ComboFix:
ComboFix 08-06-16.2 - USER 2008-06-17 9:53:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.202 [GMT -4:00]
Running from: C:\Documents and Settings\USER\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\USER\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\USER\err.log
C:\Program Files\ssembl~1
C:\temp\17o7
C:\temp\17o7\tmpTF.log
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\msettings.ini
C:\WINDOWS\opera6.ini
C:\WINDOWS\search_res.txt
C:\WINDOWS\system32\dheyltsw.ini
C:\WINDOWS\system32\drivers\core.cache(10).dsk
C:\WINDOWS\system32\drivers\core.cache(11).dsk
C:\WINDOWS\system32\drivers\core.cache(12).dsk
C:\WINDOWS\system32\drivers\core.cache(13).dsk
C:\WINDOWS\system32\drivers\core.cache(14).dsk
C:\WINDOWS\system32\drivers\core.cache(15).dsk
C:\WINDOWS\system32\drivers\core.cache(16).dsk
C:\WINDOWS\system32\drivers\core.cache(17).dsk
C:\WINDOWS\system32\drivers\core.cache(18).dsk
C:\WINDOWS\system32\drivers\core.cache(19).dsk
C:\WINDOWS\system32\drivers\core.cache(2).dsk
C:\WINDOWS\system32\drivers\core.cache(20).dsk
C:\WINDOWS\system32\drivers\core.cache(21).dsk
C:\WINDOWS\system32\drivers\core.cache(22).dsk
C:\WINDOWS\system32\drivers\core.cache(23).dsk
C:\WINDOWS\system32\drivers\core.cache(24).dsk
C:\WINDOWS\system32\drivers\core.cache(25).dsk
C:\WINDOWS\system32\drivers\core.cache(26).dsk
C:\WINDOWS\system32\drivers\core.cache(27).dsk
C:\WINDOWS\system32\drivers\core.cache(28).dsk
C:\WINDOWS\system32\drivers\core.cache(29).dsk
C:\WINDOWS\system32\drivers\core.cache(3).dsk
C:\WINDOWS\system32\drivers\core.cache(30).dsk
C:\WINDOWS\system32\drivers\core.cache(31).dsk
C:\WINDOWS\system32\drivers\core.cache(32).dsk
C:\WINDOWS\system32\drivers\core.cache(33).dsk
C:\WINDOWS\system32\drivers\core.cache(34).dsk
C:\WINDOWS\system32\drivers\core.cache(35).dsk
C:\WINDOWS\system32\drivers\core.cache(36).dsk
C:\WINDOWS\system32\drivers\core.cache(37).dsk
C:\WINDOWS\system32\drivers\core.cache(38).dsk
C:\WINDOWS\system32\drivers\core.cache(39).dsk
C:\WINDOWS\system32\drivers\core.cache(4).dsk
C:\WINDOWS\system32\drivers\core.cache(40).dsk
C:\WINDOWS\system32\drivers\core.cache(41).dsk
C:\WINDOWS\system32\drivers\core.cache(42).dsk
C:\WINDOWS\system32\drivers\core.cache(43).dsk
C:\WINDOWS\system32\drivers\core.cache(44).dsk
C:\WINDOWS\system32\drivers\core.cache(45).dsk
C:\WINDOWS\system32\drivers\core.cache(46).dsk
C:\WINDOWS\system32\drivers\core.cache(47).dsk
C:\WINDOWS\system32\drivers\core.cache(48).dsk
C:\WINDOWS\system32\drivers\core.cache(49).dsk
C:\WINDOWS\system32\drivers\core.cache(5).dsk
C:\WINDOWS\system32\drivers\core.cache(50).dsk
C:\WINDOWS\system32\drivers\core.cache(51).dsk
C:\WINDOWS\system32\drivers\core.cache(52).dsk
C:\WINDOWS\system32\drivers\core.cache(53).dsk
C:\WINDOWS\system32\drivers\core.cache(54).dsk
C:\WINDOWS\system32\drivers\core.cache(55).dsk
C:\WINDOWS\system32\drivers\core.cache(56).dsk
C:\WINDOWS\system32\drivers\core.cache(57).dsk
C:\WINDOWS\system32\drivers\core.cache(58).dsk
C:\WINDOWS\system32\drivers\core.cache(59).dsk
