Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

My hijack this log. [RESOLVED]


  • This topic is locked This topic is locked

#1
snake24

snake24

    Member

  • Member
  • PipPip
  • 16 posts
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:00:30 AM, on 5/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
H:\Program Files\iolo\common\lib\ioloServiceManager.exe
H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\System32\svchost.exe
H:\PROGRA~1\AVG\AVG8\avgrsx.exe
H:\PROGRA~1\AVG\AVG8\avgemc.exe
H:\WINDOWS\System32\alg.exe
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\RUNDLL32.EXE
H:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
H:\PROGRA~1\AVG\AVG8\avgtray.exe
H:\WINDOWS\system32\Rundll32.exe
H:\WINDOWS\system32\ctfmon.exe
H:\WINDOWS\system32\rundll32.exe
H:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
H:\Program Files\Windows Live\Messenger\msnmsgr.exe
H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
H:\Program Files\Windows Live\Messenger\usnsvc.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\Trend Micro\HijackThis\Crusty.exe.exe
H:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 69.10.150.116:35550
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - H:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5BF1A788-483A-4283-BBF4-EED8A710DF60} - H:\WINDOWS\system32\yayVLEVn.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {E54F518D-0CEA-4579-8181-22C4A3AE9515} - H:\WINDOWS\system32\mlJBQJYS.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SMSystemAnalyzer] "H:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] H:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [887407b3] rundll32.exe "H:\WINDOWS\system32\ytkhmogw.dll",b
O4 - HKLM\..\Run: [BM7f92ed9d] Rundll32.exe "H:\WINDOWS\system32\phkqtymm.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "H:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA9097] command /c del "H:\WINDOWS\system32\mlJBQJYS.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7838] cmd /c del "H:\WINDOWS\system32\mlJBQJYS.dll_old"
O4 - HKCU\..\Run: [NVIDIA nTune] "H:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] H:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "H:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - H:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://H:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1185550855000
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.co.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1196543575515
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.on...e/en/crlocx.ocx
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/...gradeVerify.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - H:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - H:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - H:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - H:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe

--
End of file - 9004 bytes
  • 0

Advertisements


#2
snake24

snake24

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Anyone here that can help???? Please.
  • 0

#3
snake24

snake24

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
IS ANYONE READING THIS???????/


OKAY I AM GOING AGAINST THE RULES BUT EVERYONE JUST IGNORES MY POST.

WHY??????????????????????????????????????
  • 0

#4
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello snake24, my name is fenzodahl512 and welcome to Geekstogo.. Apology for our late reply.. Real-life commitment has intrude us...

I'm looking at your log now and currently consulting with the experts about your malware problem..

I'll be back as soon as possible.. Thank you for your patience and understanding..

Regards
fenzodahl512
  • 0

#5
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello snake24, my name is fenzodahl512 and welcome to Geekstogo.. Please do the following..


Please read my post CAREFULLY before proceed with this step. Please download ComboFix by sUBs from HERE or HERE and save it to your Desktop.
For more information regarding this download, please visit this webpage

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Please go HERE to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: DO NOT mouseclick combofix's window while it's running. That may cause it to stall**



Regards
fenzodahl512
  • 0

#6
snake24

snake24

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
OKay done what u told me to.

I have iolo's system mechanic i do not know if it needs to be disabled or not but i did it anyway.


I ran combofix twice. cos i forgot to totally turn off avg. I turned it off when combofix was running but forgot to turn off the restart so when the pc was restarted and combofix was writing the log, avg might have tried to start up. So i turned off the auto restart the 2nd time and ran combofix another time. Hopefully nothing goes wrong. I do not know how to turn off iolo's system mechanic so i am not sure it it started up again. I usually use tea timer to turn off start up programs but it was altready disabled.

OKay here's my new combofix log :


ComboFix 08-05-15.3 - Virgil 2008-05-16 19:04:21.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2827 [GMT 8:00]
Running from: H:\Documents and Settings\Virgil\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-04-16 to 2008-05-16 )))))))))))))))))))))))))))))))
.

2008-05-14 22:19 . 2008-05-16 13:46 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Azureus
2008-05-14 22:19 . 2008-05-14 22:19 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\Azureus
2008-05-14 22:18 . 2008-05-14 22:18 <DIR> d-------- H:\Program Files\Azureus
2008-05-14 20:28 . 2008-05-14 20:28 <DIR> d-------- H:\Program Files\Camfrog
2008-05-14 20:28 . 2008-05-14 20:28 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Camfrog
2008-05-11 18:19 . 2008-05-11 18:19 81,920 --a------ H:\WINDOWS\system32\ytkhmogw.dll
2008-05-11 18:18 . 2008-05-11 18:18 91,648 --a------ H:\WINDOWS\system32\phkqtymm.dll
2008-05-11 18:06 . 2008-05-11 18:19 414 --ahs---- H:\WINDOWS\system32\nsuwwpya.ini
2008-05-11 18:00 . 2008-05-16 18:43 1,024 --ah----- H:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-11 17:34 . 2008-05-11 17:34 <DIR> d-------- H:\VundoFix Backups
2008-05-11 17:10 . 2008-05-11 17:16 2,194 --a------ H:\WINDOWS\system32\tmp.reg
2008-05-11 17:02 . 2008-05-11 17:02 91,648 --a------ H:\WINDOWS\system32\aixrjrxu.dll
2008-05-11 17:01 . 2008-05-12 01:49 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-11 14:10 . 2008-05-12 01:48 <DIR> d-------- H:\Program Files\SUPERAntiSpyware
2008-05-11 14:10 . 2008-05-12 01:48 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\SUPERAntiSpyware.com
2008-05-11 14:10 . 2008-05-11 14:10 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-11 13:44 . 2008-05-11 13:44 <DIR> d-------- H:\Program Files\Trend Micro
2008-05-11 11:56 . 2008-05-11 11:56 81,920 --a------ H:\WINDOWS\system32\tdkjqjfe.dll
2008-05-11 11:51 . 2008-05-11 18:13 109,807 --a------ H:\WINDOWS\BM7f92ed9d.xml
2008-05-11 11:51 . 2008-05-11 11:51 91,136 --a------ H:\WINDOWS\system32\phspdcqy.dll
2008-05-11 00:24 . 2008-05-12 12:44 <DIR> d--h----- H:\$AVG8.VAULT$
2008-05-11 00:21 . 2008-05-16 12:55 <DIR> d-------- H:\WINDOWS\system32\drivers\Avg
2008-05-11 00:21 . 2008-05-11 11:16 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\AVGTOOLBAR
2008-05-11 00:21 . 2008-05-11 00:21 96,520 --a------ H:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-11 00:21 . 2008-05-11 00:21 75,272 --a------ H:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-11 00:21 . 2008-05-11 00:21 10,520 --a------ H:\WINDOWS\system32\avgrsstx.dll
2008-05-11 00:20 . 2008-05-11 00:20 <DIR> d-------- H:\Program Files\AVG
2008-05-11 00:20 . 2008-05-13 10:38 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\avg8
2008-05-11 00:05 . 2008-05-11 00:08 <DIR> d-------- H:\Documents and Settings\Virgil\.housecall6.6
2008-05-10 23:54 . 2008-05-12 00:43 269 --a------ H:\WINDOWS\wininit.ini
2008-05-10 23:38 . 2008-05-10 23:38 30,720 --a------ H:\WINDOWS\system32\cbXOEtUO.dll.vir
2008-05-09 15:56 . 2008-05-09 15:56 <DIR> d-------- H:\Program Files\Geekbench 2
2008-05-07 18:11 . 2008-05-06 16:49 428,904 --a------ H:\WINDOWS\system32\Incinerator.dll
2008-05-07 18:11 . 2008-03-24 08:53 34,304 --a------ H:\WINDOWS\system32\iolobtdfg.exe
2008-05-07 18:11 . 2008-03-24 08:53 22,528 --a------ H:\WINDOWS\system32\smrgdf.exe
2008-05-07 18:11 . 2006-07-24 18:51 9,341 --a------ H:\WINDOWS\system32\drivers\filedisk.sys
2008-05-07 16:52 . 2008-04-14 00:10 10,240 --------- H:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-05-07 13:17 . 2008-04-14 05:39 13,463,552 --a--c--- H:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-05-07 12:59 . 2008-05-07 16:11 23,392 --a------ H:\WINDOWS\system32\nscompat.tlb
2008-05-07 12:59 . 2008-05-07 16:11 16,832 --a------ H:\WINDOWS\system32\amcompat.tlb
2008-05-07 11:56 . 2008-05-07 16:56 <DIR> d-------- H:\WINDOWS\system32\scripting
2008-05-07 11:56 . 2008-05-07 16:56 <DIR> d-------- H:\WINDOWS\system32\en
2008-05-07 11:56 . 2008-05-07 16:56 <DIR> d-------- H:\WINDOWS\l2schemas
2008-05-03 04:49 . 2008-05-03 04:49 <DIR> d-------- H:\Program Files\AviSynth 2.5
2008-05-03 04:49 . 2004-02-22 10:11 719,872 --a------ H:\WINDOWS\system32\devil.dll
2008-05-03 04:49 . 2006-10-07 17:43 502,784 --a------ H:\WINDOWS\x2.64.exe
2008-05-03 04:49 . 2008-02-07 16:15 408,576 --a------ H:\WINDOWS\system32\Smab.dll
2008-05-03 04:49 . 2007-05-17 17:30 318,976 --a------ H:\WINDOWS\system32\avisynth.dll
2008-05-03 04:49 . 2005-02-28 13:16 240,128 --a------ H:\WINDOWS\system32\x.264.exe
2008-05-03 04:49 . 2006-04-12 09:47 217,073 --a------ H:\WINDOWS\meta4.exe
2008-05-03 04:49 . 2004-01-25 00:00 70,656 --a------ H:\WINDOWS\system32\yv12vfw.dll
2008-05-03 04:49 . 2004-01-25 00:00 70,656 --a------ H:\WINDOWS\system32\i420vfw.dll
2008-05-03 04:49 . 2005-07-14 12:31 27,648 --a------ H:\WINDOWS\system32\AVSredirect.dll
2008-05-03 04:48 . 2008-05-03 04:48 <DIR> d-------- H:\Program Files\eRightSoft
2008-04-21 02:08 . 2008-04-21 03:31 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Command & Conquer 3 Tiberium Wars

