Right
I ran ComboFix
It didn't like that AVG was still running and i couldn't find a way to stop it so it continued anyway.
I downloaded the Microsoft restore service or something. That was fine
Attached is the log
Thank you again
Layth
ComboFix 09-06-15.07 - Vix 16/06/2009 18:48.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.495.136 [GMT 1:00]
Running from: F:\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\system32\winmplayer.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.
2009-06-16 17:24 . 2009-06-16 17:24 -------- d-----w- C:\_OTS
2009-06-16 16:44 . 2009-06-16 16:44 -------- d-----w- c:\windows\LastGood
2009-06-16 15:32 . 2009-06-16 15:32 0 ----a-w- c:\windows\nsreg.dat
2009-06-16 15:32 . 2009-06-16 15:32 -------- d-----w- c:\documents and settings\Vix\Local Settings\Application Data\Mozilla
2009-06-16 15:17 . 2009-06-16 15:17 -------- d-----w- c:\program files\ERUNT
2009-06-16 14:56 . 2009-06-16 14:00 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-16 13:52 . 2009-06-16 14:00 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-16 13:52 . 2009-06-16 13:52 -------- d-----w- c:\windows\system32\DRVSTORE
2009-06-16 13:52 . 2009-06-16 13:52 -------- d--h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-16 13:52 . 2009-03-12 08:17 2902048 ----a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-16 13:51 . 2009-06-16 13:51 -------- d-----w- c:\program files\Lavasoft
2009-06-16 13:51 . 2009-06-16 13:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-15 21:25 . 2009-06-15 21:25 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-15 21:07 . 2009-06-15 21:07 -------- d-----w- c:\windows\system32\scripting
2009-06-15 21:07 . 2009-06-15 21:07 -------- d-----w- c:\windows\l2schemas
2009-06-15 21:07 . 2009-06-15 21:07 -------- d-----w- c:\windows\system32\en
2009-06-15 21:07 . 2009-06-15 21:07 -------- d-----w- c:\windows\system32\bits
2009-06-15 20:28 . 2009-06-15 20:28 -------- d-----w- c:\windows\ie8updates
2009-06-15 20:26 . 2003-02-28 17:26 139536 ----a-w- c:\windows\system32\javaee.dll
2009-06-15 20:24 . 2009-06-15 20:24 -------- d--h--w- C:\$AVG8.VAULT$
2009-06-15 20:19 . 2009-06-15 20:19 -------- d-----w- c:\program files\MSXML 4.0
2009-06-15 20:17 . 2008-04-14 00:12 4874240 ------w- c:\windows\system32\dllcache\wmp.dll
2009-06-15 20:17 . 2008-09-10 01:14 1307648 ------w- c:\windows\system32\msxml6.dll
2009-06-15 20:17 . 2008-09-10 01:14 1307648 ------w- c:\windows\system32\dllcache\msxml6.dll
2009-06-15 20:15 . 2008-04-14 00:11 48640 ------w- c:\windows\system32\dhcpqec.dll
2009-06-15 20:14 . 2008-04-14 00:12 114688 ------w- c:\windows\system32\dllcache\wmpasf.dll
2009-06-15 20:13 . 2003-03-31 11:00 403 ------w- c:\windows\system32\dllcache\npdrmv2.zip
2009-06-15 20:13 . 2003-03-31 11:00 22060 ------w- c:\windows\system32\dllcache\npds.zip
2009-06-15 19:48 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2009-06-15 19:46 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-06-15 19:46 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2009-06-15 19:46 . 2008-12-11 10:57 333952 ------w- c:\windows\system32\dllcache\srv.sys
2009-06-15 19:46 . 2008-05-01 14:33 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2009-06-15 19:45 . 2008-04-11 19:04 691712 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-06-15 19:45 . 2008-10-24 11:21 455296 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2009-06-15 19:45 . 2008-10-03 10:02 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-06-15 19:45 . 2008-09-04 17:15 1106944 ------w- c:\windows\system32\dllcache\msxml3.dll
2009-06-15 19:44 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-06-15 19:44 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-06-15 19:44 . 2009-06-15 19:44 -------- d--h--w- c:\windows\$hf_mig$
2009-06-15 19:35 . 2009-06-15 19:35 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-15 19:35 . 2009-06-15 19:35 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-15 19:35 . 2009-06-15 19:35 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-15 19:35 . 2009-06-15 19:35 -------- d-----w- c:\windows\system32\drivers\Avg
2009-06-15 19:35 . 2009-06-15 19:35 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-15 19:34 . 2009-06-15 19:34 -------- d-----w- c:\program files\AVG
2009-06-15 19:34 . 2009-06-15 19:34 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-15 19:23 . 2009-06-15 19:23 -------- d-----w- c:\documents and settings\Vix\Application Data\AVG8
2009-06-15 19:21 . 2009-06-15 19:21 -------- d-sh--w- c:\documents and settings\Vix\IECompatCache
2009-06-15 19:21 . 2009-06-15 19:21 -------- d-sh--w- c:\documents and settings\Vix\PrivacIE
2009-06-15 19:19 . 2009-06-15 19:19 -------- d-sh--w- c:\documents and settings\Vix\IETldCache
2009-06-15 19:15 . 2009-06-15 19:15 -------- d--h--w- c:\windows\ie8
2009-06-15 19:07 . 2009-06-15 19:07 -------- d-----w- c:\windows\system32\wbem\AutoRecover
2009-06-15 18:58 . 2008-04-14 00:12 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-06-15 18:56 . 2008-04-14 00:12 1737856 ------w- c:\windows\system32\mtxparhd.dll
2009-06-15 18:53 . 2009-06-15 18:53 -------- d-----w- c:\windows\ServicePackFiles
2009-06-15 18:49 . 2008-04-13 17:39 2897920 ------w- c:\windows\system32\xpsp2res.dll
2009-06-15 18:46 . 2009-01-07 17:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-06-15 18:43 . 2009-06-15 18:43 -------- d-----w- c:\windows\EHome
2009-05-28 20:08 . 2009-02-15 16:49 38200 ----a-w- c:\documents and settings\Beebop\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-05-28 19:36 . 2009-05-28 19:36 0 ----a-w- c:\windows\system32\cok458en.dat
2009-05-28 19:36 . 2009-05-28 19:36 0 ----a-w- c:\windows\system32\mmd109en.dat
2009-05-27 13:39 . 2009-05-27 13:39 16896 ----a-w- c:\windows\system32\perfc5932.dat
2009-05-27 13:39 . 2009-05-27 13:39 1 ----a-w- c:\windows\system32\perfc7683.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 21:13 . 2004-01-03 09:08 76487 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-06-15 20:26 . 2009-06-15 20:26 2678 ----a-w- c:\windows\java\Packages\Data\YONNRR5V.DAT
2009-06-15 20:26 . 2009-06-15 20:26 2678 ----a-w- c:\windows\java\Packages\Data\7VVBZRBV.DAT
2009-06-15 20:26 . 2009-06-15 20:26 2678 ----a-w- c:\windows\java\Packages\Data\L79J3XVT.DAT
2009-06-15 20:26 . 2009-06-15 20:26 2678 ----a-w- c:\windows\java\Packages\Data\HR797R5R.DAT
2009-06-15 20:26 . 2009-06-15 20:26 2678 ----a-w- c:\windows\java\Packages\Data\AOIPRTR7.DAT
2009-06-15 19:35 . 2008-01-30 22:46 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-15 19:08 . 2004-10-31 09:42 79608 ----a-w- c:\documents and settings\Vix\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-15 17:43 . 1979-12-31 23:00 530772 ----a-w- c:\windows\system32\pst.dat
2009-05-26 12:20 . 2009-01-05 21:04 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 12:19 . 2009-01-05 21:04 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-13 05:15 . 1979-12-31 23:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 1979-12-31 23:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-17 12:26 . 1979-12-31 23:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-01-03 09:59 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-12 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-10-02 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-10-02 118784]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2003-04-28 184320]
"LManager"="c:\progra~1\LAUNCH~1\CPLBCL53.EXE" [2003-12-15 262144]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 40960]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-07-25 151552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-06-04 286720]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-10-15 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"CONNECTScheduler"="c:\program files\Sony\CONNECTAutoUpdate\CONNECTScheduler.exe" [2005-11-15 69632]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-15 1948440]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-16 518488]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2003-05-14 55296]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-07-25 88363]
"bcmwltry"="bcmwltry.exe" - c:\windows\system32\bcmwltry.exe [2003-07-25 462848]
"RemoveCpl"="RemoveCpl.exe" - c:\windows\system32\RemoveCpl.exe [2003-01-14 24576]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
PI Monitor.lnk - c:\program files\ArcSoft\PhotoImpression 5\PI Monitor.exe [2004-12-25 86016]
CONNECTAUTrayApp.lnk - c:\program files\Sony\CONNECTAutoUpdate\CONNECTAUTrayApp.exe [2005-11-15 114688]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Exif Launcher 2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2007-8-1 294912]
USB Wireless Client Utility.lnk - c:\program files\Wireless USB\Installer\WINXP\USB Wireless Client Utility.exe [2009-1-8 598016]
Net Send GUI.lnk - c:\program files\Fomine Net Send GUI\NetSendGUI.exe [2008-2-25 258048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-15 19:35 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Fomine Net Send GUI\\NetSendGUI.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [16/06/2009 14:52 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [15/06/2009 20:35 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [15/06/2009 20:35 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [15/06/2009 20:34 298776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 20:06 1005904]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-16 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 14:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe"
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {ACC5B0A3-BC18-4CA2-A631-568266DE2E8F} = 192.168.0.1
TCP: {BF1C3B9B-2ECF-49B0-8295-FF0FF8BB7C4B} = 192.168.0.1
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-16 18:56
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-16 18:59
ComboFix-quarantined-files.txt 2009-06-16 17:59
Pre-Run: 5,190,631,424 bytes free
Post-Run: 5,166,006,272 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
186 --- E O F --- 2009-06-16 16:49