hi.
the following are my reports;
hijack this;
Logfile of HijackThis v1.99.1
Scan saved at 22:03:49, on 19/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virgin Broadband\PCguard\fws.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe
C:\Program Files\Virgin Broadband\PCguard\Rps.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Virgin Broadband\advisor\BroadbandadvisorComHandler.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\jmwdavww.dll (file missing)
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Virgin Broadband\PCguard\pkR.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Virgin Broadband\PCguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [AOL_Demo] C:\Applications\Tool\AOL Demo\DSGDemo.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Broadbandadvisor.exe] "C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [PCguard] "C:\Program Files\Virgin Broadband\PCguard\Rps.exe"
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Catalyst System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/s...
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by116fd.bay116.hotmail.msn.c...
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls...
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game05.zylom.com/activex/zyl...
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/zu...
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PCguard Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Virgin Broadband\PCguard\fws.exe
combo fix;
"Brad Wood" - 07-04-19 18:39:43 Service Pack 2
ComboFix 07-04-19.2V - Running from: C:\Documents and Settings\Brad Wood\Desktop\
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\ddayy.dll
C:\WINDOWS\system32\gjywdpse.dll
C:\WINDOWS\system32\igapefrl.dll
C:\WINDOWS\system32\kflrvaav.dll
C:\WINDOWS\system32\lsyxuuol.dll
C:\WINDOWS\system32\rvxglemk.dll
C:\WINDOWS\system32\ttlpcvdf.dll
C:\WINDOWS\system32\wptresri.dll
C:\WINDOWS\system32\awtqq.dll
C:\WINDOWS\system32\jkhff.dll
C:\WINDOWS\system32\byxxyya.dll
C:\WINDOWS\system32\cbxvvuu.dll
C:\WINDOWS\system32\hggebcc.dll
C:\WINDOWS\system32\iifccba.dll
C:\WINDOWS\system32\mljhgec.dll
C:\WINDOWS\system32\mljijhi.dll
C:\WINDOWS\system32\mljjgec.dll
C:\WINDOWS\system32\mljjhhe.dll
C:\WINDOWS\system32\mljkjif.dll
C:\WINDOWS\system32\opnkkjk.dll
C:\WINDOWS\system32\opnmjgh.dll
C:\WINDOWS\system32\qomjghg.dll
C:\WINDOWS\system32\wvuttut.dll
C:\WINDOWS\system32\xxyyaxx.dll
C:\WINDOWS\system32\yayywus.dll
C:\WINDOWS\system32\yyadd.ini
C:\WINDOWS\system32\mmllm.bak1
C:\WINDOWS\system32\mmllm.bak2
C:\WINDOWS\system32\mmllm.ini
C:\WINDOWS\system32\mmllm.ini2
C:\WINDOWS\system32\mmllm.tmp
C:\WINDOWS\system32\qqtwa.ini
C:\WINDOWS\system32\ffhkj.ini
C:\WINDOWS\system32\mllmm.dll
C:\WINDOWS\system32\iifgeec.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((( Files Created from 2007-03-19 to 2007-04-19 ))))))))))))))))))))))))))))))))))
2007-04-19 18:12 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-19 17:30 <DIR> d-------- C:\DOCUME~1\BRADWO~1\APPLIC~1\Help
2007-04-17 11:50 <DIR> d-------- C:\Program Files\LimeWire
2007-04-17 11:50 <DIR> d-------- C:\DOCUME~1\BRADWO~1\.limewire
2007-04-15 21:35 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2007-04-15 21:35 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-04-15 19:52 33,408 --a------ C:\WINDOWS\system32\drivers\freedom.sys
2007-04-15 19:51 <DIR> d-------- C:\Program Files\Common Files\PestPatrol
2007-04-15 19:51 <DIR> d-------- C:\Program Files\Common Files\Command Software
2007-04-15 19:36 <DIR> d-------- C:\Program Files\Virgin Broadband
2007-04-15 19:36 <DIR> d-------- C:\DOCUME~1\BRADWO~1\APPLIC~1\Virgin Broadband
2007-04-15 19:36 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Virgin Broadband
2007-04-14 10:50 4,146 --a------ C:\WINDOWS\system32\tmp.reg
2007-04-09 12:46 <DIR> d-------- C:\Program Files\Windows Defender
2007-04-07 13:25 <DIR> d-------- C:\Program Files\Lavasoft
2007-04-07 13:25 <DIR> d-------- C:\DOCUME~1\BRADWO~1\APPLIC~1\Lavasoft
2007-04-07 13:24 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-04-07 13:06 192,000 --a------ C:\DOCUME~1\BRADWO~1\pp.exe
2007-04-07 10:49 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-03-30 15:52 <DIR> d-------- C:\Program Files\Driving Test Success Practical
2007-03-25 12:44 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-03-25 12:43 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-03-25 12:43 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-03-25 12:43 <DIR> d-------- C:\b9a0e7fa4706a7fc1dae
2007-03-20 19:35 <DIR> d-------- C:\Program Files\iTunes
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-15 14:54 -------- d-------- C:\Program Files\java
2007-04-09 12:22 -------- d-------- C:\Program Files\Common Files\freeloadercom shared
2007-04-08 20:24 -------- d-------- C:\DOCUME~1\BRADWO~1\APPLIC~1\mcafee.com personal firewall
2007-04-08 11:30 -------- d-------- C:\Program Files\msn messenger
2007-03-30 15:52 -------- d--h----- C:\Program Files\installshield installation information
2007-03-20 19:35 -------- d-------- C:\Program Files\ipod
2007-03-17 14:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-11 14:12 -------- d-------- C:\Program Files\quicktime
2007-03-08 16:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 16:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 16:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 14:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-02-26 20:21 -------- d-------- C:\Program Files\speedlink
2007-02-26 19:47 -------- d-------- C:\DOCUME~1\BRADWO~1\APPLIC~1\google
2007-02-25 18:35 -------- d-------- C:\Program Files\google
2007-02-20 17:16 -------- d-------- C:\Program Files\microsoft games
2007-02-19 14:28 -------- d-------- C:\DOCUME~1\BRADWO~1\APPLIC~1\real
2007-02-19 14:23 -------- d-------- C:\Program Files\Common Files\xing shared
2007-02-19 14:22 -------- d-------- C:\Program Files\real
2007-02-19 14:22 -------- d-------- C:\Program Files\Common Files\real
2007-02-19 13:12 -------- d-------- C:\Program Files\trymedia
2007-02-05 21:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-01-27 14:33 967 --a------ C:\WINDOWS\scunin.pif
2007-01-27 14:33 68096 --a------ C:\WINDOWS\scunin.exe
2007-01-27 14:33 12264 --a------ C:\WINDOWS\scunin.dat
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-08 19:13 0 --a------ C:\DOCUME~1\BRADWO~1\APPLIC~1\wklnhst.dat
2007-01-05 20:12 4616695 --a------ C:\Program Files\movie maker.zip
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{1557B435-8242-4686-9AA3-9265BF7525A4} C:\WINDOWS\system32\jmwdavww.dll [x]
{3C060EA2-E6A9-4E49-A530-D4657B8C449A} C:\Program Files\Virgin Broadband\PCguard\pkR.dll
{56071E0D-C61B-11D3-B41C-00E02927A304} C:\Program Files\Virgin Broadband\PCguard\FBHR.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
{9030D464-4C02-4ABF-8ECC-5164760863C6} C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
@=""
"SoundMan"="SOUNDMAN.EXE"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
"AOL_Demo"="C:\\Applications\\Tool\\AOL Demo\\DSGDemo.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"Sony Ericsson PC Suite"="\"C:\\Program Files\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"Broadbandadvisor.exe"="\"C:\\Program Files\\Virgin Broadband\\advisor\\Broadbandadvisor.exe\" /AUTORUN"
"MSKDetectorExe"="C:\\Program Files\\McAfee\\SpamKiller\\MSKDetct.exe /uninstall"
"PCguard"="\"C:\\Program Files\\Virgin Broadband\\PCguard\\Rps.exe\""
"SNM"="C:\\Program Files\\SpyNoMore\\SNM.exe /startup"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Power2GoExpress"="\"C:\\Program Files\\CyberLink\\Power2Go\\Power2GoExpress.exe\" /Startup"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"BitTorrent"="\"C:\\Program Files\\BitTorrent\\bittorrent.exe\" --force_start_minimized"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\Z]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVGASCLN
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-19 18:48:59 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-04-19 18:48
combofix quarantine report;
[code]
07-04-07 10:47 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mljijhi.dll.vir
07-04-07 10:47 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mljjhhe.dll.vir
07-04-07 10:47 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\xxyyaxx.dll.vir
07-04-07 10:48 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\opnmjgh.dll.vir
07-04-07 10:57 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\iifgeec.dll.vir
07-04-07 11:03 280676 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\awtqq.dll.vir
07-04-07 11:03 280676 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ddayy.dll.vir
07-04-07 11:03 280676 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\jkhff.dll.vir
07-04-07 11:03 280676 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mllmm.dll.vir
07-04-07 11:03 353 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ffhkj.ini.vir
07-04-07 11:03 353 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\qqtwa.ini.vir
07-04-07 11:03 353 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\yyadd.ini.vir
07-04-07 11:03 769401 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mmllm.bak1.vir
07-04-07 13:07 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\opnkkjk.dll.vir
07-04-07 13:12 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\cbxvvuu.dll.vir
07-04-07 14:37 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\byxxyya.dll.vir
07-04-07 16:52 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\qomjghg.dll.vir
07-04-07 19:02 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mljhgec.dll.vir
07-04-07 20:47 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mljkjif.dll.vir
07-04-07 22:29 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\iifccba.dll.vir
07-04-07 22:32 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\yayywus.dll.vir
07-04-07 22:34 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\hggebcc.dll.vir
07-04-08 00:42 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mljjgec.dll.vir
07-04-08 00:44 26694 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\wvuttut.dll.vir
07-04-11 15:52 123972 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\rvxglemk.dll.vir
07-04-12 18:08 123972 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\kflrvaav.dll.vir
07-04-13 18:08 123972 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\wptresri.dll.vir
07-04-15 10:41 123972 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\lsyxuuol.dll.vir
07-04-16 10:41 123972 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\igapefrl.dll.vir
07-04-17 10:41 123972 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ttlpcvdf.dll.vir
07-04-18 20:38 123972 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\gjywdpse.dll.vir
07-04-18 20:38 788016 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mmllm.bak2.vir
07-04-19 16:58 787698 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mmllm.ini.vir
07-04-19 16:58 787698 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mmllm.tmp.vir
07-04-19 18:42 791264 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mmllm.ini2.vir
Folder PATH listing
Volume serial number is 34FC-C05F
C:\QOOBOX
\---Quarantine
+---C
| \---WINDOWS
| \---system32
| awtqq.dll.vir
| byxxyya.dll.vir
| cbxvvuu.dll.vir
| ddayy.dll.vir
| ffhkj.ini.vir
| gjywdpse.dll.vir
| hggebcc.dll.vir
| igapefrl.dll.vir
| iifccba.dll.vir
| iifgeec.dll.vir
| jkhff.dll.vir
| kflrvaav.dll.vir
| lsyxuuol.dll.vir
| mljhgec.dll.vir
| mljijhi.dll.vir
| mljjgec.dll.vir
| mljjhhe.dll.vir
| mljkjif.dll.vir
| mllmm.dll.vir
| mmllm.bak1.vir
| mmllm.bak2.vir
| mmllm.ini.vir
| mmllm.ini2.vir
| mmllm.tmp.vir
| opnkkjk.dll.vir
| opnmjgh.dll.vir
| qomjghg.dll.vir
| qqtwa.ini.vir
| rvxglemk.dll.vir
| ttlpcvdf.dll.vir
| wptresri.dll.vir
| wvuttut.dll.vir
| xxyyaxx.dll.vir
| yayywus.dll.vir
| yyadd.ini.vir
|
\---Registry_backups
[/code]
AVG Anti-Spyware - Scan Report
+ Created at: 21:57:44 19/04/2007
+ Scan result:
Nothing found.
::Report end
Thanks for the help.