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-16 10:37 --------- d-----w H:\Documents and Settings\Virgil\Application Data\MegauploadToolbar
2008-05-16 09:55 --------- d-----w H:\Documents and Settings\Virgil\Application Data\Skype
2008-05-16 09:28 --------- d-----w H:\Documents and Settings\Virgil\Application Data\skypePM
2008-05-14 03:54 --------- d-----w H:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-13 03:11 --------- d-----w H:\Documents and Settings\Virgil\Application Data\X-NetStat
2008-05-13 02:56 --------- d-----w H:\Program Files\Yahoo!
2008-05-12 07:32 --------- d-----w H:\Program Files\MegauploadToolbar
2008-05-12 04:57 --------- d-----w H:\Program Files\Java
2008-05-11 17:49 --------- d-----w H:\Program Files\Common Files\Wise Installation Wizard
2008-05-11 14:50 --------- d-----w H:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-09 07:53 --------- d-----w H:\Program Files\CCleaner
2008-05-07 10:11 --------- d-----w H:\Program Files\iolo
2008-05-07 10:03 --------- d-----w H:\Program Files\Spybot - Search & Destroy
2008-05-07 08:26 --------- d-----w H:\Documents and Settings\All Users\Application Data\iolo
2008-04-29 16:53 --------- d-----w H:\Program Files\Steam
2008-04-25 05:45 --------- d-----w H:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-23 18:30 --------- d-----w H:\Program Files\FMA 2
2008-04-20 13:10 --------- d-----w H:\Program Files\Electronic Arts
2008-04-13 21:43 40,840 ----a-w H:\WINDOWS\system32\drivers\termdd.sys
2008-04-13 21:43 21,896 ----a-w H:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-13 21:43 139,656 ----a-w H:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-13 21:43 12,040 ----a-w H:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-13 21:42 69,120 ----a-w H:\WINDOWS\notepad.exe
2008-04-13 21:42 50,688 ----a-w H:\WINDOWS\twain_32.dll
2008-04-13 21:42 32,866 ----a-w H:\WINDOWS\slrundll.exe
2008-04-13 21:42 3,901 ----a-w H:\WINDOWS\system32\drivers\siint5.dll
2008-04-13 21:42 283,648 ----a-w H:\WINDOWS\winhlp32.exe
2008-04-13 21:42 146,432 ----a-w H:\WINDOWS\regedit.exe
2008-04-13 21:42 11,325 ----a-w H:\WINDOWS\system32\drivers\vchnt5.dll
2008-04-13 21:42 10,752 ----a-w H:\WINDOWS\hh.exe
2008-04-13 21:42 1,033,728 ----a-w H:\WINDOWS\explorer.exe
2008-04-13 16:58 175,744 ----a-w H:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 16:51 162,816 ----a-w H:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 16:50 91,520 ----a-w H:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 16:50 361,344 ----a-w H:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 16:50 182,656 ----a-w H:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 16:49 75,264 ----a-w H:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 16:49 51,328 ----a-w H:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 16:49 48,384 ----a-w H:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 16:49 146,048 ----a-w H:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 16:49 138,112 ----a-w H:\WINDOWS\system32\drivers\afd.sys
2008-04-13 16:48 52,480 ----a-w H:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 16:47 83,072 ----a-w H:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 16:47 456,576 ----a-w H:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 16:47 105,344 ----a-w H:\WINDOWS\system32\drivers\mup.sys
2008-04-13 16:46 49,536 ----a-w H:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 16:46 141,056 ----a-w H:\WINDOWS\system32\drivers\ks.sys
2008-04-13 16:45 64,512 ----a-w H:\WINDOWS\system32\drivers\serial.sys
2008-04-13 16:45 60,800 ----a-w H:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 16:45 574,976 ----a-w H:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 16:45 334,848 ----a-w H:\WINDOWS\system32\drivers\srv.sys
2008-04-13 16:44 63,744 ----a-w H:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 16:44 143,744 ----a-w H:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 16:30 30,080 ----a-w H:\WINDOWS\system32\drivers\modem.sys
2008-04-13 16:30 225,664 ----a-w H:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 16:30 19,072 ----a-w H:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 16:27 41,472 ----a-w H:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 16:27 40,576 ----a-w H:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 16:27 34,560 ----a-w H:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 16:27 20,864 ----a-w H:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 16:27 152,832 ----a-w H:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 16:27 14,336 ----a-w H:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 16:27 10,112 ----a-w H:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 16:26 88,320 ----a-w H:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 16:26 69,120 ----a-w H:\WINDOWS\system32\drivers\psched.sys
2008-04-13 16:26 35,072 ----a-w H:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 16:26 34,688 ----a-w H:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 16:26 30,592 ----a-w H:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 16:26 30,592 ----a-w H:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 16:26 14,592 ----a-w H:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 16:26 12,800 ----a-w H:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 16:26 12,800 ----a-w H:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 16:26 12,288 ----a-w H:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 16:25 202,624 ----a-w H:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 16:24 11,264 ----a-w H:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 16:23 71,552 ----a-w H:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 16:23 40,320 ----a-w H:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 16:23 36,608 ----a-w H:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 16:23 264,832 ----a-w H:\WINDOWS\system32\drivers\http.sys
2008-04-13 16:21 61,824 ----a-w H:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 16:21 60,800 ----a-w H:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 16:21 59,904 ----a-w H:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 16:21 55,808 ----a-w H:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 16:21 101,120 ----a-w H:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 16:17 25,856 ----a-w H:\WINDOWS\system32\drivers\usbprint.sys
2008-04-13 16:15 60,160 ----a-w H:\WINDOWS\system32\drivers\drmk.sys
2008-04-13 16:14 81,664 ----a-w H:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 16:14 799,744 ----a-w H:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 16:14 20,992 ----a-w H:\WINDOWS\system32\drivers\vga.sys
2008-04-13 16:14 153,344 ----a-w H:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 16:13 14,208 ----a-w H:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 16:13 12,672 ----a-w H:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 16:11 52,352 ----a-w H:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 16:11 42,112 ----a-w H:\WINDOWS\system32\drivers\imapi.sys
2008-04-13 16:09 92,544 ----a-w H:\WINDOWS\system32\drivers\mqac.sys
2008-04-13 16:09 7,552 ----a-w H:\WINDOWS\system32\drivers\mskssrv.sys
2008-04-13 16:09 5,504 ----a-w H:\WINDOWS\system32\drivers\mstee.sys
2008-04-13 16:09 5,376 ----a-w H:\WINDOWS\system32\drivers\mspclock.sys
2008-04-13 16:09 42,368 ----a-w H:\WINDOWS\system32\drivers\mountmgr.sys
2008-04-13 16:09 4,992 ----a-w H:\WINDOWS\system32\drivers\mspqm.sys
2006-05-03 09:06 163,328 --sha-r H:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sha-r H:\WINDOWS\system32\msfDX.dll
2007-12-17 12:43 27,648 --sha-w H:\WINDOWS\system32\Smab0.dll
.

((((((((((((((((((((((((((((( snapshot@2008-05-16_18.52.38.50 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-16 10:45:18 2,048 --s-a-w H:\WINDOWS\bootstat.dat
+ 2008-05-16 11:10:05 2,048 --s-a-w H:\WINDOWS\bootstat.dat
+ 2008-05-16 11:11:10 16,384 ----atw H:\WINDOWS\Temp\Perflib_Perfdata_20c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-11 00:21 2050816 --a------ H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-11 00:21 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-11 00:21 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="H:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 19:25 81920]
"ctfmon.exe"="H:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 18:54 16116224 H:\WINDOWS\RTHDCPL.EXE]
"NvCplDaemon"="H:\WINDOWS\system32\NvCpl.dll" [2008-03-04 11:02 8523776]
"nwiz"="nwiz.exe" [2008-03-04 11:02 1626112 H:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="H:\WINDOWS\system32\NvMcTray.dll" [2008-03-04 11:02 81920]
"SunJavaUpdateSched"="H:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

H:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111T Smart Wizard.lnk - H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe [2007-07-27 23:00:57 483412]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXOEtUO]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
"vidc.ffds"= H:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Steam"=
"Skype"="H:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"MSMSGS"="H:\Program Files\Messenger\msmsgs.exe" /background
"System Mechanic Popup Blocker"="H:\Program Files\iolo\System Mechanic Professional 7\PopupBlocker.exe"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="H:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"DAEMON Tools"="H:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
"Orb"="H:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
"Comrade.exe"=H:\Program Files\GameSpy\Comrade\Comrade.exe
"MsnMsgr"="H:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"=H:\Program Files\Winamp\winampa.exe
"QuickTime Task"="H:\Program Files\QuickTime\QTTask.exe" -atboottime
"LanguageShortcut"="H:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"NeroFilterCheck"=H:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"RemoteControl"="H:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"Adobe Reader Speed Launcher"="H:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Sony Ericsson PC Suite"="H:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"BrMfcWnd"=H:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
"ControlCenter3"=H:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
"SetDefPrt"=H:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
"SkyTel"=SkyTel.EXE
"IMJPMIG8.1"="H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"MSPY2002"=H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"PHIME2002A"=H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"iolo Personal Firewall"="H:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe"
"!AVG Anti-Spyware"="H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
"BM7f92ed9d"=Rundll32.exe "H:\WINDOWS\system32\phkqtymm.dll",s
"AVG8_TRAY"=H:\PROGRA~1\AVG\AVG8\avgtray.exe
"SMSystemAnalyzer"="H:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program Files\\mIRC\\mirc.exe"=
"H:\\Program Files\\Messenger\\msmsgs.exe"=
"H:\\Program Files\\Steam\\Steam.exe"=
"H:\\Program Files\\Steam\\SteamApps\\common\\Lost Planet Extreme Condition\\LostPlanetDx10.exe"=
"H:\\Program Files\\Steam\\SteamApps\\common\\Lost Planet Extreme Condition\\LostPlanetDx9.exe"=
"H:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology\\aom.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology_2\\aom.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology_2\\aomx.exe"=
"H:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"H:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"=
"H:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"H:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"H:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"H:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"H:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mpCrack13.exe"=
"H:\\WINDOWS\\system32\\dpvsetup.exe"=
"H:\\Program Files\\Hamachi\\hamachi.exe"=
"H:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"H:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"H:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"H:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"H:\\Program Files\\Microsoft Games\\Gears of War\\Binaries\\WarGame-G4WLive.exe"=
"H:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"H:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"H:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"H:\\Program Files\\DNA\\btdna.exe"=
"H:\\Program Files\\BitTorrent\\bittorrent.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"H:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"H:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"H:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"H:\\Program Files\\Steam\\SteamApps\\common\\sega rally\\SEGA Rally.exe"=
"H:\\Program Files\\Steam\\SteamApps\\deadly_snake\\dark messiah might and magic multi-player\\mm.exe"=
"I:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.0\\cnc3game.dat"=
"I:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.9\\cnc3game.dat"=
"H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"H:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"H:\\Program Files\\Internet Explorer\\iexplore.exe"=
"H:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"H:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"H:\\Program Files\\Azureus\\Azureus.exe"=
"H:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18054:TCP"= 18054:TCP:BitComet 18054 TCP
"18054:UDP"= 18054:UDP:BitComet 18054 UDP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 AvgLdx86;AVG AVI Loader Driver x86;H:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-11 00:21]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};H:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 16:51]
R2 avg8emc;AVG8 E-mail Scanner;H:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-11 00:20]
R2 avg8wd;AVG8 WatchDog;H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-11 00:20]
R2 AvgTdiX;AVG8 Network Redirector;H:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-11 00:21]
R2 ioloFileInfoList;iolo FileInfoList Service;H:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-05-02 12:31]
R2 ioloSystemService;iolo System Service;H:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-05-02 12:31]
R3 AR5523;NETGEAR WG111T USB2.0 Wireless Card Service;H:\WINDOWS\system32\DRIVERS\wg11tnd5.sys [2004-10-15 10:41]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;H:\WINDOWS\System32\DNINDIS5.SYS [2003-07-24 12:10]
S1 TVicPort64;TVicPort64;H:\WINDOWS\SysWOW64\drivers\TVicPort64.sys []
S3 Aruba;QuikTouch/USB2 Device;H:\WINDOWS\system32\DRIVERS\Aruba.sys [2004-06-14 20:55]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;H:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-14 18:24]
S3 BrScnUsb;Brother USB Still Image driver;H:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
S3 gdrv;gdrv;H:\WINDOWS\gdrv.sys [2008-02-03 06:09]
S3 ggflt;SEMC USB Flash Driver Filter;H:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-03-21 04:47]
S3 MarkFun_NT;MarkFun_NT;H:\Program Files\Gigabyte\@BIOS\markfun.w32 [2007-08-21 19:49]
S3 motccgp;Motorola USB Composite Device Driver;H:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-06-20 14:57]
S3 motccgpfl;MotCcgpFlService;H:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 20:03]
S3 MotDev;Motorola Inc. USB Device;H:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-05-07 15:11]
S3 se44bus;Sony Ericsson Device 068 driver (WDM);H:\WINDOWS\system32\DRIVERS\se44bus.sys [2006-11-30 15:58]
S3 se44mdfl;Sony Ericsson Device 068 USB WMC Modem Filter;H:\WINDOWS\system32\DRIVERS\se44mdfl.sys [2006-11-30 15:58]
S3 se44mdm;Sony Ericsson Device 068 USB WMC Modem Driver;H:\WINDOWS\system32\DRIVERS\se44mdm.sys [2006-11-30 15:58]
S3 se44mgmt;Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM);H:\WINDOWS\system32\DRIVERS\se44mgmt.sys [2006-11-30 15:58]
S3 se44nd5;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS);H:\WINDOWS\system32\DRIVERS\se44nd5.sys [2006-11-30 15:58]
S3 se44obex;Sony Ericsson Device 068 USB WMC OBEX Interface;H:\WINDOWS\system32\DRIVERS\se44obex.sys [2006-11-30 15:58]
S3 se44unic;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM);H:\WINDOWS\system32\DRIVERS\se44unic.sys [2006-11-30 15:58]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-16 19:10:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MarkFun_NT]
"ImagePath"="\??\H:\Program Files\Gigabyte\@BIOS\markfun.w32"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\H:\Program Files\CyberLink\PowerDVD\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: H:\WINDOWS\system32\winlogon.exe
-> H:\Program Files\iolo\common\lib\ioloHL.dll

PROCESS: H:\WINDOWS\system32\lsass.exe
-> H:\Program Files\iolo\common\lib\ioloHL.dll

PROCESS: H:\WINDOWS\system32\csrss.exe
-> H:\Program Files\iolo\common\lib\ioloHL.dll
.
------------------------ Other Running Processes ------------------------
.
H:\WINDOWS\system32\rundll32.exe
H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\system32\wscntfy.exe
H:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-16 19:16:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-16 11:16:07
ComboFix2.txt 2008-05-16 10:52:50

Pre-Run: 74,455,638,016 bytes free
Post-Run: 74,433,507,328 bytes free

360 --- E O F --- 2008-05-07 09:48:08











Here is my new hijack this log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:21:00 PM, on 5/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\RUNDLL32.EXE
H:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
H:\Program Files\iolo\common\lib\ioloServiceManager.exe
H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\System32\svchost.exe
H:\PROGRA~1\AVG\AVG8\avgemc.exe
H:\WINDOWS\System32\alg.exe
H:\WINDOWS\system32\wscntfy.exe
H:\WINDOWS\explorer.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\AVG\AVG8\avgrsx.exe
H:\Program Files\Trend Micro\HijackThis\Crusty.exe.exe
H:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 69.10.150.116:35550
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - H:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - H:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - H:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIDIA nTune] "H:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - H:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://H:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1185550855000
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.co.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1196543575515
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.on...e/en/crlocx.ocx
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/...gradeVerify.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: cbXOEtUO - H:\WINDOWS\
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - H:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - H:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7975 bytes







Just another thing to add. I have renamed my hijack this file to crusty.exe as advice given from this website. http://www.techspot....topic58138.html


I followed the procedure they gave but their help forums are very slow. Thank you for following up on my case.

Edited by snake24, 16 May 2008 - 05:22 AM.

  • 0

#7
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello snake.. Thanks for the reply.. Lets do the following.. Oh yeah.. About disable security programs, same rules applies here :)


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
H:\WINDOWS\system32\ytkhmogw.dll
H:\WINDOWS\system32\phkqtymm.dll
H:\WINDOWS\system32\nsuwwpya.ini
H:\WINDOWS\system32\aixrjrxu.dll
H:\WINDOWS\system32\tdkjqjfe.dll
H:\WINDOWS\BM7f92ed9d.xml
H:\WINDOWS\system32\phspdcqy.dll
H:\WINDOWS\system32\cbXOEtUO.dll.vir

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXOEtUO]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"BM7f92ed9d"=-


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the ComboFix log in your next reply..




NEXT


Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O20 - Winlogon Notify: cbXOEtUO - H:\WINDOWS\

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.




NEXT


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Please post the following logs in your next reply... Please post each log in separate post..

1. ComboFix log
2. MalwareBytes' Anti-Malware report
3. A fresh HijackThis log (after MalwareBytes' step)
4. Tell me about your computer behaviour


Regards
fenzodahl512
  • 0

#8
snake24

snake24

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
HI just to inform you about the entries u wanted me to remove from the hijack this.

Number O20 - Winlogon Notify: cbXOEtUO - H:\WINDOWS\ does not show anymore.

Instead this shows:

O20 - AppInit_DLLs: avgrsstx.dll



I removed entry 6 like u told me to.


Will post the other logs like u told me to.

