Jump to content

I'm Running Into Some Big Problems


Recommended Posts

Hey all,

First off thanks for all you do. You have no idea how much of an asset those of you who are willing to help can be in times of need. I've never posted here, but I've run into a bit, of a problem here. I tried to download a movie that I needed to watch for a class off BT, and despite a few seeders, it still turned out to be a complete dud. Long story short, it's caused a terrible mess on my desktop and I can't get rid of it. Some of the problems I'm having with this nasty little bugger is that it wouldn't let me run Malwarebytes in the first place. I had to change the directory name just to run the program. Everytime I search for something on google, or any search engine for that matter, I'm automatically redirected. It runs one of my SVChosts, which consumes half my computers resources, renders the internet nearly useless, and when I try and end the process it shuts the computer down in 60 seconds. It won't let me connect to update Malwarebytes, or Avira Antivir, and it won't even let me connect to the Malwarebytes website. I can't get rid of it no matter what I do, and it's driving me crazy! Here's a post of both my Malwarebytes and my Hyjackthis logs....any help would be greatly appreciated.

C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

C:\WINDOWS\system32\svchost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)

O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"

O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe

O4 - HKLM\..\Run: [iSUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall

O4 - HKLM\..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll

O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1197034437\ee\AOLSoftware.exe

O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler

O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - Startup: MaxTV.lnk = C:\Program Files\DMV\MaxTV\MaxTV.exe

O4 - Global Startup: Digital Line Detect.lnk = ?

O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BU..._2/axofupld.cab

O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab

O16 - DPF: {A959E4A5-0B3D-449E-9998-348705BD4092} (Desktop.Smdesk) - http://www.servicemagic.com/smod/smdesktop.CAB

O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe

O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--

End of file - 11059 bytes

Malwarebytes' Anti-Malware 1.34

Database version: 1749

Windows 5.1.2600 Service Pack 2

3/22/2009 11:26:11 PM

mbam-log-2009-03-22 (23-26-11).txt

Scan type: Quick Scan

Objects scanned: 131390

Time elapsed: 19 minute(s), 1 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

welcome to malwarebytes forum

My name is Dan, and I will be helping you to remove any infection(s) that you may have.

Please note! that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

Please observe these rules while we work:

  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • REMEMBER, ABSENCE OF SYMPTOMS DOES NOT MEAN THE INFECTION IS ALL GONE.

If you can do these things, everything should go smoothly.

  • Please note you'll need to have Administrator priviledges to perform the fixes. (XP accounts are Administrator by default)
  • Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.

Unless informed of in advance, failure to post replies within 5 days will result in this thread being closed.

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Installed Programs

Please could you give me a list of the programs that are installed.

  • Start HijackThis
  • Click on the Misc Tools button
  • Click on the Open Uninstall Manager button.

You will see a list with the programs installed in your computer.

Click on save list button and specify where you would like to save this file.

When you press Save button a notepad will open with the contents of that file.

Simply copy and paste the contents of that notepad into your next post.

I'm presently looking over your log and hope not to be too long.

Will be back with you as soon as I can.

Thanks dan

Link to post
Share on other sites

One other note to add to what you wish for me to include is that periodically I get an svchost.exe - Application error. The error message says, "The instruction at 0x7x911c48 referenced memory at 0xfffffffff8. The memory could not be read. Click ok to terminate the program.

Here is the log you asked for:

Adobe AIR

Adobe Flash Player 10 Plugin

Adobe Flash Player ActiveX

Adobe Reader 9

Adobe Shockwave Player

AOL Coach Version 2.0(Build:20041026.5 en)

AOL Instant Messenger

AOL Toolbar

AOL Uninstaller

AOL You've Got Pictures Screensaver

AOLIcon

Apple Mobile Device Support

Apple Software Update

ATI - Software Uninstall Utility

ATI Catalyst Control Center

ATI Control Panel

ATI Display Driver

Avira AntiVir Personal - Free Antivirus

BitTorrent 5.0.9

Bonjour

Canon MP150

Company of Heroes

Company of Heroes - Balance Playtest

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Company of Heroes - FAKEMSI

Conexant D850 56K V.9x DFVc Modem

Corel Photo Album 6

Dell CinePlayer

Dell Digital Jukebox Driver

Dell Driver Reset Tool

Digital Content Portal

Digital Line Detect

Download Updater (AOL LLC)

EA Download Manager

EA SPORTS online 2007

EarthLink setup files

Easy-WebPrint

EducateU

ELIcon

ESPNMotion

FIFA 09

FileASSASSIN

FLV Player 1.3.3

Free Games Offer, Desktop Shortcut

Full Tilt Poker

GemMaster Mystic

Get High Speed Internet!

Google Earth

Google Updater

High Definition Audio Driver Package - KB835221

HijackThis 2.0.2

Hotfix for Windows Internet Explorer 7 (KB947864)

Hotfix for Windows Media Format 11 SDK (KB929399)

Hotfix for Windows Media Player 10 (KB903157)

Hotfix for Windows Media Player 11 (KB939683)

Hotfix for Windows XP (KB888795)

Hotfix for Windows XP (KB891593)

Hotfix for Windows XP (KB895961)

Hotfix for Windows XP (KB899337)

Hotfix for Windows XP (KB899510)

Hotfix for Windows XP (KB902841)

Hotfix for Windows XP (KB914440)

Hotfix for Windows XP (KB915865)

Hotfix for Windows XP (KB926239)

Hotfix for Windows XP (KB952287)

Intel® PRO Network Connections Drivers

Intel® PROSet for Wired Connections

iTunes

J2SE Runtime Environment 5.0 Update 10

J2SE Runtime Environment 5.0 Update 6

Java 2 Runtime Environment, SE v1.4.2_03

Java 6 Update 2

Java 6 Update 5

Java SE Runtime Environment 6 Update 1

Learn2 Player (Uninstall Only)

LG USB Modem driver

Malwarebytes' Anti-Malware

MCU

Medal of Honor Allied Assault

Microsoft .NET Framework 1.0 Hotfix (KB887998)

Microsoft .NET Framework 1.0 Hotfix (KB930494)

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1

Microsoft .NET Framework 1.1 Hotfix (KB928366)

Microsoft .NET Framework 2.0 Service Pack 1

Microsoft Compression Client Pack 1.0 for Windows XP

Microsoft Internationalized Domain Names Mitigation APIs

Microsoft Location Finder

Microsoft National Language Support Downlevel APIs

Microsoft Off ice Word Viewer 2003

Microsoft Plus! Digital Media Edition Installer

Microsoft Plus! Photo Story 2 LE

Microsoft Silverlight

Microsoft User-Mode Driver Framework Feature Pack 1.0

Microsoft VC9 runtime libraries

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual J# .NET Redistributable Package 1.1

mIRC

Modem Helper

Move Networks Player for Firefox

Mozilla Firefox (3.0.7)

MSXML 4.0 SP2 (KB927978)

MSXML 4.0 SP2 (KB936181)

MSXML 4.0 SP2 (KB954430)

Musicmatch

Link to post
Share on other sites

IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

BitTorrent

I'd like you to read the MRU policy for P2P Programs.

