S3 SASENUM;SASENUM;\??\c:\docume~1\user\locals~1\temp\sas_selfextract\sasenum.sys --> c:\docume~1\user\locals~1\temp\sas_selfextract\SASENUM.SYS [?]

    ============== File Associations ===============

    JSEFile=NOTEPAD.EXE %1
    VBSFile=NOTEPAD.EXE %1

    =============== Created Last 30 ================

    2010-02-06 20:42:42 0 d-----w- c:\documents and settings\user\BackUp
    2010-02-05 23:51:52 4096 ----a-w- c:\windows\system32\crash
    2010-02-05 08:01:00 0 d-----w- c:\program files\Secunia
    2010-02-03 01:18:55 971232 ----a-w- c:\windows\system32\drivers\tdrpm147.sys
    2010-02-03 00:55:51 0 d-----w- c:\program files\RapidBIT
    2010-02-02 20:55:52 0 d-----w- C:\Win. Hotmail
    2010-02-02 20:43:49 0 dc-h--w- c:\windows\ie8
    2010-01-31 03:36:44 24576 -c--a-w- c:\windows\system32\dllcache\agcgauge.ax
    2010-01-31 03:34:28 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
    2010-01-31 02:48:05 0 d-----w- c:\docume~1\user\applic~1\IObit
    2010-01-31 02:48:04 0 d-----w- c:\program files\IObit
    2010-01-31 00:43:58 6 ----a-w- c:\windows\dcstds3.dll
    2010-01-30 23:57:10 0 d-----w- c:\docume~1\user\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2010-01-30 20:47:06 0 d-----w- c:\docume~1\user\applic~1\Facebook
    2010-01-30 13:32:52 0 ----a-w- c:\windows\system32\app_dll.dll
    2010-01-30 03:46:47 0 d-----w- C:\spoolerlogs
    2010-01-28 23:51:45 4 ----a-w- c:\program files\2783453.dat
    2010-01-27 23:06:56 0 d-----w- C:\stdtsa
    2010-01-27 21:16:10 0 d-----w- c:\docume~1\user\applic~1\QuickScan
    2010-01-27 20:31:54 82 ----a-w- c:\windows\wininit.ini
    2010-01-27 06:21:36 130 ----a-w- c:\windows\cfplogvw.INI
    2010-01-27 03:52:46 220257 ----a-w- c:\windows\system32\drivers\sfi.dat
    2010-01-26 23:40:58 0 d-----w- c:\docume~1\user\applic~1\SUPERAntiSpyware.com
    2010-01-26 23:40:58 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
    2010-01-26 03:00:18 0 d-----w- c:\docume~1\alluse~1\applic~1\F-Secure
    2010-01-24 17:54:49 0 d-----w- c:\docume~1\alluse~1\applic~1\Systweak
    2010-01-24 17:48:00 0 d-----w- c:\docume~1\user\applic~1\Systweak
    2010-01-24 17:46:27 0 d-----w- c:\program files\Advanced System Optimizer 3
    2010-01-24 13:52:05 6435 ----a-w- c:\windows\system32\WORK.DAT
    2010-01-19 14:11:13 0 ----a-w- c:\windows\EEventManager.INI
    2010-01-19 13:33:38 0 d-----w- c:\windows\system32\wbem\Repository
    2010-01-19 13:32:31 0 d-----w- c:\program files\Panda Security
    2010-01-17 20:39:12 6652 ----a-w- c:\docume~1\user\applic~1\settings.dat
    2010-01-13 23:35:36 0 d-----w- c:\docume~1\alluse~1\applic~1\UDL
    2010-01-13 23:25:12 0 d-----w- c:\docume~1\alluse~1\applic~1\EPSON
    2010-01-13 06:44:15 0 d-----w- c:\program files\Platinum Guard
    2010-01-11 22:51:47 867 ----a-w- C:\lxcginst.csv
    2010-01-11 22:51:39 275 ----a-w- C:\lxcgfire.csv

    ==================== Find3M ====================

    2010-02-08 09:36:07 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
    2010-02-03 01:06:08 540000 ----a-w- c:\windows\system32\drivers\timntr.sys
    2010-02-03 01:06:08 44704 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
    2010-01-07 16:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-01-07 16:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-12-21 19:14:05 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-12-17 17:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-12-08 15:26:12 11952 ----a-w- c:\windows\system32\avgrsstx.dll




    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-12-01.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 01/06/2009 20:19:37
    System Uptime: 02/08/2010 09:35:39 (-4200 hours ago)

    Motherboard: NEC COMPUTERS INTERNATIONAL | | GA-8I915PM
    Processor: Intel(R) Pentium(R) 4 CPU 2.93GHz | Socket 775 | 2925/133mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 149 GiB total, 26.623 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: MAC Bridge Miniport
    Device ID: ROOT\MS_BRIDGEMP\0000
    Manufacturer: Microsoft
    Name: MAC Bridge Miniport
    PNP Device ID: ROOT\MS_BRIDGEMP\0000
    Service: BridgeMP

    ==== System Restore Points ===================

    RP198: 01/02/2010 19:06:13 - System Checkpoint
    RP199: 01/02/2010 19:22:55 - Avg8 Update
    RP200: 02/02/2010 20:44:40 - Installed Windows Internet Explorer 8.
    RP201: 02/02/2010 20:45:41 - Software Distribution Service 3.0
    RP202: 02/02/2010 21:20:10 - Software Distribution Service 3.0
    RP203: 03/02/2010 01:04:55 - Installed Acronis*True*Image*Home
    RP204: 04/02/2010 12:21:04 - System Checkpoint
    RP205: 05/02/2010 00:44:00 - Removed Acronis*True*Image*Home
    RP206: 05/02/2010 01:30:21 - Removed Acrobat.com
    RP207: 05/02/2010 01:30:56 - Removed RapidBIT Suite
    RP208: 05/02/2010 21:33:12 - Installed Google Earth
    RP209: 05/02/2010 21:50:28 - Removed Microsoft Office Enterprise 2007
    RP210: 05/02/2010 23:39:31 - Installed Google Earth Pro.
    RP211: 06/02/2010 20:21:35 - Software Distribution Service 3.0
    RP212: 06/02/2010 20:26:09 - Removed Google Earth Pro.
    RP213: 07/02/2010 04:31:31 - Installed ATI Catalyst Control Center

    ==== Installed Programs ======================

    Adobe AIR
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.3
    Adobe Shockwave Player 11.5
    Advanced SystemCare 3
    Apple Application Support
    Apple Software Update
    ATI - Software Uninstall Utility
    ATI Catalyst Control Center
    ATI Display Driver
    AVG 8.5
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center HydraVision Full
    Catalyst Control Center Localization All
    ccc-core-preinstall
    ccc-core-static
    ccc-utility
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    CCleaner
    Choice Guard
    ConvertHelper 2.2
    Critical Update for Windows Media Player 11 (KB959772)
    DivX Plus Web Player
    DVD Shrink 3.2
    dvdSanta 4.50
    Facebook Plug-In
    Google Chrome
    Google Earth
    Google Toolbar for Internet Explorer
    Google Update Helper
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB976098-v2)
    Java Auto Updater
    Java(TM) 6 Update 18
    K-Lite Codec Pack 2.27 Full
    Lexmark 2300 Series
    Logitech Audio Echo Cancellation Component
    Logitech QuickCam
    Logitech Video Enumerator
    Logitech® Camera Driver
    Malwarebytes' Anti-Malware
    Messenger Plus! Live
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Mozilla Firefox (3.6)
    MSN
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MVision
    QuickTime
    Secunia PSI
    Security Update for CAPICOM (KB931906)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB963027)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Segoe UI
    Skins
    Spybot - Search & Destroy
    Sweepi 5.4.00
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB978506)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB961503)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    VC80CRTRedist - 8.0.50727.4053
    VLC media player 1.0.5
    WebFldrs XP
    Windows Internet Explorer 8
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    Wireless Manager
    XP Repair Pro 4.0

    ==== Event Viewer Messages From Past Week ========

    08/02/2010 09:52:16, error: Service Control Manager [7000] - The AFGSp50 NDIS Protocol Driver service failed to start due to the following error: The system cannot find the file specified.
    08/02/2010 09:49:22, error: Service Control Manager [7016] - The SmartLinkService service has reported an invalid current state 0.
    08/02/2010 09:49:21, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the rpcapd service.

    ==== End Of File ===========================


    ============= FINISH: 9:58:35.48 ===============


    I hope i`m doing this right & i`m not posting incorrectly. I have read the posting instructions.
     
  2. 2010/02/08
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    You did fine.

    A Malware expert will have a look at your log in due course.
     
    scouse71 likes this.

  3. to hide this advert.

  4. 2010/02/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Malwarebytes before running the scans.***


    STEP 1. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform Quick Scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    STEP 2. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    RESTART COMPUTER

    STEP 3. Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Installer under Version 2.0.2
    [DO NOT download version 2.0.3 (beta)]
    Install, and run it.
    Post HijackThis log.
    NOTE. If you're using Vista, or 7, right click on HijackThis, and click Run as Administrator
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  5. 2010/02/08
    scouse71

    scouse71 Inactive Thread Starter

    Joined:
    2010/01/29
    Messages:
    10
    Likes Received:
    0
    HI broni , thanks for replying so soon. Here`s a copy of the logs you ask for , by the way , when i was doing the scan with malwarebytes i had the following show as a pop up detection but they are not showing in the actual scan report. These are processes that were blocked :-

    18:07:03 (null) MESSAGE IP Protection started successfully
    18:13:04 (null) DETECTION C:\WINDOWS\system32\app_dll.dll Trojan.Agent.Gen QUARANTINE
    18:19:50 (null) DETECTION C:\WINDOWS\system32\WORK.DAT Spyware.Passwords QUARANTINE

    = = = = = = = = = = = = = = = = = = =

    Heres the logs you requested :-

    Malwarebytes' Anti-Malware 1.44
    Database version: 3709
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    08/02/2010 18:24:21
    mbam-log-2010-02-08 (18-24-21).txt

    Scan type: Quick Scan
    Objects scanned: 111530
    Time elapsed: 16 minute(s), 22 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    = = = = = = = = = = =

    GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-02-08 19:15:22
    Windows 5.1.2600 Service Pack 3
    Running: 80b5355b.exe; Driver: C:\DOCUME~1\user\LOCALS~1\Temp\kgpcqpoc.sys


    ---- Kernel code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF7B29000, 0x1C5D38, 0xE8000020]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\Program Files\Mozilla Firefox\firefox.exe[4360] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

    ---- EOF - GMER 1.0.15 ----

    = = = = = = = = = = = = = = =

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:20:54, on 08/02/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files\WinPcap\rpcapd.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Virgin Broadband Wireless\ndis_events.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\msfeedssync.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\user\Start Menu\My Documents\Downloads\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - S-1-5-18 Startup: CCC.lnk.disabled (User 'SYSTEM')
    O4 - .DEFAULT Startup: CCC.lnk.disabled (User 'Default user')
    O4 - Startup: CCC.lnk.disabled
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: app_dll.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Remote Connections Service (FlexService) - Unknown owner - C:\Program Files\RapidBIT\cisvc.exe (file missing)
    O23 - Service: Google Update Service (gupdate1c9e7712253ae80) (gupdate1c9e7712253ae80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

    --
    End of file - 6739 bytes
     
  6. 2010/02/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.


    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Please, never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    NOTE 1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt " along with a new HijackThis log for further review.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
    scouse71 likes this.
  7. 2010/02/08
    scouse71

    scouse71 Inactive Thread Starter

    Joined:
    2010/01/29
    Messages:
    10
    Likes Received:
    0
    Hi broni , you & your team are pure genius , (genii ?) , with a magic wand called combofix ! Here is the report from combofix and since running it all pop up warnings have ceased and my computer seems to be back to normal. If there is nothing out of the ordinary with the report at your end i will mark this down as resolved. By the way if things look normal , could you please advise as to what security i need to keep & what`s not needed as i`ve read on here that too many can actually work against you. Once again my praise & gratitude go out to you & yours. Thank you !

    ComboFix 10-02-08.02 - user 08/02/2010 23:49:31.1.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.511.249 [GMT 0:00]
    Running from: c:\documents and settings\user\Start Menu\My Documents\Downloads\ComboFix.exe
    AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\user\Application Data\inst.exe
    c:\program files\WinPCap
    c:\program files\WinPCap\daemon_mgm.exe
    c:\program files\WinPCap\npf_mgm.exe
    c:\program files\WinPCap\rpcapd.exe
    c:\windows\dcstds3.dll
    c:\windows\system32\ctfmon .exe
    c:\windows\system32\drivers\npf.sys
    c:\windows\system32\Packet.dll
    c:\windows\system32\pthreadVC.dll
    c:\windows\system32\WanPacket.dll
    c:\windows\system32\wpcap.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_NPF
    -------\Service_NPF


    ((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 )))))))))))))))))))))))))))))))
    .

    2010-02-08 14:47 . 2010-02-08 14:47 -------- d-----w- c:\documents and settings\All Users\Application Data\vsosdk
    2010-02-08 13:04 . 2010-02-08 13:04 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
    2010-02-08 13:04 . 2010-02-08 13:04 47360 ----a-w- c:\documents and settings\user\Application Data\pcouffin.sys
    2010-02-08 13:04 . 2010-02-08 15:12 -------- d-----w- c:\documents and settings\user\Application Data\Vso
    2010-02-08 13:03 . 2009-09-02 16:41 65602 ----a-w- c:\windows\system32\cook3260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 217127 ----a-w- c:\windows\system32\drv43260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 208935 ----a-w- c:\windows\system32\drv33260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 176165 ----a-w- c:\windows\system32\drv23260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 102439 ----a-w- c:\windows\system32\sipr3260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 626688 ----a-w- c:\windows\system32\vp7vfw.dll
    2010-02-08 13:03 . 2009-09-02 16:41 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
    2010-02-08 13:03 . 2010-02-08 13:03 -------- d-----w- c:\program files\VSO
    2010-02-07 04:42 . 2010-02-07 04:42 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
    2010-02-06 20:42 . 2010-02-06 20:42 -------- d-----w- c:\documents and settings\user\BackUp
    2010-02-05 21:37 . 2010-02-08 17:33 -------- d-----w- c:\documents and settings\user\Application Data\vlc
    2010-02-05 08:01 . 2010-02-05 08:01 -------- d-----w- c:\program files\Secunia
    2010-02-03 01:18 . 2010-02-03 03:04 971232 ----a-w- c:\windows\system32\drivers\tdrpm147.sys
    2010-02-03 01:05 . 2010-02-03 01:05 -------- d-----w- c:\program files\Acronis
    2010-02-03 00:55 . 2010-02-05 01:45 -------- d-----w- c:\program files\RapidBIT
    2010-02-02 20:55 . 2010-02-02 20:55 -------- d-----w- C:\Win. Hotmail
    2010-02-02 20:43 . 2010-02-02 20:45 -------- dc-h--w- c:\windows\ie8
    2010-01-31 05:11 . 2010-01-31 05:11 0 ----a-w- c:\windows\nsreg.dat
    2010-01-31 05:11 . 2010-01-31 05:11 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
    2010-01-31 05:10 . 2010-01-31 05:10 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee
    2010-01-31 03:34 . 2001-08-17 14:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
    2010-01-31 03:01 . 2010-02-06 05:45 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2010-01-31 02:48 . 2010-02-05 01:45 -------- d-----w- c:\documents and settings\user\Application Data\IObit
    2010-01-31 02:48 . 2010-01-31 02:48 -------- d-----w- c:\program files\IObit
    2010-01-31 00:50 . 2010-01-31 00:50 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Help
    2010-01-30 23:57 . 2010-01-30 23:57 -------- d-----w- c:\documents and settings\user\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2010-01-30 23:22 . 2009-11-20 11:08 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2010-01-30 23:22 . 2010-01-30 23:22 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2010-01-30 23:20 . 2010-01-30 23:20 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2010-01-30 23:16 . 2010-02-01 17:37 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Adobe
    2010-01-30 23:15 . 2010-01-30 23:16 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
    2010-01-30 22:21 . 2010-01-30 22:21 -------- d-----w- c:\program files\Common Files\Java
    2010-01-30 20:47 . 2010-01-30 20:49 50354 ----a-w- c:\documents and settings\user\Application Data\Facebook\uninstall.exe
    2010-01-30 20:47 . 2010-01-31 03:01 -------- d-----w- c:\documents and settings\user\Application Data\Facebook
    2010-01-30 03:57 . 2010-01-30 03:57 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft Help
    2010-01-30 03:46 . 2010-01-30 03:46 -------- d-----w- C:\spoolerlogs
    2010-01-28 23:56 . 2010-01-28 23:56 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
    2010-01-28 23:54 . 2010-01-28 23:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2010-01-28 23:53 . 2010-01-30 03:51 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
    2010-01-28 23:53 . 2009-08-16 02:01 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
    2010-01-28 23:53 . 2010-02-07 05:37 -------- d-----w- c:\documents and settings\Administrator
    2010-01-28 23:51 . 2010-01-28 23:51 4 ----a-w- c:\program files\2783453.dat
    2010-01-27 23:27 . 2010-01-27 23:27 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Sophos
    2010-01-27 23:06 . 2010-01-30 03:54 -------- d-----w- C:\stdtsa
    2010-01-27 21:16 . 2010-01-27 21:22 -------- d-----w- c:\documents and settings\user\Application Data\QuickScan
    2010-01-27 03:52 . 2010-01-27 20:36 220257 ----a-w- c:\windows\system32\drivers\sfi.dat
    2010-01-27 03:21 . 2010-01-27 03:21 847040 ----a-w- c:\documents and settings\user\Application Data\Facebook\axfbootloader.dll
    2010-01-27 03:20 . 2010-01-27 03:20 5578752 ----a-w- c:\documents and settings\user\Application Data\Facebook\npfbplugin_1_0_1.dll
    2010-01-26 23:40 . 2010-01-26 23:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2010-01-26 03:00 . 2010-01-26 03:00 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
    2010-01-24 17:54 . 2010-01-30 03:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Systweak
    2010-01-24 17:46 . 2010-01-30 03:56 -------- d-----w- c:\program files\Advanced System Optimizer 3
    2010-01-19 13:36 . 2010-01-24 16:14 -------- d-----w- c:\documents and settings\user\Application Data\Epson
    2010-01-19 13:33 . 2010-01-19 13:33 -------- d-----w- c:\windows\system32\wbem\Repository
    2010-01-19 13:32 . 2010-02-05 00:44 -------- d-----w- c:\program files\Common Files\Acronis
    2010-01-19 13:32 . 2010-01-19 13:32 -------- d-----w- c:\program files\Panda Security
    2010-01-13 23:35 . 2010-01-13 23:35 -------- d-----w- c:\documents and settings\All Users\Application Data\UDL
    2010-01-13 23:25 . 2010-01-13 23:25 -------- dc----w- c:\windows\system32\DRVSTORE
    2010-01-13 23:25 . 2010-01-13 23:38 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
    2010-01-13 06:44 . 2010-01-13 07:03 -------- d-----w- c:\program files\Platinum Guard
    2010-01-12 00:54 . 2010-01-12 00:54 -------- d-----w- c:\program files\Common Files\Apple
    2010-01-11 00:46 . 2010-01-11 00:46 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\WMTools Downloaded Files

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-02-08 23:57 . 2009-06-18 13:39 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
    2010-02-08 15:21 . 2009-09-23 21:24 -------- d-----w- c:\documents and settings\user\Application Data\dvdcss
    2010-02-08 11:41 . 2009-07-29 19:45 -------- d-----w- c:\program files\dvdSanta
    2010-02-07 04:33 . 2009-07-25 16:12 -------- d-----w- c:\program files\ATI Technologies
    2010-02-06 20:27 . 2009-06-03 21:34 -------- d-----w- c:\program files\Google
    2010-02-05 22:59 . 2009-06-11 22:10 67216 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-02-05 22:18 . 2009-08-15 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2010-02-05 22:13 . 2009-06-20 07:24 -------- d-----w- c:\program files\MSBuild
    2010-02-05 21:33 . 2009-06-03 08:32 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-02-03 01:06 . 2009-07-16 02:20 540000 ----a-w- c:\windows\system32\drivers\timntr.sys
    2010-02-03 01:06 . 2009-07-16 02:20 44704 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
    2010-02-01 03:41 . 2010-01-08 05:26 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
    2010-02-01 00:03 . 2009-12-29 15:33 -------- d-----w- c:\program files\XP Repair Pro 4.0
    2010-01-31 03:54 . 2009-06-01 19:52 -------- d-----w- c:\program files\Common Files\Adobe
    2010-01-30 22:19 . 2009-06-27 14:45 -------- d-----w- c:\program files\Java
    2010-01-30 20:27 . 2009-12-27 03:25 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-01-30 09:14 . 2009-08-04 20:44 -------- d-----w- c:\program files\QuickTime
    2010-01-30 09:14 . 2009-12-08 12:58 -------- d-----w- c:\program files\Virgin Broadband Wireless
    2010-01-30 09:14 . 2009-06-11 16:37 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-01-30 03:56 . 2009-08-04 20:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
    2010-01-30 03:56 . 2009-06-03 23:53 -------- d-----w- c:\program files\Lexmark 2300 Series
    2010-01-28 23:06 . 2009-06-01 19:46 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
    2010-01-26 07:53 . 2009-06-03 23:54 -------- d-----w- c:\program files\Lx_cats
    2010-01-24 13:49 . 2010-01-17 20:39 6652 ----a-w- c:\documents and settings\user\Application Data\settings.dat
    2010-01-21 11:30 . 2009-06-03 21:29 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-01-13 23:31 . 2009-06-03 08:32 -------- d-----w- c:\program files\Common Files\InstallShield
    2010-01-13 23:26 . 2010-01-13 23:26 -------- d-----w- c:\documents and settings\user\Application Data\InstallShield
    2010-01-11 00:25 . 2009-12-09 22:58 -------- d-----w- c:\documents and settings\user\Application Data\LimeWire
    2010-01-08 22:03 . 2009-12-27 03:30 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
    2010-01-08 05:26 . 2010-01-08 05:26 -------- d-----w- c:\program files\DVD Shrink
    2010-01-07 16:07 . 2009-12-27 03:26 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-01-07 16:07 . 2009-12-27 03:25 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-01-05 21:31 . 2009-06-19 20:50 -------- d-----w- c:\program files\Windows Media Connect 2
    2009-12-31 18:43 . 2009-06-18 13:33 -------- d-----w- c:\program files\Common Files\LogiShrd
    2009-12-29 15:43 . 2009-12-29 15:43 32038 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{FE74C184-4939-4FFA-B8C9-8E0CD6A6AA57}\ARPPRODUCTICON.exe
    2009-12-26 17:11 . 2009-06-07 13:08 -------- d-----w- c:\program files\DivX
    2009-12-21 19:14 . 2006-02-28 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-12-17 17:14 . 2009-06-27 14:45 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-12-15 16:48 . 2009-12-15 16:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-12-14 20:23 . 2009-06-11 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-12-12 20:40 . 2009-12-12 20:40 -------- d-----w- c:\documents and settings\user\Application Data\OpenDNS Updater
    2009-12-08 16:04 . 2009-12-08 16:04 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
    2009-12-08 16:03 . 2009-12-08 16:03 79488 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
    2009-12-08 15:26 . 2009-12-08 15:22 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-12-08 15:26 . 2009-12-08 15:22 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-12-08 15:26 . 2009-12-08 15:22 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-12-08 15:26 . 2009-12-08 15:22 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-12-08 15:26 . 2009-12-08 15:22 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
    2009-11-21 15:51 . 2006-02-28 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
    2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
    2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
    .
    Code:
    <pre>
    c:\program files\Advanced System Optimizer 3\memoryoptimizer .exe
    c:\program files\Advanced System Optimizer 3\systemprotector       .exe
    c:\program files\Common Files\LogiShrd\LComMgr\communications_helper .exe
    c:\program files\Lexmark 2300 Series\ezprint .exe
    c:\program files\Lexmark 2300 Series\lxcgmon .exe
    c:\program files\Logitech\QuickCam10\quickcam10 .exe
    c:\program files\Malwarebytes' Anti-Malware\mbam .exe
    c:\program files\Microsoft Office\Office12\groovemonitor .exe
    c:\program files\QuickTime\qttask     .exe
    c:\program files\Windows Live\Messenger\msnmsgr  .exe
    c:\program files\XP Repair Pro 4.0\controlcenter .exe
    c:\windows\pchealth\helpctr\binaries\msconfig .exe
    </pre>
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Wireless Manager "= "c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
    "AVG8_TRAY "= "c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-11 2043160]
    "Malwarebytes' Anti-Malware "= "c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-07 429392]

    c:\documents and settings\user\Start Menu\Programs\Startup\
    CCC.lnk.disabled [2009-7-25 841]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-12-08 15:26 11952 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32

    [HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
    backup=c:\windows\pss\Microsoft Office Groove.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^Secunia PSI.lnk]
    backup=c:\windows\pss\Secunia PSI.lnkStartup
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_Reader
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Internet Security
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mealbend
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemProtector
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Systweak Memory Optimizer
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPRP Control Center

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
    2010-01-06 15:33 2335952 ----a-w- c:\program files\IObit\Advanced SystemCare 3\AWC.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
    2005-05-03 17:43 69632 ----a-w- c:\windows\ALCMTR.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2009-12-08 19:09 135664 ----atw- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    c:\program files\Microsoft Office\Office12\GrooveMonitor.exe [N/A]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
    2007-02-08 01:12 488984 ----a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
    2007-02-08 01:13 774168 ----a-w- c:\program files\Logitech\QuickCam10\QuickCam10.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCGCATS]
    2005-07-20 12:48 73728 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\lxcgtime.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcgmon.exe]
    [N/A]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
    2009-02-06 17:51 3885408 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr .exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    2009-09-29 22:13 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2010-02-05 17:56 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "msnmsgr "=REM "c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
    "ctfmon.exe "=c:\windows\system32\ctfmon.exe
    "Advanced SystemCare 3 "= "c:\program files\IObit\Advanced SystemCare 3\AWC.exe" /startup

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "AlcWzrd "=ALCWZRD.EXE
    "SoundMan "=SOUNDMAN.EXE
    "GrooveMonitor "=REM "c:\program files\Microsoft Office\Office12\GrooveMonitor.exe "
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe "

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe "=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe "=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgam.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgdiag.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe "=
    "c:\\Program Files\\XP Repair Pro 4.0\\RegistryRepair.exe "=
    "c:\\Program Files\\XP Repair Pro 4.0\\DiskCleanup.exe "=
    "c:\\Program Files\\XP Repair Pro 4.0\\RegistryDefrag.exe "=
    "c:\\Program Files\\Windows Media Player\\wmplayer.exe "=

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [08/12/2009 15:22 12552]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [08/12/2009 15:22 335240]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [08/12/2009 15:22 108552]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [08/12/2009 15:22 297752]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [27/12/2009 03:26 236368]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [27/12/2009 03:25 19160]
    S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS --> c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
    S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys --> c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys [?]
    S2 FlexService;Remote Connections Service; "c:\program files\RapidBIT\cisvc.exe" --> c:\program files\RapidBIT\cisvc.exe [?]
    S2 gupdate1c9e7712253ae80;Google Update Service (gupdate1c9e7712253ae80);c:\program files\Google\Update\GoogleUpdate.exe [07/06/2009 13:09 133104]
    S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [08/11/2004 17:59 2825088]
    S3 ADASPROT;SYSTWEAKASO;\??\c:\program files\Advanced System Optimizer 3\adasprot32.sys --> c:\program files\Advanced System Optimizer 3\adasprot32.sys [?]
    S3 DrmRAudio;DrmRAudio;c:\windows\system32\drivers\DrmRAudio.sys [23/07/2009 02:23 23096]
    S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [17/06/2009 12:20 12648]
    S3 SASENUM;SASENUM;\??\c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS --> c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS [?]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-07 13:08]

    2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-07 13:08]

    2010-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-507921405-2000478354-839522115-1004Core.job
    - c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-05 19:09]

    2010-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-507921405-2000478354-839522115-1004UA.job
    - c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-05 19:09]

    2010-02-05 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
    - c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2009-06-11 14:31]

    2010-02-08 c:\windows\Tasks\User_Feed_Synchronization-{E2DEE579-4556-408C-9730-1CDFAE486098}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 04:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\a7qdwyy7.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:eek:fficial
    FF - prefs.js: keyword.URL - hxxp://www.google.com/search?&q=
    FF - prefs.js: network.proxy.http - 66.63.165.11
    FF - prefs.js: network.proxy.http_port - 3128
    FF - prefs.js: network.proxy.type - 4
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - plugin: c:\documents and settings\user\Application Data\Facebook\npfbplugin_1_0_1.dll
    FF - plugin: c:\documents and settings\user\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: browser.cache.memory.capacity - 16000
    FF - user.js: browser.chrome.favicons - false
    FF - user.js: browser.display.show_image_placeholders - true
    FF - user.js: browser.turbo.enabled - true
    FF - user.js: browser.urlbar.autocomplete.enabled - true
    FF - user.js: browser.urlbar.autofill - true
    FF - user.js: content.max.tokenizing.time - 3000000
    FF - user.js: content.maxtextrun - 4095
    FF - user.js: content.notify.backoffcount - 5
    FF - user.js: content.notify.interval - 1000000
    FF - user.js: content.notify.ontimer - true
    FF - user.js: content.switch.threshold - 1000000
    FF - user.js: dom.disable_window_status_change - true
    FF - user.js: network.http.max-connections - 48
    FF - user.js: network.http.max-connections-per-server - 16
    FF - user.js: network.http.max-persistent-connections-per-proxy - 16
    FF - user.js: network.http.max-persistent-connections-per-server - 8
    FF - user.js: network.http.pipelining - true
    FF - user.js: network.http.pipelining.firstrequest - true
    FF - user.js: network.http.pipelining.maxrequests - 8
    FF - user.js: network.http.proxy.pipelining - true
    FF - user.js: network.http.request.max-start-delay - 0
    FF - user.js: nglayout.initialpaint.delay - 1000
    FF - user.js: plugin.expose_full_path - true
    FF - user.js: ui.submenuDelay - 0
    FF - user.js: yahoo.homepage.dontask - true
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_popup_windows ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.enable_click_image_resizing ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "accessibility.browsewithcaret_shortcut.enabled ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "javascript.options.mem.high_water_mark ", 32);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "javascript.options.mem.gc_frequency ", 1600);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.trackpoint_hack.enabled ", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.debug ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.agedWeight ", 2);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.bucketSize ", 1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.maxTimeGroupings ", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.timeGroupingSize ", 604800);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.boundaryWeight ", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.prefixWeight ", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "html5.enable ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "app.update.download.backgroundInterval ", 600);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "app.update.url.manual ", "http://www.firefox.com ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-ja ", "mozff ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add ", "addons.mozilla.org ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add.36 ", "getpersonas.com ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "lightweightThemes.update.enabled ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.allTabs.previews ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.hide_infobar_for_outdated_plugin ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "toolbar.customization.usesheet ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.enable ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.max ", 20);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.cachetime ", 20);
    .
    .
    ------- File Associations -------
    .
    JSEFile=NOTEPAD.EXE %1
    .
    - - - - ORPHANS REMOVED - - - -

    Toolbar-Locked - (no file)
    WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-02-08 23:57
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-507921405-2000478354-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(700)
    c:\windows\system32\Ati2evxx.dll

    - - - - - - - > 'explorer.exe'(6380)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\Ati2evxx.exe
    c:\windows\system32\Ati2evxx.exe
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    c:\program files\Virgin Broadband Wireless\AffinegyService.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\progra~1\AVG\AVG8\avgam.exe
    c:\progra~1\AVG\AVG8\avgrsx.exe
    c:\progra~1\AVG\AVG8\avgnsx.exe
    c:\program files\AVG\AVG8\avgcsrvx.exe
    c:\windows\system32\wbem\wmiapsrv.exe
    c:\program files\Virgin Broadband Wireless\ndis_events.exe
    .
    **************************************************************************
    .
    Completion time: 2010-02-09 00:01:07 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-02-09 00:01

    Pre-Run: 26,301,661,184 bytes free
    Post-Run: 26,155,061,248 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= "Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut

    - - End Of File - - 00FD5FED106BCCDF8617E9113539EF1E
     
  8. 2010/02/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm glad, your computer is doing better :)
    I'll surely let you know, when it's totally clean and I'll give some other advice.
    One thing at a time.
    I'll review your Combofix log, but I still need fresh HJT log.
     
  9. 2010/02/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    1. Please open Notepad
    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    Code:
    File::
    c:\program files\2783453.dat
    c:\windows\system32\drivers\lvuvc.hs
    c:\program files\Advanced System Optimizer 3\memoryoptimizer .exe
    c:\program files\Advanced System Optimizer 3\systemprotector       .exe
    c:\program files\Common Files\LogiShrd\LComMgr\communications_helper .exe
    c:\program files\Lexmark 2300 Series\ezprint .exe
    c:\program files\Lexmark 2300 Series\lxcgmon .exe
    c:\program files\Logitech\QuickCam10\quickcam10 .exe
    c:\program files\Malwarebytes' Anti-Malware\mbam .exe
    c:\program files\Microsoft Office\Office12\groovemonitor .exe
    c:\program files\QuickTime\qttask     .exe
    c:\program files\Windows Live\Messenger\msnmsgr  .exe
    c:\program files\XP Repair Pro 4.0\controlcenter .exe
    c:\windows\pchealth\helpctr\binaries\msconfig .exe
    c:\windows\ALCMTR.EXE
    
    
    Folder::
    
    Driver::
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
    
    RegLockDel::
    
    

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    [​IMG]


    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    • Combofix.txt
    • A new HijackThis log.
     
  10. 2010/02/09
    scouse71

    scouse71 Inactive Thread Starter

    Joined:
    2010/01/29
    Messages:
    10
    Likes Received:
    0
    Apologies for jumping the gun , i got a little excited & fascinated with your work. Here are the requested logs :-

    ComboFix 10-02-08.09 - user 09/02/2010 13:12:17.2.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.511.262 [GMT 0:00]
    Running from: c:\documents and settings\user\Start Menu\My Documents\Downloads\ComboFix.exe
    Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt
    AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    FILE ::
    "c:\program files\2783453.dat "
    "c:\program files\Advanced System Optimizer 3\memoryoptimizer .exe "
    "c:\program files\Advanced System Optimizer 3\systemprotector .exe "
    "c:\program files\Common Files\LogiShrd\LComMgr\communications_helper .exe "
    "c:\program files\Lexmark 2300 Series\ezprint .exe "
    "c:\program files\Lexmark 2300 Series\lxcgmon .exe "
    "c:\program files\Logitech\QuickCam10\quickcam10 .exe "
    "c:\program files\Malwarebytes' Anti-Malware\mbam .exe "
    "c:\program files\Microsoft Office\Office12\groovemonitor .exe "
    "c:\program files\QuickTime\qttask .exe "
    "c:\program files\Windows Live\Messenger\msnmsgr .exe "
    "c:\program files\XP Repair Pro 4.0\controlcenter .exe "
    "c:\windows\ALCMTR.EXE "
    "c:\windows\pchealth\helpctr\binaries\msconfig .exe "
    "c:\windows\system32\drivers\lvuvc.hs "
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\2783453.dat
    c:\program files\Advanced System Optimizer 3\memoryoptimizer .exe
    c:\program files\Advanced System Optimizer 3\systemprotector .exe
    c:\program files\Common Files\LogiShrd\LComMgr\communications_helper .exe
    c:\program files\Lexmark 2300 Series\ezprint .exe
    c:\program files\Lexmark 2300 Series\lxcgmon .exe
    c:\program files\Logitech\QuickCam10\quickcam10 .exe
    c:\program files\Malwarebytes' Anti-Malware\mbam .exe
    c:\program files\Microsoft Office\Office12\groovemonitor .exe
    c:\program files\QuickTime\qttask .exe
    c:\program files\Windows Live\Messenger\msnmsgr .exe
    c:\program files\XP Repair Pro 4.0\controlcenter .exe
    c:\windows\ALCMTR.EXE
    c:\windows\pchealth\helpctr\binaries\msconfig .exe
    c:\windows\system32\drivers\lvuvc.hs

    .
    ((((((((((((((((((((((((( Files Created from 2010-01-09 to 2010-02-09 )))))))))))))))))))))))))))))))
    .

    2010-02-08 14:47 . 2010-02-08 14:47 -------- d-----w- c:\documents and settings\All Users\Application Data\vsosdk
    2010-02-08 13:04 . 2010-02-08 13:04 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
    2010-02-08 13:04 . 2010-02-08 13:04 47360 ----a-w- c:\documents and settings\user\Application Data\pcouffin.sys
    2010-02-08 13:04 . 2010-02-08 15:12 -------- d-----w- c:\documents and settings\user\Application Data\Vso
    2010-02-08 13:03 . 2009-09-02 16:41 65602 ----a-w- c:\windows\system32\cook3260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 217127 ----a-w- c:\windows\system32\drv43260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 208935 ----a-w- c:\windows\system32\drv33260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 176165 ----a-w- c:\windows\system32\drv23260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 102439 ----a-w- c:\windows\system32\sipr3260.dll
    2010-02-08 13:03 . 2009-09-02 16:41 626688 ----a-w- c:\windows\system32\vp7vfw.dll
    2010-02-08 13:03 . 2009-09-02 16:41 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
    2010-02-08 13:03 . 2010-02-08 13:03 -------- d-----w- c:\program files\VSO
    2010-02-07 04:42 . 2010-02-07 04:42 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
    2010-02-06 20:42 . 2010-02-06 20:42 -------- d-----w- c:\documents and settings\user\BackUp
    2010-02-05 21:37 . 2010-02-09 06:15 -------- d-----w- c:\documents and settings\user\Application Data\vlc
    2010-02-05 08:01 . 2010-02-05 08:01 -------- d-----w- c:\program files\Secunia
    2010-02-03 01:18 . 2010-02-03 03:04 971232 ----a-w- c:\windows\system32\drivers\tdrpm147.sys
    2010-02-03 01:05 . 2010-02-03 01:05 -------- d-----w- c:\program files\Acronis
    2010-02-03 00:55 . 2010-02-05 01:45 -------- d-----w- c:\program files\RapidBIT
    2010-02-02 20:55 . 2010-02-02 20:55 -------- d-----w- C:\Win. Hotmail
    2010-02-02 20:43 . 2010-02-02 20:45 -------- dc-h--w- c:\windows\ie8
    2010-01-31 05:11 . 2010-01-31 05:11 0 ----a-w- c:\windows\nsreg.dat
    2010-01-31 05:11 . 2010-01-31 05:11 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
    2010-01-31 05:10 . 2010-01-31 05:10 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee
    2010-01-31 03:34 . 2001-08-17 14:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
    2010-01-31 03:01 . 2010-02-06 05:45 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2010-01-31 02:48 . 2010-02-05 01:45 -------- d-----w- c:\documents and settings\user\Application Data\IObit
    2010-01-31 02:48 . 2010-01-31 02:48 -------- d-----w- c:\program files\IObit
    2010-01-31 00:50 . 2010-01-31 00:50 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Help
    2010-01-30 23:57 . 2010-01-30 23:57 -------- d-----w- c:\documents and settings\user\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2010-01-30 23:22 . 2009-11-20 11:08 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2010-01-30 23:22 . 2010-01-30 23:22 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2010-01-30 23:20 . 2010-01-30 23:20 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2010-01-30 23:16 . 2010-02-01 17:37 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Adobe
    2010-01-30 23:15 . 2010-01-30 23:16 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
    2010-01-30 22:21 . 2010-01-30 22:21 -------- d-----w- c:\program files\Common Files\Java
    2010-01-30 20:47 . 2010-01-30 20:49 50354 ----a-w- c:\documents and settings\user\Application Data\Facebook\uninstall.exe
    2010-01-30 20:47 . 2010-01-31 03:01 -------- d-----w- c:\documents and settings\user\Application Data\Facebook
    2010-01-30 03:57 . 2010-01-30 03:57 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft Help
    2010-01-30 03:46 . 2010-01-30 03:46 -------- d-----w- C:\spoolerlogs
    2010-01-28 23:56 . 2010-01-28 23:56 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
    2010-01-28 23:54 . 2010-01-28 23:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2010-01-28 23:53 . 2010-01-30 03:51 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
    2010-01-28 23:53 . 2009-08-16 02:01 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
    2010-01-28 23:53 . 2010-02-07 05:37 -------- d-----w- c:\documents and settings\Administrator
    2010-01-27 23:27 . 2010-01-27 23:27 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Sophos
    2010-01-27 23:06 . 2010-01-30 03:54 -------- d-----w- C:\stdtsa
    2010-01-27 21:16 . 2010-01-27 21:22 -------- d-----w- c:\documents and settings\user\Application Data\QuickScan
    2010-01-27 03:52 . 2010-01-27 20:36 220257 ----a-w- c:\windows\system32\drivers\sfi.dat
    2010-01-27 03:21 . 2010-01-27 03:21 847040 ----a-w- c:\documents and settings\user\Application Data\Facebook\axfbootloader.dll
    2010-01-27 03:20 . 2010-01-27 03:20 5578752 ----a-w- c:\documents and settings\user\Application Data\Facebook\npfbplugin_1_0_1.dll
    2010-01-26 23:40 . 2010-01-26 23:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2010-01-26 03:00 . 2010-01-26 03:00 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
    2010-01-24 17:54 . 2010-01-30 03:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Systweak
    2010-01-24 17:46 . 2010-02-09 13:17 -------- d-----w- c:\program files\Advanced System Optimizer 3
    2010-01-19 13:36 . 2010-01-24 16:14 -------- d-----w- c:\documents and settings\user\Application Data\Epson
    2010-01-19 13:33 . 2010-01-19 13:33 -------- d-----w- c:\windows\system32\wbem\Repository
    2010-01-19 13:32 . 2010-02-05 00:44 -------- d-----w- c:\program files\Common Files\Acronis
    2010-01-19 13:32 . 2010-01-19 13:32 -------- d-----w- c:\program files\Panda Security
    2010-01-13 23:35 . 2010-01-13 23:35 -------- d-----w- c:\documents and settings\All Users\Application Data\UDL
    2010-01-13 23:25 . 2010-01-13 23:25 -------- dc----w- c:\windows\system32\DRVSTORE
    2010-01-13 23:25 . 2010-01-13 23:38 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
    2010-01-13 06:44 . 2010-01-13 07:03 -------- d-----w- c:\program files\Platinum Guard
    2010-01-12 00:54 . 2010-01-12 00:54 -------- d-----w- c:\program files\Common Files\Apple
    2010-01-11 00:46 . 2010-01-11 00:46 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\WMTools Downloaded Files

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-02-09 13:17 . 2009-12-29 15:33 -------- d-----w- c:\program files\XP Repair Pro 4.0
    2010-02-09 13:17 . 2009-08-04 20:44 -------- d-----w- c:\program files\QuickTime
    2010-02-09 13:17 . 2009-12-27 03:25 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-02-09 13:17 . 2009-06-03 23:53 -------- d-----w- c:\program files\Lexmark 2300 Series
    2010-02-08 15:21 . 2009-09-23 21:24 -------- d-----w- c:\documents and settings\user\Application Data\dvdcss
    2010-02-08 11:41 . 2009-07-29 19:45 -------- d-----w- c:\program files\dvdSanta
    2010-02-07 04:33 . 2009-07-25 16:12 -------- d-----w- c:\program files\ATI Technologies
    2010-02-06 20:27 . 2009-06-03 21:34 -------- d-----w- c:\program files\Google
    2010-02-05 22:59 . 2009-06-11 22:10 67216 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-02-05 22:18 . 2009-08-15 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2010-02-05 22:13 . 2009-06-20 07:24 -------- d-----w- c:\program files\MSBuild
    2010-02-05 21:33 . 2009-06-03 08:32 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-02-03 01:06 . 2009-07-16 02:20 540000 ----a-w- c:\windows\system32\drivers\timntr.sys
    2010-02-03 01:06 . 2009-07-16 02:20 44704 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
    2010-02-01 03:41 . 2010-01-08 05:26 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
    2010-01-31 03:54 . 2009-06-01 19:52 -------- d-----w- c:\program files\Common Files\Adobe
    2010-01-30 22:19 . 2009-06-27 14:45 -------- d-----w- c:\program files\Java
    2010-01-30 09:14 . 2009-12-08 12:58 -------- d-----w- c:\program files\Virgin Broadband Wireless
    2010-01-30 09:14 . 2009-06-11 16:37 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-01-30 03:56 . 2009-08-04 20:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
    2010-01-28 23:06 . 2009-06-01 19:46 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
    2010-01-26 07:53 . 2009-06-03 23:54 -------- d-----w- c:\program files\Lx_cats
    2010-01-24 13:49 . 2010-01-17 20:39 6652 ----a-w- c:\documents and settings\user\Application Data\settings.dat
    2010-01-21 11:30 . 2009-06-03 21:29 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-01-13 23:31 . 2009-06-03 08:32 -------- d-----w- c:\program files\Common Files\InstallShield
    2010-01-13 23:26 . 2010-01-13 23:26 -------- d-----w- c:\documents and settings\user\Application Data\InstallShield
    2010-01-11 00:25 . 2009-12-09 22:58 -------- d-----w- c:\documents and settings\user\Application Data\LimeWire
    2010-01-08 22:03 . 2009-12-27 03:30 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
    2010-01-08 05:26 . 2010-01-08 05:26 -------- d-----w- c:\program files\DVD Shrink
    2010-01-07 16:07 . 2009-12-27 03:26 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-01-07 16:07 . 2009-12-27 03:25 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-01-05 21:31 . 2009-06-19 20:50 -------- d-----w- c:\program files\Windows Media Connect 2
    2009-12-31 18:43 . 2009-06-18 13:33 -------- d-----w- c:\program files\Common Files\LogiShrd
    2009-12-29 15:43 . 2009-12-29 15:43 32038 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{FE74C184-4939-4FFA-B8C9-8E0CD6A6AA57}\ARPPRODUCTICON.exe
    2009-12-26 17:11 . 2009-06-07 13:08 -------- d-----w- c:\program files\DivX
    2009-12-21 19:14 . 2006-02-28 12:00 916480 ------w- c:\windows\system32\wininet.dll
    2009-12-17 17:14 . 2009-06-27 14:45 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-12-15 16:48 . 2009-12-15 16:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-12-14 20:23 . 2009-06-11 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-12-12 20:40 . 2009-12-12 20:40 -------- d-----w- c:\documents and settings\user\Application Data\OpenDNS Updater
    2009-12-08 16:04 . 2009-12-08 16:04 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
    2009-12-08 16:03 . 2009-12-08 16:03 79488 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
    2009-12-08 15:26 . 2009-12-08 15:22 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-12-08 15:26 . 2009-12-08 15:22 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-12-08 15:26 . 2009-12-08 15:22 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-12-08 15:26 . 2009-12-08 15:22 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-12-08 15:26 . 2009-12-08 15:22 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
    2009-11-21 15:51 . 2006-02-28 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
    2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
    2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
    .

    ((((((((((((((((((((((((((((( SnapShot@2010-02-08_23.57.41 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2010-02-09 11:56 . 2010-02-09 11:56 16384 c:\windows\Temp\Perflib_Perfdata_24c.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Wireless Manager "= "c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
    "AVG8_TRAY "= "c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-11 2043160]
    "Malwarebytes' Anti-Malware "= "c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-07 429392]

    c:\documents and settings\user\Start Menu\Programs\Startup\
    CCC.lnk.disabled [2009-7-25 841]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-12-08 15:26 11952 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32

    [HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
    backup=c:\windows\pss\Microsoft Office Groove.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^Secunia PSI.lnk]
    backup=c:\windows\pss\Secunia PSI.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
    2010-01-06 15:33 2335952 ----a-w- c:\program files\IObit\Advanced SystemCare 3\AWC.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2009-12-08 19:09 135664 ----atw- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
    2007-02-08 01:12 488984 ----a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
    2007-02-08 01:13 774168 ----a-w- c:\program files\Logitech\QuickCam10\QuickCam10.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXCGCATS]
    2005-07-20 12:48 73728 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\lxcgtime.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    2009-09-29 22:13 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2010-02-05 17:56 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "msnmsgr "=REM "c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
    "ctfmon.exe "=c:\windows\system32\ctfmon.exe
    "Advanced SystemCare 3 "= "c:\program files\IObit\Advanced SystemCare 3\AWC.exe" /startup
    "SpybotSD TeaTimer "=c:\program files\Spybot - Search & Destroy\TeaTimer.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "AlcWzrd "=ALCWZRD.EXE
    "SoundMan "=SOUNDMAN.EXE
    "GrooveMonitor "=REM "c:\program files\Microsoft Office\Office12\GrooveMonitor.exe "
    "SunJavaUpdateSched "= "c:\program files\Java\jre6\bin\jusched.exe "

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "c:\\Program Files\\Messenger\\msmsgs.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe "=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe "=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgam.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgdiag.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe "=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe "=
    "c:\\Program Files\\XP Repair Pro 4.0\\RegistryRepair.exe "=
    "c:\\Program Files\\XP Repair Pro 4.0\\DiskCleanup.exe "=
    "c:\\Program Files\\XP Repair Pro 4.0\\RegistryDefrag.exe "=
    "c:\\Program Files\\Windows Media Player\\wmplayer.exe "=

    R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [08/12/2009 15:22 12552]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [08/12/2009 15:22 335240]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [08/12/2009 15:22 108552]
    R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [08/12/2009 15:22 297752]
    R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [27/12/2009 03:26 236368]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [27/12/2009 03:25 19160]
    S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS --> c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
    S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys --> c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys [?]
    S2 FlexService;Remote Connections Service; "c:\program files\RapidBIT\cisvc.exe" --> c:\program files\RapidBIT\cisvc.exe [?]
    S2 gupdate1c9e7712253ae80;Google Update Service (gupdate1c9e7712253ae80);c:\program files\Google\Update\GoogleUpdate.exe [07/06/2009 13:09 133104]
    S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [08/11/2004 17:59 2825088]
    S3 ADASPROT;SYSTWEAKASO;\??\c:\program files\Advanced System Optimizer 3\adasprot32.sys --> c:\program files\Advanced System Optimizer 3\adasprot32.sys [?]
    S3 DrmRAudio;DrmRAudio;c:\windows\system32\drivers\DrmRAudio.sys [23/07/2009 02:23 23096]
    S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [17/06/2009 12:20 12648]
    S3 SASENUM;SASENUM;\??\c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS --> c:\docume~1\user\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS [?]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-07 13:08]

    2010-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-07 13:08]

    2010-02-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-507921405-2000478354-839522115-1004Core.job
    - c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-05 19:09]

    2010-02-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-507921405-2000478354-839522115-1004UA.job
    - c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-05 19:09]

    2010-02-05 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
    - c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2009-06-11 14:31]

    2010-02-09 c:\windows\Tasks\User_Feed_Synchronization-{E2DEE579-4556-408C-9730-1CDFAE486098}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 04:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\a7qdwyy7.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:eek:fficial
    FF - prefs.js: keyword.URL - hxxp://www.google.com/search?&q=
    FF - prefs.js: network.proxy.http - 66.63.165.11
    FF - prefs.js: network.proxy.http_port - 3128
    FF - prefs.js: network.proxy.type - 4
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - plugin: c:\documents and settings\user\Application Data\Facebook\npfbplugin_1_0_1.dll
    FF - plugin: c:\documents and settings\user\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: browser.cache.memory.capacity - 16000
    FF - user.js: browser.chrome.favicons - false
    FF - user.js: browser.display.show_image_placeholders - true
    FF - user.js: browser.turbo.enabled - true
    FF - user.js: browser.urlbar.autocomplete.enabled - true
    FF - user.js: browser.urlbar.autofill - true
    FF - user.js: content.max.tokenizing.time - 3000000
    FF - user.js: content.maxtextrun - 4095
    FF - user.js: content.notify.backoffcount - 5
    FF - user.js: content.notify.interval - 1000000
    FF - user.js: content.notify.ontimer - true
    FF - user.js: content.switch.threshold - 1000000
    FF - user.js: dom.disable_window_status_change - true
    FF - user.js: network.http.max-connections - 48
    FF - user.js: network.http.max-connections-per-server - 16
    FF - user.js: network.http.max-persistent-connections-per-proxy - 16
    FF - user.js: network.http.max-persistent-connections-per-server - 8
    FF - user.js: network.http.pipelining - true
    FF - user.js: network.http.pipelining.firstrequest - true
    FF - user.js: network.http.pipelining.maxrequests - 8
    FF - user.js: network.http.proxy.pipelining - true
    FF - user.js: network.http.request.max-start-delay - 0
    FF - user.js: nglayout.initialpaint.delay - 1000
    FF - user.js: plugin.expose_full_path - true
    FF - user.js: ui.submenuDelay - 0
    FF - user.js: yahoo.homepage.dontask - true
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.use_native_popup_windows ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.enable_click_image_resizing ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "accessibility.browsewithcaret_shortcut.enabled ", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "javascript.options.mem.high_water_mark ", 32);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "javascript.options.mem.gc_frequency ", 1600);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "ui.trackpoint_hack.enabled ", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.debug ", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.agedWeight ", 2);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.bucketSize ", 1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.maxTimeGroupings ", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.timeGroupingSize ", 604800);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.boundaryWeight ", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "browser.formfill.prefixWeight ", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref( "html5.enable ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "app.update.download.backgroundInterval ", 600);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "app.update.url.manual ", "http://www.firefox.com ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-ja ", "mozff ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add ", "addons.mozilla.org ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add.36 ", "getpersonas.com ");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "lightweightThemes.update.enabled ", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.allTabs.previews ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.hide_infobar_for_outdated_plugin ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "toolbar.customization.usesheet ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.enable ", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.max ", 20);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.cachetime ", 20);
    .
    - - - - ORPHANS REMOVED - - - -

    MSConfigStartUp-GrooveMonitor - c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
    MSConfigStartUp-msnmsgr - c:\program files\windows live\messenger\msnmsgr .exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-02-09 13:18
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-507921405-2000478354-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(700)
    c:\windows\system32\Ati2evxx.dll
    .
    Completion time: 2010-02-09 13:21:00
    ComboFix-quarantined-files.txt 2010-02-09 13:20
    ComboFix2.txt 2010-02-09 00:01

    Pre-Run: 26,168,365,056 bytes free
    Post-Run: 26,104,221,696 bytes free

    Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
    - - End Of File - - F7879B8311A8A07D8C1FB78694BB1545

    = = = = = = = = = = = = = = =

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:32:05, on 09/02/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Documents and Settings\user\Start Menu\My Documents\Downloads\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    O4 - S-1-5-18 Startup: CCC.lnk.disabled (User 'SYSTEM')
    O4 - .DEFAULT Startup: CCC.lnk.disabled (User 'Default user')
    O4 - Startup: CCC.lnk.disabled
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Remote Connections Service (FlexService) - Unknown owner - C:\Program Files\RapidBIT\cisvc.exe (file missing)
    O23 - Service: Google Update Service (gupdate1c9e7712253ae80) (gupdate1c9e7712253ae80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

    --
    End of file - 5867 bytes
     
  11. 2010/02/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    1. Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.


    2. Go to Kaspersky website and perform an online antivirus scan.

    1. Disable your active antivirus program.
    2. Read through the requirements and privacy statement and click on Accept button.
    3. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    4. When the downloads have finished, click on Settings.
    5. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:

    • Spyware, Adware, Dialers, and other potentially dangerous programs
      [*] Archives
      [*] Mail databases
    6. Click on My Computer under Scan.
    7. Once the scan is complete, it will display the results. Click on View Scan Report.
    8. You will see a list of infected items there. Click on Save Report As....
    9. Save this report to a convenient place. Change the Files of type to Text file (.txt before clicking on the Save button. Then post it here.

    Post fresh HijackThis log as well.
     
  12. 2010/02/09
    scouse71

    scouse71 Inactive Thread Starter

    Joined:
    2010/01/29
    Messages:
    10
    Likes Received:
    0
    Hi broni, sorry it took so long i had to wait for my wife to finish.

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Tuesday, February 9, 2010
    Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Tuesday, February 09, 2010 19:18:59
    Records in database: 3458112
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    C:\
    D:\

    Scan statistics:
    Objects scanned: 41684
    Threats found: 2
    Infected objects found: 4
    Suspicious objects found: 0
    Scan duration: 01:59:12


    File name / Threat / Threats count
    C:\System Volume Information\_restore{CB2C589C-03CC-4A28-8BF4-B59ABBF062BF}\RP199\A0081721.old Infected: Trojan.Win32.Vilsel.rlb 1
    C:\System Volume Information\_restore{CB2C589C-03CC-4A28-8BF4-B59ABBF062BF}\RP199\A0081721.old Infected: Trojan-Clicker.Win32.Cycler.nmt 1
    C:\System Volume Information\_restore{CB2C589C-03CC-4A28-8BF4-B59ABBF062BF}\RP199\A0081722.old Infected: Trojan.Win32.Vilsel.rlb 1
    C:\System Volume Information\_restore{CB2C589C-03CC-4A28-8BF4-B59ABBF062BF}\RP199\A0081722.old Infected: Trojan-Clicker.Win32.Cycler.nmt 1

    Selected area has been scanned.


    = = = = = = = = = = = = = = = =

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:00:17, on 09/02/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\user\Start Menu\My Documents\Downloads\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe "
    O4 - S-1-5-18 Startup: CCC.lnk.disabled (User 'SYSTEM')
    O4 - .DEFAULT Startup: CCC.lnk.disabled (User 'Default user')
    O4 - Startup: CCC.lnk.disabled
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Remote Connections Service (FlexService) - Unknown owner - C:\Program Files\RapidBIT\cisvc.exe (file missing)
    O23 - Service: Google Update Service (gupdate1c9e7712253ae80) (gupdate1c9e7712253ae80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

    --
    End of file - 5681 bytes
     
  13. 2010/02/09
    scouse71

    scouse71 Inactive Thread Starter

    Joined:
    2010/01/29
    Messages:
    10
    Likes Received:
    0
    sorry had to delete i double posted.
     
    Last edited: 2010/02/09
  14. 2010/02/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    How are the issues?

    Uninstall Combofix:
    Go Start > Run [Vista users, go Start> "Start search"]
    Type in:
    Combofix /Uninstall
    Note the space between the "Combofix" and the "/Uninstall "
    Click OK (Vista users - press Enter).
    Restart computer.

    ================================================================

    Print this post out, since you won't have an access to it, at some point.

    1. Open HijackThis.

    2. Close all windows, except for HijackThis.

    3. Put checkmarks next to the following HijackThis entries:

    - R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    - R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    - O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    - O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)



    4. You should also checkmark following entries (these are unnecessary startups; no actual programs will be removed):

    - O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe "


    5. Click on Fix checked button.

    6. Go Start>Run (Vista users - "Start search "), type in:
    cmd
    Click OK (Vista users - hold CTRL, and SHIFT keys, press Enter).

    Command Prompt window will open.
    Type in:
    sc stop FlexService
    Press Enter.
    Wait for the service to be stopped.

    Type in:
    sc delete FlexService
    Press Enter.
    Wait for confirmation.

    7. Restart computer.

    8. Post new HijackThis log.
     
  15. 2010/02/09
    scouse71

    scouse71 Inactive Thread Starter

    Joined:
    2010/01/29
    Messages:
    10
    Likes Received:
    0
    Hi broni , the computer seems to be running back to normal , if not then a bit slower , but that could be down to my other half downloading stupidness and bloating the system. The original problem went as soon as i ran the first combofix.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 04:55:57, on 10/02/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\WINDOWS\system32\slserv.exe
    C:\PROGRA~1\AVG\AVG8\avgam.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Virgin Broadband Wireless\ndis_events.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\Documents and Settings\user\Start Menu\My Documents\Downloads\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skip-search.com/?cfg=2-82-0-khS5

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [Wireless Manager] "C:\Program Files\Virgin Broadband Wireless\Wireless Manager.exe" startup
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - S-1-5-18 Startup: CCC.lnk.disabled (User 'SYSTEM')
    O4 - .DEFAULT Startup: CCC.lnk.disabled (User 'Default user')
    O4 - Startup: CCC.lnk.disabled
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Virgin Broadband Wireless\AffinegyService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Google Update Service (gupdate1c9e7712253ae80) (gupdate1c9e7712253ae80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe (file missing)
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

    --
    End of file - 6199 bytes
     
  16. 2010/02/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    ...and the official word is....

    Your computer is clean :)

    1. Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore ".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C: ")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    2. Restart computer.

    3. Turn System Restore on.

    4. Make sure, Windows Updates are current.

    [SIZE= "4"]5. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately![/SIZE]

    6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    7. Run defrag at your convenience.

    8. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
     
  17. 2010/02/10
    scouse71

    scouse71 Inactive Thread Starter

    Joined:
    2010/01/29
    Messages:
    10
    Likes Received:
    0
    Hi broni , my system is back to normal thanks to you. If i could be cheeky & ask one more thing , i have Malwarebytes , ccleaner , AVG anti virus , XP repair pro , Advanced system care , Spybot & yooapps Sweepi all running on my computer. Talk about being paranoid:eek: ,could you advise on which to keep and get rid of as i read that too many counter act each other ? Thanks.
     
  18. 2010/02/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    AVG as your AV program is a must be application.
    Malwarebytes - must have program.
    CCleaner is fine, as long, as you don't touch registry part.
    I'd uninstall Spybot - it's not up to par program anymore.
    No need for three others.
     
  19. 2010/02/11
    scouse71

    scouse71 Inactive Thread Starter

    Joined:
    2010/01/29
    Messages:
    10
    Likes Received:
    0
    Thanks broni you are a star.
     
  20. 2010/02/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're welcome :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.