Thanks.
  • 0

#9
snake24

snake24

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Here is my combofix log:










ComboFix 08-05-15.3 - Virgil 2008-05-17 1:12:17.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2824 [GMT 8:00]
Running from: H:\Documents and Settings\Virgil\Desktop\ComboFix.exe
Command switches used :: H:\Documents and Settings\Virgil\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
H:\WINDOWS\BM7f92ed9d.xml
H:\WINDOWS\system32\aixrjrxu.dll
H:\WINDOWS\system32\cbXOEtUO.dll.vir
H:\WINDOWS\system32\nsuwwpya.ini
H:\WINDOWS\system32\phkqtymm.dll
H:\WINDOWS\system32\phspdcqy.dll
H:\WINDOWS\system32\tdkjqjfe.dll
H:\WINDOWS\system32\ytkhmogw.dll
.
The following files were disabled during the run:
H:\Program Files\iolo\common\lib\ioloHL.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

H:\Program Files\iolo\common\lib\ioloHL.dll
H:\WINDOWS\BM7f92ed9d.xml
H:\WINDOWS\system32\aixrjrxu.dll
H:\WINDOWS\system32\cbXOEtUO.dll.vir
H:\WINDOWS\system32\nsuwwpya.ini
H:\WINDOWS\system32\phkqtymm.dll
H:\WINDOWS\system32\phspdcqy.dll
H:\WINDOWS\system32\tdkjqjfe.dll
H:\WINDOWS\system32\ytkhmogw.dll

.
((((((((((((((((((((((((( Files Created from 2008-04-16 to 2008-05-16 )))))))))))))))))))))))))))))))
.

2008-05-16 20:58 . 2006-04-05 08:09 66,560 --a------ H:\WINDOWS\MOTA113.exe
2008-05-14 22:19 . 2008-05-16 13:46 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Azureus
2008-05-14 22:19 . 2008-05-14 22:19 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\Azureus
2008-05-14 22:18 . 2008-05-14 22:18 <DIR> d-------- H:\Program Files\Azureus
2008-05-14 20:28 . 2008-05-14 20:28 <DIR> d-------- H:\Program Files\Camfrog
2008-05-14 20:28 . 2008-05-14 20:28 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Camfrog
2008-05-11 18:00 . 2008-05-16 18:43 1,024 --ah----- H:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-11 17:34 . 2008-05-11 17:34 <DIR> d-------- H:\VundoFix Backups
2008-05-11 17:10 . 2008-05-11 17:16 2,194 --a------ H:\WINDOWS\system32\tmp.reg
2008-05-11 17:01 . 2008-05-12 01:49 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-11 14:10 . 2008-05-12 01:48 <DIR> d-------- H:\Program Files\SUPERAntiSpyware
2008-05-11 14:10 . 2008-05-12 01:48 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\SUPERAntiSpyware.com
2008-05-11 14:10 . 2008-05-11 14:10 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-11 13:44 . 2008-05-11 13:44 <DIR> d-------- H:\Program Files\Trend Micro
2008-05-11 00:24 . 2008-05-12 12:44 <DIR> d--h----- H:\$AVG8.VAULT$
2008-05-11 00:21 . 2008-05-16 12:55 <DIR> d-------- H:\WINDOWS\system32\drivers\Avg
2008-05-11 00:21 . 2008-05-11 11:16 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\AVGTOOLBAR
2008-05-11 00:21 . 2008-05-11 00:21 96,520 --a------ H:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-11 00:21 . 2008-05-11 00:21 75,272 --a------ H:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-11 00:21 . 2008-05-11 00:21 10,520 --a------ H:\WINDOWS\system32\avgrsstx.dll
2008-05-11 00:20 . 2008-05-11 00:20 <DIR> d-------- H:\Program Files\AVG
2008-05-11 00:20 . 2008-05-13 10:38 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\avg8
2008-05-11 00:05 . 2008-05-11 00:08 <DIR> d-------- H:\Documents and Settings\Virgil\.housecall6.6
2008-05-10 23:54 . 2008-05-12 00:43 269 --a------ H:\WINDOWS\wininit.ini
2008-05-09 15:56 . 2008-05-09 15:56 <DIR> d-------- H:\Program Files\Geekbench 2
2008-05-07 18:11 . 2008-05-06 16:49 428,904 --a------ H:\WINDOWS\system32\Incinerator.dll
2008-05-07 18:11 . 2008-03-24 08:53 34,304 --a------ H:\WINDOWS\system32\iolobtdfg.exe
2008-05-07 18:11 . 2008-03-24 08:53 22,528 --a------ H:\WINDOWS\system32\smrgdf.exe
2008-05-07 18:11 . 2006-07-24 18:51 9,341 --a------ H:\WINDOWS\system32\drivers\filedisk.sys
2008-05-07 16:52 . 2008-04-14 00:10 10,240 --------- H:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-05-07 13:17 . 2008-04-14 05:39 13,463,552 --a--c--- H:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-05-07 12:59 . 2008-05-07 16:11 23,392 --a------ H:\WINDOWS\system32\nscompat.tlb
2008-05-07 12:59 . 2008-05-07 16:11 16,832 --a------ H:\WINDOWS\system32\amcompat.tlb
2008-05-07 11:56 . 2008-05-07 16:56 <DIR> d-------- H:\WINDOWS\system32\scripting
2008-05-07 11:56 . 2008-05-07 16:56 <DIR> d-------- H:\WINDOWS\system32\en
2008-05-07 11:56 . 2008-05-07 16:56 <DIR> d-------- H:\WINDOWS\l2schemas
2008-05-03 04:49 . 2008-05-03 04:49 <DIR> d-------- H:\Program Files\AviSynth 2.5
2008-05-03 04:49 . 2004-02-22 10:11 719,872 --a------ H:\WINDOWS\system32\devil.dll
2008-05-03 04:49 . 2006-10-07 17:43 502,784 --a------ H:\WINDOWS\x2.64.exe
2008-05-03 04:49 . 2008-02-07 16:15 408,576 --a------ H:\WINDOWS\system32\Smab.dll
2008-05-03 04:49 . 2007-05-17 17:30 318,976 --a------ H:\WINDOWS\system32\avisynth.dll
2008-05-03 04:49 . 2005-02-28 13:16 240,128 --a------ H:\WINDOWS\system32\x.264.exe
2008-05-03 04:49 . 2006-04-12 09:47 217,073 --a------ H:\WINDOWS\meta4.exe
2008-05-03 04:49 . 2004-01-25 00:00 70,656 --a------ H:\WINDOWS\system32\yv12vfw.dll
2008-05-03 04:49 . 2004-01-25 00:00 70,656 --a------ H:\WINDOWS\system32\i420vfw.dll
2008-05-03 04:49 . 2005-07-14 12:31 27,648 --a------ H:\WINDOWS\system32\AVSredirect.dll
2008-05-03 04:48 . 2008-05-03 04:48 <DIR> d-------- H:\Program Files\eRightSoft
2008-04-21 02:08 . 2008-04-21 03:31 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Command & Conquer 3 Tiberium Wars

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-16 17:05 --------- d-----w H:\Documents and Settings\Virgil\Application Data\MegauploadToolbar
2008-05-16 09:55 --------- d-----w H:\Documents and Settings\Virgil\Application Data\Skype
2008-05-16 09:28 --------- d-----w H:\Documents and Settings\Virgil\Application Data\skypePM
2008-05-14 03:54 --------- d-----w H:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-13 03:11 --------- d-----w H:\Documents and Settings\Virgil\Application Data\X-NetStat
2008-05-13 02:56 --------- d-----w H:\Program Files\Yahoo!
2008-05-12 07:32 --------- d-----w H:\Program Files\MegauploadToolbar
2008-05-12 04:57 --------- d-----w H:\Program Files\Java
2008-05-11 17:49 --------- d-----w H:\Program Files\Common Files\Wise Installation Wizard
2008-05-11 14:50 --------- d-----w H:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-09 07:53 --------- d-----w H:\Program Files\CCleaner
2008-05-07 10:11 --------- d-----w H:\Program Files\iolo
2008-05-07 10:03 --------- d-----w H:\Program Files\Spybot - Search & Destroy
2008-05-07 08:26 --------- d-----w H:\Documents and Settings\All Users\Application Data\iolo
2008-04-29 16:53 --------- d-----w H:\Program Files\Steam
2008-04-25 05:45 --------- d-----w H:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-23 18:30 --------- d-----w H:\Program Files\FMA 2
2008-04-20 13:10 --------- d-----w H:\Program Files\Electronic Arts
2008-04-13 21:43 40,840 ----a-w H:\WINDOWS\system32\drivers\termdd.sys
2008-04-13 21:43 21,896 ----a-w H:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-13 21:43 139,656 ----a-w H:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-13 21:43 12,040 ----a-w H:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-13 21:42 69,120 ----a-w H:\WINDOWS\notepad.exe
2008-04-13 21:42 50,688 ----a-w H:\WINDOWS\twain_32.dll
2008-04-13 21:42 34,816 ----a-w H:\WINDOWS\Help\sniffpol.dll
2008-04-13 21:42 33,280 ----a-w H:\WINDOWS\Help\sstub.dll
2008-04-13 21:42 32,866 ----a-w H:\WINDOWS\slrundll.exe
2008-04-13 21:42 3,901 ----a-w H:\WINDOWS\system32\drivers\siint5.dll
2008-04-13 21:42 283,648 ----a-w H:\WINDOWS\winhlp32.exe
2008-04-13 21:42 279,040 ----a-w H:\WINDOWS\Help\tshoot.dll
2008-04-13 21:42 146,432 ----a-w H:\WINDOWS\regedit.exe
2008-04-13 21:42 11,325 ----a-w H:\WINDOWS\system32\drivers\vchnt5.dll
2008-04-13 21:42 10,752 ----a-w H:\WINDOWS\hh.exe
2008-04-13 21:42 1,033,728 ----a-w H:\WINDOWS\explorer.exe
2008-04-13 16:58 175,744 ----a-w H:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 16:51 162,816 ----a-w H:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 16:50 91,520 ----a-w H:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 16:50 361,344 ----a-w H:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 16:50 182,656 ----a-w H:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 16:49 75,264 ----a-w H:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 16:49 51,328 ----a-w H:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 16:49 48,384 ----a-w H:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 16:49 146,048 ----a-w H:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 16:49 138,112 ----a-w H:\WINDOWS\system32\drivers\afd.sys
2008-04-13 16:48 52,480 ----a-w H:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 16:47 83,072 ----a-w H:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 16:47 456,576 ----a-w H:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 16:47 105,344 ----a-w H:\WINDOWS\system32\drivers\mup.sys
2008-04-13 16:46 49,536 ----a-w H:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 16:46 141,056 ----a-w H:\WINDOWS\system32\drivers\ks.sys
2008-04-13 16:45 64,512 ----a-w H:\WINDOWS\system32\drivers\serial.sys
2008-04-13 16:45 60,800 ----a-w H:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 16:45 574,976 ----a-w H:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 16:45 334,848 ----a-w H:\WINDOWS\system32\drivers\srv.sys
2008-04-13 16:44 63,744 ----a-w H:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 16:44 143,744 ----a-w H:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 16:30 30,080 ----a-w H:\WINDOWS\system32\drivers\modem.sys
2008-04-13 16:30 225,664 ----a-w H:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 16:30 19,072 ----a-w H:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 16:27 41,472 ----a-w H:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 16:27 40,576 ----a-w H:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 16:27 34,560 ----a-w H:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 16:27 20,864 ----a-w H:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 16:27 152,832 ----a-w H:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 16:27 14,336 ----a-w H:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 16:27 10,112 ----a-w H:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 16:26 88,320 ----a-w H:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 16:26 69,120 ----a-w H:\WINDOWS\system32\drivers\psched.sys
2008-04-13 16:26 35,072 ----a-w H:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 16:26 34,688 ----a-w H:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 16:26 30,592 ----a-w H:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 16:26 30,592 ----a-w H:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 16:26 14,592 ----a-w H:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 16:26 12,800 ----a-w H:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 16:26 12,800 ----a-w H:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 16:26 12,288 ----a-w H:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 16:25 202,624 ----a-w H:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 16:24 11,264 ----a-w H:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 16:23 71,552 ----a-w H:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 16:23 40,320 ----a-w H:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 16:23 36,608 ----a-w H:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 16:23 264,832 ----a-w H:\WINDOWS\system32\drivers\http.sys
2008-04-13 16:21 61,824 ----a-w H:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 16:21 60,800 ----a-w H:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 16:21 59,904 ----a-w H:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 16:21 55,808 ----a-w H:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 16:21 101,120 ----a-w H:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 16:17 25,856 ----a-w H:\WINDOWS\system32\drivers\usbprint.sys
2008-04-13 16:15 60,160 ----a-w H:\WINDOWS\system32\drivers\drmk.sys
2008-04-13 16:14 81,664 ----a-w H:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 16:14 799,744 ----a-w H:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 16:14 20,992 ----a-w H:\WINDOWS\system32\drivers\vga.sys
2008-04-13 16:14 153,344 ----a-w H:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 16:13 14,208 ----a-w H:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 16:13 12,672 ----a-w H:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 16:11 52,352 ----a-w H:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 16:11 42,112 ----a-w H:\WINDOWS\system32\drivers\imapi.sys
2008-04-13 16:09 92,544 ----a-w H:\WINDOWS\system32\drivers\mqac.sys
2008-04-13 16:09 7,552 ----a-w H:\WINDOWS\system32\drivers\mskssrv.sys
2008-04-13 16:09 5,504 ----a-w H:\WINDOWS\system32\drivers\mstee.sys
2006-05-03 09:06 163,328 --sha-r H:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sha-r H:\WINDOWS\system32\msfDX.dll
2007-12-17 12:43 27,648 --sha-w H:\WINDOWS\system32\Smab0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-11 00:21 2050816 --a------ H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-11 00:21 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-11 00:21 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="H:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 19:25 81920]
"ctfmon.exe"="H:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 18:54 16116224 H:\WINDOWS\RTHDCPL.EXE]
"NvCplDaemon"="H:\WINDOWS\system32\NvCpl.dll" [2008-03-04 11:02 8523776]
"nwiz"="nwiz.exe" [2008-03-04 11:02 1626112 H:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="H:\WINDOWS\system32\NvMcTray.dll" [2008-03-04 11:02 81920]

H:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111T Smart Wizard.lnk - H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe [2007-07-27 23:00:57 483412]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
"vidc.ffds"= H:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Steam"=
"Skype"="H:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"MSMSGS"="H:\Program Files\Messenger\msmsgs.exe" /background
"System Mechanic Popup Blocker"="H:\Program Files\iolo\System Mechanic Professional 7\PopupBlocker.exe"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="H:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"DAEMON Tools"="H:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
"Orb"="H:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
"Comrade.exe"=H:\Program Files\GameSpy\Comrade\Comrade.exe
"MsnMsgr"="H:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"=H:\Program Files\Winamp\winampa.exe
"QuickTime Task"="H:\Program Files\QuickTime\QTTask.exe" -atboottime
"LanguageShortcut"="H:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"NeroFilterCheck"=H:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"RemoteControl"="H:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"Adobe Reader Speed Launcher"="H:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Sony Ericsson PC Suite"="H:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"BrMfcWnd"=H:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
"ControlCenter3"=H:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
"SetDefPrt"=H:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
"SkyTel"=SkyTel.EXE
"IMJPMIG8.1"="H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"MSPY2002"=H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"PHIME2002A"=H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"iolo Personal Firewall"="H:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe"
"!AVG Anti-Spyware"="H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
"BM7f92ed9d"=Rundll32.exe "H:\WINDOWS\system32\phkqtymm.dll",s
"AVG8_TRAY"=H:\PROGRA~1\AVG\AVG8\avgtray.exe
"SMSystemAnalyzer"="H:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
"SunJavaUpdateSched"="H:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program Files\\mIRC\\mirc.exe"=
"H:\\Program Files\\Messenger\\msmsgs.exe"=
"H:\\Program Files\\Steam\\Steam.exe"=
"H:\\Program Files\\Steam\\SteamApps\\common\\Lost Planet Extreme Condition\\LostPlanetDx10.exe"=
"H:\\Program Files\\Steam\\SteamApps\\common\\Lost Planet Extreme Condition\\LostPlanetDx9.exe"=
"H:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology\\aom.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology_2\\aom.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology_2\\aomx.exe"=
"H:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"H:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"=
"H:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"H:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"H:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"H:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"H:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mpCrack13.exe"=
"H:\\WINDOWS\\system32\\dpvsetup.exe"=
"H:\\Program Files\\Hamachi\\hamachi.exe"=
"H:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"H:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"H:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"H:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"H:\\Program Files\\Microsoft Games\\Gears of War\\Binaries\\WarGame-G4WLive.exe"=
"H:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"H:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"H:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"H:\\Program Files\\DNA\\btdna.exe"=
"H:\\Program Files\\BitTorrent\\bittorrent.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"H:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"H:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"H:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"H:\\Program Files\\Steam\\SteamApps\\common\\sega rally\\SEGA Rally.exe"=
"H:\\Program Files\\Steam\\SteamApps\\deadly_snake\\dark messiah might and magic multi-player\\mm.exe"=
"I:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.0\\cnc3game.dat"=
"I:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.9\\cnc3game.dat"=
"H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"H:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"H:\\Program Files\\Internet Explorer\\iexplore.exe"=
"H:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"H:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"H:\\Program Files\\Azureus\\Azureus.exe"=
"H:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18054:TCP"= 18054:TCP:BitComet 18054 TCP
"18054:UDP"= 18054:UDP:BitComet 18054 UDP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 AvgLdx86;AVG AVI Loader Driver x86;H:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-11 00:21]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};H:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 16:51]
R2 avg8emc;AVG8 E-mail Scanner;H:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-11 00:20]
R2 avg8wd;AVG8 WatchDog;H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-11 00:20]
R2 AvgTdiX;AVG8 Network Redirector;H:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-11 00:21]
R2 ioloFileInfoList;iolo FileInfoList Service;H:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-05-02 12:31]
R2 ioloSystemService;iolo System Service;H:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-05-02 12:31]
R3 AR5523;NETGEAR WG111T USB2.0 Wireless Card Service;H:\WINDOWS\system32\DRIVERS\wg11tnd5.sys [2004-10-15 10:41]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;H:\WINDOWS\System32\DNINDIS5.SYS [2003-07-24 12:10]
S1 TVicPort64;TVicPort64;H:\WINDOWS\SysWOW64\drivers\TVicPort64.sys []
S3 Aruba;QuikTouch/USB2 Device;H:\WINDOWS\system32\DRIVERS\Aruba.sys [2004-06-14 20:55]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;H:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-14 18:24]
S3 BrScnUsb;Brother USB Still Image driver;H:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
S3 gdrv;gdrv;H:\WINDOWS\gdrv.sys [2008-02-03 06:09]
S3 ggflt;SEMC USB Flash Driver Filter;H:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-03-21 04:47]
S3 MarkFun_NT;MarkFun_NT;H:\Program Files\Gigabyte\@BIOS\markfun.w32 [2007-08-21 19:49]
S3 motccgp;Motorola USB Composite Device Driver;H:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-06-20 14:57]
S3 motccgpfl;MotCcgpFlService;H:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 20:03]
S3 MotDev;Motorola Inc. USB Device;H:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-05-07 15:11]
S3 se44bus;Sony Ericsson Device 068 driver (WDM);H:\WINDOWS\system32\DRIVERS\se44bus.sys [2006-11-30 15:58]
S3 se44mdfl;Sony Ericsson Device 068 USB WMC Modem Filter;H:\WINDOWS\system32\DRIVERS\se44mdfl.sys [2006-11-30 15:58]
S3 se44mdm;Sony Ericsson Device 068 USB WMC Modem Driver;H:\WINDOWS\system32\DRIVERS\se44mdm.sys [2006-11-30 15:58]
S3 se44mgmt;Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM);H:\WINDOWS\system32\DRIVERS\se44mgmt.sys [2006-11-30 15:58]
S3 se44nd5;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS);H:\WINDOWS\system32\DRIVERS\se44nd5.sys [2006-11-30 15:58]
S3 se44obex;Sony Ericsson Device 068 USB WMC OBEX Interface;H:\WINDOWS\system32\DRIVERS\se44obex.sys [2006-11-30 15:58]
S3 se44unic;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM);H:\WINDOWS\system32\DRIVERS\se44unic.sys [2006-11-30 15:58]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-17 01:18:54
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MarkFun_NT]
"ImagePath"="\??\H:\Program Files\Gigabyte\@BIOS\markfun.w32"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\H:\Program Files\CyberLink\PowerDVD\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: H:\WINDOWS\system32\winlogon.exe
-> H:\Program Files\iolo\common\lib\ioloHL.dll

