WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionAntimalware Doctor virus - Page 1 EmptyRe: Antimalware Doctor virus

more_horiz
Hmm.
Can you re-run Combofix for me please and post the new log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Antimalware Doctor virus - Page 1 DXwU4
Antimalware Doctor virus - Page 1 VvYDg

descriptionAntimalware Doctor virus - Page 1 EmptyRe: Antimalware Doctor virus

more_horiz
will do

descriptionAntimalware Doctor virus - Page 1 EmptyRe: Antimalware Doctor virus

more_horiz
ComboFix 10-09-09.04 - Chantal 11/09/2010 0:00.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.1982.966 [GMT -3:00]
Running from: c:\users\Chantal\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Chantal\AppData\Roaming\Microsoft\Windows\Templates\memory.tmp

.
((((((((((((((((((((((((( Files Created from 2010-08-11 to 2010-09-11 )))))))))))))))))))))))))))))))
.

2010-09-11 03:14 . 2010-09-11 03:14 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-11 03:14 . 2010-09-11 03:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-11 02:55 . 2010-09-11 02:56 -------- d-----w- C:\32788R22FWJFW
2010-09-11 00:14 . 2010-09-11 00:14 -------- d-----w- c:\program files\7-Zip
2010-09-10 20:50 . 2010-09-10 20:50 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-09-10 20:48 . 2007-10-20 21:21 278016 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2010-09-10 20:44 . 2007-10-20 21:25 118272 ----a-w- c:\windows\system32\hpz3l5mu.dll
2010-09-10 20:44 . 2010-09-10 20:45 -------- d-----w- c:\windows\LastGood
2010-09-10 20:40 . 2010-09-10 20:40 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2010-09-10 20:23 . 2010-09-10 20:52 163194 ----a-w- c:\windows\hpoins28.dat
2010-09-10 20:23 . 2008-05-12 19:46 796 ------w- c:\windows\hpomdl28.dat
2010-09-10 20:22 . 2008-01-25 12:23 271704 ----a-w- c:\windows\system32\hpzids01.dll
2010-09-10 20:22 . 2008-01-25 12:22 729088 ----a-w- c:\windows\system32\hpowiax7.dll
2010-09-10 20:22 . 2008-01-25 12:22 303104 ----a-w- c:\windows\system32\hpovst15.dll
2010-09-10 20:22 . 2008-01-25 12:22 372736 ----a-w- c:\windows\system32\hppldcoi.dll
2010-09-10 20:22 . 2008-01-25 12:22 581632 ----a-w- c:\windows\system32\hpotscl6.dll
2010-09-10 20:22 . 2008-01-25 12:22 309760 ----a-w- c:\windows\system32\difxapi.dll
2010-09-10 20:15 . 2010-09-10 20:15 -------- d-----w- c:\programdata\Uniblue
2010-09-10 20:15 . 2010-09-10 20:15 -------- d-----w- c:\users\Chantal\AppData\Roaming\Uniblue
2010-09-10 20:15 . 2010-09-10 20:15 -------- d-----w- c:\program files\Uniblue
2010-09-10 01:17 . 2010-09-10 01:17 -------- d-----w- c:\program files\ESET
2010-08-27 02:03 . 2010-09-11 03:06 -------- d-----w- c:\users\Chantal\AppData\Roaming\skypePM
2010-08-27 02:01 . 2010-09-10 14:26 -------- d-----w- c:\users\Chantal\AppData\Roaming\Skype
2010-08-27 02:01 . 2010-08-27 02:01 -------- d-----w- c:\program files\Common Files\Skype
2010-08-27 02:01 . 2010-08-27 02:01 -------- d-----r- c:\program files\Skype

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-10 20:48 . 2007-05-04 19:15 -------- d-----w- c:\programdata\Hewlett-Packard
2010-09-10 20:41 . 2007-05-04 18:08 -------- d-----w- c:\program files\Hp
2010-09-10 14:22 . 2009-04-20 20:22 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-08 23:18 . 2008-09-08 16:31 13119 ----a-w- c:\users\Chantal\AppData\Roaming\nvModes.dat
2010-08-30 20:06 . 2009-08-17 23:19 1102 ----a-w- c:\users\Chantal\AppData\Roaming\wklnhst.dat
2010-08-27 02:03 . 2010-08-27 02:03 56 ---ha-w- c:\programdata\ezsidmv.dat
2010-08-27 02:01 . 2008-09-23 04:27 -------- d-----w- c:\programdata\Skype
2010-08-25 06:37 . 2007-05-04 18:33 -------- d-----w- c:\programdata\Microsoft Help
2010-07-25 01:52 . 2010-07-25 01:29 -------- d-----w- c:\program files\Ubisoft
2010-07-25 01:29 . 2007-05-04 18:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-24 03:32 . 2010-07-24 03:08 -------- d-----w- c:\program files\Ubi Soft
2010-07-24 03:32 . 2010-07-24 03:32 -------- d-----w- c:\programdata\QuickTime
2010-07-24 03:31 . 2010-07-24 03:31 -------- d-----w- c:\program files\directx
2010-07-24 03:08 . 2010-07-24 03:06 -------- d-----w- c:\program files\iTunes
2010-07-24 03:06 . 2010-07-24 03:06 -------- d-----w- c:\program files\iPod
2010-07-24 03:06 . 2010-01-25 00:27 -------- d-----w- c:\program files\Common Files\Apple
2010-07-24 03:00 . 2010-07-24 03:00 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{33a329ee-7f7d-471e-ac67-15c54d970678}"= "c:\program files\Jaybob's_Movies\tbJayb.dll" [2009-04-27 2088472]

[HKEY_CLASSES_ROOT\clsid\{33a329ee-7f7d-471e-ac67-15c54d970678}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{33a329ee-7f7d-471e-ac67-15c54d970678}]
2009-04-27 22:36 2088472 ----a-w- c:\program files\Jaybob's_Movies\tbJayb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{33a329ee-7f7d-471e-ac67-15c54d970678}"= "c:\program files\Jaybob's_Movies\tbJayb.dll" [2009-04-27 2088472]

[HKEY_CLASSES_ROOT\clsid\{33a329ee-7f7d-471e-ac67-15c54d970678}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{33A329EE-7F7D-471E-AC67-15C54D970678}"= "c:\program files\Jaybob's_Movies\tbJayb.dll" [2009-04-27 2088472]

[HKEY_CLASSES_ROOT\clsid\{33a329ee-7f7d-471e-ac67-15c54d970678}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-09-08 1232896]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-11 26959144]
"DriverScanner"="c:\program files\Uniblue\DriverScanner\launcher.exe" [2010-08-25 338296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-02-28 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-28 7770112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-28 81920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-03-29 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 50696]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-10 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-08-01 2048352]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2008-08-01 675840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Vongo Tray.lnk - c:\windows\Installer\{8C3AE2D1-854D-4650-A73D-C7CC7EE36B80}\NewShortcut2_DB7E00C96DEF489A8112D8F81614F45A.exe [2007-5-4 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2009-05-08 12552]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-07-31 335240]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-05-08 108552]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-07-31 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-07-31 297752]


--- Other Services/Drivers In Memory ---

*NewlyCreated* - CPUZ132

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2010-09-11 c:\windows\Tasks\User_Feed_Synchronization-{F650F526-C568-4D3A-87C2-E03AC2725E1E}.job
- c:\windows\system32\msfeedssync.exe [2010-07-02 04:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
FF - ProfilePath - c:\users\Chantal\AppData\Roaming\Mozilla\Firefox\Profiles\5n3erpa0.default\
FF - prefs.js: browser.startup.homepage - hxxp://mail.redcow.ca
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-11 00:14
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-09-11 00:20:45
ComboFix-quarantined-files.txt 2010-09-11 03:20
ComboFix2.txt 2010-09-10 00:33
ComboFix3.txt 2009-02-09 20:57

Pre-Run: 68,286,291,968 bytes free
Post-Run: 68,454,588,416 bytes free

- - End Of File - - 6E116E9A95A1429FBA06C41C4FB83410

descriptionAntimalware Doctor virus - Page 1 EmptyRe: Antimalware Doctor virus

more_horiz
oh I can open the internet page now, and the ESET online scan log, but there happens to be nothing in the log... should i run the ESET scan again?

descriptionAntimalware Doctor virus - Page 1 EmptyRe: Antimalware Doctor virus

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum