Page 1 of 1

HELP NEEDED PLS... PC is freezing up ...logs attached..

PostPosted: Mon Sep 07, 2009 6:17 pm
by KenA
Hi there

I ran Malwarebytes and it detected 3 trojans and deleted them on reboot. it wont run Firefox now but WILL run IE. the trojans were located in the Firefox folder.

I cant disable or uninstall AVG internet security thats installed. However, i still ran combofix and hijack this. Its a little better but still VERY slow.

heres the logs:
HIJACKTHIS

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:49:19, on 07/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\WINDOWS\vVX6000.exe
C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - *{0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (file missing)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-21-2052111302-1336601894-725345543-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0413775653
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 0430515484
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 7864 bytes


COMBOFIX

ComboFix 09-09-06.06 - ALL 07/09/2009 16:36.1.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1790.1317 [GMT 1:00]
Running from: E:\ComboFix.exe
AV: AVG Internet Security 3-pack *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\8e82a.msi

.
((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.

2009-08-29 15:52 . 2009-09-07 10:08 -------- d-----w- c:\program files\CDex_150
2009-08-21 02:05 . 2009-08-21 02:05 -------- d-----w- C:\e625d13149515dd8c2108a2320ef5f
2009-08-12 19:25 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-21 02:19 . 2009-04-22 22:00 69232 ----a-w- c:\documents and settings\ALL\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-15 12:46 . 2009-07-18 18:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-13 02:02 . 2009-07-18 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-05 09:01 . 2002-06-25 21:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 12:36 . 2009-07-18 18:55 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 12:36 . 2009-07-18 18:55 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-30 17:25 . 2009-04-22 18:29 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-30 17:25 . 2009-04-22 18:29 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-30 17:25 . 2009-04-22 18:29 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-26 11:23 . 2009-04-25 13:06 -------- d-----w- c:\documents and settings\ALL\Application Data\Canon
2009-07-20 10:21 . 2009-07-20 10:21 -------- d-----w- c:\program files\Windows Media Connect 2
2009-07-18 19:02 . 2009-07-18 19:02 -------- d-----w- c:\program files\Microsoft Works
2009-07-18 19:01 . 2009-04-24 19:55 -------- d-----w- c:\program files\MSBuild
2009-07-18 19:00 . 2009-07-18 19:00 -------- d-----w- c:\program files\Microsoft.NET
2009-07-18 18:59 . 2009-07-18 18:59 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-07-18 18:55 . 2009-07-18 18:55 -------- d-----w- c:\documents and settings\ALL\Application Data\Malwarebytes
2009-07-18 18:55 . 2009-07-18 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-18 18:53 . 2009-07-18 18:53 -------- d-----w- c:\program files\D-Tools
2009-07-17 19:01 . 2002-06-25 21:36 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2004-08-04 07:56 286208 ------w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2002-03-05 07:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 ------w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2002-06-25 21:37 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2002-06-25 21:49 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2002-06-25 21:45 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2002-06-25 21:45 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2002-06-25 21:42 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2002-06-25 21:40 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2002-06-25 21:39 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2002-06-25 21:39 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2002-06-25 21:47 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2002-06-25 21:38 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2002-06-25 21:48 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2002-06-25 21:36 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 08:19 . 2009-04-22 04:03 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2002-06-25 21:50 132096 ----a-w- c:\windows\system32\wkssvc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-02 12:38 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-12 2007832]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-22 148888]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\ALL\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-30 17:25 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [22/04/2009 19:29 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [22/04/2009 19:29 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [22/04/2009 19:29 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [24/04/2009 19:51 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [23/04/2009 18:50 297752]
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [24/04/2009 19:51 1370488]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [22/04/2009 19:27 29208]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [22/04/2009 19:27 29208]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [18/07/2009 19:55 38160]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14/05/2007 10:26 508288]
S3 PAC7302;PAC7302 VGA USB Camera;c:\windows\system32\drivers\PAC7302.SYS [21/06/2009 21:21 457856]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [23/04/2009 18:20 2077840]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-GEST - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ie/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-07 16:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\MSCompPackV1.log 8181 bytes
c:\windows\msdfmap.ini 1405 bytes
c:\windows\msgsocm.log 25639 bytes
c:\windows\MSI30-KB884016.log 5245 bytes
c:\windows\msxml4-KB954430-enu.LOG 335172 bytes
c:\windows\mui
c:\windows\network diagnostic
c:\windows\NIRCMD.exe 31232 bytes executable
c:\windows\NLSDownlevelMapping.log 6826 bytes
c:\windows\notepad.exe 69120 bytes executable
c:\windows\nsreg.dat 0 bytes
c:\windows\ntdtcsetup.log 106921 bytes
c:\windows\setuplog.txt 792676 bytes
c:\windows\SHELLNEW
c:\windows\SkyTel.exe 1826816 bytes executable
c:\windows\slrundll.exe 32866 bytes executable
c:\windows\Soap Bubbles.bmp 65978 bytes
c:\windows\SoftwareDistribution
c:\windows\SOUNDMAN.EXE 77824 bytes executable
c:\windows\spupdsvc.log 149584 bytes
c:\windows\spupdsvc.log.1.log 187 bytes
c:\windows\srchasst
c:\windows\Sti_Trace.log 0 bytes
c:\windows\Sun
c:\windows\svcpack.log 881755 bytes
c:\windows\SWREG.exe 161792 bytes executable
c:\windows\SWSC.exe 136704 bytes executable
c:\windows\SWXCACLS.exe 212480 bytes executable
c:\windows\SxsCaPendDel
c:\windows\system.ini 231 bytes
c:\windows\system32
c:\windows\TASKMAN.EXE 15360 bytes executable
c:\windows\Tasks
c:\windows\temp
c:\windows\tsoc.log 197639 bytes
c:\windows\twain.dll 94784 bytes
c:\windows\twain_32
c:\windows\twain_32.dll 50688 bytes executable
c:\windows\twunk_16.exe 49680 bytes
c:\windows\twunk_32.exe 25600 bytes executable
c:\windows\updspapi.log 145048 bytes
c:\windows\USetup.iss 553 bytes
c:\windows\ERDNT
c:\windows\explorer.exe 1033728 bytes executable
c:\windows\explorer.scf 80 bytes
c:\windows\FaxSetup.log 504838 bytes
c:\windows\FeatherTexture.bmp 16730 bytes
c:\windows\Fonts
c:\windows\gdrv.sys 16608 bytes executable
c:\windows\Gone Fishing.bmp 17336 bytes
c:\windows\Greenstone.bmp 26582 bytes
c:\windows\grep.exe 80412 bytes executable
c:\windows\Help
c:\windows\hh.exe 10752 bytes executable
c:\windows\HideWin.exe 319488 bytes executable
c:\windows\IDNMitigationAPIs.log 8702 bytes
c:\windows\ie7
c:\windows\ie7.log 38956 bytes
c:\windows\ie7updates
c:\windows\ie7_main.log 35559 bytes
c:\windows\ie8_main.log 39850 bytes
c:\windows\iis6.log 78316 bytes
c:\windows\repair
c:\windows\Resources
c:\windows\Rhododendron.bmp 17362 bytes
c:\windows\River Sumida.bmp 26680 bytes
c:\windows\RTHDCPL.EXE 16851456 bytes executable
c:\windows\RtkUpd.exe 1200128 bytes executable
c:\windows\RTLCPL.EXE 9715200 bytes executable
c:\windows\RtlExUpd.dll 528384 bytes executable
c:\windows\RtlUpd.exe 1200128 bytes executable
c:\windows\Santa Fe Stucco.bmp 65832 bytes
c:\windows\SchedLgU.Txt 20620 bytes
c:\windows\security
c:\windows\sed.exe 98816 bytes executable
c:\windows\ServicePackFiles
c:\windows\sessmgr.setup.log 1536 bytes
c:\windows\SET1B.tmp 178803 bytes
c:\windows\SET3.tmp 1085913 bytes
c:\windows\SET7.tmp 13608 bytes
c:\windows\SETD.tmp 7046 bytes
c:\windows\setupact.log 175734 bytes
c:\windows\setupapi.log 606659 bytes
c:\windows\setupapi.log.0.old 1141941 bytes
c:\windows\vbaddin.ini 37 bytes
c:\windows\vmmreg32.dll 18944 bytes executable
c:\windows\vVX6000.exe 713744 bytes executable
c:\windows\VX6000.src 13022 bytes
c:\windows\VX6KStd.ini 15497 bytes
c:\windows\WBEM
c:\windows\Web
c:\windows\WFT-E3Utility.INI 108 bytes
c:\windows\wiadebug.log 159 bytes
c:\windows\wiaservc.log 48 bytes
c:\windows\win.ini 891 bytes
c:\windows\Windows Update.log 240 bytes
c:\windows\WindowsShell.Manifest 749 bytes
c:\windows\WindowsUpdate.log 1936287 bytes
c:\windows\COM+.log 1436 bytes
c:\windows\EHome
c:\windows\ime
c:\windows\KB938464-v2.log 12780 bytes
c:\windows\KB952954.log 27633 bytes
c:\windows\KB961501.log 15148 bytes
c:\windows\msapps
c:\windows\Q308677.log 30265 bytes
c:\windows\regopt.log 1630 bytes
c:\windows\setuperr.log 0 bytes
c:\windows\vb.ini 36 bytes
c:\windows\winhelp.exe 256192 bytes
c:\windows\Q308928.log 7369 bytes
c:\windows\Q309056.log 431 bytes
c:\windows\Q310051.log 4072 bytes
c:\windows\Q310601.log 28602 bytes
c:\windows\Q311542.log 10988 bytes
c:\windows\Q311822.log 2239 bytes
c:\windows\Q311889.log 26888 bytes
c:\windows\Q311967.log 5591 bytes
c:\windows\Q313596.log 21961 bytes
c:\windows\Q314147.log 8981 bytes
c:\windows\Q315000.log 20249 bytes
c:\windows\Q315403.log 12701 bytes
c:\windows\Q316134.log 18746 bytes
c:\windows\Q316253.log 23526 bytes
c:\windows\Q317277.log 16994 bytes
c:\windows\Q319580.log 7948 bytes
c:\windows\regedit.exe 146432 bytes executable
c:\windows\Registration
c:\windows\REGLOCS.OLD 8192 bytes
c:\windows\comsetup.log 177469 bytes
c:\windows\Config
c:\windows\Connection Wizard
c:\windows\control.ini 0 bytes
c:\windows\Cursors
c:\windows\daemon.dll 69120 bytes executable
c:\windows\Debug
c:\windows\desktop.ini 2 bytes
c:\windows\DirectX.log 244180 bytes
c:\windows\Downloaded Installations
c:\windows\Downloaded Program Files
c:\windows\Driver Cache
c:\windows\DtcInstall.log 586 bytes
c:\windows\imsins.BAK 1374 bytes
c:\windows\imsins.log 1374 bytes
c:\windows\inf
c:\windows\Installer
c:\windows\java
c:\windows\KB842773.log 9790 bytes
c:\windows\KB888111.log 4801 bytes
c:\windows\KB892130.log 9876 bytes
c:\windows\KB898461.log 6743 bytes
c:\windows\KB915865.log 2061 bytes
c:\windows\KB923561.log 9615 bytes
c:\windows\KB929399.log 8471 bytes
c:\windows\KB932823-v3.log 22545 bytes
c:\windows\KB936782.log 7946 bytes
c:\windows\KB938127-v2-IE7.log 6523 bytes
c:\windows\0.log 0 bytes
c:\windows\002234_.tmp 19528 bytes
c:\windows\004965_.tmp 19569 bytes
c:\windows\addins
c:\windows\ALCMTR.EXE 57344 bytes executable
c:\windows\ALCWZRD.EXE 2808832 bytes executable
c:\windows\AMCap.exe 163840 bytes executable
c:\windows\AppPatch
c:\windows\assembly
c:\windows\atiogl.xml 14849 bytes
c:\windows\ativpsrm.bin 0 bytes
c:\windows\Blue Lace 16.bmp 1272 bytes
c:\windows\bootstat.dat 2048 bytes
c:\windows\clock.avi 82944 bytes
c:\windows\cmsetacl.log 373 bytes
c:\windows\Coffee Bean.bmp 17062 bytes
c:\windows\KB954154.log 4321 bytes
c:\windows\KB954459.log 12110 bytes
c:\windows\KB954600.log 11973 bytes
c:\windows\KB955069.log 11763 bytes
c:\windows\KB955839.log 39349 bytes
c:\windows\KB956572.log 22227 bytes
c:\windows\KB956744.log 13668 bytes
c:\windows\KB956802.log 16219 bytes
c:\windows\KB956803.log 20120 bytes
c:\windows\KB957097.log 14979 bytes
c:\windows\KB958644.log 12287 bytes
c:\windows\KB958687.log 14901 bytes
c:\windows\KB958690.log 18987 bytes
c:\windows\KB959426.log 27255 bytes
c:\windows\KB959772.log 5275 bytes
c:\windows\KB960225.log 25169 bytes
c:\windows\KB960715.log 14390 bytes
c:\windows\KB960803.log 17757 bytes
c:\windows\KB960859.log 23845 bytes
c:\windows\KB961118.log 4825 bytes
c:\windows\KB961371.log 11147 bytes
c:\windows\KB961373.log 26266 bytes
c:\windows\KB961503.log 10871 bytes
c:\windows\KB963027.log 16939 bytes
c:\windows\KB967715.log 20274 bytes
c:\windows\KB968389.log 15439 bytes
c:\windows\KB968537.log 11912 bytes
c:\windows\KB969897.log 16191 bytes
c:\windows\KB969898.log 7853 bytes
c:\windows\KB970238.log 12246 bytes
c:\windows\KB970653-v3.log 33794 bytes
c:\windows\KB971557.log 23409 bytes
c:\windows\KB971633.log 11713 bytes
c:\windows\KB971657.log 23905 bytes
c:\windows\KB972260-IE7.log 70369 bytes
c:\windows\KB972260.log 14729 bytes
c:\windows\KB973346.log 12764 bytes
c:\windows\KB973354.log 13022 bytes
c:\windows\KB973507.log 24052 bytes
c:\windows\KB973540.log 13386 bytes
c:\windows\KB973815.log 22590 bytes
c:\windows\KB973869.log 13273 bytes
c:\windows\l2schemas
c:\windows\MAXLINK.INI 412 bytes
c:\windows\Media
c:\windows\MicCal.exe 2165760 bytes executable
c:\windows\Microsoft.NET
c:\windows\msagent
c:\windows\ocgen.log 256525 bytes
c:\windows\ocmsn.log 28185 bytes
c:\windows\ODBCINST.INI 4161 bytes
c:\windows\OEWABLog.txt 1514 bytes
c:\windows\Offline Web Pages
c:\windows\OPTIONS
c:\windows\PCHEALTH
c:\windows\peernet
c:\windows\PEV.exe 230912 bytes executable
c:\windows\PixArt
c:\windows\Prairie Wind.bmp 65954 bytes
c:\windows\Prefetch
c:\windows\provisioning
c:\windows\Q306676.log 14930 bytes
c:\windows\Q308387.log 25176 bytes
c:\windows\Q308402.log 25176 bytes
c:\windows\KB939683.log 8191 bytes
c:\windows\KB941569.log 10790 bytes
c:\windows\KB942288-v3.log 9551 bytes
c:\windows\KB946648.log 20624 bytes
c:\windows\KB950760.log 13954 bytes
c:\windows\KB950762.log 14921 bytes
c:\windows\KB950974.log 25835 bytes
c:\windows\KB951066.log 14456 bytes
c:\windows\KB951376-v2.log 21921 bytes
c:\windows\KB951748.log 19821 bytes
c:\windows\KB951978.log 13960 bytes
c:\windows\KB952004.log 21779 bytes
c:\windows\KB952069.log 12352 bytes
c:\windows\KB952287.log 14600 bytes
c:\windows\$NtUninstallKB969898$
c:\windows\$NtUninstallKB970238$
c:\windows\$NtUninstallKB970653-v3$
c:\windows\$NtUninstallKB971557$
c:\windows\$NtUninstallKB971633$
c:\windows\$NtUninstallKB971657$
c:\windows\$NtUninstallKB972260$
c:\windows\$NtUninstallKB973346$
c:\windows\$NtUninstallKB973354$
c:\windows\$NtUninstallKB973507$
c:\windows\$NtUninstallKB973540_WM9$
c:\windows\$NtUninstallKB973815$
c:\windows\$NtUninstallKB973869$
c:\windows\$NtUninstallMSCompPackV1$
c:\windows\$NtUninstallWMFDist11$
c:\windows\$NtUninstallwmp11$
c:\windows\$NtUninstallWudf01000$
c:\windows\winhlp32.exe 283648 bytes executable
c:\windows\winnt.bmp 48680 bytes
c:\windows\winnt256.bmp 48680 bytes
c:\windows\WinSxS
c:\windows\WMFDist11.log 107343 bytes
c:\windows\wmp11.log 21129 bytes
c:\windows\wmsetup.log 13547 bytes
c:\windows\wmsetup10.log 394 bytes
c:\windows\WMSysPr9.prx 316640 bytes
c:\windows\WMSysPrx.prx 299552 bytes
c:\windows\WORDPAD.INI 754 bytes
c:\windows\Wudf01000Inst.log 10380 bytes
c:\windows\Zapotec.bmp 9522 bytes
c:\windows\zip.exe 68096 bytes executable
c:\windows\_default.pif 707 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Finnish.bin 22868 bytes
c:\docume~1\ALL\LOCALS~1\Temp\French.bin 27246 bytes
c:\docume~1\ALL\LOCALS~1\Temp\gaopdx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\German.bin 25764 bytes
c:\docume~1\ALL\LOCALS~1\Temp\geyekr000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Greek.bin 25093 bytes
c:\docume~1\ALL\LOCALS~1\Temp\gxvxc000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Hebrew.bin 19564 bytes
c:\docume~1\ALL\LOCALS~1\Temp\hjgrui000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\hsperfdata_ALL
c:\docume~1\ALL\LOCALS~1\Temp\Hungarian.bin 26094 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Italian.bin 27465 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Japanese.bin 24340 bytes
c:\docume~1\ALL\LOCALS~1\Temp\java_install_reg.log 582 bytes
c:\docume~1\ALL\LOCALS~1\Temp\jusched.log 3549 bytes
c:\docume~1\ALL\LOCALS~1\Temp\kbiwkm000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Korean.bin 20145 bytes
c:\docume~1\ALL\LOCALS~1\Temp\kungsf000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\d2Farec0BPd38AwkgBzAFxL1e0fg= 2330 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\ErrorResponse.xml 1984 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\G82vH7n3+PsFISdIk3ciAqK6BFY= 374130 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\QJwDfPchunK6+PZOmuBiMS51WO4= 29379 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\Sounds
c:\docume~1\ALL\LOCALS~1\Temp\msivx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\msqpdx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Norwegian.bin 21975 bytes
c:\docume~1\ALL\LOCALS~1\Temp\ose00000.exe 145184 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\outlook logging
c:\docume~1\ALL\LOCALS~1\Temp\outlook logging\firstrun.log 111 bytes
c:\docume~1\ALL\LOCALS~1\Temp\ovfsth000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Polish.bin 24232 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Portuguese(Brazil).bin 25082 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Portuguese.bin 26271 bytes
c:\docume~1\ALL\LOCALS~1\Temp\quadra000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\rotscx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Russian.bin 26136 bytes
c:\docume~1\ALL\LOCALS~1\Temp\seneka000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\set7B.tmp 121064 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\SimChin.bin 16420 bytes
c:\docume~1\ALL\LOCALS~1\Temp\skynet000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Spanish.bin 27764 bytes
c:\docume~1\ALL\LOCALS~1\Temp\SWEDISH.bin 24099 bytes
c:\docume~1\ALL\LOCALS~1\Temp\tdss000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Thai.bin 21987 bytes
c:\docume~1\ALL\LOCALS~1\Temp\TradChin.bin 16962 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Turkish.bin 22263 bytes
c:\docume~1\ALL\LOCALS~1\Temp\uac000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\vsfoce000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\wmplog00.sqm 2004 bytes
c:\docume~1\ALL\LOCALS~1\Temp\WPDNSE
c:\docume~1\ALL\LOCALS~1\Temp\wzszx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\ytasfw000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_1MIMjDFg3exAgEVKwVMo 28704 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_7yYKJWbC6DLaDq7t7KSr 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_CMjcjfLDwbKb15K69YEk 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_cnbFkVvruneuE5obkUqE 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_e9x62ffIXRRuAPBOVkZA 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_HFFnYjN1H9gANbWJiFIu 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_KCwBhUDYBvw1ICO8VzNd 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_XssudSABpVd5G5V4VNA6 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_yAGvX24XF0E39gmKrmBb 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_yqwXMzplR31f8CoZWift 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Arabic.bin 20991 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Av-test.txt 72 bytes
c:\docume~1\ALL\LOCALS~1\Temp\avg8inst.log 69415 bytes
c:\docume~1\ALL\LOCALS~1\Temp\catchme.dll 53248 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\CEOSUTL
c:\docume~1\ALL\LOCALS~1\Temp\cmd.execf 389120 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\Czech.bin 24321 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Danish.bin 22794 bytes
c:\docume~1\ALL\LOCALS~1\Temp\dgm000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Dutch.bin 25758 bytes
c:\docume~1\ALL\LOCALS~1\Temp\English.bin 21944 bytes
c:\docume~1\ALL\LOCALS~1\Temp\esqul000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_0sPWJHWW9d2OGiQ6MUcJ 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\_is1.exe 460248 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\_w7UKS7t.pdf.part 195721 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{83BD5167-4996-4DF8-A187-EBC0DA81F647}
c:\docume~1\ALL\LOCALS~1\Temp\{83BD5167-4996-4DF8-A187-EBC0DA81F647}\ISSetup.dll 492164 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\{83BD5167-4996-4DF8-A187-EBC0DA81F647}\setup.isn 64392 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{83BD5167-4996-4DF8-A187-EBC0DA81F647}\_Setup.dll 373680 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\{8C04BD2C-B1BB-44D3-BD74-71964D99B87E}
c:\docume~1\ALL\LOCALS~1\Temp\{8C04BD2C-B1BB-44D3-BD74-71964D99B87E}\{E8AEA11B-E60A-455E-B008-E4E763604612}
c:\docume~1\ALL\LOCALS~1\Temp\{8C04BD2C-B1BB-44D3-BD74-71964D99B87E}\{E8AEA11B-E60A-455E-B008-E4E763604612}\urlhooks.txt 40 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{99663C9E-00F3-420A-A136-4ADC0126250F}
c:\docume~1\ALL\LOCALS~1\Temp\{99663C9E-00F3-420A-A136-4ADC0126250F}\setup.isn 256664 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{C79E7FFD-AD4E-4ABA-9D93-80D1E071F0C1}
c:\docume~1\ALL\LOCALS~1\Temp\{C79E7FFD-AD4E-4ABA-9D93-80D1E071F0C1}\setup.isn 256664 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{FC6BA59A-C07F-459B-9C80-AD363AC43994}
c:\docume~1\ALL\LOCALS~1\Temp\{FC6BA59A-C07F-459B-9C80-AD363AC43994}\setup.isn 256664 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DF8ACB.tmp 311296 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DF9662.tmp 311296 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DFDF49.tmp 311296 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DFEBA7.tmp 311296 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DFFBE6.tmp 16384 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DFFBF1.tmp 512 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Extensions
c:\documents and settings\ALL\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
c:\documents and settings\ALL\Application Data\Mozilla\Firefox
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009040821 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009042316 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009060215 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009070611 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009073022 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Desktop Background.bmp
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\blocklist.xml 2644 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-08-30.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-08-31.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-09-01.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-09-02.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-09-05.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarks.html 7139 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\cert8.db 114688 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\chrome
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\chrome\userChrome-example.css 1078 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\chrome\userContent-example.css 663 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\compatibility.ini 180 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\compreg.dat 146533 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\content-prefs.sqlite 7168 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\cookies.sqlite 203776 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\downloads.sqlite 19456 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome\chrome_user.jar 27394 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome.manifest 2005 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences\defaults.js 424 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\install.rdf 1271 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions.cache 791 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions.ini 494 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions.rdf 5241 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\formhistory.sqlite 24576 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\key3.db 16384 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\localstore.rdf 7435 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\mimeTypes.rdf 3286 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\minidumps
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\minidumps\1e1a3c01-21b2-4d0b-94db-d2877e97e67a.dmp 0 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\permissions.sqlite 15360 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\places.sqlite 1777664 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\pluginreg.dat 3889 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\prefs.js 6811 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\search.sqlite 2048 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\secmod.db 16384 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\signons3.txt 57 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\urlclassifierkey3.txt 154 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\webappsstore.sqlite 26624 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\xpti.dat 97053 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\profiles.ini 111 bytes

scan completed successfully
hidden files: 438

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\æHõwæ*]
"DisplayName"="??È\17?\11\09"
"DeviceDesc"="??È\17?\11\09"
"ProviderName"="???\11?\18?\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.8"
"DeviceInstanceIds"=multi:"d:\\chipset\\7-ser\\xp\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1052)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-09-07 16:50
ComboFix-quarantined-files.txt 2009-09-07 15:50

Pre-Run: 117,633,208,320 bytes free
Post-Run: 117,620,563,968 bytes free

596 --- E O F --- 2009-09-02 02:00

Re: HELP NEEDED PLS... PC is freezing up ...logs attached..

PostPosted: Tue Sep 08, 2009 1:26 am
by Gecko

Re: HELP NEEDED PLS... PC is freezing up ...logs attached..

PostPosted: Tue Sep 08, 2009 6:09 am
by KenA
Ive no idea Gecko....didnt even kow they were hidden. What does this mean?

Re: HELP NEEDED PLS... PC is freezing up ...logs attached..

PostPosted: Tue Sep 08, 2009 5:45 pm
by KenA
Ok Gecko...i did what you asked.

First time round combofix produced an empty logfile and said there as a problem. I ran it again and the log produced is below.

The new Hijackthis log is included also.

ComboFix 09-09-07.05 - ALL 08/09/2009 16:33.3.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1790.1290 [GMT 1:00]
Running from: E:\ComboFix.exe
AV: AVG Internet Security 3-pack *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.

((((((((((((((((((((((((( Files Created from 2009-08-08 to 2009-09-08 )))))))))))))))))))))))))))))))
.

2009-09-08 15:22 . 2009-09-08 15:22 -------- d-----w- C:\found.001
2009-09-08 11:39 . 2009-09-08 11:39 -------- d-----w- c:\documents and settings\ALL\Tracing
2009-09-08 03:02 . 2009-09-08 03:02 -------- d-----w- C:\$AVG8.VAULT$
2009-09-07 17:18 . 2009-09-07 17:18 -------- d-----w- C:\found.000
2009-09-07 16:48 . 2009-09-07 16:48 -------- d-----w- c:\program files\Trend Micro
2009-09-07 16:45 . 2009-09-07 16:46 -------- d-----w- c:\windows\BDOSCAN8
2009-09-07 16:26 . 2009-09-07 16:26 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-29 15:52 . 2009-09-07 10:08 -------- d-----w- c:\program files\CDex_150
2009-08-21 02:04 . 2009-08-21 02:18 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-12 19:25 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-07 17:21 . 2009-04-22 22:11 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-15 12:46 . 2009-07-18 18:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-13 02:02 . 2009-07-18 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-05 09:01 . 2002-06-25 21:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 12:36 . 2009-07-18 18:55 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 12:36 . 2009-07-18 18:55 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-30 17:25 . 2009-04-22 18:29 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-30 17:25 . 2009-04-22 18:29 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-30 17:25 . 2009-04-22 18:29 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-26 11:23 . 2009-04-25 13:06 -------- d-----w- c:\documents and settings\ALL\Application Data\Canon
2009-07-20 10:21 . 2009-07-20 10:21 -------- d-----w- c:\program files\Windows Media Connect 2
2009-07-18 19:02 . 2009-07-18 19:02 -------- d-----w- c:\program files\Microsoft Works
2009-07-18 19:01 . 2009-04-24 19:55 -------- d-----w- c:\program files\MSBuild
2009-07-18 19:00 . 2009-07-18 19:00 -------- d-----w- c:\program files\Microsoft.NET
2009-07-18 18:59 . 2009-07-18 18:59 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-07-18 18:55 . 2009-07-18 18:55 -------- d-----w- c:\documents and settings\ALL\Application Data\Malwarebytes
2009-07-18 18:55 . 2009-07-18 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-18 18:53 . 2009-07-18 18:53 -------- d-----w- c:\program files\D-Tools
2009-07-17 19:01 . 2002-06-25 21:36 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2004-08-04 07:56 286208 ------w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2002-03-05 07:56 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 ------w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2002-06-25 21:37 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2002-06-25 21:49 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2002-06-25 21:45 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2002-06-25 21:45 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2002-06-25 21:42 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2002-06-25 21:40 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2002-06-25 21:39 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2002-06-25 21:39 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2002-06-25 21:47 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2002-06-25 21:38 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2002-06-25 21:48 76288 ----a-w- c:\windows\system32\telnet.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 10:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-12 2007832]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-22 148888]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"VX6000"="c:\windows\vVX6000.exe" [2008-08-04 713744]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-08-26 16851456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\ALL\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-30 17:25 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [22/04/2009 19:29 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [22/04/2009 19:29 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [22/04/2009 19:29 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [24/04/2009 19:51 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [23/04/2009 18:50 297752]
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [24/04/2009 19:51 1370488]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [22/04/2009 19:27 29208]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [22/04/2009 19:27 29208]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14/05/2007 10:26 508288]
S3 PAC7302;PAC7302 VGA USB Camera;c:\windows\system32\drivers\PAC7302.SYS [21/06/2009 21:21 457856]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [23/04/2009 18:20 2077840]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ie/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-08 16:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\æHõwæ*]
"DisplayName"="??È\17?\11\09"
"DeviceDesc"="??È\17?\11\09"
"ProviderName"="???\11?\18?\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.8"
"DeviceInstanceIds"=multi:"d:\\chipset\\7-ser\\xp\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2624)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-09-08 16:35
ComboFix-quarantined-files.txt 2009-09-08 15:35
ComboFix2.txt 2009-09-07 15:50

Pre-Run: 117,615,919,104 bytes free
Post-Run: 117,603,442,688 bytes free

164 --- E O F --- 2009-09-02 02:00

HIJACKTHIS

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:36:37, on 08/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - *{0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0413775653
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 0430515484
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 7033 bytes

Re: HELP NEEDED PLS... PC is freezing up ...logs attached..

PostPosted: Wed Sep 09, 2009 3:39 am
by Gecko
KenA,

It is looking better, how is it running now?

I've never seen that "æHõwæ*" registry key before and it's still there.
So either combo fix couldn't remove it or it was reinstalled by something.
The odd naming has me worried it just looks like a bad key and google has nothing.

Let me look into it some more and see what the best steps to remove it will be.

Re: HELP NEEDED PLS... PC is freezing up ...logs attached..

PostPosted: Wed Sep 09, 2009 3:37 pm
by KenA
Gecko,

Its running better alright but still not perfect. Havent a clue what that reg key is about.

Ive lost use of Firefox though and cant uninstall AVG IS. Internt Explorer works fine but the bookmarks were in Firefox. I could download firefox again but id like to try retrieve my bookmarks.

Ive done all i can to remove AVG including registry keys but it still shows up in the system tray and combofix said its still active.

Re: HELP NEEDED PLS... PC is freezing up ...logs attached..

PostPosted: Wed Sep 09, 2009 9:53 pm
by Gecko

Re: HELP NEEDED PLS... PC is freezing up ...logs attached..

PostPosted: Sun Nov 01, 2009 5:45 pm
by KenA
Gecko thanks for the help here.....PC cleaned up and was running much better.

Got a call yesterday from my dad who was experiencing more problems witht he PC...was freezing some more and the cursor moving in slow motion etc. I had a quick look and spotted the extraction fan not working. More than likely this was causing a cooling problem. Gonna get one of those today and shove it in.

I downloaded the latest version of AVG and un-installed it like you said but still no joy. When re-started, AVg comes up in the system tray, and opens up when you click on it. However, its not in the programs list ??? Is there any other way to make sure this is removed correctly?

Re: HELP NEEDED PLS... PC is freezing up ...logs attached..

PostPosted: Sun Nov 01, 2009 7:56 pm
by Gecko
KenA,

I never had a problem uninstalling AVG.
Looking over their FAQ and knowledge base it only gives the same information I already gave you, download new, start the install, select uninstall, roboot.

I'll do a little more research and see what I can find

Found this one the public support form:
How to uninstall AVG:
- Download AVG uninstall/cleanup utilty and run it ( if running Vista or Windows 7: remember to right-click on it and choose "Run as Administrator"):



- After restart please remove these folders*:

Windows XP/2000
C:\Program Files\AVG or C:\Program files(x86)\AVG (for 64bit OS)
C:\Documents and settings\All users\Application data\AVG8

Windows Vista
C:\Program Files\AVG or C:\Program files(x86)\AVG (for 64bit OS)
C:\ProgramData\AVG8
C:\Users\<user>\AppData\Roaming\AVG8

( Stop here if not re-installing )