PROCESS: H:\WINDOWS\system32\lsass.exe
-> H:\Program Files\iolo\common\lib\ioloHL.dll

PROCESS: H:\WINDOWS\system32\csrss.exe
-> H:\Program Files\iolo\common\lib\ioloHL.dll
.
------------------------ Other Running Processes ------------------------
.
H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\system32\wscntfy.exe
H:\WINDOWS\system32\rundll32.exe
H:\Program Files\AVG\AVG8\avgrsx.exe
H:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-17 1:24:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-16 17:24:52
ComboFix2.txt 2008-05-16 11:16:11
ComboFix3.txt 2008-05-16 10:52:50

Pre-Run: 74,464,284,672 bytes free
Post-Run: 74,393,403,392 bytes free

373 --- E O F --- 2008-05-07 09:48:08
  • 0

#10
snake24

snake24

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Here is my malwarebyes log:











Malwarebytes' Anti-Malware 1.12
Database version: 755

Scan type: Quick Scan
Objects scanned: 37687
Time elapsed: 3 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

Advertisements


#11
snake24

snake24

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Here is my new hijack this log after the malware scan:








Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:47:54 AM, on 5/17/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
H:\Program Files\iolo\common\lib\ioloServiceManager.exe
H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\System32\svchost.exe
H:\PROGRA~1\AVG\AVG8\avgemc.exe
H:\WINDOWS\system32\wscntfy.exe
H:\WINDOWS\System32\alg.exe
H:\WINDOWS\system32\ctfmon.exe
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\RUNDLL32.EXE
H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
H:\WINDOWS\explorer.exe
H:\WINDOWS\system32\notepad.exe
H:\Program Files\AVG\AVG8\avgrsx.exe
H:\Program Files\AVG\AVG8\avgrsx.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\Windows Live\Messenger\msnmsgr.exe
H:\Program Files\Windows Live\Messenger\usnsvc.exe
H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
H:\Program Files\Trend Micro\HijackThis\Crusty.exe.exe
H:\WINDOWS\notepad.exe
H:\WINDOWS\system32\NOTEPAD.EXE
H:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 69.10.150.116:35550
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - H:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - H:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - H:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [NVIDIA nTune] "H:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "H:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - H:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1185550855000
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.co.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1196543575515
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.on...e/en/crlocx.ocx
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/...gradeVerify.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - H:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - H:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7694 bytes
  • 0

#12
snake24

snake24

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
My pc behaviour:


HI My pc has not shown any erratic behavior. Prior to posting here i was at http://www.techspot....topic58138.html and it told me to d/l combofix, vundofix and many more etc etc. I suspected that it did not fix everything as some advertisements would pop up on my browser. I got the virus and vundo from an msn contact whom was using a public pc. This virus would spread by sending itself to all your contacts and the browser would pop out adverts.


I just suspect that reminants of the virus might still remain somewhere in my pc.

As of now pc is stable and does not show any signs of suspicious behavior.

Hopefully it is totally cured.


Thanks for taking the time and giving advice. Greatly appreciated.
  • 0

#13
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello snake.. don't worry about that 020-entry you found in HijackThis.. Its from your AVG8..

Just a little bit more.. lets do the following..



1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BM7f92ed9d"=-


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

  • 0

#14
snake24

snake24

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
OKay i ran combofix twice cos i forgot to turn off teatimer and Avg. So i ran it the 2nd time with both programs off and i noticed this window popping up before it shut down on the 2nd time i ran combofix.

Posted Image


I hope there's no problem



Here's my combo fix log and hijack this:




ComboFix 08-05-15.3 - Virgil 2008-05-17 13:47:20.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2831 [GMT 8:00]
Running from: H:\Documents and Settings\Virgil\Desktop\ComboFix.exe
Command switches used :: H:\Documents and Settings\Virgil\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-04-17 to 2008-05-17 )))))))))))))))))))))))))))))))
.

2008-05-17 01:35 . 2008-05-17 01:35 <DIR> d-------- H:\Program Files\Malwarebytes' Anti-Malware
2008-05-17 01:35 . 2008-05-17 01:35 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Malwarebytes
2008-05-17 01:35 . 2008-05-17 01:35 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-17 01:35 . 2008-05-05 20:46 27,048 --a------ H:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-17 01:35 . 2008-05-05 20:46 15,864 --a------ H:\WINDOWS\system32\drivers\mbam.sys
2008-05-16 20:58 . 2006-04-05 08:09 66,560 --a------ H:\WINDOWS\MOTA113.exe
2008-05-14 22:19 . 2008-05-17 04:24 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Azureus
2008-05-14 22:19 . 2008-05-14 22:19 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\Azureus
2008-05-14 22:18 . 2008-05-14 22:18 <DIR> d-------- H:\Program Files\Azureus
2008-05-14 20:28 . 2008-05-14 20:28 <DIR> d-------- H:\Program Files\Camfrog
2008-05-14 20:28 . 2008-05-14 20:28 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Camfrog
2008-05-11 18:00 . 2008-05-16 18:43 1,024 --ah----- H:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-11 17:34 . 2008-05-11 17:34 <DIR> d-------- H:\VundoFix Backups
2008-05-11 17:10 . 2008-05-11 17:16 2,194 --a------ H:\WINDOWS\system32\tmp.reg
2008-05-11 17:01 . 2008-05-12 01:49 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-11 14:10 . 2008-05-12 01:48 <DIR> d-------- H:\Program Files\SUPERAntiSpyware
2008-05-11 14:10 . 2008-05-12 01:48 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\SUPERAntiSpyware.com
2008-05-11 14:10 . 2008-05-11 14:10 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-11 13:44 . 2008-05-11 13:44 <DIR> d-------- H:\Program Files\Trend Micro
2008-05-11 00:24 . 2008-05-12 12:44 <DIR> d--h----- H:\$AVG8.VAULT$
2008-05-11 00:21 . 2008-05-17 13:20 <DIR> d-------- H:\WINDOWS\system32\drivers\Avg
2008-05-11 00:21 . 2008-05-11 11:16 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\AVGTOOLBAR
2008-05-11 00:21 . 2008-05-11 00:21 96,520 --a------ H:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-11 00:21 . 2008-05-11 00:21 75,272 --a------ H:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-11 00:21 . 2008-05-11 00:21 10,520 --a------ H:\WINDOWS\system32\avgrsstx.dll
2008-05-11 00:20 . 2008-05-11 00:20 <DIR> d-------- H:\Program Files\AVG
2008-05-11 00:20 . 2008-05-13 10:38 <DIR> d-------- H:\Documents and Settings\All Users\Application Data\avg8
2008-05-11 00:05 . 2008-05-11 00:08 <DIR> d-------- H:\Documents and Settings\Virgil\.housecall6.6
2008-05-10 23:54 . 2008-05-12 00:43 269 --a------ H:\WINDOWS\wininit.ini
2008-05-09 15:56 . 2008-05-09 15:56 <DIR> d-------- H:\Program Files\Geekbench 2
2008-05-07 18:11 . 2008-05-06 16:49 428,904 --a------ H:\WINDOWS\system32\Incinerator.dll
2008-05-07 18:11 . 2008-03-24 08:53 34,304 --a------ H:\WINDOWS\system32\iolobtdfg.exe
2008-05-07 18:11 . 2008-03-24 08:53 22,528 --a------ H:\WINDOWS\system32\smrgdf.exe
2008-05-07 18:11 . 2006-07-24 18:51 9,341 --a------ H:\WINDOWS\system32\drivers\filedisk.sys
2008-05-07 16:52 . 2008-04-14 00:10 10,240 --------- H:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-05-07 13:17 . 2008-04-14 05:39 13,463,552 --a--c--- H:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-05-07 12:59 . 2008-05-07 16:11 23,392 --a------ H:\WINDOWS\system32\nscompat.tlb
2008-05-07 12:59 . 2008-05-07 16:11 16,832 --a------ H:\WINDOWS\system32\amcompat.tlb
2008-05-07 11:56 . 2008-05-07 16:56 <DIR> d-------- H:\WINDOWS\system32\scripting
2008-05-07 11:56 . 2008-05-07 16:56 <DIR> d-------- H:\WINDOWS\system32\en
2008-05-07 11:56 . 2008-05-07 16:56 <DIR> d-------- H:\WINDOWS\l2schemas
2008-05-03 04:49 . 2008-05-03 04:49 <DIR> d-------- H:\Program Files\AviSynth 2.5
2008-05-03 04:49 . 2004-02-22 10:11 719,872 --a------ H:\WINDOWS\system32\devil.dll
2008-05-03 04:49 . 2006-10-07 17:43 502,784 --a------ H:\WINDOWS\x2.64.exe
2008-05-03 04:49 . 2008-02-07 16:15 408,576 --a------ H:\WINDOWS\system32\Smab.dll
2008-05-03 04:49 . 2007-05-17 17:30 318,976 --a------ H:\WINDOWS\system32\avisynth.dll
2008-05-03 04:49 . 2005-02-28 13:16 240,128 --a------ H:\WINDOWS\system32\x.264.exe
2008-05-03 04:49 . 2006-04-12 09:47 217,073 --a------ H:\WINDOWS\meta4.exe
2008-05-03 04:49 . 2004-01-25 00:00 70,656 --a------ H:\WINDOWS\system32\yv12vfw.dll
2008-05-03 04:49 . 2004-01-25 00:00 70,656 --a------ H:\WINDOWS\system32\i420vfw.dll
2008-05-03 04:49 . 2005-07-14 12:31 27,648 --a------ H:\WINDOWS\system32\AVSredirect.dll
2008-05-03 04:48 . 2008-05-03 04:48 <DIR> d-------- H:\Program Files\eRightSoft
2008-04-21 02:08 . 2008-04-21 03:31 <DIR> d-------- H:\Documents and Settings\Virgil\Application Data\Command & Conquer 3 Tiberium Wars