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

------------------------

Remove Poker programs

From your log I can see you've installed poker programs. A lot of poker programs are infected/can infect you with malware.

I would advise you to go to Add/Remove programs and uninstall your poker programs.

Full Tilt Poker

Here are links to some poker sites regarded as safe for your reference.

* http://www.pokerstars.net/ - This is a simple play money version.

* http://www.pokerstars.com/ - This is a bigger play money and real money version.

Optional Fix

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player

Link to post
Share on other sites

Here is a log of what you've requested. Additionally, I took the steps to remove BitTorrent and Viewpoint. Let me know if you need any additional information. Thanks.

GooredFix v1.92 by jpshortstuff

Log created at 23:34 on 24/03/2009 running Option #1 (Stephen Conroy)

Firefox version 3.0.7 (en-US)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]

"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.7\extensions]

"Components"="C:\Program Files\Mozilla Firefox\components"

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:37:08 PM, on 3/24/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\WINDOWS\system32\inetsrv\inetinfo.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\mqsvc.exe

C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe

C:\WINDOWS\system32\mqtgsvc.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\dllhost.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\ehome\ehtray.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\stsystra.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\Program Files\Dell\Media Experience\DMXLauncher.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\Program Files\Common Files\AOL\1197034437\ee\AOLSoftware.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Digital Line Detect\DLG.exe

c:\program files\common files\aol\1197034437\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe

C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll

O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"

O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe

O4 - HKLM\..\Run: [iSUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall

O4 - HKLM\..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll

O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1197034437\ee\AOLSoftware.exe

O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler

O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - Startup: MaxTV.lnk = C:\Program Files\DMV\MaxTV\MaxTV.exe

O4 - Global Startup: Digital Line Detect.lnk = ?

O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BU..._2/axofupld.cab

O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab

O16 - DPF: {A959E4A5-0B3D-449E-9998-348705BD4092} (Desktop.Smdesk) - http://www.servicemagic.com/smod/smdesktop.CAB

O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe

O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe

--

End of file - 9720 bytes

Link to post
Share on other sites

  • Please create a BOOTLOG
  • Restart the computer and press F8 when Windows start booting. This will bring up the startup options.
  • Select "Enable Boot Logging" option and press enter.
  • Windows prompts you to select a Windows Installation (even if there is only one windows installation)
  • This boots windows normally and creates a boot log named ntbtlog.txt and saves it to C:\Windows
    If you're already running inside Windows you can enable it the following way.
  • Click on START - RUN and type in MSCONFIG go to the BOOT.INI tab and place a check mark by /BOOTLOG
  • Click on OK and you will be prompted to RESTART Windows. Please do restart now.
  • After Windows restarts open the file C:\Windows\ntbtlog.txt with Notepad
  • From the Edit menu choose Select All then Edit, COPY and post that back on your next reply.
  • Note: Vista users can type in the Search and it will show on the menu, then Right click and choose Run as Adminsitrator
  • The tab is called BOOT on Vista. Then choose Boot log

RootRepeal - Rootkit Detector

  • Please download the following tool: RootRepeal - Rootkit Detector
  • Direct download link is here: RootRepeal.rar
  • If you don't already have a program to open a .RAR compressed file you can download a trial version from here: WinRAR
  • Extract the program file to a new folder such as C:\RootRepeal
  • Run the program RootRepeal.exe and go to the REPORT tab and click on the Scan button
  • Select ALL of the checkboxes and then click OK and it will start scanning your system.
  • If you have multiple drives you only need to check the C: drive or the one Windows is installed on.
  • When done, click on Save Report
  • Save it to the same location where you ran it from, such as C:\RootRepeal
  • Save it as your_name_rootrepeal.txt - where your_name is your forum name
  • This makes it more easy to track who the log belongs to.
  • Then open that log and select all and copy/paste it back on your next reply please.
  • Quit the RootRepeal program.

Post the logs

Link to post
Share on other sites

I'd like you to note that I have not had access and will not have access to my infected computer until Sunday. I will promptly run the tests and post the logs at some point on Sunday. I felt it necessary to inform you of this as you've been of great help to me thus far. Thanks again.

Link to post
Share on other sites

Ok, here is the latest. Sorry for the delay but I haven't been near the infected computer for a number of days now. However, I got a few minutes today and was able to take a look at it. First off, the computer starts up but while the desktop is loading the computer hangs up. I can't do much of anything starting Windows in normal mode. When I go over to Safe Mode, I've got a lot more success. I can access the internet, though not malwarebytes.org, and I can get into the C drive to retrieve the last Boot Log on the computer. When I opened up RootRepeal in Safe Mode it told me to use it at my own risk when operating in Safe Mode. My question is, should I run RootRepeal in Safe Mode with Networking? Here is my last boot log. Thanks!

Service Pack 2 3 31 2009 19:39:51.375

Loaded driver \WINDOWS\system32\ntoskrnl.exe

Loaded driver \WINDOWS\system32\hal.dll

Loaded driver \WINDOWS\system32\KDCOM.DLL

Loaded driver \WINDOWS\system32\BOOTVID.dll

Loaded driver sptd.sys

Loaded driver \WINDOWS\System32\Drivers\WMILIB.SYS

Loaded driver \WINDOWS\System32\Drivers\SPTD9933.SYS

Loaded driver ACPI.sys

Loaded driver pci.sys

Loaded driver isapnp.sys

Loaded driver pciide.sys

Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS

Loaded driver MountMgr.sys

Loaded driver ftdisk.sys

Loaded driver dmload.sys

Loaded driver dmio.sys

Loaded driver PartMgr.sys

Loaded driver sfsync02.sys

Loaded driver VolSnap.sys

Loaded driver atapi.sys

Loaded driver disk.sys

Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS

Loaded driver fltMgr.sys

Loaded driver sr.sys

Loaded driver Lbd.sys

Loaded driver DRVMCDB.SYS

Loaded driver PxHelp20.sys

Loaded driver KSecDD.sys

Loaded driver WudfPf.sys

Loaded driver Ntfs.sys

Loaded driver NDIS.sys

Loaded driver sfhlp02.sys

Loaded driver sfdrv01.sys

Loaded driver Mup.sys

Did not load driver ACPI Multiprocessor PC

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys

Loaded driver \SystemRoot\system32\DRIVERS\usbuhci.sys

Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys

Did not load driver Conexant D850 56K V.9x DFVc Modem

Loaded driver \SystemRoot\system32\DRIVERS\e100b325.sys

Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys

Loaded driver \SystemRoot\System32\Drivers\DLACDBHM.SYS

Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys

Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys

Loaded driver \SystemRoot\System32\Drivers\GEARAspiWDM.sys

Loaded driver \SystemRoot\System32\Drivers\dtscsi.sys

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys

Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys

Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys

Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys

Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys

Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys

Loaded driver \SystemRoot\system32\DRIVERS\psched.sys

Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys

Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys

Loaded driver \SystemRoot\system32\DRIVERS\wanatw4.sys

Loaded driver \SystemRoot\system32\DRIVERS\rdpdr.sys

Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys

Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys

Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys

Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys

Loaded driver \SystemRoot\system32\DRIVERS\update.sys

Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS

Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS

Loaded driver \SystemRoot\System32\Drivers\i2omgmt.SYS

Did not load driver \SystemRoot\System32\Drivers\Changer.SYS

Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS

Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS

Loaded driver \SystemRoot\System32\Drivers\Null.SYS

Loaded driver \SystemRoot\System32\Drivers\Beep.SYS

Loaded driver \SystemRoot\System32\Drivers\DLARTL_N.SYS

Did not load driver i8042prt.SYS

Did not load driver kbdhid.SYS

Loaded driver \SystemRoot\System32\drivers\vga.sys

Did not load driver mnmdd.SYS

Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys

Loaded driver \systemroot\system32\drivers\gaopdxfpykxxugnqmoeasrvqxruolmeoyngpxj.sys

Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS

Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS

Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys

Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys

Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys

Did not load driver Wanarp.SYS

Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys

Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys

Loaded driver \SystemRoot\System32\drivers\afd.sys

Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys

Did not load driver Serial.SYS

Did not load driver intelppm.SYS

Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS

Did not load driver WS2IFSL.SYS

Did not load driver ssmdrv.SYS

Did not load driver SCDEmu.SYS

Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys

Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys

Did not load driver Fips.SYS

Did not load driver avipbb.SYS

Did not load driver avgio.SYS

Loaded driver \SystemRoot\system32\DRIVERS\hidusb.sys

Loaded driver \SystemRoot\system32\DRIVERS\kbdhid.sys

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Loaded driver \SystemRoot\system32\DRIVERS\mouhid.sys

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS

Did not load driver Intel Processor

Did not load driver Intel Processor

Did not load driver RADEON Radeon X300/X550/X1050 Series

Did not load driver RADEON Radeon X300/X550/X1050 Series Secondary

Did not load driver SigmaTel High Definition Audio CODEC

Did not load driver Conexant D850 56K V.9x DFVc Modem

Did not load driver Audio Codecs

Did not load driver Legacy Audio Drivers

Did not load driver Media Control Devices

Did not load driver Legacy Video Capture Devices

Did not load driver Video Codecs

Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys

Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys

Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys

Loaded driver \SystemRoot\system32\DRIVERS\srv.sys

Did not load driver \SystemRoot\system32\DRIVERS\ipnat.sys

Link to post
Share on other sites

Can see your having problems let's try this..

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1

Link 2

Link 3

CF_download_FF.gif

CF_download_rename.gif

--------------------------------------------------------------------

Double click on Combo-Fix.exe & follow the prompts.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
Link to post
Share on other sites

Is it OK to run these in Safe Mode w/ Networking, or should I really try and perform these scans in normal Windows, even though I'm having great difficulty in doing anything in normal Windows? Combofix sounds like a powerful program and I don't want to cause a disaster running it in Safe Mode.

Thanks

Link to post
Share on other sites

I can't run a HJT scan and log in normal Windows. It locks up everytime it goes to scan O4 - Registry & Start Menu autoruns. I haven't tried Combo-fix on regular Windows yet, but it's highly doubtful it will run. There's very little I can do in Windows without it locking up. Suggestions? Run this stuff in Safe Mode?

Link to post
Share on other sites

Great news! I ran both Hijackthis and Combofix in normal Windows, and it seems Combofix has done a good job. Check my logs and let me know what my next action should be. I must say the computer is running MUCH better after running combofix.

ComboFix 09-04-04.01 - Stephen Conroy 2009-04-04 18:11:05.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1583 [GMT -4:00]

Running from: c:\documents and settings\Stephen Conroy\Desktop\Combo-Fix.exe

AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Stephen Conroy\Start Menu\Programs\WatchFree

C:\install.exe

c:\windows\system32\Cache

c:\windows\system32\drivers\gaopdxfpykxxugnqmoeasrvqxruolmeoyngpxj.sys

c:\windows\system32\gaopdxcounter

c:\windows\system32\gaopdxddjnjaliugotixisvloempmtaiydcanw.dll

c:\windows\system32\smartdrv.exe

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Service_gaopdxserv.sys

((((((((((((((((((((((((( Files Created from 2009-03-04 to 2009-04-04 )))))))))))))))))))))))))))))))

.

2009-03-22 23:38 . 2009-03-22 23:38 <DIR> d-------- c:\program files\Trend Micro

2009-03-13 00:47 . 2009-03-13 00:47 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes

2009-03-13 00:34 . 2009-03-13 00:34 <DIR> d-------- c:\program files\Avira

2009-03-13 00:34 . 2009-03-13 00:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira

2009-03-12 23:05 . 2009-03-12 23:05 <DIR> d-------- c:\documents and settings\Stephen Conroy\Application Data\Malwarebytes

2009-03-12 21:59 . 2009-03-12 21:59 <DIR> d-------- c:\program files\FileASSASSIN

2009-03-12 21:54 . 2009-03-12 22:52 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware

2009-03-12 21:54 . 2009-03-12 21:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-03-12 21:54 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-03-12 21:54 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-03-11 00:56 . 2009-01-18 17:35 15,688 --a------ c:\windows\system32\lsdelete.exe

2009-03-11 00:45 . 2009-03-11 00:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft

2009-03-11 00:45 . 2009-03-11 00:45 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}

2009-03-11 00:45 . 2009-01-18 17:30 64,160 --a------ c:\windows\system32\drivers\Lbd.sys

2009-03-05 01:40 . 2009-03-13 14:32 54,156 --ah----- c:\windows\QTFont.qfn

2009-03-05 01:40 . 2009-03-05 01:40 1,409 --a------ c:\windows\QTFont.for

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-04-01 02:24 7,520 --sha-w c:\windows\system32\KGyGaAvL.sys

2009-03-25 03:13 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint

2009-03-25 03:12 --------- d-----w c:\program files\Full Tilt Poker

2009-03-25 03:05 --------- d-----w c:\program files\BitTorrent

2009-03-12 13:55 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater

2009-03-12 12:42 --------- d-----w c:\documents and settings\Stephen Conroy\Application Data\utorrent

2009-03-11 04:45 --------- d-----w c:\program files\Lavasoft

2009-02-21 14:25 --------- d-----w c:\documents and settings\Patrick\Application Data\Apple Computer

2009-02-14 22:09 --------- d--h--w c:\documents and settings\Patrick\Application Data\Move Networks

2009-02-06 18:49 --------- d-----w c:\program files\PartyGaming

2009-02-06 18:49 --------- d-----w c:\program files\Google

2009-02-06 18:46 --------- d-----w c:\program files\MUSICMATCH

2009-02-06 18:45 --------- d--h--w c:\documents and settings\Peggy\Application Data\Gtek

2009-02-06 18:45 --------- d-----w c:\documents and settings\All Users\Application Data\GTek

2009-02-06 18:44 --------- d-----w c:\program files\Fifa Master

2009-02-06 18:43 --------- d-----w c:\program files\V CAST Music with Rhapsody

2009-01-17 02:35 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]

"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]

"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]

"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]

"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2007-08-28 73728]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]

"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]

"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

"HostManager"="c:\program files\Common Files\AOL\1197034437\ee\AOLSoftware.exe" [2008-06-24 41824]

"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]

"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 c:\windows\stsystra.exe]

"MsmqIntCert"="mqrt.dll" [2007-07-06 c:\windows\system32\mqrt.dll]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-04-11 24576]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]

-ra------ 2006-10-23 08:50 71216 c:\program files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

--a------ 2008-06-24 14:34 41824 c:\program files\Common Files\AOL\1197034437\EE\aolsoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

--a------ 2008-03-30 10:36 267048 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]

--a------ 2005-09-08 20:20 8192 c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

--a------ 2007-06-25 23:49 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]

--a------ 2006-06-16 11:46 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\mIRC\\mirc.exe"=

"c:\\Program Files\\AIM\\aim.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\SopCast\\SopCast.exe"=

"c:\\Documents and Settings\\Stephen Conroy\\Application Data\\SopCast\\adv\\SopAdver.exe"=

"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=

"c:\\WINDOWS\\system32\\mqsvc.exe"=

"c:\\Program Files\\TVAnts\\Tvants.exe"=

"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=

"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=

"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=

"c:\\Program Files\\Common Files\\AOL\\1197034437\\EE\\aolsoftware.exe"=

"c:\\Program Files\\AOL 9.1\\waol.exe"=

"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=

"c:\\Program Files\\Common Files\\AOL\\1197034437\\ee\\aolservicehost.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\WINDOWS\\system32\\dplaysvr.exe"=

"c:\\Program Files\\EA SPORTS\\MVP Baseball 2005\\mvp2005.exe"=

"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=

"c:\\Program Files\\THQ\\Company of Heroes - Balance Playtest\\RelicCOH.exe"=

"c:\\Program Files\\THQ\\Company of Heroes - Balance Playtest\\RelicDownloader\\RelicDownloader.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"67:UDP"= 67:UDP:0.0.0.0/255.255.255.255:Enabled:DHCP Discovery Service

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-11 64160]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]

S0 xrxyv;xrxyv;c:\windows\system32\drivers\uhzzdvnk.sys --> c:\windows\system32\drivers\uhzzdvnk.sys [?]

S2 VTFOJMZE;VTFOJMZE;\??\c:\windows\system32\vtfojmze.fzv --> c:\windows\system32\vtfojmze.fzv [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

\Shell\AutoRun\command - D:\Launch.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]

\Shell\AutoRun\command - E:\setup.exe

.

Contents of the 'Scheduled Tasks' folder

2009-03-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:34]

2009-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]

2009-04-04 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 00:07]

.

- - - - ORPHANS REMOVED - - - -

HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.live.com

mStart Page = hxxp://www.yahoo.com/

uInternet Settings,ProxyOverride = *.local

IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

Trusted Zone: musicmatch.com\online

FF - ProfilePath - c:\documents and settings\Stephen Conroy\Application Data\Mozilla\Firefox\Profiles\yrichvqd.default\

FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll

FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npmnqmp07030901.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll

FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll

.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-04-04 18:21:12

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VTFOJMZE]

"ImagePath"="\??\c:\windows\system32\vtfojmze.fzv"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2560306997-580925832-812904618-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

"??"=hex:8f,b3,f3,87,0e,7a,e6,7b,42,6d,b7,10,64,57,30,16,70,ef,72,63,a4,9a,8d,

98,35,65,c9,8a,c9,8f,0f,ea,e7,d1,52,50,99,7d,9d,ae,c9,f9,d2,f2,c2,9c,cb,75,\

"??"=hex:0c,2b,0c,1b,89,60,a6,e2,ba,7b,8b,cd,62,81,bf,a6

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(632)

c:\windows\system32\Ati2evxx.dll

.

Completion time: 2009-04-04 18:23:32

ComboFix-quarantined-files.txt 2009-04-04 22:23:01

Pre-Run: 1,897,512,960 bytes free

Post-Run: 4,546,736,128 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

212 --- E O F --- 2009-03-06 08:01:04

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 6:33:01 PM, on 4/4/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\WINDOWS\system32\inetsrv\inetinfo.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe

C:\WINDOWS\system32\mqsvc.exe

C:\WINDOWS\system32\mqtgsvc.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll

O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"

O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe

O4 - HKLM\..\Run: [iSUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall

O4 - HKLM\..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll

O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1197034437\ee\AOLSoftware.exe

O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - Startup: MaxTV.lnk = C:\Program Files\DMV\MaxTV\MaxTV.exe

O4 - Global Startup: Digital Line Detect.lnk = ?

O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BU..._2/axofupld.cab

O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab

O16 - DPF: {A959E4A5-0B3D-449E-9998-348705BD4092} (Desktop.Smdesk) - http://www.servicemagic.com/smod/smdesktop.CAB

O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe

O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe

--

End of file - 9028 bytes

Link to post
Share on other sites

You will be able to run in normal mode now

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::c:\windows\system32\drivers\uhzzdvnk.sys c:\windows\system32\vtfojmze.fzv Folder::c:\program files\Full Tilt Pokerc:\program files\BitTorrentc:\documents and settings\Stephen Conroy\Application Data\utorrentDriver::xrxyv;xrxyvVTFOJMZERegistry::[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}][HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VTFOJMZE]"ImagePath"=-

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Can you update malwarebytes and do a full scan.

Post:

combofix report

Malwarebytes report

Link to post
Share on other sites

Sorry, it's busy season at work, and haven't had a lot of time at home lately. Anyway, here are the logs you asked for:

Malwarebytes' Anti-Malware 1.36

Database version: 1954

Windows 5.1.2600 Service Pack 2

4/9/2009 1:06:46 AM

mbam-log-2009-04-09 (01-06-46).txt

Scan type: Full Scan (C:\|)

Objects scanned: 218300

Time elapsed: 53 minute(s), 20 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

ComboFix 09-04-04.01 - Stephen Conroy 2009-04-08 23:52:33.3 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1540 [GMT -4:00]

Running from: c:\documents and settings\Stephen Conroy\Desktop\Combo-Fix.exe

Command switches used :: c:\documents and settings\Stephen Conroy\Desktop\CFScript.txt

AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)

* Created a new restore point

FILE ::

c:\windows\system32\drivers\uhzzdvnk.sys

c:\windows\system32\vtfojmze.fzv

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Service_VTFOJMZE

((((((((((((((((((((((((( Files Created from 2009-03-09 to 2009-04-09 )))))))))))))))))))))))))))))))

.

2009-04-05 22:25 . 2009-04-05 22:25 410,984 --a------ c:\windows\system32\deploytk.dll

2009-03-22 23:38 . 2009-03-22 23:38 <DIR> d-------- c:\program files\Trend Micro

2009-03-13 00:47 . 2009-03-13 00:47 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes

2009-03-13 00:34 . 2009-03-13 00:34 <DIR> d-------- c:\program files\Avira

2009-03-13 00:34 . 2009-03-13 00:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira

2009-03-12 23:05 . 2009-03-12 23:05 <DIR> d-------- c:\documents and settings\Stephen Conroy\Application Data\Malwarebytes

2009-03-12 21:59 . 2009-03-12 21:59 <DIR> d-------- c:\program files\FileASSASSIN

2009-03-12 21:54 . 2009-04-04 20:41 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware

2009-03-12 21:54 . 2009-03-12 21:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-03-12 21:54 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-03-12 21:54 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-03-11 00:56 . 2009-01-18 17:35 15,688 --a------ c:\windows\system32\lsdelete.exe

2009-03-11 00:45 . 2009-03-11 00:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft

2009-03-11 00:45 . 2009-03-11 00:45 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}

2009-03-11 00:45 . 2009-04-06 00:45 64,160 --a------ c:\windows\system32\drivers\Lbd.sys

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-04-08 05:28 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater

2009-04-06 02:25 --------- d-----w c:\program files\Java

2009-04-06 02:24 --------- d-----w c:\program files\Common Files\Adobe

2009-03-25 03:13 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint

2009-03-11 04:45 --------- d-----w c:\program files\Lavasoft

2009-02-21 14:25 --------- d-----w c:\documents and settings\Patrick\Application Data\Apple Computer

2009-02-14 22:09 --------- d--h--w c:\documents and settings\Patrick\Application Data\Move Networks

.

((((((((((((((((((((((((((((( SnapShot@2009-04-04_18.22.05.59 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-02-09 10:20:05 1,847,424 ----a-w c:\windows\$hf_mig$\KB958690\SP2QFE\win32k.sys

+ 2009-02-09 11:13:27 1,846,784 ----a-w c:\windows\$hf_mig$\KB958690\SP3GDR\win32k.sys

+ 2009-02-09 11:08:53 1,847,552 ----a-w c:\windows\$hf_mig$\KB958690\SP3QFE\win32k.sys

+ 2008-07-09 07:38:24 17,272 ----a-w c:\windows\$hf_mig$\KB958690\spmsg.dll

+ 2008-07-09 07:38:25 231,288 ----a-w c:\windows\$hf_mig$\KB958690\spuninst.exe

+ 2008-07-09 07:38:24 26,488 ----a-w c:\windows\$hf_mig$\KB958690\update\spcustom.dll

+ 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB958690\update\update.exe

+ 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB958690\update\updspapi.dll

+ 2008-12-05 06:41:26 144,896 ----a-w c:\windows\$hf_mig$\KB960225\SP2QFE\schannel.dll

+ 2008-12-05 06:54:55 144,896 ----a-w c:\windows\$hf_mig$\KB960225\SP3GDR\schannel.dll

+ 2008-12-05 06:58:08 144,896 ----a-w c:\windows\$hf_mig$\KB960225\SP3QFE\schannel.dll

+ 2007-11-30 11:18:51 17,272 ----a-w c:\windows\$hf_mig$\KB960225\spmsg.dll

+ 2007-11-30 11:18:51 231,288 ----a-w c:\windows\$hf_mig$\KB960225\spuninst.exe

+ 2007-11-30 11:18:51 26,488 ----a-w c:\windows\$hf_mig$\KB960225\update\spcustom.dll

+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB960225\update\update.exe

+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB960225\update\updspapi.dll

+ 2005-10-21 00:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE

- 2009-03-13 01:08:28 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2009-04-09 01:24:16 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat

- 2009-03-13 01:08:28 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

+ 2009-04-09 01:24:16 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

- 2007-04-25 14:21:15 144,896 ------w c:\windows\system32\dllcache\schannel.dll

+ 2008-12-05 07:12:45 144,896 ------w c:\windows\system32\dllcache\schannel.dll

- 2008-09-15 11:57:41 1,846,016 ------w c:\windows\system32\dllcache\win32k.sys

+ 2009-02-09 10:19:34 1,846,272 ------w c:\windows\system32\dllcache\win32k.sys

+ 2009-04-06 04:45:20 64,160 -c--a-w c:\windows\system32\DRVSTORE\lbd_1D149FE61E2CD0936E43877117FE3EF0674B9944\Lbd.sys

- 2008-11-20 20:59:15 197,752 ----a-w c:\windows\system32\FNTCACHE.DAT

+ 2009-04-05 07:09:24 197,752 ----a-w c:\windows\system32\FNTCACHE.DAT

- 2009-04-04 22:10:06 223,913 ----a-w c:\windows\system32\inetsrv\MetaBase.bin

+ 2009-04-09 04:01:07 223,912 ----a-w c:\windows\system32\inetsrv\MetaBase.bin

- 2008-02-22 05:23:35 135,168 ----a-w c:\windows\system32\java.exe

+ 2009-04-06 02:25:36 144,792 ----a-w c:\windows\system32\java.exe

- 2008-02-22 05:23:39 135,168 ----a-w c:\windows\system32\javaw.exe

+ 2009-04-06 02:25:36 144,792 ----a-w c:\windows\system32\javaw.exe

- 2008-02-22 06:33:32 139,264 ----a-w c:\windows\system32\javaws.exe

+ 2009-04-06 02:25:36 148,888 ----a-w c:\windows\system32\javaws.exe

- 2009-04-01 02:24:27 7,520 --sha-w c:\windows\system32\KGyGaAvL.sys

+ 2009-04-08 02:28:19 7,520 --sha-w c:\windows\system32\KGyGaAvL.sys

- 2009-02-03 23:21:12 21,244,864 ----a-w c:\windows\system32\MRT.exe

+ 2009-02-25 16:55:00 24,768,960 ----a-w c:\windows\system32\MRT.exe

- 2007-04-25 14:21:15 144,896 ----a-w c:\windows\system32\schannel.dll

+ 2008-12-05 07:12:45 144,896 ----a-w c:\windows\system32\schannel.dll

- 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll

+ 2007-11-30 11:18:51 17,272 ------w c:\windows\system32\spmsg.dll

- 2006-10-16 20:10:58 23,856 ----a-w c:\windows\system32\spupdsvc.exe

+ 2007-07-27 13:41:38 26,488 ----a-w c:\windows\system32\spupdsvc.exe

- 2008-09-15 11:57:41 1,846,016 ----a-w c:\windows\system32\win32k.sys

+ 2009-02-09 10:19:34 1,846,272 ----a-w c:\windows\system32\win32k.sys

- 2007-06-12 03:51:12 10,834,944 ----a-w c:\windows\system32\wmp.dll

+ 2008-11-11 22:34:42 10,838,016 ----a-w c:\windows\system32\wmp.dll

+ 2009-04-09 04:00:43 16,384 ----atw c:\windows\temp\Perflib_Perfdata_f4.dat

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 136600]

"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]

"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]

"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2007-08-28 73728]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]

"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]

"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]

"HostManager"="c:\program files\Common Files\AOL\1197034437\ee\AOLSoftware.exe" [2008-06-24 41824]

"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-06 515416]

"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 c:\windows\stsystra.exe]

"MsmqIntCert"="mqrt.dll" [2007-07-06 c:\windows\system32\mqrt.dll]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-04-11 24576]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]

-ra------ 2006-10-23 08:50 71216 c:\program files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

--a------ 2008-06-24 14:34 41824 c:\program files\Common Files\AOL\1197034437\EE\aolsoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

--a------ 2008-03-30 10:36 267048 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]

--a------ 2005-09-08 20:20 8192 c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

--a------ 2007-06-25 23:49 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]

--a------ 2006-06-16 11:46 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\mIRC\\mirc.exe"=

"c:\\Program Files\\AIM\\aim.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\SopCast\\SopCast.exe"=

"c:\\Documents and Settings\\Stephen Conroy\\Application Data\\SopCast\\adv\\SopAdver.exe"=

"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=

"c:\\WINDOWS\\system32\\mqsvc.exe"=

"c:\\Program Files\\TVAnts\\Tvants.exe"=

"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=

"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=

"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=

"c:\\Program Files\\Common Files\\AOL\\1197034437\\EE\\aolsoftware.exe"=

"c:\\Program Files\\AOL 9.1\\waol.exe"=

"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=

"c:\\Program Files\\Common Files\\AOL\\1197034437\\ee\\aolservicehost.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\WINDOWS\\system32\\dplaysvr.exe"=

"c:\\Program Files\\EA SPORTS\\MVP Baseball 2005\\mvp2005.exe"=

"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=

"c:\\Program Files\\THQ\\Company of Heroes - Balance Playtest\\RelicCOH.exe"=

"c:\\Program Files\\THQ\\Company of Heroes - Balance Playtest\\RelicDownloader\\RelicDownloader.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"67:UDP"= 67:UDP:0.0.0.0/255.255.255.255:Enabled:DHCP Discovery Service

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-11 64160]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]

S0 xrxyv;xrxyv;c:\windows\system32\drivers\uhzzdvnk.sys --> c:\windows\system32\drivers\uhzzdvnk.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

\Shell\AutoRun\command - D:\Launch.exe

.

Contents of the 'Scheduled Tasks' folder

2009-04-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-04-06 00:45]

2009-04-05 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]

2009-04-09 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 00:07]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.live.com

mStart Page = hxxp://www.yahoo.com/

uInternet Settings,ProxyOverride = *.local

IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

Trusted Zone: musicmatch.com\online

FF - ProfilePath - c:\documents and settings\Stephen Conroy\Application Data\Mozilla\Firefox\Profiles\yrichvqd.default\

FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll

FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npmnqmp07030901.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll

FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll

.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-04-09 00:03:06

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2560306997-580925832-812904618-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

"??"=hex:8f,b3,f3,87,0e,7a,e6,7b,42,6d,b7,10,64,57,30,16,70,ef,72,63,a4,9a,8d,

98,35,65,c9,8a,c9,8f,0f,ea,e7,d1,52,50,99,7d,9d,ae,c9,f9,d2,f2,c2,9c,cb,75,\

"??"=hex:0c,2b,0c,1b,89,60,a6,e2,ba,7b,8b,cd,62,81,bf,a6

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(632)

c:\windows\system32\Ati2evxx.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\ati2evxx.exe

c:\windows\system32\ati2evxx.exe

c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe

c:\windows\system32\msdtc.exe

c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe

c:\program files\Common Files\AOL\ACS\AOLacsd.exe

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\windows\ehome\ehrecvr.exe

c:\windows\ehome\ehSched.exe

c:\windows\system32\inetsrv\inetinfo.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\mqsvc.exe

c:\program files\Pure Networks\Network Magic\nmsrvc.exe

c:\windows\ehome\mcrdsvc.exe

c:\windows\system32\mqtgsvc.exe

c:\windows\system32\dllhost.exe

c:\windows\system32\wbem\unsecapp.exe

c:\windows\ehome\ehmsas.exe

c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

c:\windows\system32\wscntfy.exe

c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

c:\program files\Common Files\AOL\1197034437\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe

.

**************************************************************************

.

Completion time: 2009-04-09 0:10:27 - machine was rebooted

ComboFix-quarantined-files.txt 2009-04-09 04:10:24

ComboFix2.txt 2009-04-05 00:20:10

ComboFix3.txt 2009-04-04 22:23:33

Pre-Run: 5,281,476,608 bytes free

Post-Run: 5,359,824,896 bytes free

269 --- E O F --- 2009-04-05 07:03:05

Link to post
Share on other sites

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KILLALL::File::c:\windows\system32\drivers\uhzzdvnk.sysDriver:: xrxyv

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

-------------------------------

Please go into the Control Panel, Add/Remove and for now remove ALL versions of JAVA

Then run this tool to help cleanup any left over Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer (or other web browser) before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location and post it back when you reply
    Then look for the following Java folders and if found delete them.
    C:\Program Files\Java
    C:\Program Files\Common Files\Java
    C:\Documents and Settings\All Users\Application Data\Java
    C:\Documents and Settings\All Users\Application Data\Sun\Java
    C:\Documents and Settings\username\Application Data\Java
    C:\Documents and Settings\username\Application Data\Sun\Java

------------------------

Download and Update Java Runtime

The most current version of Sun Java is: Java Runtime Environment (JRE) 6 Update 13.

  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Go to Java Runtime Environment (JRE) 6 Update 13 about half way down the page and click on the Download button.
  • In Platform box choose Windows.
  • Check the box to Accept License Agreement and click Continue.
  • Click on Windows Offline Installation, click on the link under it which says jre-6u12-windows-i586-p.exe and save the downloaded file to your desktop.
  • Install the new version by running the newly-downloaded file with the java icon which will be on your desktop, and follow the on-screen instructions.
  • Uncheck the Toolbar button (unless you want the toolbar)
  • Reboot your computer

----------------------

Please go to Kaspersky website and perform an online antivirus scan.

  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases

[*]Click on My Computer under Scan.

[*]Once the scan is complete, it will display the results. Click on View Scan Report.

[*]You will see a list of infected items there. Click on Save Report As....

[*]Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

[*]Please post this log in your next reply.

Post combofix log

java report

kaspersky report

Link to post
Share on other sites

ComboFix 09-04-04.01 - Stephen Conroy 2009-04-11 16:02:01.4 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1538 [GMT -4:00]

Running from: c:\documents and settings\Stephen Conroy\Desktop\Combo-Fix.exe

Command switches used :: c:\documents and settings\Stephen Conroy\Desktop\CFScript.txt

AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)

* Created a new restore point

FILE ::

c:\windows\system32\drivers\uhzzdvnk.sys

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Service_xrxyv

((((((((((((((((((((((((( Files Created from 2009-03-11 to 2009-04-11 )))))))))))))))))))))))))))))))

.

2009-04-05 22:25 . 2009-04-05 22:25 410,984 --a------ c:\windows\system32\deploytk.dll

2009-03-22 23:38 . 2009-03-22 23:38 <DIR> d-------- c:\program files\Trend Micro

2009-03-13 00:47 . 2009-03-13 00:47 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes

2009-03-13 00:34 . 2009-03-13 00:34 <DIR> d-------- c:\program files\Avira

2009-03-13 00:34 . 2009-03-13 00:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira

2009-03-12 23:05 . 2009-03-12 23:05 <DIR> d-------- c:\documents and settings\Stephen Conroy\Application Data\Malwarebytes

2009-03-12 21:59 . 2009-03-12 21:59 <DIR> d-------- c:\program files\FileASSASSIN

2009-03-12 21:54 . 2009-04-09 00:13 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware

2009-03-12 21:54 . 2009-03-12 21:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-03-12 21:54 . 2009-04-06 15:32 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-03-12 21:54 . 2009-04-06 15:32 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-03-11 00:56 . 2009-01-18 17:35 15,688 --a------ c:\windows\system32\lsdelete.exe

2009-03-11 00:45 . 2009-03-11 00:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft

2009-03-11 00:45 . 2009-03-11 00:45 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}

2009-03-11 00:45 . 2009-04-06 00:45 64,160 --a------ c:\windows\system32\drivers\Lbd.sys

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-04-11 14:20 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater

2009-04-10 22:15 --------- d--h--w c:\documents and settings\Patrick\Application Data\Move Networks

2009-04-10 14:39 --------- d-----w c:\program files\AOL 9.1

2009-04-06 02:25 --------- d-----w c:\program files\Java

2009-04-06 02:24 --------- d-----w c:\program files\Common Files\Adobe

2009-03-25 03:13 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint

2009-03-11 04:45 --------- d-----w c:\program files\Lavasoft

2009-02-21 14:25 --------- d-----w c:\documents and settings\Patrick\Application Data\Apple Computer

.

((((((((((((((((((((((((((((( SnapShot_2009-04-09_ 0.09.37.57 )))))))))))))))))))))))))))))))))))))))))

.

- 2009-04-09 01:24:16 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat

+ 2009-04-11 01:24:20 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat

- 2009-04-09 01:24:16 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

+ 2009-04-11 01:24:20 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

- 2009-04-09 04:01:07 223,912 ----a-w c:\windows\system32\inetsrv\MetaBase.bin

+ 2009-04-11 20:20:52 223,915 ----a-w c:\windows\system32\inetsrv\MetaBase.bin

- 2009-04-08 02:28:19 7,520 --sha-w c:\windows\system32\KGyGaAvL.sys

+ 2009-04-11 01:27:06 7,520 --sha-w c:\windows\system32\KGyGaAvL.sys

+ 2009-04-11 20:20:36 16,384 ----atw c:\windows\temp\Perflib_Perfdata_148.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]

"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 136600]

"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]

"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]

"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2007-08-30 205480]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2007-08-28 73728]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]

"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]

"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]

"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]

"HostManager"="c:\program files\Common Files\AOL\1197034437\ee\AOLSoftware.exe" [2008-06-24 41824]

"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-06 515416]

"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 c:\windows\stsystra.exe]

"MsmqIntCert"="mqrt.dll" [2007-07-06 c:\windows\system32\mqrt.dll]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-04-11 24576]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]

-ra------ 2006-10-23 08:50 71216 c:\program files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]

--a------ 2008-06-24 14:34 41824 c:\program files\Common Files\AOL\1197034437\EE\aolsoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]

--a------ 2008-03-30 10:36 267048 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]

--a------ 2005-09-08 20:20 8192 c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

--a------ 2007-06-25 23:49 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]

--a------ 2006-06-16 11:46 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=

"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\mIRC\\mirc.exe"=

"c:\\Program Files\\AIM\\aim.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\SopCast\\SopCast.exe"=

"c:\\Documents and Settings\\Stephen Conroy\\Application Data\\SopCast\\adv\\SopAdver.exe"=

"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=

"c:\\WINDOWS\\system32\\mqsvc.exe"=

"c:\\Program Files\\TVAnts\\Tvants.exe"=

"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=

"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=

"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=

"c:\\Program Files\\Common Files\\AOL\\1197034437\\EE\\aolsoftware.exe"=

"c:\\Program Files\\AOL 9.1\\waol.exe"=

"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=

"c:\\Program Files\\Common Files\\AOL\\1197034437\\ee\\aolservicehost.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\WINDOWS\\system32\\dplaysvr.exe"=

"c:\\Program Files\\EA SPORTS\\MVP Baseball 2005\\mvp2005.exe"=

"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=

"c:\\Program Files\\THQ\\Company of Heroes - Balance Playtest\\RelicCOH.exe"=

"c:\\Program Files\\THQ\\Company of Heroes - Balance Playtest\\RelicDownloader\\RelicDownloader.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"67:UDP"= 67:UDP:0.0.0.0/255.255.255.255:Enabled:DHCP Discovery Service

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-11 64160]

R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

\Shell\AutoRun\command - D:\Launch.exe

.

Contents of the 'Scheduled Tasks' folder

2009-04-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-04-06 00:45]

2009-04-05 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]

2009-04-11 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 00:07]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.live.com

mStart Page = hxxp://www.yahoo.com/

uInternet Settings,ProxyOverride = *.local

IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

Trusted Zone: musicmatch.com\online

FF - ProfilePath - c:\documents and settings\Stephen Conroy\Application Data\Mozilla\Firefox\Profiles\yrichvqd.default\

FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll

FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npmnqmp07030901.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll

FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll

.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-04-11 16:21:49

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2560306997-580925832-812904618-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]

"??"=hex:8f,b3,f3,87,0e,7a,e6,7b,42,6d,b7,10,64,57,30,16,70,ef,72,63,a4,9a,8d,

98,35,65,c9,8a,c9,8f,0f,ea,e7,d1,52,50,99,7d,9d,ae,c9,f9,d2,f2,c2,9c,cb,75,\

"??"=hex:0c,2b,0c,1b,89,60,a6,e2,ba,7b,8b,cd,62,81,bf,a6

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(632)

c:\windows\system32\Ati2evxx.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\ati2evxx.exe

c:\windows\system32\ati2evxx.exe

c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe

c:\windows\system32\msdtc.exe

c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe

c:\program files\Common Files\AOL\ACS\AOLacsd.exe

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\windows\ehome\ehrecvr.exe

c:\windows\ehome\ehSched.exe

c:\windows\system32\inetsrv\inetinfo.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\ehome\mcrdsvc.exe

c:\windows\system32\mqsvc.exe

c:\program files\Pure Networks\Network Magic\nmsrvc.exe

c:\windows\system32\mqtgsvc.exe

c:\windows\system32\wbem\unsecapp.exe

c:\windows\system32\dllhost.exe

c:\windows\ehome\ehmsas.exe

c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

c:\program files\Common Files\AOL\1197034437\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe

c:\windows\system32\wscntfy.exe

c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

.

**************************************************************************

.

Completion time: 2009-04-11 16:28:53 - machine was rebooted

ComboFix-quarantined-files.txt 2009-04-11 20:28:50

ComboFix2.txt 2009-04-09 04:10:28

ComboFix3.txt 2009-04-05 00:20:10

ComboFix4.txt 2009-04-04 22:23:33

Pre-Run: 5,054,513,152 bytes free

Post-Run: 5,178,810,368 bytes free

225 --- E O F --- 2009-04-05 07:03:05

JavaRa 1.13 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Sat Apr 11 16:36:17 2009

Found and removed: C:\Program Files\Java\j2re1.4.2_03

Found and removed: C:\Program Files\Java\jre1.6.0_02

Found and removed: Software\JavaSoft\Java2D\1.5.0_03

Found and removed: Software\JavaSoft\Java2D\1.5.0_06

Found and removed: Software\JavaSoft\Java2D\1.5.0_10

Found and removed: SOFTWARE\Classes\JavaPlugin.150_06

Found and removed: SOFTWARE\Classes\JavaPlugin.150_10

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\Classes\JavaPlugin.142_03

Found and removed: Software\Classes\JavaPlugin.160_01

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_02\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

------------------------------------

Finished reporting.

--------------------------------------------------------------------------------

KASPERSKY ONLINE SCANNER 7.0 REPORT

Saturday, April 11, 2009

Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)

Kaspersky Online Scanner version: 7.0.26.13

Program database last update: Saturday, April 11, 2009 22:07:24

Records in database: 2035235

--------------------------------------------------------------------------------

Scan settings:

Scan using the following database: extended

Scan archives: yes

Scan mail databases: yes

Scan area - My Computer:

C:\

D:\

E:\

Scan statistics:

Files scanned: 131987

Threat name: 3

Infected objects: 3

Suspicious objects: 0

Duration of the scan: 02:12:12

File name / Threat name / Threats count

C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1

C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\gaopdxfpykxxugnqmoeasrvqxruolmeoyngpxj.sys.vir Infected: Trojan.Win32.Tdss.ttk 1

C:\Qoobox\Quarantine\C\WINDOWS\system32\gaopdxddjnjaliugotixisvloempmtaiydcanw.dll.vir Infected: Trojan-Spy.Win32.Small.cbd 1

The selected area was scanned.

Link to post
Share on other sites

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 3:36:50 PM, on 4/12/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\WINDOWS\system32\inetsrv\inetinfo.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\mqsvc.exe

C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe

C:\WINDOWS\system32\mqtgsvc.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\ehome\ehtray.exe

C:\WINDOWS\stsystra.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\Program Files\Dell\Media Experience\DMXLauncher.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe

C:\Program Files\Common Files\AOL\1197034437\ee\AOLSoftware.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Digital Line Detect\DLG.exe

c:\program files\common files\aol\1197034437\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\Program Files\AIM\aim.exe

C:\Program Files\Common Files\AOL\1197034437\EE\aolsoftware.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll

O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll

O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"

O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe

O4 - HKLM\..\Run: [iSUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall

O4 - HKLM\..\Run: [startCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll

O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1197034437\ee\AOLSoftware.exe

O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKUS\S-1-5-21-2560306997-580925832-812904618-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Patrick')

O4 - HKUS\S-1-5-21-2560306997-580925832-812904618-1006\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Patrick')

O4 - HKUS\S-1-5-21-2560306997-580925832-812904618-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Patrick')

O4 - HKUS\S-1-5-21-2560306997-580925832-812904618-1006\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 (User 'Patrick')

O4 - HKUS\S-1-5-21-2560306997-580925832-812904618-1006\..\Run: [shutterflyStudio] C:\Program Files\Shutterfly\Studio\BIN\SFlyStudio.exe /trayonly (User 'Patrick')

O4 - HKUS\S-1-5-21-2560306997-580925832-812904618-1006\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler (User 'Patrick')

O4 - Startup: MaxTV.lnk = C:\Program Files\DMV\MaxTV\MaxTV.exe

O4 - Global Startup: Digital Line Detect.lnk = ?

O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html

O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab

O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BU..._2/axofupld.cab

O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab

O16 - DPF: {A959E4A5-0B3D-449E-9998-348705BD4092} (Desktop.Smdesk) - http://www.servicemagic.com/smod/smdesktop.CAB

O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe

O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe

--

End of file - 11000 bytes

Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.