Alright, here's combofix's log.
ComboFix 10-08-17.02 - DC17 18/08/2010 0:30.3.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.2.1033.18.3070.2416 [GMT -4:00]
Running from: f:\documents and settings\DC17\Desktop\ComboFix.exe
Command switches used :: f:\documents and settings\DC17\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"f:\windows\system32\drivers\lltipxi.sys"
.
((((((((((((((((((((((((( Files Created from 2010-07-18 to 2010-08-18 )))))))))))))))))))))))))))))))
.
2010-08-15 00:05 . 2010-08-15 00:05 -------- d-----w- F:\_OTS
2010-08-11 06:18 . 2010-08-11 06:34 -------- d-----w- f:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-11 06:18 . 2010-08-11 06:18 -------- d-----w- f:\program files\Spybot - Search & Destroy
2010-08-09 22:33 . 2010-08-09 22:33 -------- d-----w- f:\documents and settings\DC17\Local Settings\Application Data\Bizarre Creations
2010-08-01 06:17 . 2010-06-14 14:31 744448 -c----w- f:\windows\system32\dllcache\helpsvc.exe
2010-08-01 06:08 . 2010-08-01 06:08 12536 ----a-w- f:\windows\system32\avgrsstx.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-18 04:40 . 2008-09-25 02:10 -------- d-----w- f:\documents and settings\DC17\Application Data\Skype
2010-08-18 04:04 . 2008-09-25 02:10 -------- d-----w- f:\documents and settings\DC17\Application Data\skypePM
2010-08-11 07:03 . 2009-08-31 03:52 -------- d-----w- f:\program files\Free Offers from Freeze.com
2010-08-10 16:13 . 2009-11-10 21:24 -------- d-----w- f:\documents and settings\All Users\Application Data\avg9
2010-08-08 11:30 . 2010-08-08 11:30 503808 ----a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1b307008-n\msvcp71.dll
2010-08-08 11:30 . 2010-08-08 11:30 499712 ----a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1b307008-n\jmc.dll
2010-08-08 11:30 . 2010-08-08 11:30 348160 ----a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1b307008-n\msvcr71.dll
2010-08-08 11:30 . 2010-08-08 11:30 61440 ----a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1f6ec9e3-n\decora-sse.dll
2010-08-08 11:30 . 2010-08-08 11:30 12800 ----a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1f6ec9e3-n\decora-d3d.dll
2010-08-01 09:01 . 2010-01-23 02:28 -------- d-----w- f:\program files\Ask.com
2010-08-01 07:04 . 2008-10-20 23:07 -------- d-----w- f:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-01 06:10 . 2010-08-01 06:10 29512 ----a-w- f:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-08-01 06:10 . 2010-08-01 06:10 242896 ----a-w- f:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-08-01 06:10 . 2010-08-01 06:10 216200 ----a-w- f:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-08-01 06:08 . 2008-09-21 04:19 243024 ----a-w- f:\windows\system32\drivers\avgtdix.sys
2010-08-01 06:08 . 2008-09-21 04:19 29584 ----a-w- f:\windows\system32\drivers\avgmfx86.sys
2010-08-01 06:07 . 2008-09-21 04:19 216400 ----a-w- f:\windows\system32\drivers\avgldx86.sys
2010-08-01 06:05 . 2010-08-01 06:05 813336 ----a-w- f:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-08-01 06:05 . 2010-08-01 06:05 624920 ----a-w- f:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-08-01 06:05 . 2010-08-01 06:05 1690464 ----a-w- f:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-08-01 06:05 . 2010-08-01 06:05 1038688 ----a-w- f:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-08-01 06:02 . 2010-08-01 06:02 2944904 ----a-w- f:\documents and settings\DC17\Application Data\Mozilla\Firefox\Profiles\t3svmb5a.default\extensions\
[email protected]\chrome\temp\askToolbar.exe
2010-06-14 14:31 . 2008-09-20 23:10 744448 ----a-w- f:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-23 11:30 . 2010-05-23 11:30 61440 -c--a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-1213f078-n\decora-sse.dll
2010-05-23 11:30 . 2010-05-23 11:30 503808 -c--a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-71b15646-n\msvcp71.dll
2010-05-23 11:30 . 2010-05-23 11:30 348160 -c--a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-71b15646-n\msvcr71.dll
2010-05-23 11:30 . 2010-05-23 11:30 499712 -c--a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-71b15646-n\jmc.dll
2010-05-23 11:30 . 2010-05-23 11:30 12800 -c--a-w- f:\documents and settings\DC17\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-1213f078-n\decora-d3d.dll
2009-12-05 08:27 . 2009-11-11 02:25 25 -c-h--w- f:\program files\Common Files\common.log
2008-03-09 12:25 . 2008-12-01 21:12 236 -c-ha-w- f:\program files\Common Files\dx.reg
2006-07-13 15:19 . 2008-09-27 07:21 6718464 -c--a-w- f:\program files\mozilla firefox\plugins\libvlc.dll
2009-10-11 23:50 . 2009-10-11 23:50 76 -csh--r- f:\windows\ICSET40.BIN
2006-05-03 10:06 . 2008-11-02 21:12 163328 --sh--r- f:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2008-11-02 21:12 31232 -csh--r- f:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2008-11-17 00:39 216064 -csh--r- f:\windows\system32\nbDX.dll
2007-12-17 12:43 . 2008-11-02 21:12 27648 -csh--w- f:\windows\system32\Smab0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 19:23 1385864 ----a-w- f:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "f:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "f:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="f:\program files\Skype\\Phone\Skype.exe" [2010-03-09 26100520]
"AdobeUpdater"="f:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-06-26 2356088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"JMB36X IDE Setup"="f:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="f:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"M-Audio Taskbar Icon"="f:\windows\System32\M-AudioTaskBarIcon.exe" [2008-05-15 356864]
"DigidesignMMERefresh"="c:\program files\Digidesign\Digidesign\Drivers\MMERefresh.exe" [2007-10-31 77824]
"SunJavaUpdateSched"="f:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"AVG9_TRAY"="f:\progra~1\AVG\AVG9\avgtray.exe" [2010-08-01 2065760]
"Adobe Reader Speed Launcher"="f:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="f:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"XboxStat"="f:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 718688]
"NvCplDaemon"="f:\windows\system32\NvCpl.dll" [2009-11-21 12669544]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="f:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
f:\documents and settings\DC17\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2007-10-22 575488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-08-01 06:08 12536 ----a-w- f:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Nokia Nseries PC Suite.lnk]
path=f:\documents and settings\All Users\Start Menu\Programs\Startup\Nokia Nseries PC Suite.lnk
backup=f:\windows\pss\Nokia Nseries PC Suite.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
2008-08-14 11:58 611712 ----a-w- f:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2009-06-26 21:03 2356088 ----a-w- f:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-12-01 01:00 323392 ----a-w- f:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
2008-07-22 17:34 2772992 -c--a-w- f:\program files\Electronic Arts\EADM\Core.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy TM Forever]
2008-11-17 19:35 399872 ----a-w- c:\program files\Easy TM\EasyTM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GEST]
2007-12-14 15:46 236040 ----a-w- f:\program files\GIGABYTE\GEST\run.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-08-11 19:30 249856 -c--a-w- f:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2006-09-11 08:40 86960 -c--a-w- f:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 21:33 141600 -c--a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memeo Send]
2009-07-21 17:52 236816 -c--a-w- c:\program files\Memeo\Memeo Send\MemeoLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- f:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2001-07-09 15:50 155648 -c--a-w- f:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerStrip]
2008-11-19 21:26 737312 -c--a-w- c:\program files\PowerStrip\PStrip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 -c--a-w- f:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-01-26 19:31 2144088 --sha-r- f:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-05-10 16:24 1238352 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wefi]
2009-10-25 17:07 500056 ----a-w- f:\program files\WeFi\WeFi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-19 00:05 204288 -c----w- f:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoomText]
2009-04-23 15:04 3462392 ----a-w- f:\program files\ZoomText 9.1\Zt.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"f:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"f:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"f:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"f:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\Program Files\\Vuze\\Azureus.exe"=
"f:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spectraball\\Spectraball.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2009\\3dsmax.exe"=
"f:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Crazybump\\CB.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"f:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"f:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"f:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\zuma's revenge\\ZumasRevenge.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fatale\\FATALE.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\trackmania united\\TmForever.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\trackmania united\\TmForeverLauncher.exe"=
"f:\\Program Files\\DNA\\btdna.exe"=
"f:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"f:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\osmos\\osmos.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\LuxRender\\luxconsole.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis SP Demo\\Bin32\\Crysis.exe"=
"f:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\torchlight\\Torchlight.exe"=
"f:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\geometry wars\\GeometryWars.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\beat hazard\\BeatHazard.exe"=
"f:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"29101:TCP"= 29101:TCP:???? ??
"6880:TCP"= 6880:TCP:torrent
"8107:TCP"= 8107:TCP:eAmuse
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"58173:TCP"= 58173:TCP:Pando Media Booster
"58173:UDP"= 58173:UDP:Pando Media Booster
R0 DigiFilter;DigiFilter;f:\windows\system32\drivers\DigiFilt.sys [25/11/2008 4:05 AM 16384]
R1 Ai2sXP;Ai2sXP;f:\windows\system32\drivers\Ai2sXP.sys [25/03/2009 9:07 PM 7680]
R1 AvgLdx86;AVG AVI Loader Driver x86;f:\windows\system32\drivers\avgldx86.sys [21/09/2008 12:19 AM 216400]
R1 AvgTdiX;AVG8 Network Redirector;f:\windows\system32\drivers\avgtdix.sys [21/09/2008 12:19 AM 243024]
R2 avg9emc;AVG Free E-mail Scanner;f:\program files\AVG\AVG9\avgemc.exe [01/08/2010 2:07 AM 921952]
R2 avg9wd;AVG Free WatchDog;f:\program files\AVG\AVG9\avgwdsvc.exe [01/08/2010 2:07 AM 308136]
R2 HssWd;Hotspot Shield Monitoring Service;c:\documents and settings\David McKee\My Documents\Hotspot Shield\bin\hsswd.exe [31/03/2010 8:24 PM 194608]
R2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max Design 2009 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [10/03/2008 1:04 AM 65536]
R2 PStrip;PStrip;f:\windows\system32\drivers\pstrip.sys [14/07/2007 10:37 PM 27992]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;f:\windows\system32\drivers\ScreamingBAudio.sys [07/09/2008 9:02 PM 21920]
S3 FSVD2DRIVER;Freedom Scientific Video Device 2;f:\windows\system32\drivers\fsvd2strm.sys [12/11/2008 7:12 PM 31000]
S3 GEST Service;GEST Service for program management.;f:\program files\GIGABYTE\GEST\GSvr.exe [20/09/2008 7:56 PM 47624]
S3 iLokDrvr;iLok;f:\windows\system32\drivers\iLokDrvr.sys [08/09/2008 2:05 PM 54256]
S3 MAUSBFTP;Service for M-Audio Fast Track Pro (WDM);f:\windows\system32\drivers\mausb.sys [21/11/2008 12:55 AM 143624]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;f:\windows\system32\drivers\nmwcdnsu.sys [29/10/2008 2:39 PM 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;f:\windows\system32\drivers\nmwcdnsuc.sys [29/10/2008 2:39 PM 8320]
S3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [10/03/2010 11:33 AM 14424]
S3 UsbGps;LGE CDMA USB GPS NMEA Port;f:\windows\system32\drivers\lgusbgps.sys [20/03/2010 10:32 AM 19968]
S3 WefiEngSvc;WeFi Engine Service;f:\program files\WeFi\WefiEngSvc.exe [25/10/2009 1:07 PM 140632]
S3 XDva193;XDva193;\??\f:\windows\system32\XDva193.sys --> f:\windows\system32\XDva193.sys [?]
S3 XDva203;XDva203;\??\f:\windows\system32\XDva203.sys --> f:\windows\system32\XDva203.sys [?]
S3 XDva209;XDva209;\??\f:\windows\system32\XDva209.sys --> f:\windows\system32\XDva209.sys [?]
S3 XDva212;XDva212;\??\f:\windows\system32\XDva212.sys --> f:\windows\system32\XDva212.sys [?]
S3 XDva222;XDva222;\??\f:\windows\system32\XDva222.sys --> f:\windows\system32\XDva222.sys [?]
S3 XDva223;XDva223;\??\f:\windows\system32\XDva223.sys --> f:\windows\system32\XDva223.sys [?]
S3 XDva347;XDva347;\??\f:\windows\system32\XDva347.sys --> f:\windows\system32\XDva347.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-08-18 f:\windows\Tasks\OGALogon.job
- f:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
2010-08-18 f:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- f:\program files\Ask.com\UpdateTask.exe [2010-05-26 19:23]
.
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
IE: &Winamp Search - f:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
DPF: {1CE47888-DD62-482C-9723-4814BB04D45D} - hxxp://pump.musicshake.com/NewDownload/musicshake.cab
DPF: {36A4B20A-2B75-4101-86CE-F9B03CA4B91C} - hxxp://bgweb.nowcdn.co.kr/bin/DownStarter.cab
DPF: {47D22CCE-3C08-4DB0-BB99-B7D2266EEF5C} - hxxp://ez2on.uplay.co.kr/dll/RetroLauncher_10224.cab
DPF: {6DFC930D-4E50-4997-BC36-C37E41E52A23} - hxxp://ez2on.uplay.co.kr/dll/Retro_SystemCheck.cab
DPF: {9A48FC0D-F45B-4C77-9FE4-09ABE7F095F1} - hxxp://ez2on.uplay.co.kr/dataroom/atc1802.cab
DPF: {E91B6C86-494B-40B8-8266-627E5D57DA31} - hxxp://cdnfile.hclc.co.kr/cdn_file/X_ClientExx.cab
FF - ProfilePath - f:\documents and settings\DC17\Application Data\Mozilla\Firefox\Profiles\t3svmb5a.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npff_gdm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: f:\documents and settings\DC17\Application Data\Mozilla\Firefox\Profiles\t3svmb5a.default\extensions\
[email protected]\plugins\npWildPocketsLoader.dll
FF - plugin: f:\documents and settings\DC17\Application Data\Vusion\npWARPVideoPlugin.303954.dll
FF - plugin: f:\documents and settings\DC17\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: f:\documents and settings\DC17\Local Settings\Application Data\Yahoo!\BrowserPlus\2.8.1\Plugins\npybrowserplus_2.8.1.dll
FF - plugin: f:\documents and settings\DC17\LocalLow\StoneTrip\Web Player\npShiVa3D.dll
FF - plugin: f:\program files\3DVIA\3DVIAStudioPlayer\bin\win32_dynamic\release\npvtmp3dlifeplayer.dll
FF - plugin: f:\program files\Common Files\ParallelGraphics\Cortona\npCortona.dll
FF - plugin: f:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: f:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: f:\program files\Virtools\3D Life Player\npvirtools.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - f:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.order.1 - Google
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-18 00:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(928)
f:\windows\system32\WININET.dll
f:\progra~1\WINDOW~2\wmpband.dll
f:\windows\system32\ieframe.dll
f:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
f:\windows\system32\WPDShServiceObj.dll
f:\windows\system32\PortableDeviceTypes.dll
f:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
f:\windows\system32\nvsvc32.exe
f:\program files\AVG\AVG9\avgchsvx.exe
f:\program files\AVG\AVG9\avgrsx.exe
f:\program files\AVG\AVG9\avgcsrvx.exe
f:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
f:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
f:\program files\Bonjour\mDNSResponder.exe
c:\documents and settings\David McKee\My Documents\Hotspot Shield\HssWPR\hsssrv.exe
f:\program files\AVG\AVG9\avgnsx.exe
f:\program files\Java\jre6\bin\jqs.exe
f:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
f:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
f:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
f:\windows\system32\WgaTray.exe
f:\program files\Windows Media Player\WMPNetwk.exe
f:\program files\AVG\AVG9\avgcsrvx.exe
f:\program files\Internet Explorer\IEXPLORE.EXE
f:\program files\winamp toolbar\WinampTbServer.exe
f:\windows\RTHDCPL.EXE
f:\program files\Skype\Phone\Skype.exe
f:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2010-08-18 00:43:18 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-18 04:43
ComboFix2.txt 2010-08-18 04:24
ComboFix3.txt 2010-08-15 05:23
Pre-Run: 2,014,445,568 bytes free
Post-Run: 2,005,803,008 bytes free
- - End Of File - - 03962D775412BA6F5BE999C437283865
MalwarebytesMalwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4443
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
18/08/2010 1:20:37 AM
mbam-log-2010-08-18 (01-20-37).txt
Scan type: Quick scan
Objects scanned: 137350
Time elapsed: 4 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
F:\WINDOWS\efuvanomozolo.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
F:\Program Files\Common Files\common.log (Trojan.Agent) -> Quarantined and deleted successfully.
F:\WINDOWS\system32\d3dx10d.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
F:\WINDOWS\system32\TDSSuvggbtme.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
Note. I found this file called wuiaproi.dll in my WINDOWS folder. I can't find any info on it... is that file ok or not?
JavaRaJavaRa 1.16 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Wed Aug 18 02:29:53 2010
Found and removed: F:\Documents and Settings\DC17\Application Data\Sun\Java\jre1.6.0_11
Found and removed: F:\Documents and Settings\DC17\Application Data\Sun\Java\jre1.6.0_12
Found and removed: F:\Documents and Settings\DC17\Application Data\Sun\Java\jre1.6.0_14
Found and removed: F:\Documents and Settings\DC17\Application Data\Sun\Java\jre1.6.0_15
Found and removed: F:\Documents and Settings\DC17\Application Data\Sun\Java\jre1.6.0_18
Found and removed: Software\JavaSoft\Java2D\1.5.0_05
Found and removed: SOFTWARE\Classes\JavaPlugin.150_05
Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\JavaSoft\Java2D\1.6.0
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
JavaRa 1.16 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Wed Aug 18 02:30:16 2010
------------------------------------
Finished reporting.
I'm going to post these logs in seperate posts just incase my computer restarts before I got to post.
Edited by Dreamcube017, 18 August 2010 - 12:33 AM.