It is currently Tue Sep 01, 2026 12:11 pm


PC infected and running slowwww

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Re: PC infected and running slowwww

Postby Donna57 » Thu Jan 15, 2009 4:49 am

Gecko, I wasnt aware that Partypoker infects systems with malware. My husband is disabled and has played on Partypoker for about 6 yrs now. We have never had a problem like this one before, so now I dont know what to do about him playing online. But I followed your instructions and here are the logs....

Combofix Log

ComboFix 09-01-13.04 - Donna 2009-01-14 22:32:50.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2558.1904 [GMT -5:00]
Running from: c:\documents and settings\Donna\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Donna\Desktop\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated)
FW: AVG Firewall *enabled*
* Created a new restore point

FILE ::
c:\windows\System32\lztvit.dll
c:\windows\wgatyznd
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\TEMP
c:\windows\wgatyznd

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_AVG


((((((((((((((((((((((((( Files Created from 2008-12-15 to 2009-01-15 )))))))))))))))))))))))))))))))
.

2009-01-14 00:17 . 2009-01-14 00:17 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-14 00:17 . 2009-01-14 00:17 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-01-10 13:09 . 2009-01-14 18:42 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-01-10 13:09 . 2009-01-11 08:29 324,872 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-01-10 13:09 . 2009-01-11 08:29 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-01-10 13:09 . 2009-01-11 08:29 12,552 --a------ c:\windows\system32\drivers\avgrkx86.sys
2009-01-10 13:09 . 2009-01-11 08:29 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-01-10 13:08 . 2009-01-11 08:29 50,968 --a------ c:\windows\system32\avgfwdx.dll
2009-01-10 13:08 . 2009-01-11 08:29 29,208 --a------ c:\windows\system32\drivers\avgfwdx.sys
2009-01-10 11:32 . 2007-03-23 14:44 692,224 --a------ c:\windows\system32\lxdidrs.dll
2009-01-10 11:32 . 2007-03-30 09:13 344,064 --a------ c:\windows\system32\lxdicoin.dll
2009-01-10 11:32 . 2007-02-09 13:07 69,632 --a------ c:\windows\system32\lxdicnv4.dll
2009-01-10 11:32 . 2007-01-23 18:40 65,536 --a------ c:\windows\system32\lxdicaps.dll
2009-01-10 11:32 . 2006-08-01 00:53 40,960 --a------ c:\windows\system32\lxdivs.dll
2009-01-10 11:31 . 2009-01-10 11:32 <DIR> d-------- c:\program files\Lexmark Fax Solutions
2009-01-10 11:31 . 2007-02-22 02:13 45,056 --a------ c:\windows\system32\LXF3PMON.DLL
2009-01-10 11:31 . 2006-11-07 10:02 36,864 --a------ c:\windows\system32\lxf3oem.dll
2009-01-10 11:31 . 2007-02-22 02:12 32,768 --a------ c:\windows\system32\LXF3FXPU.DLL
2009-01-10 11:31 . 2007-01-22 04:53 60 --ah----- c:\windows\system32\lxdirwrd.ini
2009-01-10 11:30 . 2009-01-10 11:32 <DIR> d-------- c:\program files\Lexmark 3500-4500 Series
2008-12-23 01:44 . 2007-10-08 09:27 436,784 --a------ c:\windows\system32\vnetlib.dll
2008-12-23 01:44 . 2007-10-08 09:26 150,064 --a------ c:\windows\system32\vmnat.exe
2008-12-23 01:44 . 2007-10-08 09:26 121,392 --a------ c:\windows\system32\vmnetdhcp.exe
2008-12-23 01:44 . 2007-10-08 09:26 50,992 -ra------ c:\windows\system32\vmnetbridge.dll
2008-12-23 01:44 . 2007-10-08 09:26 28,592 -ra------ c:\windows\system32\drivers\vmnetbridge.sys
2008-12-23 01:44 . 2007-10-08 09:27 25,008 --a------ c:\windows\system32\drivers\vmnetuserif.sys
2008-12-23 01:44 . 2007-10-08 09:27 20,912 --a------ c:\windows\system32\drivers\VMkbd.sys
2008-12-23 01:44 . 2007-10-08 09:26 17,712 -ra------ c:\windows\system32\drivers\vmnet.sys
2008-12-23 01:44 . 2007-10-08 09:26 16,816 -ra------ c:\windows\system32\drivers\vmnetadapter.sys
2008-12-23 01:44 . 2007-10-08 09:26 13,104 -ra------ c:\windows\system32\vnetinst.dll
2008-12-23 01:43 . 2008-12-23 01:43 <DIR> d-------- c:\program files\VMware
2008-12-23 01:43 . 2008-12-23 01:43 <DIR> d-------- c:\program files\Common Files\VMware
2008-12-23 01:23 . 2009-01-14 22:36 <DIR> d-------- c:\documents and settings\Donna\Application Data\VMware
2008-12-23 01:18 . 2009-01-14 22:36 <DIR> d-------- c:\documents and settings\LocalService\Application Data\VMware
2008-12-23 01:16 . 2009-01-14 22:36 <DIR> d-------- c:\documents and settings\All Users\Application Data\VMware
2008-12-22 15:35 . 2008-12-22 15:35 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2008-12-18 23:28 . 2008-12-18 23:29 <DIR> d-------- c:\program files\Hotspot Shield

