With the help of a friend, I got finally the above instructions sorted out. Since the infection my desktop has not been turned on other than for running HijackThis, MWB Anti-Malware, MS Recovery Console and ComboFix and not been hooked up to the internet other than to download the MS Windows Recovery Console. The combo fix log is as follows:
=====================================================
ComboFix 09-12-06.07 - Owner 12/06/2009 15:01.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1370 [GMT -6]
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Local Settings\Application Data\lhyfco
c:\documents and settings\Owner\Local Settings\Application Data\lhyfco\vorlsysguard.exe
c:\recycler\S-1-5-21-3217367115-1376598253-32396715-1003
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.
2009-11-25 01:26 . 2009-11-25 01:26 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-11-25 01:25 . 2009-09-10 20:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-25 01:25 . 2009-11-25 01:25 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-25 01:25 . 2009-11-25 01:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-25 01:25 . 2009-09-10 20:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-23 01:01 . 2009-11-23 01:01 -------- d-----w- c:\program files\Trend Micro
2009-11-10 23:35 . 2008-04-13 19:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-11-10 23:35 . 2008-04-13 19:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-11-10 23:35 . 2008-04-13 19:45 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-11-10 23:35 . 2008-04-13 19:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-10 09:59 . 2006-02-01 12:32 33440 -c--a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-06 13:45 . 2009-08-17 23:06 -------- d-----w- c:\program files\Eagle Lander 3D v212
2009-11-04 01:32 . 2009-08-11 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-01 04:36 . 2006-02-01 09:21 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-29 09:36 . 2009-10-29 09:34 -------- d-----w- c:\program files\Landing Pattern
2009-10-29 09:35 . 2009-10-29 09:35 -------- d-----w- c:\program files\AGEIA Technologies
2009-10-29 09:34 . 2009-10-29 09:34 -------- d-----w- c:\program files\OpenAL
2009-10-29 09:34 . 2009-10-29 09:34 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2009-10-29 09:34 . 2009-10-29 09:34 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2009-10-22 10:33 . 2009-11-06 15:14 2064152 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-10-21 02:51 . 2009-10-21 02:51 -------- d-----w- c:\program files\G1000 Route Planning
2009-10-20 14:43 . 2009-10-20 14:43 2025752 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-10-14 20:58 . 2006-02-01 09:30 -------- d-----w- c:\program files\Microsoft Works
2009-09-11 14:18 . 2004-08-26 16:12 136192 ----a-w- c:\windows\system32\msv1_0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0" [X]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"SoundMan"="SOUNDMAN.EXE" [2005-09-26 90112]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-03 2028312]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-11 08:22 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Cessna NAVIII G1000 Trainer v8.01\\CDUSIMv2.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\X-PLANE 9.311 FINAL\\X-Plane.exe"=
"j:\\XP 9.40 FINAL\\X-Plane.exe"=
"j:\\XP 8.xx\\XP 8.64\\X-Plane 864.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/11/2009 2:22 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/11/2009 2:22 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/11/2009 2:21 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/11/2009 2:21 AM 297752]
R3 chdrvr01;CH Control Manager Driver 1;c:\windows\system32\drivers\chdrvr01.sys [2/2/2008 3:25 PM 215104]
R3 chdrvr02;CH Control Manager Driver 2;c:\windows\system32\drivers\chdrvr02.sys [2/2/2008 3:25 PM 3744]
R3 chdrvr03;CH Control Manager Driver 3;c:\windows\system32\drivers\chdrvr03.sys [2/2/2008 3:25 PM 9024]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [8/16/2009 4:15 PM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [8/16/2009 4:15 PM 3072]
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {4C304F1E-5DBE-4D8B-A4AE-0BD29B34AC22} = 68.94.156.1 151.164.8.201
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
HKLM-Run-QuickTime Task - c:\program files\QuickTime\qttask.exe
AddRemove-NVIDIA Drivers - c:\windows\system32\nvuninst.exe UninstallGUI
AddRemove-PictureItSuiteTrial_v11 - c:\program files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe ADDREMOVE=1 SKU=TRIAL VERSION=11
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-06 15:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
Completion time: 2009-12-06 15:10
ComboFix-quarantined-files.txt 2009-12-06 21:10
Pre-Run: 61,302,595,584 bytes free
Post-Run: 62,523,502,592 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 174E50CCCE8C8E93EBB91D6AA9030B83
=====================================================
When ComboFix completed stage 50, a note appeared that a few files were deleted. I was not fast enough to write down which files this were. At that time also 5 windows popped up, announcing items that were shutdown:
1. Data Execution Prevention – Microsoft WindowsTo help protect your computer, Windows has closed this program.
CTF Loader
MS Corporation
2. Realtek Sound Manager3. Power DVD RC Service4. AVG 8.5 (was disabled previously – or so I thought)
5. Windows Security Notification App Combo-Fix ?????
Thanks for looking into this and thanks for your time.
GMK
Last edited by GMK on 6th December 2009, 10:06 pm; edited 1 time in total (Reason for editing : EDIT: spelling)