Options

Start-up Error

Hi,
My computer freezes on start-up with this error:

"Error Signature"
AppName: explore.exe
AppVer:6.0.2900.3241
ModName: Shell32.dll
ModVer:6.0.2900.3241
Offset:0004892b

-I tried reverting to a safe point but the problem persisted.
-I then ran a HJT scan and put the log into an analyzer which revealed several threats.
-All threats were deleted except for this: "C:\WINDOWS\explore.exe"

---Here is my resulting HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:13:26 AM, on 12/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>;*.local
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TrueTransparency] "C:\Documents and Settings\Bret Harper\Desktop\Tweaks\truetransparency-crystalxp.net-en-5139\TrueTransparency\TrueTransparency.exe"
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\Bret Harper\Application Data\gadcom\gadcom.exe" 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKCU\..\Run: [Windows Service] C:\Documents and Settings\Bret Harper\service.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {FC6703A7-5B7E-4f58-BE6D-2693AA3906AE} (HP Content Update) - http://h30043.www3.hp.com/netassist/en/check/install/gtdownhp.cab?1,0,0,94
O22 - SharedTaskScheduler: grassily - {4233ac08-a2c4-4742-a0b4-83719613d62c} - C:\WINDOWS\system32\ilmpjy.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSG20s.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 5134 bytes

Comments

  • VekaVeka Finland
    edited December 2008
    Hi, welcome to Icrontic.

    Step 1:

    Run Hijackthis and click on the Do a system scan only.

    Place a tick next to the following entries:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\Bret Harper\Application Data\gadcom\gadcom.exe" 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
    O4 - HKCU\..\Run: [Windows Service] C:\Documents and Settings\Bret Harper\service.exe

    Close all open windows or programs (including this one) and click on the Fix Checked.

    Step 2:

    Please download SDFix and save it to your Desktop.

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    Please then reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.

    Running SDFix in Safe Mode:
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to Clipboard ready for posting back on the forum).
    • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log.
  • edited December 2008
    Thanks for the help

    **Note: The following file you told me to check on HJT was not there when I rescanned, but was deleted with the SDFix scan

    O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\Bret Harper\Application Data\gadcom\gadcom.exe" 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

    here are both reports you asked for.



    SDFix: Version 1.240
    Run by Bret Harper on Wed 12/10/2008 at 12:52 AM

    Microsoft Windows XP [Version 5.1.2600]
    Running From: C:\SDFix

    Checking Services :


    Restoring Default Security Values
    Restoring Default Hosts File

    Rebooting


    Checking Files :

    Trojan Files Found:

    C:\WINDOWS\system32\nnnlklkj.dll - Deleted
    C:\Temp\1cb\syscheck.log - Deleted
    C:\WINDOWS\system32\winpfz33.sys - Deleted
    C:\WINDOWS\explore.exe - Deleted
    C:\WINDOWS\Fonts\Setup.exe - Deleted
    C:\WINDOWS\Fonts\svchost.exe - Deleted
    C:\WINDOWS\smdat32a.sys - Deleted
    C:\WINDOWS\system32\atmtd.dll._ - Deleted
    C:\WINDOWS\system32\dwwnw64r.exe - Deleted
    C:\WINDOWS\system32\msnav32.ax - Deleted
    C:\WINDOWS\system32\pac.txt - Deleted
    C:\WINDOWS\system32\zxdnt3d.cfg - Deleted
    C:\WINDOWS\Fonts\*.zip - 1 File(s) 115,951 bytes - Deleted


    Could Not Remove C:\WINDOWS\system32\drivers\core.cache.dsk

    Folder C:\Documents and Settings\Bret Harper\Application Data\gadcom - Removed
    Folder C:\Temp\1cb - Removed
    Folder C:\Temp\tn3 - Removed


    Removing Temp Files

    ADS Check :



    Final Check :

    disk not found C:\

    please note that you need administrator rights to perform deep scan

    Remaining Services :




    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
    "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
    "C:\\Program Files\\StreamCast\\Morpheus\\mldonkey\\mlnet.exe"="C:\\Program Files\\StreamCast\\Morpheus\\mldonkey\\mlnet.exe:*:Disabled:MLdonkey - multiuser P2P daemon"
    "C:\\Program Files\\StreamCast\\Morpheus\\MorphEXE.exe"="C:\\Program Files\\StreamCast\\Morpheus\\MorphEXE.exe:*:Enabled:Morpheus"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
    "C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
    "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
    "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Application Loader"
    "C:\\Program Files\\America Online 9.0a\\waol.exe"="C:\\Program Files\\America Online 9.0a\\waol.exe:*:Enabled:AOL"
    "C:\\Program Files\\Common Files\\AOL\\1145235296\\EE\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1145235296\\EE\\AOLServiceHost.exe:*:Enabled:AOL"
    "C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL"
    "C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"="C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe:*:Enabled:AOL"
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\game.exe"="C:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\game.exe:*:Disabled:Main executable for Red Alert 2"
    "C:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\mph.exe"="C:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\mph.exe:*:Disabled:mph"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    Remaining Files :

    C:\WINDOWS\system32\drivers\core.cache.dsk Found

    File Backups: - C:\SDFix\backups\backups.zip

    Files with Hidden Attributes :

    Tue 2 Aug 2005 187,904 A.SHR --- "C:\WINDOWS\QnJldCBIYXJwZXI\asappsrv.dll"
    Sun 28 Mar 2004 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
    Wed 30 Jun 2004 400 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.bla.bak"
    Wed 30 Jun 2004 48 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.sec.bak"
    Wed 30 Jun 2004 400 A.SH. --- "C:\Documents and Settings\All Users\DRM\v3ks.bla.bak"
    Thu 27 Jan 2005 1,810 A..H. --- "C:\Program Files\InterActual\InterActual Player\itiBC.tmp"
    Sat 29 Nov 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
    Fri 19 Jan 2007 19,968 ...H. --- "C:\Documents and Settings\Bret Harper\Application Data\Microsoft\Word\~WRL0080.tmp"
    Thu 18 Sep 2008 24,064 ...H. --- "C:\Documents and Settings\Bret Harper\My Documents\Christian\Humanities\~WRL0002.tmp"
    Thu 18 Sep 2008 25,600 ...H. --- "C:\Documents and Settings\Bret Harper\My Documents\Christian\Humanities\~WRL1134.tmp"
    Thu 18 Sep 2008 24,576 ...H. --- "C:\Documents and Settings\Bret Harper\My Documents\Christian\Humanities\~WRL2253.tmp"
    Thu 18 Sep 2008 28,672 ...H. --- "C:\Documents and Settings\Bret Harper\My Documents\Christian\Humanities\~WRL2827.tmp"
    Mon 8 Dec 2008 24,576 ...H. --- "C:\Documents and Settings\Bret Harper\My Documents\Christian\Surb\~WRL0004.tmp"

    Finished!






    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:19:38 AM, on 12/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\HPConfig.exe
    C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\vssvc.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\notepad.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>;*.local
    O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [6b0e693d] rundll32.exe "C:\WINDOWS\system32\fkkdkrfj.dll",b
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TrueTransparency] "C:\Documents and Settings\Bret Harper\Desktop\Tweaks\truetransparency-crystalxp.net-en-5139\TrueTransparency\TrueTransparency.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {FC6703A7-5B7E-4f58-BE6D-2693AA3906AE} (HP Content Update) - http://h30043.www3.hp.com/netassist/en/check/install/gtdownhp.cab?1,0,0,94
    O20 - AppInit_DLLs: utzioi.dll
    O22 - SharedTaskScheduler: grassily - {4233ac08-a2c4-4742-a0b4-83719613d62c} - C:\WINDOWS\system32\ilmpjy.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
    O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
    O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSG20s.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    --
    End of file - 5752 bytes

  • VekaVeka Finland
    edited December 2008
    Thank you.

    We will use ComboFix.exe next. Please visit this webpage for download links, and instructions for running the tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:
    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    2. Click Yes to allow ComboFix to continue scanning for malware.

    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New HijackThis log.
  • edited December 2008
    Everything went well with the directions you gave me. Here are the logs you asked for.


    ComboFix 08-12-09.02 - Bret Harper 2008-12-10 5:09:39.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.93 [GMT -5:00]
    Running from: c:\documents and settings\Bret Harper\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Bret Harper\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Bret Harper\Local Settings\Temporary Internet Files\fbk.sts
    c:\program files\FunWebProducts
    c:\program files\FunWebProducts\ScreenSaver\Images\05DCCF25.urr
    c:\program files\FunWebProducts\Shared\06F346B1.dat
    c:\program files\MyWay
    c:\program files\MyWay\myBar\History\search
    c:\program files\MyWay\myBar\Settings\prevcfg.htm
    c:\program files\MyWebSearch
    c:\program files\MyWebSearch\bar\History\search
    c:\program files\MyWebSearch\bar\Settings\s_pid.dat
    c:\program files\MyWebSearch\bar\Settings\settings.dat
    c:\program files\MyWebSearch\bar\Settings\settings.htm
    c:\temp\DIV55
    c:\temp\DIV55\xDb.log
    c:\temp\FT62
    c:\temp\FT62\teTU.log
    c:\windows\Downloaded Program Files\setup.inf
    c:\windows\Fonts\'
    c:\windows\smdat32m.sys
    c:\windows\system32\axurhagw.dll
    c:\windows\system32\dPI02
    c:\windows\system32\dPI02\dPI022328.exe
    c:\windows\system32\fkkdkrfj.dll
    c:\windows\system32\poWyIRqr.ini
    c:\windows\system32\poWyIRqr.ini2
    c:\windows\system32\rqRIyWop.dll
    c:\windows\system32\s5
    c:\windows\system32\s5\HIDR6I35.exe
    c:\windows\system32\tmp.reg
    c:\windows\system32\utzioi.dll
    c:\windows\system32\uXPi02
    c:\windows\system32\uXPi02\uXPi022328.exe
    c:\windows\system32\wegucyrq.dll
    c:\windows\Tasks\ggcspjzj.job
    c:\windows\system32\drivers\core.cache.dsk . . . . failed to delete

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    \Legacy_NETWORK_MONITOR


    ((((((((((((((((((((((((( Files Created from 2008-11-10 to 2008-12-10 )))))))))))))))))))))))))))))))
    .

    2008-12-10 05:21 . 2008-12-10 05:21 <DIR> d
    c:\temp\tn3
    2008-12-10 04:02 . 2008-12-10 04:02 <DIR> d
    c:\program files\uTorrent
    2008-12-10 04:02 . 2008-12-10 04:29 <DIR> d
    c:\documents and settings\Bret Harper\Application Data\uTorrent
    2008-12-10 03:52 . 2008-12-10 03:56 <DIR> d
    c:\documents and settings\All Users\Application Data\Lavasoft
    2008-12-10 03:51 . 2008-12-10 03:51 <DIR> d
    c:\program files\Common Files\Wise Installation Wizard
    2008-12-10 01:56 . 2008-12-10 03:19 1,547,651 --ahs---- c:\windows\system32\qrycugew.ini
    2008-12-10 01:01 . 2008-12-10 05:20 932
    c:\windows\system32\drivers\core.cache.dsk
    2008-12-10 00:39 . 2008-12-10 00:39 <DIR> d
    c:\windows\ERUNT
    2008-12-10 00:34 . 2008-12-10 01:09 <DIR> d
    C:\SDFix
    2008-12-09 01:53 . 2008-12-10 01:54 1,547,624 --ahs---- c:\windows\system32\jfrkdkkf.ini
    2008-12-09 01:44 . 2008-12-09 01:44 <DIR> d
    c:\program files\Alwil Software
    2008-12-09 00:59 . 2008-12-09 00:59 <DIR> d
    c:\program files\Trend Micro
    2008-12-07 15:00 . 2008-12-07 15:00 73 --a
    c:\windows\3926.bat
    2008-12-07 14:59 . 2008-12-07 14:59 121,344 --a
    c:\windows\task32.exe
    2008-12-03 02:39 . 2008-12-03 02:39 <DIR> d
    C:\VundoFix Backups
    2008-12-01 12:42 . 2008-12-01 12:42 <DIR> d
    c:\program files\Windows Defender
    2008-11-29 17:07 . 2008-12-10 03:22 <DIR> d--hs---- c:\windows\QnJldCBIYXJwZXI
    2008-11-29 17:06 . 2008-11-29 17:06 <DIR> d
    c:\windows\system32\oca
    2008-11-29 17:06 . 2008-11-29 17:07 <DIR> d
    c:\windows\system32\LN
    2008-11-29 17:06 . 2008-11-29 17:06 <DIR> d
    c:\windows\system32\jec
    2008-11-29 17:06 . 2008-11-29 17:06 <DIR> d
    c:\windows\system32\DEC
    2008-11-29 17:06 . 2008-11-29 17:06 <DIR> d
    c:\windows\system32\AI
    2008-11-29 17:06 . 2008-11-29 17:06 86,272 --a
    c:\windows\system32\drivers\ati1xbxxx.sys
    2008-11-29 17:06 . 2008-11-29 17:06 32,256 --a
    c:\windows\system32\tuvSjJax.dll
    2008-11-29 16:21 . 2008-11-29 16:21 147,456 --a
    c:\windows\system32\vbzip10.dll
    2008-11-29 16:18 . 2007-03-07 18:51 129,784 --a
    c:\windows\system32\pxafs.dll
    2008-11-29 16:00 . 2001-08-17 12:15 455,680 --a
    c:\windows\system32\dllcache\fus2base.sys
    2008-11-29 16:00 . 2001-08-17 12:15 455,296 --a
    c:\windows\system32\dllcache\fusbbase.sys
    2008-11-29 16:00 . 2001-08-17 12:14 444,416 --a
    c:\windows\system32\dllcache\fpcibase.sys
    2008-11-29 16:00 . 2001-08-17 12:15 442,240 --a
    c:\windows\system32\dllcache\fpnpbase.sys
    2008-11-29 16:00 . 2001-08-17 12:14 441,728 --a
    c:\windows\system32\dllcache\fpcmbase.sys
    2008-11-29 16:00 . 2001-08-17 22:36 92,160 --a
    c:\windows\system32\dllcache\fuusd.dll
    2008-11-29 16:00 . 2001-08-17 22:36 71,680 --a
    c:\windows\system32\dllcache\fnfilter.dll
    2008-11-29 16:00 . 2004-08-04 08:31 34,173 --a
    c:\windows\system32\dllcache\forehe.sys
    2008-11-29 16:00 . 2002-08-29 02:00 14,848 --a
    c:\windows\system32\dllcache\flattemp.exe
    2008-11-29 15:58 . 2001-08-17 12:14 952,007 --a
    c:\windows\system32\dllcache\diwan.sys
    2008-11-29 15:57 . 2002-08-29 02:00 1,677,824 --a
    c:\windows\system32\dllcache\chsbrkr.dll
    2008-11-29 15:56 . 2002-08-29 02:00 195,618 --a
    c:\windows\system32\dllcache\c_10002.nls
    2008-11-29 15:55 . 2001-08-17 13:28 871,388 --a
    c:\windows\system32\dllcache\bcmdm.sys
    2008-11-29 15:54 . 2001-08-17 13:28 762,780 --a
    c:\windows\system32\dllcache\3cwmcru.sys
    2008-11-29 15:53 . 2001-08-17 14:56 66,048 --a
    c:\windows\system32\dllcache\s3legacy.dll
    2008-11-29 15:04 . 2004-08-04 02:56 221,184 --a
    c:\windows\system32\wmpns.dll
    2008-11-17 14:19 . 2008-11-17 14:19 <DIR> d
    c:\program files\MSECache
    2008-11-16 00:48 . 2008-11-16 02:22 <DIR> d
    c:\windows\system32\Adobe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-10 08:53
    d
    w c:\program files\Lavasoft
    2008-11-29 21:53
    d--h--w c:\program files\InstallShield Installation Information
    2008-11-29 21:53
    d
    w c:\program files\Philips
    2008-11-17 19:21 102,432 ----a-w c:\documents and settings\Bret Harper\Application Data\GDIPFONTCACHEV1.DAT
    2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2007-04-23 01:29 19,520,976 ----a-w c:\program files\sdsetup.exe
    2007-02-17 21:56 10,135,688 ----a-w c:\program files\MPSetupXP.exe
    2004-05-04 15:12 590,336 ----a-w c:\program files\kmd.exe
    2003-10-03 20:47 66,490,368 ----a-w c:\program files\Norton Internet Security 2003.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MaxtorOneTouch"="c:\progra~1\Maxtor\OneTouch\Utils\OneTouch.exe" [2003-05-21 45056]
    "HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
    "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
    "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-01-24 290816]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
    "ATIModeChange"="Ati2mdxx.exe" [2002-06-11 c:\windows\system32\Ati2mdxx.exe]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-12 83360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=utzioi.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "MSACM.MI-SC4"= MI-SC4.acm

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
    backup=c:\windows\pss\Billminder.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
    backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
    backup=c:\windows\pss\Quicken Startup.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Bret Harper^Start Menu^Programs^Startup^WinFlip.lnk]
    path=c:\documents and settings\Bret Harper\Start Menu\Programs\Startup\WinFlip.lnk
    backup=c:\windows\pss\WinFlip.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
    --a
    2003-02-26 19:25 180316 c:\program files\HPQ\Default Settings\Cpqset.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    --a
    2004-08-04 02:56 15360 c:\windows\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Display Settings]
    --a
    2002-08-15 09:26 45056 c:\program files\HPQ\Notebook Utilities\hptasks.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
    --a
    2005-03-07 23:42 176128 c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QT4HPOT]
    --a
    2003-01-30 18:02 102400 c:\program files\HPQ\One-Touch\ONETOUCH.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a
    2008-01-10 15:27 385024 c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\srmclean]
    --a
    2001-07-24 16:34 36864 c:\cpqs\scom\srmclean.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    --a
    2004-12-06 20:31 36975 c:\program files\Java\jre1.5.0_01\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TV Now]
    --a
    2003-01-30 13:34 282624 c:\program files\HPQ\Notebook Utilities\TvNow.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    --a
    2006-11-03 19:20 866584 c:\program files\Windows Defender\MSASCui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
    --a
    2003-05-21 14:35 4608 c:\windows\system32\carpserv.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "TapiSrv"=3 (0x3)
    "seclogon"=2 (0x2)
    "RSVP"=3 (0x3)
    "ProtectedStorage"=2 (0x2)
    "mnmsrvc"=2 (0x2)
    "iPod Service"=3 (0x3)
    "helpsvc"=2 (0x2)
    "FastUserSwitchingCompatibility"=3 (0x3)
    "ERSvc"=2 (0x2)
    "Bonjour Service"=2 (0x2)
    "Apple Mobile Device"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\game.exe"=
    "c:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\mph.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-09 78416]
    R1 ati1xbxxx;ati1xbxxx;c:\windows\system32\drivers\ati1xbxxx.sys [2008-11-29 86272]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-09 20560]
    R2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
    R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;c:\windows\system32\drivers\caliaud.sys [2003-01-01 291328]
    R3 CALIHALA;CALIHALA;c:\windows\system32\drivers\calihal.sys [2003-01-01 244608]
    S3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;c:\windows\system32\DRIVERS\DP83815.SYS [2003-01-01 16512]
    S3 LxrSG20d;LxrSG20d;\??\c:\windows\system32\Drivers\LxrSG20d.sys [2007-08-17 68672]
    S3 LxrSG20s;Lexar SG20;LxrSG20s.exe []

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35510fe0-48fe-11dd-a6c9-00904b48db47}]
    \Shell\AutoRun\command - E:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f52fb330-7e31-11d9-a63e-00038a000015}]
    \Shell\AutoRun\command - e:\jdsecure\Windows\JDSecure20.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-10 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

    2008-12-10 c:\windows\Tasks\Symantec NetDetect.job
    - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-07-19 09:26]
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{80e73a1d-3052-446d-978d-a5006c34a34d} - c:\windows\system32\utzioi.dll
    BHO-{AEBD150B-106E-480D-9BEE-D06616ABB735} - c:\windows\system32\rqRIyWop.dll
    HKCU-Run-TrueTransparency - c:\documents and settings\Bret Harper\Desktop\Tweaks\truetransparency-crystalxp.net-en-5139\TrueTransparency\TrueTransparency.exe
    Notify-WgaLogon - (no file)
    MSConfigStartUp-AutoTBar - c:\hp\bin\autotbar.exe
    MSConfigStartUp-AVG7_CC - c:\progra~1\Grisoft\AVG7\avgcc.exe
    MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
    MSConfigStartUp-ccRegVfy - c:\program files\Common Files\Symantec Shared\ccRegVfy.exe
    MSConfigStartUp-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
    MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
    MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    MSConfigStartUp-UpdateManager - c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
    MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe


    .
    Supplementary Scan
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = 127.0.0.1;<local>;*.local
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

    O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

    O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
    FireFox -: Profile - c:\documents and settings\Bret Harper\Application Data\Mozilla\Firefox\Profiles\rvgls0t8.default\
    FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.myspace.com/
    FF -: plugin - c:\program files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
    FF -: plugin - c:\program files\Adobe\Acrobat 5.0\Reader\browser\nppdf32.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava11.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava12.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava13.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava14.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava32.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJPI150_01.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPOJI610.dll
    .

    **************************************************************************

    disk not found C:\

    please note that you need administrator rights to perform deep scan
    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files:

    **************************************************************************
    .
    Other Running Processes
    .
    c:\program files\Lavasoft\Ad-Aware\aawservice.exe
    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
    c:\program files\Alwil Software\Avast4\ashServ.exe
    c:\windows\system32\ati2evxx.exe
    c:\windows\system32\HPConfig.exe
    c:\program files\HPQ\Notebook Utilities\HPWirelessMgr.exe
    c:\windows\system32\HPZipm12.exe
    c:\windows\system32\vssvc.exe
    c:\windows\system32\WLTRYSVC.EXE
    c:\windows\system32\MsPMSPSv.exe
    c:\program files\Alwil Software\Avast4\ashMaiSv.exe
    c:\windows\system32\BCMWLTRY.EXE
    c:\program files\Alwil Software\Avast4\ashWebSv.exe
    .
    **************************************************************************
    .
    Completion time: 2008-12-10 5:27:08 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-12-10 10:27:03

    Pre-Run: 19,194,384,384 bytes free
    Post-Run: 19,478,777,856 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

    299 --- E O F --- 2008-12-08 18:39:35





    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:30:41 AM, on 12/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\HPConfig.exe
    C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\vssvc.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>;*.local
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {FC6703A7-5B7E-4f58-BE6D-2693AA3906AE} (HP Content Update) - http://h30043.www3.hp.com/netassist/en/check/install/gtdownhp.cab?1,0,0,94
    O20 - AppInit_DLLs: utzioi.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
    O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
    O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSG20s.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    --
    End of file - 5718 bytes
  • VekaVeka Finland
    edited December 2008
    Please open Notepad and copy and paste the text present inside the code box below:
    Driver::
    ati1xbxxx
    
    File::
    c:\windows\system32\qrycugew.ini
    c:\windows\system32\drivers\core.cache.dsk
    c:\windows\system32\jfrkdkkf.ini
    c:\windows\3926.bat
    c:\windows\task32.exe
    c:\windows\system32\drivers\ati1xbxxx.sys
    c:\windows\system32\tuvSjJax.dll
    c:\windows\system32\vbzip10.dll
    
    Folder:: 
    C:\VundoFix Backups
    c:\temp\tn3
    c:\windows\QnJldCBIYXJwZXI
    c:\windows\system32\oca
    c:\windows\system32\LN
    c:\windows\system32\jec
    c:\windows\system32\DEC
    c:\windows\system32\AI
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    
    Save this as CFScript.txt and place it on your desktop.

    Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.

    CFScriptb.gif
    ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal. When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.


    CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
  • edited December 2008
    Okay, here's the new combofix log. You didn't ask for a new HJT log but I included one anyways just in case.


    ComboFix 08-12-09.02 - Bret Harper 2008-12-10 11:42:46.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.93 [GMT -5:00]
    Running from: c:\documents and settings\Bret Harper\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Bret Harper\Desktop\CFScript.txt

    FILE ::
    c:\windows\3926.bat
    c:\windows\system32\drivers\ati1xbxxx.sys
    c:\windows\system32\drivers\core.cache.dsk
    c:\windows\system32\jfrkdkkf.ini
    c:\windows\system32\qrycugew.ini
    c:\windows\system32\tuvSjJax.dll
    c:\windows\system32\vbzip10.dll
    c:\windows\task32.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\temp\tn3
    C:\VundoFix Backups
    c:\windows\3926.bat
    c:\windows\QnJldCBIYXJwZXI
    c:\windows\system32\AI
    c:\windows\system32\AI\nIE65FR.exe
    c:\windows\system32\DEC
    c:\windows\system32\DEC\E5MTDg4.exe
    c:\windows\system32\drivers\ati1xbxxx.sys
    c:\windows\system32\drivers\core.cache.dsk
    c:\windows\system32\jec
    c:\windows\system32\jec\spDI504.exe
    c:\windows\system32\jfrkdkkf.ini
    c:\windows\system32\LN
    c:\windows\system32\oca
    c:\windows\system32\oca\iSR56IH.exe
    c:\windows\system32\qrycugew.ini
    c:\windows\system32\tuvSjJax.dll
    c:\windows\system32\vbzip10.dll
    c:\windows\task32.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    \Legacy_ATI1XBXXX
    \Service_ati1xbxxx


    ((((((((((((((((((((((((( Files Created from 2008-11-10 to 2008-12-10 )))))))))))))))))))))))))))))))
    .

    2008-12-10 04:02 . 2008-12-10 04:02 <DIR> d
    c:\program files\uTorrent
    2008-12-10 04:02 . 2008-12-10 04:29 <DIR> d
    c:\documents and settings\Bret Harper\Application Data\uTorrent
    2008-12-10 03:52 . 2008-12-10 03:56 <DIR> d
    c:\documents and settings\All Users\Application Data\Lavasoft
    2008-12-10 03:51 . 2008-12-10 03:51 <DIR> d
    c:\program files\Common Files\Wise Installation Wizard
    2008-12-10 00:39 . 2008-12-10 00:39 <DIR> d
    c:\windows\ERUNT
    2008-12-10 00:34 . 2008-12-10 01:09 <DIR> d
    C:\SDFix
    2008-12-09 01:44 . 2008-12-09 01:44 <DIR> d
    c:\program files\Alwil Software
    2008-12-09 00:59 . 2008-12-09 00:59 <DIR> d
    c:\program files\Trend Micro
    2008-12-01 12:42 . 2008-12-01 12:42 <DIR> d
    c:\program files\Windows Defender
    2008-11-29 16:18 . 2007-03-07 18:51 129,784 --a
    c:\windows\system32\pxafs.dll
    2008-11-29 16:00 . 2001-08-17 12:15 455,680 --a
    c:\windows\system32\dllcache\fus2base.sys
    2008-11-29 16:00 . 2001-08-17 12:15 455,296 --a
    c:\windows\system32\dllcache\fusbbase.sys
    2008-11-29 16:00 . 2001-08-17 12:14 444,416 --a
    c:\windows\system32\dllcache\fpcibase.sys
    2008-11-29 16:00 . 2001-08-17 12:15 442,240 --a
    c:\windows\system32\dllcache\fpnpbase.sys
    2008-11-29 16:00 . 2001-08-17 12:14 441,728 --a
    c:\windows\system32\dllcache\fpcmbase.sys
    2008-11-29 16:00 . 2001-08-17 22:36 92,160 --a
    c:\windows\system32\dllcache\fuusd.dll
    2008-11-29 16:00 . 2001-08-17 22:36 71,680 --a
    c:\windows\system32\dllcache\fnfilter.dll
    2008-11-29 16:00 . 2004-08-04 08:31 34,173 --a
    c:\windows\system32\dllcache\forehe.sys
    2008-11-29 16:00 . 2002-08-29 02:00 14,848 --a
    c:\windows\system32\dllcache\flattemp.exe
    2008-11-29 15:58 . 2001-08-17 12:14 952,007 --a
    c:\windows\system32\dllcache\diwan.sys
    2008-11-29 15:57 . 2002-08-29 02:00 1,677,824 --a
    c:\windows\system32\dllcache\chsbrkr.dll
    2008-11-29 15:56 . 2002-08-29 02:00 195,618 --a
    c:\windows\system32\dllcache\c_10002.nls
    2008-11-29 15:55 . 2001-08-17 13:28 871,388 --a
    c:\windows\system32\dllcache\bcmdm.sys
    2008-11-29 15:54 . 2001-08-17 13:28 762,780 --a
    c:\windows\system32\dllcache\3cwmcru.sys
    2008-11-29 15:53 . 2001-08-17 14:56 66,048 --a
    c:\windows\system32\dllcache\s3legacy.dll
    2008-11-29 15:04 . 2004-08-04 02:56 221,184 --a
    c:\windows\system32\wmpns.dll
    2008-11-17 14:19 . 2008-11-17 14:19 <DIR> d
    c:\program files\MSECache
    2008-11-16 00:48 . 2008-11-16 02:22 <DIR> d
    c:\windows\system32\Adobe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-10 08:53
    d
    w c:\program files\Lavasoft
    2008-11-29 21:53
    d--h--w c:\program files\InstallShield Installation Information
    2008-11-29 21:53
    d
    w c:\program files\Philips
    2008-11-17 19:21 102,432 ----a-w c:\documents and settings\Bret Harper\Application Data\GDIPFONTCACHEV1.DAT
    2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2007-04-23 01:29 19,520,976 ----a-w c:\program files\sdsetup.exe
    2007-02-17 21:56 10,135,688 ----a-w c:\program files\MPSetupXP.exe
    2004-05-04 15:12 590,336 ----a-w c:\program files\kmd.exe
    2003-10-03 20:47 66,490,368 ----a-w c:\program files\Norton Internet Security 2003.exe
    .

    ((((((((((((((((((((((((((((( snapshot@2008-12-10_ 5.26.13.52 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-12-10 16:49:45 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_63c.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MaxtorOneTouch"="c:\progra~1\Maxtor\OneTouch\Utils\OneTouch.exe" [2003-05-21 45056]
    "HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
    "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
    "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-01-24 290816]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
    "ATIModeChange"="Ati2mdxx.exe" [2002-06-11 c:\windows\system32\Ati2mdxx.exe]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-12 83360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "MSACM.MI-SC4"= MI-SC4.acm

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
    backup=c:\windows\pss\Billminder.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
    backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
    backup=c:\windows\pss\Quicken Startup.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Bret Harper^Start Menu^Programs^Startup^WinFlip.lnk]
    path=c:\documents and settings\Bret Harper\Start Menu\Programs\Startup\WinFlip.lnk
    backup=c:\windows\pss\WinFlip.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
    --a
    2003-02-26 19:25 180316 c:\program files\HPQ\Default Settings\Cpqset.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    --a
    2004-08-04 02:56 15360 c:\windows\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Display Settings]
    --a
    2002-08-15 09:26 45056 c:\program files\HPQ\Notebook Utilities\hptasks.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
    --a
    2005-03-07 23:42 176128 c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QT4HPOT]
    --a
    2003-01-30 18:02 102400 c:\program files\HPQ\One-Touch\ONETOUCH.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a
    2008-01-10 15:27 385024 c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\srmclean]
    --a
    2001-07-24 16:34 36864 c:\cpqs\scom\srmclean.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    --a
    2004-12-06 20:31 36975 c:\program files\Java\jre1.5.0_01\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TV Now]
    --a
    2003-01-30 13:34 282624 c:\program files\HPQ\Notebook Utilities\TvNow.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    --a
    2006-11-03 19:20 866584 c:\program files\Windows Defender\MSASCui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
    --a
    2003-05-21 14:35 4608 c:\windows\system32\carpserv.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "TapiSrv"=3 (0x3)
    "seclogon"=2 (0x2)
    "RSVP"=3 (0x3)
    "ProtectedStorage"=2 (0x2)
    "mnmsrvc"=2 (0x2)
    "iPod Service"=3 (0x3)
    "helpsvc"=2 (0x2)
    "FastUserSwitchingCompatibility"=3 (0x3)
    "ERSvc"=2 (0x2)
    "Bonjour Service"=2 (0x2)
    "Apple Mobile Device"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\game.exe"=
    "c:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Red Alert(tm) II\\RA2\\mph.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\LimeWire\\LimeWire.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-09 78416]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-09 20560]
    R2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
    R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;c:\windows\system32\drivers\caliaud.sys [2003-01-01 291328]
    R3 CALIHALA;CALIHALA;c:\windows\system32\drivers\calihal.sys [2003-01-01 244608]
    S3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;c:\windows\system32\DRIVERS\DP83815.SYS [2003-01-01 16512]
    S3 LxrSG20d;LxrSG20d;\??\c:\windows\system32\Drivers\LxrSG20d.sys [2007-08-17 68672]
    S3 LxrSG20s;Lexar SG20;LxrSG20s.exe []

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35510fe0-48fe-11dd-a6c9-00904b48db47}]
    \Shell\AutoRun\command - E:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f52fb330-7e31-11d9-a63e-00038a000015}]
    \Shell\AutoRun\command - e:\jdsecure\Windows\JDSecure20.exe
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-10 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

    2008-12-10 c:\windows\Tasks\Symantec NetDetect.job
    - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-07-19 09:26]
    .
    .
    Supplementary Scan
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = 127.0.0.1;<local>;*.local
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

    O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

    O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
    FireFox -: Profile - c:\documents and settings\Bret Harper\Application Data\Mozilla\Firefox\Profiles\rvgls0t8.default\
    FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.myspace.com/
    FF -: plugin - c:\program files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
    FF -: plugin - c:\program files\Adobe\Acrobat 5.0\Reader\browser\nppdf32.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava11.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava12.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava13.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava14.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJava32.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPJPI150_01.dll
    FF -: plugin - c:\program files\Java\jre1.5.0_01\bin\NPOJI610.dll
    .

    **************************************************************************

    disk not found C:\

    please note that you need administrator rights to perform deep scan
    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files:

    **************************************************************************
    .
    Other Running Processes
    .
    c:\program files\Lavasoft\Ad-Aware\aawservice.exe
    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
    c:\program files\Alwil Software\Avast4\ashServ.exe
    c:\windows\system32\ati2evxx.exe
    c:\windows\system32\HPConfig.exe
    c:\program files\HPQ\Notebook Utilities\HPWirelessMgr.exe
    c:\windows\system32\HPZipm12.exe
    c:\windows\system32\vssvc.exe
    c:\windows\system32\WLTRYSVC.EXE
    c:\windows\system32\MsPMSPSv.exe
    c:\program files\Alwil Software\Avast4\ashMaiSv.exe
    c:\program files\Alwil Software\Avast4\ashWebSv.exe
    c:\windows\system32\BCMWLTRY.EXE
    c:\program files\Alwil Software\Avast4\Setup\avast.setup
    .
    **************************************************************************
    .
    Completion time: 2008-12-10 11:54:44 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-12-10 16:54:39
    ComboFix2.txt 2008-12-10 10:27:10

    Pre-Run: 19,475,562,496 bytes free
    Post-Run: 19,483,217,920 bytes free

    259 --- E O F --- 2008-12-08 18:39:35










    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:00:37 PM, on 12/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\HPConfig.exe
    C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\vssvc.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>;*.local
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O16 - DPF: {FC6703A7-5B7E-4f58-BE6D-2693AA3906AE} (HP Content Update) - http://h30043.www3.hp.com/netassist/en/check/install/gtdownhp.cab?1,0,0,94
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
    O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
    O23 - Service: Lexar SG20 (LxrSG20s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSG20s.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    --
    End of file - 5654 bytes
  • VekaVeka Finland
    edited December 2008
    Looks much better now.

    Please download Malwarebytes' Anti-Malware to your desktop.
    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. please copy and paste the log into your next reply.
    • If you accidently close it, the log file is saved here and will be named like this: C:\Documents and Settings\<your username>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • edited December 2008
    Here you go:


    Malwarebytes' Anti-Malware 1.31
    Database version: 1483
    Windows 5.1.2600 Service Pack 2

    12/10/2008 10:32:49 PM
    mbam-log-2008-12-10 (22-32-49).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 116019
    Time elapsed: 52 minute(s), 58 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 7
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 15

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Qoobox\Quarantine\C\WINDOWS\system32\rqRIyWop.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ati1xbxxx.sys.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\oca\iSR56IH.exe.vir (Adware.Webhancer) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\s5\HIDR6I35.exe.vir (Adware.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP971\A0308555.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP977\A0322623.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP979\A0332682.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP981\A0334718.exe (Adware.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP981\A0334721.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP982\A0336748.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP982\A0336749.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP982\A0336750.exe (Adware.ZenoSearch) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP982\A0336752.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP982\A0336767.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Bret Harper\results.txt (Malware.Trace) -> Quarantined and deleted successfully.
  • VekaVeka Finland
    edited December 2008
    How is your computer running now? Any beter?
  • edited December 2008
    It's faster that it was before the my computer started freezing.
    Thank you so much for helping me fix my computer :rockon:.
  • VekaVeka Finland
    edited December 2008
    You're welcome! :)

    Please uninstall ComboFix.
    • Click Start then Run
    • Now type Combofix /u in the runbox and click OK

    Please download JavaRa and unzip it to your desktop.

    ***Please close any instances of Internet Explorer before continuing!***
    • Double-click on JavaRa.exe to start the program.
    • From the drop-down menu, choose English and click on Select.
    • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
    • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
    • A logfile will pop up. Please save it to a convenient location.
    Then download and install Java Runtime Environment (JRE) 6 Update 10.


    Looking over your log, it seems you don't have any evidence of a third party firewall.

    As the term conveys, a firewall is an extra layer of security installed onto computers, which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders. I want you to download a free firewall NOW from one of these excellent vendors:

    1) Comodo (Uncheck during installation "Install COMODO Antivirus (Recommended)"!, "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage")
    2) Online Armor
    3) PC Tools
    4) Sunbelt/Kerio
    5) ZoneAlarm (uncheck ZoneAlarm Spy Blocker during installation if you choose this one)

    If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.


    Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
    • Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

      You can find instructions on how to enable and re-enable system restore here:

      Windows XP System Restore Guide

    Re-enable system restore with instructions from tutorial above
    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
    • Update your AntiVirus Software and keep your other programs up-to-date Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.
      You can use one of these sites to check if any updates are needed for your pc.
      Secunia Software Inspector
      F-secure Health Check
    • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
    • Install Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
      totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

      Malwarebytes' Anti-Malware Setup Guide

      Malwarebytes' Anti-Malware Scanning Guide
    • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

      A tutorial on installing & using this product can be found here:

      Using SpywareBlaster to protect your computer from Spyware and Malware
    • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
    Follow this list and your potential for being infected again will reduce dramatically.

    Here are some additional utilities that will enhance your safety

    Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

    The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

    Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

    Happy surfing and stay clean! bigthumb.gif
  • VekaVeka Finland
    edited December 2008
    Glad we could be of assistance! The help you received here was free.

    This topic is now closed. If you wish it reopened, please send a Private Message to Trogan with a link to your thread.

    If you are not the user who started this thread, you must start your own Thread instead :)
    _______________________________
    Have we helped you with any issues you have had with your PCs or other items? If so, you can now help us by Joining Team 93 and fold for a cure.
Sign In or Register to comment.