C:\WINDOWS\system32\drivers\core.cache(6).dsk
C:\WINDOWS\system32\drivers\core.cache(60).dsk
C:\WINDOWS\system32\drivers\core.cache(61).dsk
C:\WINDOWS\system32\drivers\core.cache(62).dsk
C:\WINDOWS\system32\drivers\core.cache(63).dsk
C:\WINDOWS\system32\drivers\core.cache(64).dsk
C:\WINDOWS\system32\drivers\core.cache(65).dsk
C:\WINDOWS\system32\drivers\core.cache(66).dsk
C:\WINDOWS\system32\drivers\core.cache(67).dsk
C:\WINDOWS\system32\drivers\core.cache(68).dsk
C:\WINDOWS\system32\drivers\core.cache(69).dsk
C:\WINDOWS\system32\drivers\core.cache(7).dsk
C:\WINDOWS\system32\drivers\core.cache(70).dsk
C:\WINDOWS\system32\drivers\core.cache(71).dsk
C:\WINDOWS\system32\drivers\core.cache(72).dsk
C:\WINDOWS\system32\drivers\core.cache(73).dsk
C:\WINDOWS\system32\drivers\core.cache(74).dsk
C:\WINDOWS\system32\drivers\core.cache(75).dsk
C:\WINDOWS\system32\drivers\core.cache(76).dsk
C:\WINDOWS\system32\drivers\core.cache(77).dsk
C:\WINDOWS\system32\drivers\core.cache(78).dsk
C:\WINDOWS\system32\drivers\core.cache(79).dsk
C:\WINDOWS\system32\drivers\core.cache(8).dsk
C:\WINDOWS\system32\drivers\core.cache(80).dsk
C:\WINDOWS\system32\drivers\core.cache(81).dsk
C:\WINDOWS\system32\drivers\core.cache(82).dsk
C:\WINDOWS\system32\drivers\core.cache(83).dsk
C:\WINDOWS\system32\drivers\core.cache(84).dsk
C:\WINDOWS\system32\drivers\core.cache(85).dsk
C:\WINDOWS\system32\drivers\core.cache(86).dsk
C:\WINDOWS\system32\drivers\core.cache(87).dsk
C:\WINDOWS\system32\drivers\core.cache(88).dsk
C:\WINDOWS\system32\drivers\core.cache(9).dsk
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\ftrgekkw.ini
C:\WINDOWS\system32\ggbpbrvl.ini
C:\WINDOWS\system32\gxnckofy.dll
C:\WINDOWS\system32\iaddclbi.ini
C:\WINDOWS\system32\jyexipfj.ini
C:\WINDOWS\system32\khmdgndj.ini
C:\WINDOWS\system32\lddnvgvo.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mgmjwvmt.ini
C:\WINDOWS\system32\mgmjwvmt.ini2
C:\WINDOWS\system32\mgmjwvmt.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\muihmtxw.ini
C:\WINDOWS\system32\ogncxemq.ini
C:\WINDOWS\system32\ojsciwjc.ini
C:\WINDOWS\system32\poqkeixv.ini
C:\WINDOWS\system32\pvakpxnw.ini
C:\WINDOWS\system32\qcuplbls.ini
C:\WINDOWS\system32\qnefpffo.ini
C:\WINDOWS\system32\qxtuvkld.ini
C:\WINDOWS\system32\smpi1
C:\WINDOWS\system32\tmvwjmgm.dll
C:\WINDOWS\system32\uddwgdub.ini
C:\WINDOWS\system32\usmmjsrd.ini
C:\WINDOWS\system32\uwvwa.bak1
C:\WINDOWS\system32\uwvwa.bak2
C:\WINDOWS\system32\uwvwa.ini
C:\WINDOWS\system32\uwvwa.ini2
C:\WINDOWS\system32\uwvwa.tmp
C:\WINDOWS\system32\veacntgb.ini
C:\WINDOWS\system32\vscdlbmn.ini
C:\WINDOWS\system32\wggksqds.ini2
C:\WINDOWS\system32\wggksqds.tmp
C:\WINDOWS\system32\wkkegrtf.dll
C:\WINDOWS\system32\xggpglvk.ini2
C:\WINDOWS\system32\xspbyucb.ini
C:\WINDOWS\system32\yfokcnxg.ini
----- BITS: Possible infected sites -----
hxxp://nmextensions.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CORE
-------\Service_core
((((((((((((((((((((((((( Files Created from 2008-05-17 to 2008-06-17 )))))))))))))))))))))))))))))))
.
