I wasn't able to save a log with Avast, but I let it do a boot scan and then did a complete scan as specified in the tutorial.
HijackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:53:08 PM, on 18/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\COMODO\Firewall\cfp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www1.ca.dell....s...;l=en&s=genR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www1.ca.dell....s...;l=en&s=genR1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=2080110
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=58813O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1200435675737O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 7217 bytes
Combofix Log:
ComboFix 08-01-18.4 - Tanner 2008-01-18 0:22:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2495 [GMT -5:00]
Running from: C:\Documents and Settings\Tanner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tanner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE
C:\32D.tmp
C:\WINDOWS\system32\drvjul.dll
C:\WINDOWS\system32\RCX199.tmp
C:\WINDOWS\system32\RCX1A8.tmp
C:\WINDOWS\system32\RCX22E.tmp
C:\WINDOWS\system32\RCX24D.tmp
C:\WINDOWS\system32\RCX347.tmp
C:\WINDOWS\system32\RCX3E7.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\32D.tmp
C:\WINDOWS\system32\drvjul.dll
C:\WINDOWS\system32\RCX199.tmp
C:\WINDOWS\system32\RCX1A8.tmp
C:\WINDOWS\system32\RCX22E.tmp
C:\WINDOWS\system32\RCX24D.tmp
C:\WINDOWS\system32\RCX347.tmp
C:\WINDOWS\system32\RCX3E7.tmp
.
((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 )))))))))))))))))))))))))))))))
.
2008-01-17 21:25 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-17 16:49 . 2008-01-17 16:49 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-17 16:44 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\RkPavProc.sys
2008-01-17 16:35 . 2008-01-17 16:44 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-17 16:35 . 2008-01-17 16:35 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-17 16:35 . 2008-01-17 16:35 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-17 16:35 . 2008-01-17 16:35 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-17 16:14 . 2008-01-17 21:27 <DIR> d-------- C:\Program Files\Steam
2008-01-17 16:03 . 2008-01-17 16:03 <DIR> d-------- C:\savcc20
2008-01-16 22:38 . 2008-01-16 22:38 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-16 22:38 . 2008-01-16 23:06 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-01-16 22:38 . 2008-01-16 22:38 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-01-16 22:38 . 2008-01-16 23:07 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-16 22:25 . 2008-01-16 22:25 <DIR> d-------- C:\WINDOWS\nview
2008-01-16 22:25 . 2008-01-16 22:25 <DIR> d-------- C:\NVIDIA
2008-01-16 22:25 . 2007-12-17 13:53 159,458 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-01-16 21:28 . 2008-01-16 21:28 69,536 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-01-16 19:31 . 2008-01-16 19:31 <DIR> d-------- C:\Program Files\EA GAMES
2008-01-16 19:23 . 2008-01-16 19:23 <DIR> d-------- C:\WINDOWS\Sun
2008-01-16 16:45 . 2008-01-16 16:49 <DIR> d-------- C:\Documents and Settings\Tanner\Application Data\Ventrilo
2008-01-16 16:44 . 2008-01-16 16:44 <DIR> d-------- C:\Program Files\Ventrilo
2008-01-16 16:41 . 2008-01-16 16:41 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-16 15:58 . 2008-01-16 15:58 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-01-16 15:58 . 2008-01-16 15:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-01-16 15:58 . 2008-01-16 15:58 218,504 --a------ C:\WINDOWS\system32\drivers\pctfw2.sys
2008-01-16 06:07 . 2008-01-18 00:22 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-01-16 06:07 . 2008-01-16 06:07 <DIR> d-------- C:\Documents and Settings\Tanner\Application Data\PC Tools
2008-01-16 06:07 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-16 06:07 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-16 06:07 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-16 06:07 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-01-15 23:54 . 2008-01-16 05:13 <DIR> d-------- C:\Documents and Settings\Tanner\Contacts
2008-01-15 23:52 . 2008-01-15 23:53 <DIR> d-------- C:\Program Files\Windows Live
2008-01-15 23:52 . 2008-01-15 23:53 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-15 23:52 . 2008-01-15 23:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-15 22:10 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-01-15 22:10 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-15 22:09 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2008-01-15 20:21 . 2008-01-18 00:22 <DIR> d-------- C:\Program Files\iTunes
2008-01-15 20:21 . 2008-01-15 20:21 <DIR> d-------- C:\Program Files\iPod
2008-01-15 20:21 . 2008-01-15 20:21 <DIR> d-------- C:\Program Files\Bonjour
2008-01-15 20:21 . 2008-01-16 16:44 <DIR> d-------- C:\Documents and Settings\Tanner\Application Data\Apple Computer
2008-01-15 20:20 . 2008-01-15 22:43 <DIR> d-------- C:\Program Files\QuickTime
2008-01-15 20:20 . 2008-01-15 20:20 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-01-15 20:20 . 2008-01-15 20:20 <DIR> d-------- C:\Program Files\Apple Software Update
2008-01-15 20:20 . 2008-01-15 20:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-15 20:20 . 2008-01-15 20:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-15 20:20 . 2008-01-15 02:39 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-01-15 19:56 . 2008-01-15 19:56 <DIR> d-------- C:\Program Files\Webroot
2008-01-15 19:56 . 2008-01-15 19:56 <DIR> d-------- C:\Documents and Settings\Tanner\Application Data\Webroot
2008-01-15 19:56 . 2008-01-15 19:56 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-01-15 19:56 . 2008-01-15 19:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-01-15 19:56 . 2007-10-01 16:40 1,526,072 --a------ C:\WINDOWS\WRSetup.dll
2008-01-15 19:56 . 2007-10-01 16:24 163,640 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-01-15 19:56 . 2007-10-01 16:24 23,864 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-01-15 19:56 . 2007-10-01 16:24 21,816 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-01-15 19:56 . 2007-10-01 16:24 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-01-15 19:39 . 2008-01-15 22:43 90,112 --a------ C:\WINDOWS\UpdReg.EXE
2008-01-15 19:34 . 2008-01-15 19:34 <DIR> d-------- C:\Program Files\MSBuild
2008-01-15 19:33 . 2008-01-15 19:33 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-01-15 19:24 . 2008-01-15 22:03 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-01-15 19:24 . 2008-01-15 19:24 <DIR> dr-h----- C:\MSOCache
2008-01-15 19:24 . 2008-01-15 22:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-15 19:09 . 2008-01-15 19:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-01-15 19:04 . 2008-01-17 16:56 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-15 18:42 . 2008-01-15 18:42 4,128 --a------ C:\INFCACHE.1
2008-01-15 18:41 . 2008-01-15 20:50 376 --a------ C:\WINDOWS\ODBC.INI
2008-01-15 18:35 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-15 18:32 . 2004-01-23 19:21 65,888 --a------ C:\WINDOWS\system32\DKAAP2TH.HLP
2008-01-15 18:32 . 2004-01-23 19:21 41,984 --a------ C:\WINDOWS\system32\DKAAP2BJ.DLL
2008-01-15 18:32 . 2008-01-15 18:32 1,084 --a------ C:\WINDOWS\DKAAP2DD.ini
2008-01-15 18:31 . 2008-01-15 18:31 <DIR> d-------- C:\Program Files\Dell_HostCD
2008-01-15 18:31 . 2004-01-23 11:57 311,296 --a------ C:\WINDOWS\system32\lexlog.dll
2008-01-15 18:31 . 2004-01-23 19:21 131,072 --a------ C:\WINDOWS\system32\LEXDRVX.DLL
2008-01-15 18:31 . 2004-01-23 19:21 106,496 --a------ C:\WINDOWS\system32\LEXCFI.DLL
2008-01-15 18:31 . 2004-01-23 19:21 65,888 --a------ C:\WINDOWS\system32\DKAAP1TH.HLP
2008-01-15 18:31 . 2004-01-23 19:21 41,984 --a------ C:\WINDOWS\system32\DKAAP1BJ.DLL
2008-01-15 18:31 . 2008-01-15 19:49 2,992 --a------ C:\WINDOWS\system32\LexFiles.ulf
2008-01-15 18:31 . 2008-01-15 19:49 785 --a------ C:\WINDOWS\system32\LexFiles.usr
2008-01-15 17:46 . 2008-01-15 17:46 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-15 17:42 . 2007-07-09 08:09 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-15 17:41 . 2006-03-20 22:23 23,040 --------- C:\WINDOWS\kb913800.exe
2008-01-15 17:35 . 2008-01-15 17:35 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-15 17:29 . 2008-01-17 16:44 <DIR> d-------- C:\Program Files\mIRC
2008-01-15 17:29 . 2008-01-17 16:45 <DIR> d-------- C:\Documents and Settings\Tanner\Application Data\mIRC
2008-01-15 17:23 . 2008-01-15 23:53 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-01-15 17:23 . 2008-01-15 17:23 <DIR> d-------- C:\Program Files\Pure Networks
2008-01-15 17:23 . 2008-01-15 17:23 <DIR> d-------- C:\Program Files\DIFX
2008-01-15 17:23 . 2008-01-15 17:23 <DIR> d-------- C:\Program Files\Common Files\Pure Networks Shared
2008-01-15 17:23 . 2008-01-15 17:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Pure Networks
2008-01-15 17:23 . 2007-09-20 10:16 24,888 --a------ C:\WINDOWS\system32\drivers\purendis.sys
2008-01-15 17:23 . 2007-09-20 10:16 23,864 --a------ C:\WINDOWS\system32\drivers\pnarp.sys
2008-01-15 17:10 . 2008-01-15 17:10 <DIR> d---s---- C:\Documents and Settings\Tanner\UserData
2008-01-15 17:08 . 2008-01-09 23:26 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Roxio
2008-01-15 17:08 . 2008-01-09 23:12 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\InstallShield
2008-01-15 17:08 . 2008-01-09 23:25 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Creative
2008-01-15 17:08 . 2008-01-09 23:26 <DIR> d-------- C:\Documents and Settings\Tanner\Application Data\Roxio
2008-01-15 17:08 . 2008-01-09 23:12 <DIR> d-------- C:\Documents and Settings\Tanner\Application Data\InstallShield
2008-01-15 17:08 . 2008-01-09 23:25 <DIR> d-------- C:\Documents and Settings\Tanner\Application Data\Creative
2008-01-15 17:05 . 2004-08-04 00:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 11:02 18,944 ----a-w C:\WINDOWS\system32\CTXFIHLP.EXE
2008-01-16 04:12 15,360 ----a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-16 04:12 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
2008-01-10 03:56 7,704 ----a-w C:\WINDOWS\system32\drivers\1028_Dell_XPS_XPS720.mrk
2007-12-05 06:41 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-12-05 06:41 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-12-05 06:41 8,523,776 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-12-05 06:41 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-12-05 06:41 7,435,392 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-12-05 06:41 7,435,392 ----a-w C:\WINDOWS\system32\dllcache\nv4_mini.sys
2007-12-05 06:41 6,901,760 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-12-05 06:41 6,549,504 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-12-05 06:41 5,773,568 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-12-05 06:41 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-12-05 06:41 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-12-05 06:41 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-12-05 06:41 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-12-05 06:41 385,024 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-12-05 06:41 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe
2007-12-05 06:41 35,328 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-12-05 06:41 35,328 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-12-05 06:41 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-12-05 06:41 3,710,976 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-12-05 06:41 3,420,160 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-12-05 06:41 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-12-05 06:41 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-12-05 06:41 2,498,560 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-12-05 06:41 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-12-05 06:41 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-12-05 06:41 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-12-05 06:41 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-12-05 06:41 1,474,560 ----a-w C:\WINDOWS\system32\nview.dll
2007-12-05 06:41 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2007-12-05 06:41 1,228,800 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-12-05 06:41 1,089,536 ----a-w C:\WINDOWS\system32\nvcuda.dll
2007-12-05 06:41 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll
2007-11-14 07:26 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 09:55 3,065,856 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:35 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:39 228,864 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:39 228,864 ------w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-18 16:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-17_21.29.58.85 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-18 02:25:18 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-18 05:22:21 233,472 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-18 02:25:18 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-18 05:22:21 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-18 02:25:18 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-18 05:22:21 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-18 02:25:18 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-18 05:22:21 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-18 02:25:18 1,503,232 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-18 05:22:21 1,527,808 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-18 02:25:18 147,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-18 05:22:21 147,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2008-01-17 21:51:22 53,436 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-18 02:33:21 53,436 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-17 21:51:22 381,692 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-18 02:33:21 381,692 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-15 23:12 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2008-01-16 05:53 5724184]
"Steam"="C:\Program Files\Steam\Steam.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-10 06:00 33280 C:\WINDOWS\system32\rundll32.exe]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2008-01-15 22:43 49152]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-16 22:58 267048]
"nwiz"="nwiz.exe" []
"NvMediaCenter"="RUNDLL32.exe" [2004-08-10 06:00 33280 C:\WINDOWS\system32\rundll32.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-15 22:43 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
--a------ 2008-01-15 22:43 61440 c:\dell\bldbubg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
--a------ 2008-01-15 22:43 45056 C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
--a------ 2005-11-08 06:30 16384 C:\WINDOWS\CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
--a------ 2008-01-16 06:02 18944 C:\WINDOWS\system32\CTXFIHLP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter]
--a------ 2008-01-15 22:43 202544 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
--a------ 2008-01-15 22:43 16384 C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
--a------ 2008-01-15 22:43 17920 C:\Dell\E-Center\EULALauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2004-08-10 04:04 59392 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2008-01-15 22:43 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
--a------ 2008-01-16 16:08 1103752 C:\Program Files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2008-01-15 22:43 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2008-01-15 22:43 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmapp]
--a------ 2007-10-29 22:04 451896 C:\Program Files\Pure Networks\Network Magic\nmapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmctxth]
--a------ 2008-01-15 22:43 451896 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
--a------ 2008-01-15 22:43 118784 C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2008-01-15 22:43 221184 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-01-15 22:43 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--a------ 2008-01-15 22:43 90112 C:\WINDOWS\UpdReg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
--a------ 2008-01-15 22:43 122880 C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
"WebrootSpySweeperService"=2 (0x2)
"stllssvr"=3 (0x3)
"sdCoreService"=2 (0x2)
"sdAuxService"=2 (0x2)
"RoxMediaDB9"=3 (0x3)
"NVSvc"=2 (0x2)
"nmservice"=2 (0x2)
"nmraapache"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"ehSched"=2 (0x2)
"ehRecvr"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"Bonjour Service"=2 (0x2)
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-01-16 15:58]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-02-15 00:40]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-16 01:20:39 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-17 12:45:08 C:\WINDOWS\Tasks\wrSpySweeper_L4D77E97C37BC471AB9BE26AE47C0E0CF.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe>/ScheduleSweep=wrSpySweeper_L4D77E97C37BC471AB9BE26AE47C0E0CF
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex
- A:\
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-18 00:23:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-18 0:23:25
ComboFix-quarantined-files.txt 2008-01-18 05:23:23
ComboFix2.txt 2008-01-18 02:30:11
.
2008-01-16 03:42:38 --- E O F ---