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-15 03:13 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-14 07:33 --------- d-----w c:\program files\AMP Font Viewer
2009-01-14 05:17 --------- d-----w c:\program files\Java
2009-01-14 04:56 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-01-14 03:33 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-11 18:44 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-01-10 20:14 --------- d-----w c:\program files\Amara - Flash Slide Show Builder
2009-01-10 20:14 --------- d-----w c:\program files\Amara - Flash Photo Animation Software
2009-01-10 20:13 --------- d-----w c:\program files\The Logo Creator v4
2009-01-10 20:13 --------- d-----w c:\program files\Amara - Intro and Banner Builder
2009-01-10 17:39 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-10 16:36 --------- d-----w c:\documents and settings\Donna\Application Data\Lexmark Productivity Studio
2009-01-10 16:25 --------- d-----w c:\program files\Google
2009-01-10 15:18 --------- d-----w c:\program files\OpenVPN
2009-01-04 23:38 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-04 23:38 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-12-25 20:04 --------- d-----w c:\program files\Common Files\Adobe
2008-12-24 18:18 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-22 19:28 --------- d-----w c:\program files\WordPerfect Office 12
2008-12-22 19:28 --------- d-----w c:\program files\QuickTime
2008-12-22 19:27 --------- d-----w c:\program files\Amara - Flash News Ticker
2008-12-22 19:27 --------- d-----w c:\program files\Amara - Flash Menu Builder
2008-12-22 19:26 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-22 19:25 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-22 18:50 --------- d-----w c:\program files\Flash Particle Studio 1.0
2008-12-12 10:08 --------- d-----w c:\program files\EmpirePokerMaster
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-09 12:53 --------- d-----w c:\program files\PartyGaming
2008-12-07 03:15 --------- d-----w c:\documents and settings\Donna\Application Data\TeamViewer
2008-12-04 17:27 --------- d-----w c:\program files\WinAVI FLV Converter
2008-12-04 17:27 --------- d-----w c:\documents and settings\Donna\Application Data\WinAVI
2008-12-04 17:26 --------- d-----w c:\program files\WinAVI Video Converter
2008-12-03 00:19 --------- d-----w c:\program files\HyCam2
2008-12-02 19:00 --------- d-----w c:\documents and settings\Donna\Application Data\Apple Computer
2008-12-02 15:51 --------- d-----w c:\program files\TeamViewer3
2008-11-24 00:47 --------- d-----w c:\documents and settings\Donna\Application Data\AntsSoft
2008-11-22 20:57 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-22 20:29 --------- d-----w c:\program files\Ultra Video Joiner
.

((((((((((((((((((((((((((((( snapshot_2009-01-13_12.15.34.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-11 18:32:08 16,384 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-14 00:20:17 16,384 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-11 18:32:08 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-14 00:20:17 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-11 18:32:08 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-14 00:20:17 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-08 10:41:42 333,824 ------w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 10:57:09 333,952 ------w c:\windows\system32\dllcache\srv.sys
- 2007-09-25 02:30:28 135,168 ----a-w c:\windows\system32\java.exe
+ 2009-01-14 05:17:18 144,792 ----a-w c:\windows\system32\java.exe
- 2007-09-25 02:30:30 135,168 ----a-w c:\windows\system32\javaw.exe
+ 2009-01-14 05:17:18 144,792 ----a-w c:\windows\system32\javaw.exe
- 2007-09-25 03:31:42 139,264 ----a-w c:\windows\system32\javaws.exe
+ 2009-01-14 05:17:18 148,888 ----a-w c:\windows\system32\javaws.exe
- 2008-12-09 23:24:37 17,593,280 ----a-w c:\windows\system32\MRT.exe
+ 2009-01-10 01:35:28 20,853,704 ----a-w c:\windows\system32\MRT.exe
+ 2009-01-15 03:36:02 16,384 ----atw c:\windows\TEMP\Perflib_Perfdata_4a4.dat
+ 2009-01-15 03:36:14 16,384 ----atw c:\windows\TEMP\Perflib_Perfdata_c04.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2008-12-18 23:28 204248 --a------ c:\program files\Hotspot Shield\hssie\HssIE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-09 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vmware-tray"="c:\program files\VMware\VMware Workstation\vmware-tray.exe" [2007-10-08 72240]
"lxdimon.exe"="c:\program files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-05-07 435120]
"lxdiamon"="c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-03-05 20480]
"FaxCenterServer"="c:\program files\\Lexmark Fax Solutions\fm3032.exe" [2007-05-07 312240]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-11 1601304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-14 136600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-09 39408]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-11 08:29 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MFZ0"= MyFlashZip0.ax

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
backup=c:\windows\pss\AOL Companion.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 19:12 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdiamon]
--a------ 2007-03-05 07:40 20480 c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdimon.exe]
--a------ 2007-05-07 13:07 435120 c:\program files\Lexmark 3500-4500 Series\lxdimon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-31 22:13 385024 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-09-16 11:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-02-21 18:57 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2008-10-16 20:57 4347120 c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2005-03-23 00:20 339968 c:\windows\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aawservice"=2 (0x2)
"quickmacros2"=2 (0x2)
"OpenVPNService"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"NetSvc"=3 (0x3)
"lxdi_device"=2 (0x2)
"lxdiCATSCustConnectService"=2 (0x2)
"IAANTMon"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"DSBrokerService"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\lxdicoms.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-01-10 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-10 324872]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-10 107272]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-01-10 29208]
R4 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-11 903960]
R4 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-10 298264]
R4 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [2009-01-11 1339600]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-01-10 29208]
S3 qmphook;QM process triggers;c:\program files\Quick Macros 2\qmphook.sys [2008-09-23 4096]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [2006-10-01 26624]
S4 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service --> c:\windows\system32\lxdicoms.exe -service [?]
S4 quickmacros2;Quick Macros;c:\program files\Quick Macros 2\qmserv.exe [2008-09-23 9728]
.
Contents of the 'Scheduled Tasks' folder

2009-01-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-01-14 c:\windows\Tasks\User_Feed_Synchronization-{8FFC9F01-9120-42BF-BA90-9E4F527139A1}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.insightbb.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download FLV by WinAVI... - c:\program files\WinAVI FLV Converter\flv_link.htm
IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D}
IE: {{B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0}
IE: {{DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - {EC83A912-7EF4-410D-9CC7-3BDAA709CA71} - c:\program files\WinAVI FLV Converter\FLVTune.dll
Trusted Zone: *.antimalwareguard.com
Trusted Zone: *.gomyhit.com
Trusted Zone: online.musicmatch.com
FF - ProfilePath - c:\documents and settings\Donna\Application Data\Mozilla\Firefox\Profiles\bwz5g9ri.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.insightbb.com
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-14 22:36:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\vmnat.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\VMware\VMware Workstation\vmware-authd.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\vmnetdhcp.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2009-01-14 22:39:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-15 03:39:52
ComboFix2.txt 2009-01-14 01:10:57
ComboFix3.txt 2009-01-13 17:16:34
ComboFix4.txt 2009-01-09 21:05:17
ComboFix5.txt 2009-01-15 03:32:20

Pre-Run: 116,959,371,264 bytes free
Post-Run: 116,942,278,656 bytes free

293 --- E O F --- 2008-12-18 23:00:48

HijackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:41:28 PM, on 1/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\vmnat.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.insightbb.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [vmware-tray] C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O8 - Extra context menu item: &Download FLV by WinAVI... - C:\Program Files\WinAVI FLV Converter\flv_link.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - C:\Program Files\WinAVI FLV Converter\FLVTune.dll
O9 - Extra 'Tools' menuitem: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - C:\Program Files\WinAVI FLV Converter\FLVTune.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.insightbb.com
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.gomyhit.com
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.0.5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se8300.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe

--
End of file - 10516 bytes
Donna57
Geek in Training
Geek in Training
 
Posts: 26
Joined: Sun Jan 20, 2008 5:39 pm

Thanks given:0
Thanks received:0
Top

Re: PC infected and running slowwww

Postby Gecko » Thu Jan 15, 2009 1:56 pm

Donna57,

Well I'm not saying to take away is poker especially if he is disabled.
I was just making you aware that most poker sites can cause problems.
If he has been using them for years then it should still be safe.

I went over both logs twice just to make sure I didn't miss something.
I don't see anything bad in either log but I would suggest that you run a Malwarebytes scan again just to make sure.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: PC infected and running slowwww

Postby Donna57 » Thu Jan 15, 2009 2:30 pm

Gecko, I think I will leave his poker sites on here for now then. Like I said he has been playing them for about 6 yrs with no problem. He doesn't surf the net, just goes there and plays. My niece had visited recently and was going to Myspace, so I dont know if she got something from there or what. I ran a Malwarebytes scan and it came back clean. My AVG runs a scan every morning and it keeps getting interrupted before it's done, and my firewall briefly gets disabled. The 4 threats AVG found this morning are as follows: (but it was interrupted and didn't get to finish)

"C:\Qoobox\Quarantine\C\WINDOWS\system32\fvgzhb.dll.vir";"Trojan horse Generic12.AUUH";"Moved to Virus Vault"
"C:\Qoobox\Quarantine\C\WINDOWS\system32\imbdlail.dll.vir";"Trojan horse Generic12.AUUH";"Moved to Virus Vault"
"C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP195\A0049120.dll";"Trojan horse Generic12.AUUH";"Moved to Virus Vault"
"C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP195\A0049121.dll";"Trojan horse Generic12.AUUH";"Moved to Virus Vault"


Malwarebytes' Anti-Malware 1.33
Database version: 1654
Windows 5.1.2600 Service Pack 3

1/15/2009 8:18:20 AM
mbam-log-2009-01-15 (08-18-20).txt

Scan type: Quick Scan
Objects scanned: 54283
Time elapsed: 3 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Donna57
Geek in Training
Geek in Training
 
Posts: 26
Joined: Sun Jan 20, 2008 5:39 pm

Thanks given:0
Thanks received:0
Top

Re: PC infected and running slowwww

Postby Gecko » Thu Jan 15, 2009 9:37 pm

Donna57,

I agree in leaving the Porker on your system and yes chances are that Myspace was the source if the infection.

Of those 4 files you listed two are in a Quarantined folder (C:\Qoobox\Quarantine) and the other two are in you system restore file.
You can safely delete the two files the the C:\Qoobox\Quarantine folder, just right click on them and select delete.

The only way to remove the other two, is to clear existing restore points.

Click Start, click All Programs, click Accessories, click System Tools, and then click System Restore.
Click to add a check mark beside Turn off System Restore on all Drives, and click Apply.
When you are warned that all existing Restore Points will be deleted, click Yes to continue.

All system restore points are deleted. Now you should manually create a restore point.

Click Start, click All Programs, click Accessories, click System Tools, and then click System Restore.
Click Create a Restore Point, and then click Next.
Name your restore point. (I use the date as well as a descriptive term such as "After Restore Point Deletion.")
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: PC infected and running slowwww

Postby Donna57 » Thu Jan 15, 2009 11:33 pm

Gecko, I would like to thank you very much for guiding me through cleaning out my computer. I could not have done this without you. I have created a new restore point and computer seems to be running fine. Do I leave the Combofix on my computer or do I remove it? ....Again Thanks!!!
Donna57
Geek in Training
Geek in Training
 
Posts: 26
Joined: Sun Jan 20, 2008 5:39 pm

Thanks given:0
Thanks received:0
Top

Re: PC infected and running slowwww

Postby Gecko » Mon Jan 19, 2009 12:56 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: PC infected and running slowwww

Postby Donna57 » Mon Jan 19, 2009 3:04 pm

I have removed ComboFix from my computer and again a big THANK YOU for repairing my computer :wobble:
Donna57
Geek in Training
Geek in Training
 
Posts: 26
Joined: Sun Jan 20, 2008 5:39 pm

Thanks given:0
Thanks received:0
Top

Re: PC infected and running slowwww

Postby Gecko » Mon Jan 19, 2009 10:00 pm

You're welcome Donna57
But actually you fix your system, I just point you in the right directions we needed.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Previous

Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron