Hi,
My system seems to be acting normally again, thanks. Here are the requested logs:
ComboFix:
ComboFix 09-12-16.05 - Kevin Jones 12/17/2009 10:57:45.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1492 [GMT -5:00]
Running from: c:\documents and settings\Kevin Jones\Desktop\KittyFix.exe
Command switches used :: c:\documents and settings\Kevin Jones\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\sdfix
c:\sdfix\Add_DBFix_RunOnce_key.inf
c:\sdfix\AdminCheck2.txt
c:\sdfix\apps\assosfix.reg
c:\sdfix\apps\Cghtme.exe
c:\sdfix\apps\cliptext.exe
c:\sdfix\apps\CSweg.exe
c:\sdfix\apps\DBFix.inf
c:\sdfix\apps\download.exe
c:\sdfix\apps\dummy.sys
c:\sdfix\apps\Enable_Command_Prompt.inf
c:\sdfix\apps\Enable_Command_Prompt.reg
c:\sdfix\apps\ERDNT.E_E
c:\sdfix\apps\ERDNTDOS.LOC
c:\sdfix\apps\ERDNTWIN.LOC
c:\sdfix\apps\ERUNT.EXE
c:\sdfix\apps\ERUNT.LOC
c:\sdfix\apps\fix.reg
c:\sdfix\apps\FixBeep.reg
c:\sdfix\apps\FixBH.reg
c:\sdfix\apps\FixComponents.reg
c:\sdfix\apps\FIXCU.reg
c:\sdfix\apps\FIXLM.reg
c:\sdfix\apps\FixPath.exe
c:\sdfix\apps\FixRedir.reg
c:\sdfix\apps\FixSchedule.reg
c:\sdfix\apps\FixWebCheck.reg
c:\sdfix\apps\fixXP.reg
c:\sdfix\apps\FixXPsp2.reg
c:\sdfix\apps\grep.exe
c:\sdfix\apps\HaxdFix.reg
c:\sdfix\apps\HPFix.reg
c:\sdfix\apps\HPFix2.reg
c:\sdfix\apps\HPFix3.reg
c:\sdfix\apps\HPFix4.reg
c:\sdfix\apps\HPFix5.reg
c:\sdfix\apps\HPFix6.reg
c:\sdfix\apps\HPFix7.reg
c:\sdfix\apps\HPFix8.reg
c:\sdfix\apps\HPFix9.reg
c:\sdfix\apps\Installed.txt
c:\sdfix\apps\isadmin.exe
c:\sdfix\apps\leg2.txt
c:\sdfix\apps\legacy.txt
c:\sdfix\apps\legacybk.txt
c:\sdfix\apps\locate.com
c:\sdfix\apps\LS.exe
c:\sdfix\apps\MD5File.exe
c:\sdfix\apps\moveex.exe
c:\sdfix\apps\MyGcpvFix.reg
c:\sdfix\apps\MyGkFix2.reg
c:\sdfix\apps\Process.exe
c:\sdfix\apps\procs.exe
c:\sdfix\apps\psservice.exe
c:\sdfix\apps\Rem.txt
c:\sdfix\apps\Rem2.txt
c:\sdfix\apps\Replace\regedit.exe
c:\sdfix\apps\Replace\w2k\AUTOEXEC.NT
c:\sdfix\apps\Replace\w2k\beep.sys
c:\sdfix\apps\Replace\w2k\command.com
c:\sdfix\apps\Replace\w2k\command.PIF
c:\sdfix\apps\Replace\w2k\CONFIG.NT
c:\sdfix\apps\Replace\w2k\null.sys
c:\sdfix\apps\Replace\xp\AUTOEXEC.NT
c:\sdfix\apps\Replace\xp\beep.sys
c:\sdfix\apps\Replace\xp\command.com
c:\sdfix\apps\Replace\xp\command.PIF
c:\sdfix\apps\Replace\xp\CONFIG.NT
c:\sdfix\apps\Replace\xp\null.sys
c:\sdfix\apps\Reset_AppInit_DLLs.reg
c:\sdfix\apps\RestartIt!.exe
c:\sdfix\apps\Restore_SafeBoot_Windows2000.reg
c:\sdfix\apps\Restore_SafeBoot_WindowsXP.reg
c:\sdfix\apps\Restore_SafeBoot_WindowsXP_SP2.reg
c:\sdfix\apps\Restore_SafeBoot_WindowsXP_SP3.reg
c:\sdfix\apps\Restore_SecurityCenter.reg
c:\sdfix\apps\Restore_SharedAccess.reg
c:\sdfix\apps\sc.exe
c:\sdfix\apps\sed.exe
c:\sdfix\apps\SF.exe
c:\sdfix\apps\shutdown.exe
c:\sdfix\apps\srv2.txt
c:\sdfix\apps\srv2bk.txt
c:\sdfix\apps\svc.txt
c:\sdfix\apps\svcbk.txt
c:\sdfix\apps\Swreg.exe
c:\sdfix\apps\swsc.exe
c:\sdfix\apps\UnRAR.exe
c:\sdfix\apps\unzip.exe
c:\sdfix\apps\vfind.exe
c:\sdfix\apps\WINMSG.EXE
c:\sdfix\apps\winsec.reg
c:\sdfix\apps\zip.exe
c:\sdfix\attrib.exe
c:\sdfix\backupreg\AppInit_DLLs.reg
c:\sdfix\backupreg\bat_shell_open.reg
c:\sdfix\backupreg\BHO.reg
c:\sdfix\backupreg\com_shell_open.reg
c:\sdfix\backupreg\ControlPanel_Load.reg
c:\sdfix\backupreg\Drivers32.reg
c:\sdfix\backupreg\exe_shell_open.reg
c:\sdfix\backupreg\HKCU_SOFTWARE_Policy.reg
c:\sdfix\backupreg\HKCU_WINDOWS_Policy.reg
c:\sdfix\backupreg\HKCURun.reg
c:\sdfix\backupreg\HKCURunServices.reg
c:\sdfix\backupreg\HKLM_SOFTWARE_Policy.reg
c:\sdfix\backupreg\HKLM_WINDOWS_Policy.reg
c:\sdfix\backupreg\HKLMRun.reg
c:\sdfix\backupreg\HKLMRunServices.reg
c:\sdfix\backupreg\IEDesktop.reg
c:\sdfix\backupreg\IEMain.reg
c:\sdfix\backupreg\Installed_Components.reg
c:\sdfix\backupreg\pif_shell_open.reg
c:\sdfix\backupreg\reg_shell_open.reg
c:\sdfix\backupreg\SecurityProviders.reg
c:\sdfix\backupreg\SharedTaskScheduler.reg
c:\sdfix\backupreg\ShellServiceObjectDelayLoad.reg
c:\sdfix\backupreg\SubSystems.reg
c:\sdfix\backupreg\txt_shell_open.reg
c:\sdfix\backupreg\Winlogon.reg
c:\sdfix\backupreg\WinlogonNotify.reg
c:\sdfix\backups_old\mpncbmxjvm.exe
c:\sdfix\backups_old\RepairIconAds.reg
c:\sdfix\beepFA0.TXT
c:\sdfix\beepFA1.TXT
c:\sdfix\beepFA2.TXT
c:\sdfix\beepFA3.TXT
c:\sdfix\beepFA4.TXT
c:\sdfix\beepxcodec0.TXT
c:\sdfix\beepxcodec1.TXT
c:\sdfix\beepxcodec2.TXT
c:\sdfix\beepxcodec3.TXT
c:\sdfix\beepxcodec4.TXT
c:\sdfix\bpTEST1.TXT
c:\sdfix\bpTEST3.TXT
c:\sdfix\catchme.exe
c:\sdfix\DBFix.bat
c:\sdfix\delavi0.txt
c:\sdfix\delzip0.txt
c:\sdfix\dest.txt
c:\sdfix\dnif.exe
c:\sdfix\dummy.exe
c:\sdfix\dummy.sys
c:\sdfix\editreg.exe
c:\sdfix\FilekillList1.txt
c:\sdfix\FileList1.txt
c:\sdfix\Find.txt
c:\sdfix\Findav2009.txt
c:\sdfix\Findav2009a.txt
c:\sdfix\Findbhos1.txt
c:\sdfix\FindIRCBrute.txt
c:\sdfix\Findroguerun1.txt
c:\sdfix\Findrun002.txt
c:\sdfix\Findrun002a.txt
c:\sdfix\Findrun30.txt
c:\sdfix\Findrun31.txt
c:\sdfix\Findrun31a.txt
c:\sdfix\Findrun31b.txt
c:\sdfix\Findrun32.txt
c:\sdfix\Findrunbifrose1.txt
c:\sdfix\Findrunbot1.txt
c:\sdfix\FindrunDW_Start.txt
c:\sdfix\Findzip.txt
c:\sdfix\HOSTS
c:\sdfix\Patched2a.txt
c:\sdfix\Patched2b.txt
c:\sdfix\Patched2c.txt
c:\sdfix\RemLat.txt
c:\sdfix\Remlat1.txt
c:\sdfix\Remlat2.txt
c:\sdfix\Remlat3.txt
c:\sdfix\Remlat4.txt
c:\sdfix\Report.txt
c:\sdfix\Report_old_1.txt
c:\sdfix\rtsdnif.exe
c:\sdfix\RunThis.bat
c:\sdfix\SDFIX_ReadMe_Online.url
c:\sdfix\TESTspreadbot1.TXT
c:\sdfix\userinfix.reg
c:\sdfix\W2K_VirusAlert_Repair.inf
c:\sdfix\XP_VirusAlert_Repair.inf
.
((((((((((((((((((((((((( Files Created from 2009-11-17 to 2009-12-17 )))))))))))))))))))))))))))))))
.
2009-12-17 15:46 . 2009-11-26 14:43 2063640 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-12-17 15:46 . 2009-11-26 14:43 3514648 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-12-17 15:46 . 2009-11-26 14:43 2029336 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-12-17 03:29 . 2009-12-17 03:29 -------- d-----w- c:\windows\system32\wbem\Repository
2009-12-17 03:28 . 2009-12-17 03:28 -------- d-----w- c:\program files\Bonjour
2009-12-15 13:31 . 2009-12-16 20:42 0 ----a-w- c:\documents and settings\Kevin Jones\Local Settings\Application Data\prvlcl.dat
2009-12-14 23:45 . 2009-12-17 03:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-14 23:45 . 2009-12-17 00:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-14 21:43 . 2009-12-14 21:43 -------- d-----w- c:\documents and settings\HelpAssistant\Worms Armageddon
2009-12-14 21:43 . 2009-12-14 21:43 -------- d-----w- c:\documents and settings\HelpAssistant\workspace
2009-12-14 21:42 . 2009-12-14 21:42 -------- d-----w- c:\documents and settings\HelpAssistant\PCSX2-0.9.4
2009-12-14 21:42 . 2009-12-14 21:42 -------- d-----w- c:\documents and settings\HelpAssistant\Oracle Jar Cache
2009-12-14 17:24 . 2009-12-17 00:07 -------- d-----w- c:\documents and settings\HelpAssistant\.SunDownloadManager
2009-12-14 17:24 . 2009-12-14 17:24 -------- d-----w- c:\documents and settings\HelpAssistant\.netbeans-registration
2009-12-14 17:24 . 2009-12-14 17:24 -------- d-----w- c:\documents and settings\HelpAssistant\.netbeans-derby
2009-12-14 17:24 . 2009-12-14 17:24 -------- d-----w- c:\documents and settings\HelpAssistant\.netbeans
2009-12-14 17:24 . 2009-12-14 17:24 -------- d-----w- c:\documents and settings\HelpAssistant\.nbprofiler
2009-12-14 17:24 . 2009-12-17 00:07 -------- d-----w- c:\documents and settings\HelpAssistant\.nbi
2009-12-14 17:23 . 2009-12-17 03:26 -------- d-s---w- c:\documents and settings\HelpAssistant
2009-12-12 18:07 . 2009-12-12 18:07 -------- d-----w- c:\program files\Bethesda Softworks
2009-12-12 18:06 . 2009-12-12 18:14 -------- d-----w- c:\documents and settings\Kevin Jones\Local Settings\Application Data\Oblivion
2009-12-12 01:03 . 2009-12-12 01:03 -------- d-----w- c:\program files\SystemRequirementsLab
2009-12-12 01:03 . 2009-12-12 01:03 138240 ----a-w- c:\documents and settings\Kevin Jones\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_d.dll
2009-12-12 01:03 . 2009-12-12 01:03 138240 ----a-w- c:\documents and settings\Kevin Jones\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_c.dll
2009-12-12 01:03 . 2009-12-12 01:03 138240 ----a-w- c:\documents and settings\Kevin Jones\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_b.dll
2009-12-12 01:03 . 2009-12-12 01:03 138240 ----a-w- c:\documents and settings\Kevin Jones\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_a.dll
2009-12-04 22:24 . 2009-12-04 22:24 -------- d-----w- c:\program files\AMB Software
2009-11-20 23:58 . 2009-11-21 00:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Viper
2009-11-20 23:58 . 2009-11-20 23:58 -------- d-----w- c:\program files\Kerigwa
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-17 03:28 . 2008-12-28 19:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-17 03:27 . 2009-12-17 03:27 -------- d-----w- c:\documents and settings\Kevin Jones\Application Data\DAEMON Tools
2009-12-17 03:27 . 2008-01-02 15:58 -------- d-----w- c:\program files\Dell
2009-12-16 22:57 . 2009-12-16 22:57 1478936 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-12-16 22:57 . 2009-12-16 22:57 1143064 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-12-16 22:57 . 2009-12-16 22:57 759064 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll
2009-12-16 21:08 . 2009-12-16 21:08 4844295 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-16 18:18 . 2008-06-19 22:07 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-16 17:07 . 2008-01-02 15:45 -------- d-----w- c:\program files\Java
2009-12-15 13:40 . 2008-01-22 04:36 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-15 00:28 . 2008-12-28 18:11 -------- d-----w- c:\documents and settings\Kevin Jones\Application Data\HPAppData
2009-12-12 18:07 . 2008-01-02 15:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-12 01:03 . 2009-10-07 16:28 -------- d-----w- c:\documents and settings\Kevin Jones\Application Data\SystemRequirementsLab
2009-12-09 20:38 . 2008-03-20 17:56 4322 ----a-w- c:\documents and settings\Kevin Jones\Application Data\wklnhst.dat
2009-12-05 23:22 . 2008-12-31 21:10 -------- d-----w- c:\program files\Worms Armageddon
2009-12-05 06:59 . 2009-01-09 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-05 06:58 . 2008-01-02 16:00 -------- d-----w- c:\program files\Microsoft Works
2009-12-03 21:14 . 2008-12-28 19:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 21:13 . 2008-12-28 19:20 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-25 00:24 . 2009-11-12 00:15 -------- d-----w- c:\documents and settings\Kevin Jones\Application Data\PLT Scheme
2009-11-18 19:42 . 2009-11-12 04:54 -------- d-----w- c:\documents and settings\All Users\Application Data\PPLiveVA
2009-11-18 19:42 . 2009-11-12 04:54 -------- d-----w- c:\program files\PPLiveVA
2009-11-17 01:14 . 2008-01-03 22:09 -------- d-----w- c:\program files\Steam
2009-11-12 04:54 . 2009-11-12 04:54 -------- d-----w- c:\documents and settings\Kevin Jones\Application Data\PPLiveVA
2009-11-12 00:15 . 2009-11-12 00:13 -------- d-----w- c:\program files\PLT
2009-11-04 17:27 . 2009-11-04 16:28 -------- d-----w- c:\program files\Igneous
2009-11-04 02:59 . 2009-11-04 02:46 -------- d-----w- c:\program files\osu!
2009-10-29 12:53 . 2009-10-28 00:50 -------- d-----w- c:\documents and settings\Kevin Jones\Application Data\Winamp
2009-10-29 07:46 . 2004-08-10 17:51 832512 ------w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2004-08-10 17:51 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2004-08-10 17:50 17408 ------w- c:\windows\system32\corpol.dll
2009-10-29 01:16 . 2008-01-26 06:02 -------- d-----w- c:\program files\DivX
2009-10-29 01:16 . 2009-10-29 01:16 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-10-28 18:18 . 2008-01-16 04:07 -------- d-----w- c:\program files\Starcraft
2009-10-28 00:50 . 2009-07-28 15:30 -------- d-----w- c:\program files\Winamp
2009-10-26 14:30 . 2009-10-26 14:30 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-10-24 22:07 . 2008-01-16 22:55 -------- d-----w- c:\documents and settings\Kevin Jones\Application Data\Apple Computer
2009-10-21 18:32 . 2009-10-21 18:31 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-21 18:32 . 2009-10-21 18:31 -------- d-----w- c:\program files\iTunes
2009-10-21 18:31 . 2009-10-21 18:31 -------- d-----w- c:\program files\iPod
2009-10-21 18:31 . 2008-01-16 22:53 -------- d-----w- c:\program files\Common Files\Apple
2009-10-21 18:31 . 2009-10-21 18:30 -------- d-----w- c:\program files\QuickTime
2009-10-21 18:27 . 2009-10-21 18:27 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
2009-10-21 06:00 . 2004-08-10 17:51 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2004-08-10 17:51 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-04 04:00 263552 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:53 . 2004-08-10 17:51 266752 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:54 . 2004-08-10 17:51 69632 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2004-08-10 17:51 112128 ----a-w- c:\windows\system32\rastls.dll
2009-10-07 16:28 . 2009-10-07 16:28 138240 ----a-w- c:\documents and settings\Kevin Jones\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_13_0_d.dll
2009-10-07 16:28 . 2009-10-07 16:28 138240 ----a-w- c:\documents and settings\Kevin Jones\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_13_0_c.dll
2009-10-07 16:28 . 2009-10-07 16:28 138240 ----a-w- c:\documents and settings\Kevin Jones\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_13_0_b.dll
2009-10-07 16:28 . 2009-10-07 16:28 138240 ----a-w- c:\documents and settings\Kevin Jones\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_13_0_a.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-12-17_04.18.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-17 15:43 . 2009-12-17 15:43 16384 c:\windows\Temp\Perflib_Perfdata_324.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Octoshape Streaming Services"="c:\documents and settings\Kevin Jones\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2008-05-22 156944]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-09-26 2356088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-17 2043160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-24 18:30 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Kevin Jones^Start Menu^Programs^Startup^hamachi.lnk]
path=c:\documents and settings\Kevin Jones\Start Menu\Programs\Startup\hamachi.lnk
backup=c:\windows\pss\hamachi.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Kevin Jones^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\Kevin Jones\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Kevin Jones^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=c:\documents and settings\Kevin Jones\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=c:\windows\pss\PowerReg Scheduler.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 06:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2008-09-26 16:02 2356088 ----a-r- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2009-05-19 05:23 49968 ----a-w- c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 23:43 69632 ----a-w- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2006-09-25 14:12 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 10:00 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2007-11-15 14:24 16384 ----a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
2007-05-24 12:03 17920 ----a-w- c:\dell\E-Center\EULALauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-03-26 02:27 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2008-03-13 14:34 81920 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2006-10-03 16:35 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2006-10-03 16:37 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-21 20:36 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mount.exe]
2008-04-11 21:17 374272 ----a-w- c:\program files\GiPo@Utilities\FileUtilities.3\mount.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2006-10-20 22:23 118784 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 05:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 14:00 1116920 ----a-w- c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
2006-11-05 16:22 221184 ----a-w- c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-01-09 20:25 16859648 ----a-w- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-10-24 15:56 1217808 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-25 09:23 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-12-27 08:26 185872 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
2008-08-28 14:18 3660848 ----a-w- c:\program files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 ----a-w- c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\steamapps\\thechaosentity\\day of defeat source\\hl2.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Kevin Jones\\Desktop\\Neverwinter Nights\\NWN\\nwmain.exe"=
"c:\\Program Files\\Diablo\\Diablo.exe"=
"c:\\Program Files\\DAUM\\PotPlayer\\daumvsvr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Microprose\\Risk II\\RiskII.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Kevin Jones\\Local Settings\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\Program Files\\Steam\\steamapps\\thechaosentity\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Steam\\steamapps\\thechaosentity\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\MicroProse\\Worms2\\frontend.exe"=
"c:\\Program Files\\Worms Armageddon\\WA.exe"=
"c:\\Program Files\\DAUM\\PotPlayer\\PotPlayer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_12\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_12\\jre\\bin\\java.exe"=
"c:\\Program Files\\Pocket Tanks\\pockettanks.exe"=
"c:\\Documents and Settings\\Kevin Jones\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Steam\\steamapps\\thechaosentity\\source sdk base\\hl2.exe"=
"c:\\Documents and Settings\\Kevin Jones\\Desktop\\eclipse\\eclipse.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"7662:TCP"= 7662:TCP:Services
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/6/2008 12:11 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/6/2008 12:11 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/30/2008 9:48 AM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/2/2008 10:04 AM 297752]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/3/2008 5:13 PM 24652]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [12/28/2008 2:20 PM 38224]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1/3/2008 4:38 PM 716272]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: teamliquid.net\www
TCP: {AAFB2DF8-F7A6-443E-B8A3-CB24BCA42E7A} = 207.69.188.186,207.69.188.187
DPF: {1DABF8D5-8430-4985-9B7F-A30E53D709B3} - hxxp://cache.tv.qq.com/qqlive_ocx/QQLiveInstaller.cab
DPF: {4C833081-D026-4FF8-968F-7EAB660D2FBA} - hxxp://download.tvants.com/pub/tvants/tvants1/win32/cab/tvants.cab
DPF: {CAFECAFE-0013-0001-0028-ABCDEFABCDEF}
FF - ProfilePath - c:\documents and settings\Kevin Jones\Application Data\Mozilla\Firefox\Profiles\6tvf6qld.default\
FF - prefs.js: browser.startup.homepage -
www.google.com
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Kevin Jones\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\documents and settings\Kevin Jones\Local Settings\Application Data\Octoshape\Octoshape Streaming Services\octoprogram-L03-NMS0907280_SUA_000\npoctoshape.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np32asw.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJinit13128.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-17 11:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-12-17 11:03:47
ComboFix-quarantined-files.txt 2009-12-17 16:03
ComboFix2.txt 2009-12-17 04:24
Pre-Run: 137,447,714,816 bytes free
Post-Run: 137,404,579,840 bytes free
- - End Of File - - D6F94FFB9FAE17E94960301C480AACD5
Kapersky:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, December 17, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, December 17, 2009 15:57:24
Records in database: 3382319
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
L:\
Scan statistics:
Objects scanned: 217426
Threats found: 4
Infected objects found: 6
Suspicious objects found: 0
Scan duration: 03:27:54
File name / Threat / Threats count
C:\Documents and Settings\HelpAssistant\Application Data\Sun\Java\Deployment\cache\6.0\20\18ae5e94-4ab37335 Infected: Trojan-Downloader.Java.OpenStream.ad 1
C:\Documents and Settings\HelpAssistant\Application Data\Sun\Java\Deployment\cache\6.0\44\232f2a6c-55ae4ee7 Infected: Exploit.Java.Gimsh.a 1
C:\Documents and Settings\HelpAssistant\Application Data\Sun\Java\Deployment\cache\6.0\44\3efada6c-4b99dee7 Infected: Trojan-Downloader.Java.OpenStream.ad 1
C:\Documents and Settings\HelpAssistant\Application Data\Sun\Java\Deployment\cache\6.0\49\44da1d31-4115d822 Infected: Trojan-Downloader.Java.Agent.af 1
C:\Documents and Settings\HelpAssistant\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-51fad18-1728b96b.zip Infected: Exploit.Java.Gimsh.a 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.g 1
Selected area has been scanned.