2008-06-17 08:32 . 2008-06-17 08:32 <DIR> d-------- C:\_OTMoveIt
2008-06-16 15:09 . 2008-06-16 15:09 1,278 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-14 14:14 . 2008-06-15 08:00 <DIR> d-------- C:\Documents and Settings\kids\Application Data\AVG7
2008-06-14 14:12 . 2008-06-14 14:12 <DIR> d-------- C:\Documents and Settings\kids
2008-06-13 18:32 . 2008-06-13 18:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-13 17:36 . 2008-04-14 07:01 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 17:36 . 2008-04-14 07:01 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-13 16:24 . 2008-06-13 16:24 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-13 14:08 . 2008-06-16 12:26 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-13 14:08 . 2008-06-13 14:08 <DIR> d-------- C:\Documents and Settings\USER\Application Data\SUPERAntiSpyware.com
2008-06-12 09:20 . 2008-06-12 09:21 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-12 09:20 . 2008-06-12 09:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-08 12:50 . 2008-06-08 12:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-08 12:41 . 2003-09-03 16:45 274,432 --a------ C:\WINDOWS\system32\FFTIFF16.dll
2008-06-08 12:41 . 2006-07-12 14:39 208,896 --a------ C:\WINDOWS\system32\FFRafShellEx.dll
2008-06-08 12:41 . 2004-07-24 21:28 155,648 --a------ C:\WINDOWS\system32\FFRAFLIB.DLL
2008-06-08 12:38 . 2008-06-08 12:38 <DIR> d-------- C:\Documents and Settings\USER\Application Data\InstallShield
2008-05-30 01:07 . 2008-06-08 12:50 <DIR> d-------- C:\Program Files\Apple Software Update
2008-05-30 01:03 . 2008-06-13 13:38 <DIR> d-------- C:\Documents and Settings\USER\Application Data\FUJIFILM
2008-05-30 01:01 . 2008-06-17 09:49 <DIR> d-------- C:\Program Files\FinePixViewer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-17 12:00 --------- d-----w C:\Documents and Settings\USER\Application Data\AVG7
2008-06-14 14:52 --------- d-----w C:\Program Files\LimeWire
2008-06-13 22:31 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-12 13:34 374 ----a-w C:\Documents and Settings\USER\Application Data\internaldb6334.dat
2008-06-11 16:27 18,432 ----a-w C:\Documents and Settings\USER\Application Data\internaldb41.dat
2008-06-11 16:26 555 ----a-w C:\Documents and Settings\USER\Application Data\internaldb8467.dat
2008-06-08 16:54 --------- d-----w C:\Program Files\QuickTime
2008-06-08 16:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-08 16:26 --------- d-----w C:\Program Files\Lx_cats
2008-05-30 05:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-16 11:04 --------- d-----w C:\Documents and Settings\USER\Application Data\OpenOffice.org2
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{28D8912D-C0B5-42DE-B42C-5FE22D6A2332}]
2008-02-19 13:25 98048 --a------ C:\WINDOWS\system32\d3dram.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-16 12:26 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCTVOICE"="pctspk.exe" [2003-02-24 18:35 163840 C:\WINDOWS\system32\pctspk.exe]
"zzzHPSETUP"="D:\Setup.exe" [ ]
"lxdcmon.exe"="C:\Program Files\Lexmark 1300 Series\lxdcmon.exe" [ ]
"lxdcamon"="C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" [2007-02-05 19:32 20480]
"LXDCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll" [2007-01-22 18:05 102400]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 16:49 49152]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-23 09:03 579584]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16 286720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-19 20:08 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [2008-06-08 12:42:03 303104]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 20:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 20:50:52 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"svchost"= C:\WINDOWS\svchost.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-06-16 12:25 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-06-16 12:26 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
C:\WINDOWS\system32\LgNotify.dll 2005-07-05 04:33 188482 C:\WINDOWS\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\WINDOWS\\system32\\lxdccoms.exe"=
"C:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe"=
"C:\\Program Files\\Lexmark 1300 Series\\App4R.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
R0 wsqdqixr;wsqdqixr;C:\WINDOWS\system32\drivers\xjhgicnc.dat []
R2 lxdc_device;lxdc_device;C:\WINDOWS\system32\lxdccoms.exe [2007-02-12 19:56]
R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-04-22 00:58]
S3 CBEN5;Xircom CardBus Ethernet 10/100 Adapter family Driver;C:\WINDOWS\system32\DRIVERS\cben5.sys [2001-08-17 08:13]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2002-11-22 23:01]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76366070-396f-11dd-97bb-009096b6aa61}]
\Shell\AutoRun\command - E:\LinksysConnectPC.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-11 23:02:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-17 13:39:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-17 10:05:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\wsqdqixr]
"ImagePath"="system32\drivers\xjhgicnc.dat"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\WINDOWS\system32\scardsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Completion time: 2008-06-17 10:12:03 - machine was rebooted [USER]
ComboFix-quarantined-files.txt 2008-06-17 14:11:54
Pre-Run: 28,113,747,968 bytes free
Post-Run: 28,115,886,080 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
297 --- E O F --- 2008-06-16 15:45:26
MoveIt:
LoadLibrary failed for C:\WINDOWS\system32\d3dram.dll
C:\WINDOWS\system32\d3dram.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\d3dram.dll scheduled to be moved on reboot.
File/Folder C:\WINDOWS\systm32\vbddlq.dll not found.
File/Folder C:\Program Files\Internet Explorer\hokevofa.dll not found.
File/Folder C:\WINDOWS\system32\2s56aql3.dll not found.
File/Folder C:\Program Files\Windows Media Player\lavu.dll not found.
File/Folder C:\WINDOWS\system32\ycjcmufy.dll not found.
File/Folder C:\WINDOWS\system32\awvwu.dll not found.
File/Folder C:\Program Files\Outlook Express\hokevofa.dll not found.
File/Folder C:\WINDOWS\system32\xahp.dll not found.
File/Folder C:\WINDOWS\system32\awvwu.dll not found.
File/Folder C:\WINDOWS\mssms.dll not found.
File/Folder C:\WINDOWS\system32\ssqqrol.dll not found.
< Purity >
C:\WINDOWS\АppPatch moved successfully.
C:\WINDOWS\ΑppPatch moved successfully.
C:\WINDOWS\Ѕymantec moved successfully.
C:\WINDOWS\ѕymbols moved successfully.
C:\WINDOWS\system32\aѕsembly moved successfully.
C:\WINDOWS\system32\аѕsembly moved successfully.
C:\WINDOWS\system32\Μicrosoft.NET moved successfully.
C:\WINDOWS\system32\Міcrosoft.NET moved successfully.
C:\WINDOWS\system32\sуstem moved successfully.
C:\Program Files\Αdobe moved successfully.
C:\Program Files\Аdobe moved successfully.
C:\Program Files\Mіcrosoft moved successfully.
C:\Program Files\ѕуstem moved successfully.
C:\Program Files\WіnSxS moved successfully.
C:\Program Files\Common Files\Fοnts moved successfully.
C:\Program Files\Common Files\Mіcrosoft moved successfully.
C:\Program Files\Common Files\ѕуstem moved successfully.
C:\Program Files\Common Files\sуstem32 moved successfully.
C:\Program Files\Common Files\Tаsks moved successfully.
C:\Documents and Settings\USER\My Documents\аѕsembly moved successfully.
C:\Documents and Settings\USER\My Documents\Μicrosoft moved successfully.
C:\Documents and Settings\USER\My Documents\Ѕуmantec moved successfully.
C:\Documents and Settings\USER\My Documents\ѕуmbols\ѕуmbols moved successfully.
C:\Documents and Settings\USER\My Documents\ѕуmbols\bak moved successfully.
C:\Documents and Settings\USER\My Documents\ѕуmbols moved successfully.
C:\Documents and Settings\USER\My Documents\ѕуstem moved successfully.
C:\Documents and Settings\USER\My Documents\ѕуstem32 moved successfully.
C:\Documents and Settings\USER\Application Data\Мicrosoft moved successfully.
C:\Documents and Settings\USER\Application Data\Οracle moved successfully.
C:\Documents and Settings\USER\Application Data\ѕecurity moved successfully.
C:\Documents and Settings\USER\Application Data\Тasks moved successfully.
C:\Documents and Settings\USER\Application Data\WіnSxS moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06172008_083254
HiJack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:35, on 6/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\lxdccoms.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.msn.com/0SE...S01?FORM=TOOLBRR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
http://wpad-van.sint...kn.com/wpad.datR3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll (file missing)
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll (file missing)
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: (no name) - {28D8912D-C0B5-42DE-B42C-5FE22D6A2332} - C:\WINDOWS\system32\d3dram.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe \RESET
O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe"
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKLM\..\Policies\Explorer\Run: [svchost] C:\WINDOWS\svchost.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} (WebInstall Class) -
http://scanner2.malw...tup/webinst.cabO16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) -
http://www.vzwpix.co...loadControl.cabO20 - AppInit_DLLs:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 6797 bytes
Sorry this took so long. Thank you so much for this help, I would be lost without your instruction.