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-17 05:21 --------- d-----w H:\Documents and Settings\Virgil\Application Data\MegauploadToolbar
2008-05-16 19:58 --------- d-----w H:\Documents and Settings\Virgil\Application Data\Skype
2008-05-16 19:28 --------- d-----w H:\Documents and Settings\Virgil\Application Data\skypePM
2008-05-16 18:45 --------- d-----w H:\Documents and Settings\Virgil\Application Data\X-NetStat
2008-05-14 03:54 --------- d-----w H:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-13 02:56 --------- d-----w H:\Program Files\Yahoo!
2008-05-12 07:32 --------- d-----w H:\Program Files\MegauploadToolbar
2008-05-12 04:57 --------- d-----w H:\Program Files\Java
2008-05-11 17:49 --------- d-----w H:\Program Files\Common Files\Wise Installation Wizard
2008-05-11 14:50 --------- d-----w H:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-09 07:53 --------- d-----w H:\Program Files\CCleaner
2008-05-07 10:11 --------- d-----w H:\Program Files\iolo
2008-05-07 10:03 --------- d-----w H:\Program Files\Spybot - Search & Destroy
2008-05-07 08:26 --------- d-----w H:\Documents and Settings\All Users\Application Data\iolo
2008-04-29 16:53 --------- d-----w H:\Program Files\Steam
2008-04-25 05:45 --------- d-----w H:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-23 18:30 --------- d-----w H:\Program Files\FMA 2
2008-04-20 13:10 --------- d-----w H:\Program Files\Electronic Arts
2008-04-13 21:43 40,840 ----a-w H:\WINDOWS\system32\drivers\termdd.sys
2008-04-13 21:43 21,896 ----a-w H:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-13 21:43 139,656 ----a-w H:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-13 21:43 12,040 ----a-w H:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-13 21:41 451,072 ----a-w H:\WINDOWS\AppPatch\aclayers.dll
2008-04-13 16:58 175,744 ----a-w H:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 16:51 162,816 ----a-w H:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 16:50 91,520 ----a-w H:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 16:50 361,344 ----a-w H:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 16:50 182,656 ----a-w H:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 16:49 75,264 ----a-w H:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 16:49 51,328 ----a-w H:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 16:49 48,384 ----a-w H:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 16:49 146,048 ----a-w H:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 16:49 138,112 ----a-w H:\WINDOWS\system32\drivers\afd.sys
2008-04-13 16:48 52,480 ----a-w H:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 16:47 83,072 ----a-w H:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 16:47 456,576 ----a-w H:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 16:47 105,344 ----a-w H:\WINDOWS\system32\drivers\mup.sys
2008-04-13 16:46 49,536 ----a-w H:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 16:46 141,056 ----a-w H:\WINDOWS\system32\drivers\ks.sys
2008-04-13 16:45 64,512 ----a-w H:\WINDOWS\system32\drivers\serial.sys
2008-04-13 16:45 60,800 ----a-w H:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 16:45 574,976 ----a-w H:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 16:45 334,848 ----a-w H:\WINDOWS\system32\drivers\srv.sys
2008-04-13 16:44 63,744 ----a-w H:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 16:44 143,744 ----a-w H:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 16:30 30,080 ----a-w H:\WINDOWS\system32\drivers\modem.sys
2008-04-13 16:30 225,664 ----a-w H:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 16:30 19,072 ----a-w H:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 16:27 41,472 ----a-w H:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 16:27 40,576 ----a-w H:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 16:27 34,560 ----a-w H:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 16:27 20,864 ----a-w H:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 16:27 152,832 ----a-w H:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 16:27 14,336 ----a-w H:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 16:27 10,112 ----a-w H:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 16:26 88,320 ----a-w H:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 16:26 69,120 ----a-w H:\WINDOWS\system32\drivers\psched.sys
2008-04-13 16:26 35,072 ----a-w H:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 16:26 34,688 ----a-w H:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 16:26 30,592 ----a-w H:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 16:26 30,592 ----a-w H:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 16:26 14,592 ----a-w H:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 16:26 12,800 ----a-w H:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 16:26 12,800 ----a-w H:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 16:26 12,288 ----a-w H:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 16:25 202,624 ----a-w H:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 16:24 11,264 ----a-w H:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 16:23 71,552 ----a-w H:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 16:23 40,320 ----a-w H:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 16:23 36,608 ----a-w H:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 16:23 264,832 ----a-w H:\WINDOWS\system32\drivers\http.sys
2008-04-13 16:21 61,824 ----a-w H:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 16:21 60,800 ----a-w H:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 16:21 59,904 ----a-w H:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 16:21 55,808 ----a-w H:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 16:21 101,120 ----a-w H:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 16:17 25,856 ----a-w H:\WINDOWS\system32\drivers\usbprint.sys
2008-04-13 16:15 60,160 ----a-w H:\WINDOWS\system32\drivers\drmk.sys
2008-04-13 16:14 81,664 ----a-w H:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 16:14 799,744 ----a-w H:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 16:14 20,992 ----a-w H:\WINDOWS\system32\drivers\vga.sys
2008-04-13 16:14 153,344 ----a-w H:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 16:13 14,208 ----a-w H:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 16:13 12,672 ----a-w H:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 16:11 52,352 ----a-w H:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 16:11 42,112 ----a-w H:\WINDOWS\system32\drivers\imapi.sys
2008-04-13 16:09 92,544 ----a-w H:\WINDOWS\system32\drivers\mqac.sys
2008-04-13 16:09 7,552 ----a-w H:\WINDOWS\system32\drivers\mskssrv.sys
2008-04-13 16:09 5,504 ----a-w H:\WINDOWS\system32\drivers\mstee.sys
2008-04-13 16:09 5,376 ----a-w H:\WINDOWS\system32\drivers\mspclock.sys
2008-04-13 16:09 42,368 ----a-w H:\WINDOWS\system32\drivers\mountmgr.sys
2008-04-13 16:09 4,992 ----a-w H:\WINDOWS\system32\drivers\mspqm.sys
2008-04-13 16:09 4,352 ----a-w H:\WINDOWS\system32\drivers\swenum.sys
2008-04-13 16:09 384,768 ----a-w H:\WINDOWS\system32\drivers\update.sys
2008-04-13 16:09 24,576 ----a-w H:\WINDOWS\system32\drivers\kbdclass.sys
2008-04-13 16:09 23,040 ----a-w H:\WINDOWS\system32\drivers\mouclass.sys
2008-04-13 16:09 14,592 ----a-w H:\WINDOWS\system32\drivers\kbdhid.sys
2008-04-13 16:08 71,168 ----a-w H:\WINDOWS\system32\drivers\dxg.sys
2008-04-13 16:04 163,584 ----a-w H:\WINDOWS\system32\drivers\nwrdr.sys
2008-04-13 16:03 44,544 ----a-w H:\WINDOWS\system32\drivers\fips.sys
2006-05-03 09:06 163,328 --sha-r H:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sha-r H:\WINDOWS\system32\msfDX.dll
2007-12-17 12:43 27,648 --sha-w H:\WINDOWS\system32\Smab0.dll
.

((((((((((((((((((((((((((((( snapshot@2008-05-17_ 1.24.42.15 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-16 17:18:21 2,048 --s-a-w H:\WINDOWS\bootstat.dat
+ 2008-05-17 05:56:49 2,048 --s-a-w H:\WINDOWS\bootstat.dat
+ 2008-05-17 05:57:53 16,384 ----atw H:\WINDOWS\TEMP\Perflib_Perfdata_41c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-11 00:21 2050816 --a------ H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-11 00:21 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-11 00:21 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="H:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 19:25 81920]
"ctfmon.exe"="H:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 18:54 16116224 H:\WINDOWS\RTHDCPL.EXE]
"NvCplDaemon"="H:\WINDOWS\system32\NvCpl.dll" [2008-03-04 11:02 8523776]
"nwiz"="nwiz.exe" [2008-03-04 11:02 1626112 H:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="H:\WINDOWS\system32\NvMcTray.dll" [2008-03-04 11:02 81920]
"AVG8_TRAY"="H:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-11 00:20 1177368]
"SMSystemAnalyzer"="H:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe" [2008-05-06 16:48 764776]

H:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111T Smart Wizard.lnk - H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe [2007-07-27 23:00:57 483412]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXOEtUO]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
"vidc.ffds"= H:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Steam"=
"Skype"="H:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"MSMSGS"="H:\Program Files\Messenger\msmsgs.exe" /background
"System Mechanic Popup Blocker"="H:\Program Files\iolo\System Mechanic Professional 7\PopupBlocker.exe"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="H:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"DAEMON Tools"="H:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
"Orb"="H:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
"Comrade.exe"=H:\Program Files\GameSpy\Comrade\Comrade.exe
"MsnMsgr"="H:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"=H:\Program Files\Winamp\winampa.exe
"QuickTime Task"="H:\Program Files\QuickTime\QTTask.exe" -atboottime
"LanguageShortcut"="H:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"NeroFilterCheck"=H:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"RemoteControl"="H:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"Adobe Reader Speed Launcher"="H:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"Sony Ericsson PC Suite"="H:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"BrMfcWnd"=H:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
"ControlCenter3"=H:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
"SetDefPrt"=H:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
"SkyTel"=SkyTel.EXE
"IMJPMIG8.1"="H:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"MSPY2002"=H:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"PHIME2002A"=H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=H:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"iolo Personal Firewall"="H:\Program Files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe"
"!AVG Anti-Spyware"="H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
"SunJavaUpdateSched"="H:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Program Files\\mIRC\\mirc.exe"=
"H:\\Program Files\\Messenger\\msmsgs.exe"=
"H:\\Program Files\\Steam\\Steam.exe"=
"H:\\Program Files\\Steam\\SteamApps\\common\\Lost Planet Extreme Condition\\LostPlanetDx10.exe"=
"H:\\Program Files\\Steam\\SteamApps\\common\\Lost Planet Extreme Condition\\LostPlanetDx9.exe"=
"H:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology\\aom.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology_2\\aom.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Mythology_2\\aomx.exe"=
"H:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"H:\\Program Files\\UBISOFT\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"=
"H:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"H:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"H:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"H:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"H:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mpCrack13.exe"=
"H:\\WINDOWS\\system32\\dpvsetup.exe"=
"H:\\Program Files\\Hamachi\\hamachi.exe"=
"H:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"H:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"H:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"H:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"H:\\Program Files\\Microsoft Games\\Gears of War\\Binaries\\WarGame-G4WLive.exe"=
"H:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"H:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"H:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"H:\\Program Files\\DNA\\btdna.exe"=
"H:\\Program Files\\BitTorrent\\bittorrent.exe"=
"H:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"H:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"H:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"H:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"H:\\Program Files\\Steam\\SteamApps\\common\\sega rally\\SEGA Rally.exe"=
"H:\\Program Files\\Steam\\SteamApps\\deadly_snake\\dark messiah might and magic multi-player\\mm.exe"=
"I:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.0\\cnc3game.dat"=
"I:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.9\\cnc3game.dat"=
"H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"H:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"H:\\Program Files\\Internet Explorer\\iexplore.exe"=
"H:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"H:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"H:\\Program Files\\Azureus\\Azureus.exe"=
"H:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18054:TCP"= 18054:TCP:BitComet 18054 TCP
"18054:UDP"= 18054:UDP:BitComet 18054 UDP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 AvgLdx86;AVG AVI Loader Driver x86;H:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-11 00:21]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};H:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 16:51]
R2 avg8emc;AVG8 E-mail Scanner;H:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-11 00:20]
R2 avg8wd;AVG8 WatchDog;H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-11 00:20]
R2 AvgTdiX;AVG8 Network Redirector;H:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-11 00:21]
R2 ioloFileInfoList;iolo FileInfoList Service;H:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-05-02 12:31]
R2 ioloSystemService;iolo System Service;H:\Program Files\iolo\common\lib\ioloServiceManager.exe [2008-05-02 12:31]
R3 AR5523;NETGEAR WG111T USB2.0 Wireless Card Service;H:\WINDOWS\system32\DRIVERS\wg11tnd5.sys [2004-10-15 10:41]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;H:\WINDOWS\System32\DNINDIS5.SYS [2003-07-24 12:10]
S1 TVicPort64;TVicPort64;H:\WINDOWS\SysWOW64\drivers\TVicPort64.sys []
S3 Aruba;QuikTouch/USB2 Device;H:\WINDOWS\system32\DRIVERS\Aruba.sys [2004-06-14 20:55]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;H:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-14 18:24]
S3 BrScnUsb;Brother USB Still Image driver;H:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
S3 gdrv;gdrv;H:\WINDOWS\gdrv.sys [2008-02-03 06:09]
S3 ggflt;SEMC USB Flash Driver Filter;H:\WINDOWS\system32\DRIVERS\ggflt.sys [2008-03-21 04:47]
S3 MarkFun_NT;MarkFun_NT;H:\Program Files\Gigabyte\@BIOS\markfun.w32 [2007-08-21 19:49]
S3 motccgp;Motorola USB Composite Device Driver;H:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-06-20 14:57]
S3 motccgpfl;MotCcgpFlService;H:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 20:03]
S3 MotDev;Motorola Inc. USB Device;H:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-05-07 15:11]
S3 se44bus;Sony Ericsson Device 068 driver (WDM);H:\WINDOWS\system32\DRIVERS\se44bus.sys [2006-11-30 15:58]
S3 se44mdfl;Sony Ericsson Device 068 USB WMC Modem Filter;H:\WINDOWS\system32\DRIVERS\se44mdfl.sys [2006-11-30 15:58]
S3 se44mdm;Sony Ericsson Device 068 USB WMC Modem Driver;H:\WINDOWS\system32\DRIVERS\se44mdm.sys [2006-11-30 15:58]
S3 se44mgmt;Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM);H:\WINDOWS\system32\DRIVERS\se44mgmt.sys [2006-11-30 15:58]
S3 se44nd5;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS);H:\WINDOWS\system32\DRIVERS\se44nd5.sys [2006-11-30 15:58]
S3 se44obex;Sony Ericsson Device 068 USB WMC OBEX Interface;H:\WINDOWS\system32\DRIVERS\se44obex.sys [2006-11-30 15:58]
S3 se44unic;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM);H:\WINDOWS\system32\DRIVERS\se44unic.sys [2006-11-30 15:58]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-17 13:57:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MarkFun_NT]
"ImagePath"="\??\H:\Program Files\Gigabyte\@BIOS\markfun.w32"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\H:\Program Files\CyberLink\PowerDVD\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: H:\WINDOWS\system32\winlogon.exe
-> H:\Program Files\iolo\common\lib\ioloHL.dll

PROCESS: H:\WINDOWS\system32\lsass.exe
-> H:\Program Files\iolo\common\lib\ioloHL.dll

PROCESS: H:\WINDOWS\system32\csrss.exe
-> H:\Program Files\iolo\common\lib\ioloHL.dll
.
------------------------ Other Running Processes ------------------------
.
H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\system32\rundll32.exe
H:\WINDOWS\system32\wscntfy.exe
H:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-17 14:02:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-17 06:02:54
ComboFix2.txt 2008-05-17 05:42:28
ComboFix3.txt 2008-05-16 17:24:56
ComboFix4.txt 2008-05-16 11:16:11
ComboFix5.txt 2008-05-16 10:52:50

Pre-Run: 74,328,883,200 bytes free
Post-Run: 74,304,925,696 bytes free

362 --- E O F --- 2008-05-07 09:48:08















Hijack this log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:14:29 PM, on 5/17/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
H:\Program Files\iolo\common\lib\ioloServiceManager.exe
H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\System32\svchost.exe
H:\PROGRA~1\AVG\AVG8\avgemc.exe
H:\WINDOWS\RTHDCPL.EXE
H:\WINDOWS\system32\RUNDLL32.EXE
H:\PROGRA~1\AVG\AVG8\avgtray.exe
H:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
H:\WINDOWS\explorer.exe
H:\WINDOWS\system32\notepad.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\AVG\AVG8\avgrsx.exe
H:\Program Files\Trend Micro\HijackThis\Crusty.exe.exe
H:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 69.10.150.116:35550
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - H:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - H:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - H:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - H:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - H:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - H:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] H:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SMSystemAnalyzer] "H:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [NVIDIA nTune] "H:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = H:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - H:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - H:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1185550855000
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.co.../sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1196543575515
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.on...e/en/crlocx.ocx
O16 - DPF: {FFD85DC8-5261-4D11-B728-F7C59D911691} (iolo.ProductDetector) - http://www.iolo.com/...gradeVerify.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - H:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: cbXOEtUO - H:\WINDOWS\
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - H:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - H:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - H:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - H:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7528 bytes
  • 0

#15
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello snake, thanks for the reply.. Now, lets do the following...

Please re-open HijackThis and click on Do a system scan only. Check the boxes next to all the entries listed below.

O20 - Winlogon Notify: cbXOEtUO - H:\WINDOWS\

Now close all windows other than HijackThis, then click Fix checked. Close HijackThis.


Please post a fresh HijackThis log in your next reply.. Please tell us about your computer condition..

Regards
fenzodahl512
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP