Jump to content

MBAM - HiJackthis Blocked -


arismorse
 Share

Recommended Posts

I have tried installing Malwarebytes several different ways (changing the name of the install and .exe file). Nothing will work. I would really like to avoid a complete reformat as I had just finished that process a month ago.

I cannot run HJT so I found someone else having a similar problem and ran the diagnostic and here is what i have so far. Thanks to anyone/everyone in advance for their wisdom and assistance:

Starting up...

Log file is located at: C:\Documents and Settings\ASM\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...

Found mount point : C:\WINDOWS\addins\addins

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZA

P182.tmp\ZAP182.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZA

P217.tmp\ZAP217.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZA

P2C0.tmp\ZAP2C0.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZA

P3A7.tmp\ZAP3A7.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZA

P3C6.tmp\ZAP3C6.tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\assembly\temp\temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\assembly\tmp\tmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Config\Config

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d1\d1

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d2\d2

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d3\d3

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d4\d4

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d5\d5

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d6\d6

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d7\d7

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\CSC\d8\d8

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\chsime\applets\applets

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\CHTIME\Applets\Applets

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\imejp\applets\applets

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\imejp98\imejp98

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\imjp8_1\applets\applets

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\imkr6_1\applets\applets

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\imkr6_1\dicts\dicts

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\ime\shared\res\res

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\000021095100

90400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\000021095110

90400000000000F01FEC\12.0.4518\12.0.4518

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\000021096100

90400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\000021097110

90400000000000F01FEC\12.0.4518\12.0.4518

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\000021098100

90400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\000021099100

90400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109A100

90400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109B100

90400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109E600

90400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F2

31838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3

D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\java\classes\classes

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\java\trustlib\trustlib

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary

ASP.NET Files\Bind Logs\Bind Logs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporar

y ASP.NET Files\Temporary ASP.NET Files

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\msapps\msinfo\msinfo

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\batch\batch

Mount point destination : \Device\__max++>\^

Cannot access: C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe

[1] 2004-08-12 09:19:33 743936 C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe (

Microsoft Corporation)

[1] 2008-04-13 20:12:21 744448 C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe

()

[1] 2008-04-13 20:12:21 744448 C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe (Mic

rosoft Corporation)

Found mount point : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoi

nt

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKU

s

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\pchealth\helpctr\Temp\Temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Do

wnloaded

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SoftwareDistribution\EventCache\EventCache

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1025\1025

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1028\1028

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1031\1031

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1037\1037

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1041\1041

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1042\1042

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\1054\1054

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\2052\2052

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\3076\3076

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-790525478-1130077

14-1957994488-1003\S-1-5-21-790525478-113007714-1957994488-1003

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D

ata\Microsoft\Media Player\Media Player

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D

ata\Microsoft\SystemCertificates\My\Certificates\Certificates

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D

ata\Microsoft\SystemCertificates\My\CRLs\CRLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application D

ata\Microsoft\SystemCertificates\My\CTLs\CTLs

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Desktop\Deskt

op

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Favorites\Fav

orites

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Setting

s\Application Data\Microsoft\Internet Explorer\Recovery\Active\Active

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Setting

s\temp\temp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\My Documents\

My Documents

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHo

od

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\Pri

ntHood

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\config\systemprofile\Recent\Recent

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\dhcp\dhcp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\drivers\disdn\disdn

Mount point destination : \Device\__max++>\^

Cannot access: C:\WINDOWS\system32\eventlog.dll

[1] 2004-08-12 09:19:04 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (

Microsoft Corporation)

[1] 2008-04-13 20:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Mic

rosoft Corporation)

[1] 2008-04-13 20:11:53 62464 C:\WINDOWS\system32\eventlog.dll ()

[2] 2008-04-13 20:11:53 56320 C:\WINDOWS\system32\logevent.dll (Microsoft Corpor

ation)

Found mount point : C:\WINDOWS\system32\export\export

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\LogFiles\WUDF\WUDF

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\mui\dispspec\dispspec

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\oobe\sample\sample

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\ShellExt\ShellExt

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\wbem\mof\bad\bad

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\wbem\mof\good\good

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\wbem\snmp\snmp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\wins\wins

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\system32\xircom\xircom

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp

Mount point destination : \Device\__max++>\^

Found mount point : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18

e3b_8.0.50727.1433_x-ww_5cf844d2\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.507

27.1433_x-ww_5cf844d2

Mount point destination : \Device\__max++>\^

Finished! Press any key to exit...

Link to post
Share on other sites

Hi arismorse and Welcome to Malwarebytes!

------------------

Step 1:

------------------

We need to create a clean copy of the file we are going to replace.

Open notepad and copy/paste the text in the code box below into it.

@echo off
copy C:\WINDOWS\ServicePackFiles\i386\eventlog.dll c:\eventlog.dll
Exit

Click File > Save As... and in the dropdown box for Save as type select All Files

Then in the File name box type copy.bat and hit Save

This will create a batch file name copy.bat on your desktop.

Double click copy.bat to run it. You may see a black box appear, this is normal.

------------------

Step 2:

------------------

1. Please download The Avenger by Swandog46 to your Desktop.

  • Right click on the Avenger.zip folder and select "Extract All..."
  • Follow the prompts and extract the avenger folder to your desktop

2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to move:
c:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, open the avenger folder and start The Avenger program by clicking on its icon.

  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

[*]It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)

[*]On reboot, it will briefly open a black command window on your desktop, this is normal.

[*]After the restart, it creates a log file that should open with the results of Avenger

Link to post
Share on other sites

First off, Thank you perplexus for taking the time to help me.

Unfortunately my computer will not create the avenger log, and it will also not run malware bytes. I am only able to paste the win32diag.txt here:

Log file is located at: C:\Documents and Settings\ASM\Desktop\Win32kDiag.txt

Removing all found mount points.

Attempting to reset file permissions.

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...

Found mount point : C:\WINDOWS\addins\addins

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\addins\addins

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP182.tmp\ZAP182.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP182.tmp\ZAP182.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP217.tmp\ZAP217.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP217.tmp\ZAP217.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2C0.tmp\ZAP2C0.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP2C0.tmp\ZAP2C0.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3A7.tmp\ZAP3A7.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3A7.tmp\ZAP3A7.tmp

Found mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3C6.tmp\ZAP3C6.tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP3C6.tmp\ZAP3C6.tmp

Found mount point : C:\WINDOWS\assembly\temp\temp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\temp\temp

Found mount point : C:\WINDOWS\assembly\tmp\tmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\assembly\tmp\tmp

Found mount point : C:\WINDOWS\Config\Config

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Config\Config

Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Found mount point : C:\WINDOWS\CSC\d1\d1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d1\d1

Found mount point : C:\WINDOWS\CSC\d2\d2

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d2\d2

Found mount point : C:\WINDOWS\CSC\d3\d3

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d3\d3

Found mount point : C:\WINDOWS\CSC\d4\d4

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d4\d4

Found mount point : C:\WINDOWS\CSC\d5\d5

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d5\d5

Found mount point : C:\WINDOWS\CSC\d6\d6

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d6\d6

Found mount point : C:\WINDOWS\CSC\d7\d7

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d7\d7

Found mount point : C:\WINDOWS\CSC\d8\d8

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d8\d8

Found mount point : C:\WINDOWS\ime\chsime\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\chsime\applets\applets

Found mount point : C:\WINDOWS\ime\CHTIME\Applets\Applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\CHTIME\Applets\Applets

Found mount point : C:\WINDOWS\ime\imejp\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imejp\applets\applets

Found mount point : C:\WINDOWS\ime\imejp98\imejp98

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imejp98\imejp98

Found mount point : C:\WINDOWS\ime\imjp8_1\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imjp8_1\applets\applets

Found mount point : C:\WINDOWS\ime\imkr6_1\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imkr6_1\applets\applets

Found mount point : C:\WINDOWS\ime\imkr6_1\dicts\dicts

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imkr6_1\dicts\dicts

Found mount point : C:\WINDOWS\ime\shared\res\res

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\shared\res\res

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109510090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109510090400000000000F01FEC\12.0.6425\12.0.6425

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109511090400000000000F01FEC\12.0.4518\12.0.4518

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109511090400000000000F01FEC\12.0.4518\12.0.4518

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109610090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109610090400000000000F01FEC\12.0.6425\12.0.6425

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109711090400000000000F01FEC\12.0.4518\12.0.4518

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109711090400000000000F01FEC\12.0.4518\12.0.4518

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109810090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109810090400000000000F01FEC\12.0.6425\12.0.6425

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109910090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109910090400000000000F01FEC\12.0.6425\12.0.6425

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109A10090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109A10090400000000000F01FEC\12.0.6425\12.0.6425

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109B10090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109B10090400000000000F01FEC\12.0.6425\12.0.6425

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109E60090400000000000F01FEC\12.0.6425\12.0.6425

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\00002109E60090400000000000F01FEC\12.0.6425\12.0.6425

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729

Found mount point : C:\WINDOWS\java\classes\classes

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\java\classes\classes

Found mount point : C:\WINDOWS\java\trustlib\trustlib

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\java\trustlib\trustlib

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs

Found mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files

Found mount point : C:\WINDOWS\msapps\msinfo\msinfo

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\msapps\msinfo\msinfo

Found mount point : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES

Found mount point : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF

Found mount point : C:\WINDOWS\pchealth\helpctr\batch\batch

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\batch\batch

Cannot access: C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe

Attempting to restore permissions of : C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe

[1] 2004-08-12 09:19:33 743936 C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe (Microsoft Corporation)

[1] 2008-04-13 20:12:21 744448 C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe (Microsoft Corporation)

[1] 2008-04-13 20:12:21 744448 C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe (Microsoft Corporation)

Found mount point : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint

Found mount point : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles

Found mount point : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs

Found mount point : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS

Found mount point : C:\WINDOWS\pchealth\helpctr\Temp\Temp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\Temp\Temp

Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Found mount point : C:\WINDOWS\SoftwareDistribution\EventCache\EventCache

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\EventCache\EventCache

Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Found mount point : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel

Found mount point : C:\WINDOWS\system32\1025\1025

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1025\1025

Found mount point : C:\WINDOWS\system32\1028\1028

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1028\1028

Found mount point : C:\WINDOWS\system32\1031\1031

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1031\1031

Found mount point : C:\WINDOWS\system32\1037\1037

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1037\1037

Found mount point : C:\WINDOWS\system32\1041\1041

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1041\1041

Found mount point : C:\WINDOWS\system32\1042\1042

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1042\1042

Found mount point : C:\WINDOWS\system32\1054\1054

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1054\1054

Found mount point : C:\WINDOWS\system32\2052\2052

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\2052\2052

Found mount point : C:\WINDOWS\system32\3076\3076

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\3076\3076

Found mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi

Found mount point : C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE

Found mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-790525478-113007714-1957994488-1003\S-1-5-21-790525478-113007714-1957994488-1003

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-790525478-113007714-1957994488-1003\S-1-5-21-790525478-113007714-1957994488-1003

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs

Found mount point : C:\WINDOWS\system32\config\systemprofile\Desktop\Desktop

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Desktop\Desktop

Found mount point : C:\WINDOWS\system32\config\systemprofile\Favorites\Favorites

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Favorites\Favorites

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\Active

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\Active

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\temp\temp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\temp\temp

Found mount point : C:\WINDOWS\system32\config\systemprofile\My Documents\My Documents

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\My Documents\My Documents

Found mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood

Found mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood

Found mount point : C:\WINDOWS\system32\config\systemprofile\Recent\Recent

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Recent\Recent

Found mount point : C:\WINDOWS\system32\dhcp\dhcp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\dhcp\dhcp

Found mount point : C:\WINDOWS\system32\drivers\disdn\disdn

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\drivers\disdn\disdn

Cannot access: C:\WINDOWS\system32\dumprep.exe

Attempting to restore permissions of : C:\WINDOWS\system32\dumprep.exe

[1] 2004-08-12 09:18:56 10752 C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe (Microsoft Corporation)

[1] 2008-04-13 20:12:18 10752 C:\WINDOWS\ServicePackFiles\i386\dumprep.exe (Microsoft Corporation)

[1] 2008-04-13 20:12:18 10752 C:\WINDOWS\system32\dumprep.exe (Microsoft Corporation)

Cannot access: C:\WINDOWS\system32\eventlog.dll

Attempting to restore permissions of : C:\WINDOWS\system32\eventlog.dll

[1] 2004-08-12 09:19:04 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (Microsoft Corporation)

[1] 2008-04-13 20:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Microsoft Corporation)

[1] 2008-04-13 20:11:53 62464 C:\WINDOWS\system32\eventlog.dll ()

[2] 2008-04-13 20:11:53 56320 C:\WINDOWS\system32\logevent.dll (Microsoft Corporation)

Found mount point : C:\WINDOWS\system32\export\export

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\export\export

Found mount point : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT

Found mount point : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT

Found mount point : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT

Found mount point : C:\WINDOWS\system32\LogFiles\WUDF\WUDF

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\LogFiles\WUDF\WUDF

Found mount point : C:\WINDOWS\system32\mui\dispspec\dispspec

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\mui\dispspec\dispspec

Found mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup

Found mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust

Found mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw

Found mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg

Found mount point : C:\WINDOWS\system32\oobe\sample\sample

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\sample\sample

Found mount point : C:\WINDOWS\system32\ShellExt\ShellExt

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\ShellExt\ShellExt

Found mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS

Found mount point : C:\WINDOWS\system32\wbem\mof\bad\bad

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\wbem\mof\bad\bad

Found mount point : C:\WINDOWS\system32\wbem\mof\good\good

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\wbem\mof\good\good

Found mount point : C:\WINDOWS\system32\wbem\snmp\snmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\wbem\snmp\snmp

Found mount point : C:\WINDOWS\system32\wins\wins

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\wins\wins

Found mount point : C:\WINDOWS\system32\xircom\xircom

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\xircom\xircom

Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp

Found mount point : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2

Finished!

Link to post
Share on other sites

Can you verify that C:\eventlog.dll is present on your machine? What happened when you ran Avenger? Was there an error?

There is an eventlog.dll in c:\ directory

When I ran Avenger, it rebooted the machine relatively quickly but after after the reboot the machine locked up when I tried to double click the malware bytes install the computer completely locked up on me.

Thanks!

Link to post
Share on other sites

Hi arismorse,

What OS do you have? Let's try this with a couple more files :) Don't go on to step 3 if Step 2 fails. See if C:\avenger.txt exists and post it here.

------------------

Step 1:

------------------

We need to create a clean copy of the file we are going to replace.

Open notepad and copy/paste the text in the code box below into it.

@echo off
copy C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe c:\helpsvc.exe
copy C:\WINDOWS\ServicePackFiles\i386\eventlog.dll c:\eventlog.dll
copy C:\WINDOWS\ServicePackFiles\i386\dumprep.exe c:\dumprep.exe
Exit

Click File > Save As... and in the dropdown box for Save as type select All Files

Then in the File name box type copy.bat and hit Save

This will create a batch file name copy.bat on your desktop.

Double click copy.bat to run it. You may see a black box appear, this is normal.

------------------

Step 2:

------------------

1. You should already have Avenger on your desktop :)

2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to move:
c:\helpsvc.exe | C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe
c:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll
c:\dumprep.exe | C:\WINDOWS\system32\dumprep.exe

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, open the avenger folder and start The Avenger program by clicking on its icon.

  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

[*]It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)

[*]On reboot, it will briefly open a black command window on your desktop, this is normal.

[*]After the restart, it creates a log file that should open with the results of Avenger

Link to post
Share on other sites

Ok, let's try a slightly different Avenger script and see if that works:

2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Begin copying here:
Files to move:
c:\helpsvc.exe | C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe
c:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll
c:\dumprep.exe | C:\WINDOWS\system32\dumprep.exe

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, open the avenger folder and start The Avenger program by clicking on its icon.

  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

[*]It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)

[*]On reboot, it will briefly open a black command window on your desktop, this is normal.

[*]After the restart, it creates a log file that should open with the results of Avenger

Link to post
Share on other sites

That is correct. I had a suggestion from someone so let's try this.

Download Combofix from any of the links below and save it to your desktop. You must rename it to sVchost.exe before saving it.

Link 1

Link 2

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using FireFox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to Always ask me where to Save the files

    [*] During the download, rename it to sVchost.exe as follows:

    CF_download_FF.gif

    CF_download_rename.gif

    [*]It is important to rename it during the download and not after.

    [*]Please do not rename it to something other than what was indicated.

    [*]Make sure to do the following:

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause unpredictable results
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • Warning: ComboFix will disconnect your machine from the internet as soon as it starts.
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    [*]Double click on sVchost.exe & follow the prompts.

    [*]When finished, it will produce a report for you.

    [*]Please post the C:\ComboFix.txt log so we can continue cleaning the system.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

Link to post
Share on other sites

It's still going. I completely understand about being offline. If there is any way you can sneak a peek, I would be grateful, only because this is my office laptop (primary computer) and I would love to get it back online for tomorrow...two days of non productive work is killing me (especially in this economy!).

I really appreciate all of your help!

Here is the log file

ComboFix 09-08-31.04 - ASM 09/01/2009 14:50.2.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.764 [GMT -4:00]

Running from: c:\documents and settings\ASM\Desktop\ComboFix.exe

* Created a new restore point

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\All Users\Application Data\asunumy.lib

c:\documents and settings\All Users\Documents\difosy.com

c:\documents and settings\ASM\Application Data\ibyzeryty.com

c:\documents and settings\ASM\Application Data\lanihycox._sy

c:\documents and settings\ASM\Application Data\ugyzazenop._sy

c:\documents and settings\ASM\Cookies\avywyfonop._dl

c:\documents and settings\ASM\Cookies\ekifopa.inf

c:\documents and settings\ASM\Cookies\yvozoduma.scr

c:\documents and settings\ASM\Local Settings\Application Data\orym.sys

c:\documents and settings\ASM\Local Settings\Application Data\ovojir.scr

c:\documents and settings\ASM\Local Settings\Temporary Internet Files\esadol._sy

c:\documents and settings\ASM\Local Settings\Temporary Internet Files\gotag.bat

C:\fyblb.exe

C:\p2hhr.bat

c:\program files\Common Files\cibe.dll

c:\program files\Common Files\qorihomut.reg

c:\program files\Common Files\ukyf.exe

c:\program files\Common Files\uwoletuba.com

c:\windows\braviax.exe

c:\windows\ewaqubu.exe

c:\windows\gozopi.reg

c:\windows\hefavosymi._dl

c:\windows\Installer\178f45d.msp

c:\windows\oruwic.dl

c:\windows\pusybazuf.inf

c:\windows\run.log

c:\windows\system32\_scui.cpl

c:\windows\system32\~.exe

c:\windows\system32\braviax.exe

c:\windows\system32\cru629.dat

c:\windows\system32\Drivers\asmqm.sys

c:\windows\system32\Drivers\gkvygdk.sys

c:\windows\system32\Drivers\jtduswtl.sys

c:\windows\system32\Drivers\klltp.sys

c:\windows\system32\Drivers\poxnp.sys

c:\windows\system32\Drivers\rwplns.sys

c:\windows\system32\Drivers\sbzoqh.sys

c:\windows\system32\drivers\UACmxownloueb.sys

c:\windows\system32\Drivers\xzsoei.sys

c:\windows\system32\Drivers\zfrzsm.sys

c:\windows\system32\ejesygasix.pif

c:\windows\system32\fahihufo.dll

c:\windows\system32\ketoyibo.dll

c:\windows\system32\nufuhopa.dll

c:\windows\system32\UACckbaiihsfy.dat

c:\windows\system32\uacinit.dll

c:\windows\system32\UACldfgtexmlq.dll

c:\windows\system32\UACodgicrkdlu.dll

c:\windows\system32\UACwyrgknmqlv.dll

c:\windows\system32\UACxjuxcvrnmt.dll

c:\windows\system32\wisdstr.exe

c:\windows\system32\wscsvc32.exe

c:\windows\system32\yovimuti.dll

c:\windows\system32\zihimubi.dll

c:\windows\wuqev.ban

Infected copy of c:\windows\system32\eventlog.dll was found and disinfected

Restored copy from - c:\windows\system32\logevent.dll

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Service_UACd.sys

-------\Legacy_UACd.sys

-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}

-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}

((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))

.

2009-09-01 15:54 . 2009-09-01 15:54 31232 ----a-w- c:\windows\system32\wingenocx.dll

2009-09-01 14:24 . 2009-09-01 14:24 -------- d-----w- C:\newtool

2009-09-01 14:19 . 2008-04-14 00:12 10752 ----a-w- C:\dumprep.exe

2009-09-01 14:19 . 2008-04-14 00:12 744448 ----a-w- C:\helpsvc.exe

2009-09-01 12:00 . 2008-04-14 00:11 56320 ----a-w- C:\eventlog.dll

2009-08-31 20:22 . 2009-08-31 20:25 -------- d-----w- C:\Softexer

2009-08-31 17:44 . 2009-08-31 18:42 -------- d-----w- c:\program files\newtool

2009-08-31 14:56 . 2009-08-31 14:56 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure

2009-08-31 14:42 . 2009-08-31 14:56 -------- d-----w- c:\program files\RegCure

2009-08-31 12:24 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-08-31 12:24 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-08-31 12:21 . 2009-09-01 15:55 -------- d-----w- c:\program files\Protection System

2009-08-31 10:41 . 2009-08-31 10:41 3942048 ----a-w- C:\newtool.exe

2009-08-31 09:50 . 2009-08-31 09:50 10752 ----a-w- c:\windows\DCEBoot.exe

2009-08-31 05:53 . 2009-08-31 05:53 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE

2009-08-31 05:51 . 2009-08-31 16:12 -------- d-----w- C:\New Folder

2009-08-31 04:42 . 2009-08-31 04:42 705 ----a-w- C:\qbuf.exe

2009-08-31 04:42 . 2009-08-31 04:42 705 ----a-w- C:\enurmyv.exe

2009-08-31 04:42 . 2009-08-31 04:42 201932 ----a-w- C:\svfp.exe

2009-08-31 04:40 . 2009-08-31 04:40 17920 ----a-w- C:\osps.exe

2009-08-17 14:24 . 2009-08-17 14:24 570672 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlhttps10.dll

2009-08-17 14:24 . 2009-08-17 14:24 496944 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlrsa10.dll

2009-08-17 14:24 . 2009-08-17 14:24 296240 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlsock10.dll

2009-08-17 14:24 . 2009-08-17 14:24 263472 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlcrsa10.dll

2009-08-17 14:24 . 2009-08-17 14:24 787760 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dblgen10.dll

2009-08-17 14:24 . 2009-08-17 14:24 423216 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dbmlsync.exe

2009-08-17 14:24 . 2009-08-17 14:24 2151728 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\iAnywhere.Data.SQLAnywhere.dll

2009-08-17 14:24 . 2009-08-17 14:24 1152304 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dbtool10.dll

2009-08-17 14:24 . 2009-08-17 14:24 850736 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\dblgen11.dll

2009-08-17 14:24 . 2009-08-17 14:24 763184 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dblib10.dll

2009-08-17 14:24 . 2009-08-17 14:24 394544 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dbcon10.dll

2009-08-12 21:18 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll

2009-08-11 02:19 . 2009-08-11 02:19 0 ----a-w- c:\documents and settings\ASM\settings.dat

2009-08-10 19:41 . 2006-11-02 00:48 33664 ----a-w- c:\windows\system32\drivers\BCMWLNPF.SYS

2009-08-10 19:41 . 2006-11-02 00:48 86016 ----a-w- c:\windows\system32\preflib.dll

2009-08-10 19:41 . 2006-11-02 00:48 69632 ----a-w- c:\windows\system32\bcmwlpkt.dll

2009-08-10 19:41 . 2006-11-02 00:48 2129920 ----a-w- c:\windows\system32\WLBCGCBPRO731.DLL

2009-08-10 19:41 . 2006-11-02 00:48 757760 ----a-w- c:\windows\system32\bcm1xsup.dll

2009-08-10 19:41 . 2009-08-10 19:41 -------- d-----w- c:\program files\Dell

2009-08-10 19:41 . 2009-08-11 12:53 -------- d-----w- c:\documents and settings\ASM\Local Settings\Application Data\ApplicationHistory

2009-08-10 19:39 . 2009-08-10 19:39 -------- d-----w- c:\windows\system32\URTTEMP

2009-08-09 20:22 . 2009-08-09 20:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

2009-08-05 19:54 . 2009-08-05 19:54 -------- d-----w- c:\documents and settings\ASM\Local Settings\Application Data\Identities

2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll

2009-08-03 21:45 . 2009-08-03 21:45 -------- d-----w- c:\windows\system32\XPSViewer

2009-08-03 21:45 . 2009-08-03 21:45 -------- d-----w- c:\program files\MSBuild

2009-08-03 21:45 . 2009-08-03 21:45 -------- d-----w- c:\program files\Reference Assemblies

2009-08-03 21:44 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2009-08-03 21:44 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2009-08-03 21:44 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll

2009-08-03 21:44 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll

2009-08-03 21:44 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2009-08-03 21:44 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2009-08-03 21:44 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll

2009-08-03 21:44 . 2009-09-01 15:16 -------- d-----w- c:\windows\SxsCaPendDel

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-09-01 18:46 . 2004-08-12 13:19 56320 ----a-w- c:\windows\system32\eventlog.dll

2009-09-01 13:34 . 2009-06-12 03:59 2818 ----a-w- C:\ARIBACKUP.bat

2009-09-01 13:27 . 2009-06-12 14:19 3798 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\qbbackup.sys

2009-08-31 17:23 . 2009-06-11 22:04 19911 ----a-w- c:\windows\system32\nvModes.dat

2009-08-31 10:43 . 2009-08-31 10:43 16943 ----a-w- c:\program files\Common Files\azyx.lib

2009-08-31 10:38 . 2009-06-18 13:06 -------- d-----w- c:\program files\Family Tree Maker 2005

2009-08-23 20:25 . 2009-06-24 20:28 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet

2009-08-17 14:24 . 2009-06-12 14:02 976648 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManager.exe

2009-08-17 14:24 . 2009-06-12 14:02 195848 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManagerPatch.exe

2009-08-17 14:21 . 2009-06-12 14:01 869640 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\qbpatch.exe

2009-08-16 01:38 . 2009-06-12 01:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2009-08-13 12:37 . 2009-06-12 03:59 374 ----a-w- C:\Newresearcher.bat

2009-08-11 02:35 . 2009-06-12 19:40 -------- d-----w- c:\documents and settings\ASM\Application Data\SmartDraw

2009-08-05 15:59 . 2009-06-12 14:41 -------- d-----w- c:\documents and settings\ASM\Application Data\Apple Computer

2009-08-05 09:01 . 2004-08-12 13:23 204800 ----a-w- c:\windows\system32\mswebdvd.dll

2009-08-04 12:19 . 2009-06-11 22:21 180144 ----a-w- c:\documents and settings\ASM\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-08-03 21:32 . 2009-06-12 01:35 -------- d-----w- c:\program files\Microsoft Works

2009-07-31 19:24 . 2009-07-31 19:24 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Xerox

2009-07-30 21:08 . 2009-07-30 21:08 -------- d-----w- c:\documents and settings\LocalService\Application Data\Xerox

2009-07-26 02:46 . 2009-07-26 02:45 -------- d-----w- c:\program files\iTunes

2009-07-26 02:45 . 2009-07-26 02:45 -------- d-----w- c:\program files\iPod

2009-07-26 02:45 . 2009-06-12 14:39 -------- d-----w- c:\program files\Common Files\Apple

2009-07-26 02:36 . 2009-07-26 02:36 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe

2009-07-23 17:59 . 2009-07-23 17:59 -------- d-----w- c:\documents and settings\ASM\Application Data\LiveChatNow!

2009-07-23 17:58 . 2009-07-23 17:58 -------- d-----w- c:\program files\LiveChatNow! v4

2009-07-22 17:44 . 2009-07-22 17:44 726008 ----a-w- c:\documents and settings\ASM\gotomypc_438.exe

2009-07-17 19:01 . 2004-08-12 13:17 58880 ----a-w- c:\windows\system32\atl.dll

2009-07-14 22:10 . 2009-07-14 22:01 -------- d-----w- c:\program files\Timelog

2009-07-14 03:43 . 2004-08-12 13:34 286208 ----a-w- c:\windows\system32\wmpdxm.dll

2009-07-10 20:36 . 2009-06-18 12:43 -------- d-----w- c:\documents and settings\ASM\Application Data\mjusbsp

2009-07-08 15:54 . 2009-07-08 15:54 -------- d-----w- c:\documents and settings\ASM\Application Data\Malwarebytes

2009-07-08 15:54 . 2009-07-08 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-07-07 02:44 . 2009-07-16 20:39 937984 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe

2009-07-07 02:44 . 2009-07-16 20:39 65536 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\components\coolirisstub.dll

2009-07-07 02:44 . 2009-07-16 20:39 106496 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll

2009-07-07 02:44 . 2009-07-16 20:39 103424 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\libs\pixomatic.dll

2009-07-07 02:44 . 2009-07-16 20:39 4722688 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\libs\cooliris19.dll

2009-07-07 02:44 . 2009-07-16 20:39 344064 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe

2009-07-06 14:27 . 2009-07-06 04:13 -------- d-----w- c:\documents and settings\ASM\Application Data\DivX

2009-07-05 22:58 . 2009-07-05 22:58 -------- d-----w- c:\program files\DivX

2009-07-05 22:58 . 2009-07-05 22:58 -------- d-----w- c:\program files\Common Files\DivX Shared

2009-07-03 21:08 . 2009-07-03 21:08 726008 ----a-w- c:\documents and settings\ASM\gotomypc_437.exe

2009-07-03 17:09 . 2004-08-12 13:33 915456 ----a-w- c:\windows\system32\wininet.dll

2009-06-30 13:23 . 2009-06-30 13:23 167376 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\FlashGot.exe

2009-06-25 08:25 . 2004-08-12 13:32 54272 ----a-w- c:\windows\system32\wdigest.dll

2009-06-25 08:25 . 2004-08-12 13:28 56832 ----a-w- c:\windows\system32\secur32.dll

2009-06-25 08:25 . 2004-08-12 13:27 147456 ----a-w- c:\windows\system32\schannel.dll

2009-06-25 08:25 . 2004-08-12 13:23 136192 ----a-w- c:\windows\system32\msv1_0.dll

2009-06-25 08:25 . 2004-08-12 13:21 730112 ----a-w- c:\windows\system32\lsasrv.dll

2009-06-25 08:25 . 2004-08-12 13:20 301568 ----a-w- c:\windows\system32\kerberos.dll

2009-06-24 11:18 . 2004-08-12 13:20 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys

2009-06-22 16:02 . 2009-06-22 16:02 410984 ----a-w- c:\windows\system32\deploytk.dll

2009-06-22 15:30 . 2009-06-22 15:30 0 ----a-w- c:\windows\nsreg.dat

2009-06-19 21:28 . 2009-06-30 13:57 532480 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\{22119944-ED35-4ab1-910B-E619EA06A115}\components\rfproxy_31.dll

2009-06-16 14:36 . 2004-08-12 13:30 119808 ----a-w- c:\windows\system32\t2embed.dll

2009-06-16 14:36 . 2004-08-12 13:19 81920 ----a-w- c:\windows\system32\fontsub.dll

2009-06-12 16:26 . 2009-06-12 16:26 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe

2009-06-12 15:41 . 2009-06-12 15:41 1078 ----a-r- c:\documents and settings\ASM\Application Data\Microsoft\Installer\{EDEA8AB7-7683-4ED2-AA19-E6C078064C0D}\DocumentationShortcu_EDEA8AB776834ED2AA19E6C078064C0D.exe

2009-06-12 15:41 . 2009-06-12 15:41 10134 ----a-r- c:\documents and settings\ASM\Application Data\Microsoft\Installer\{EDEA8AB7-7683-4ED2-AA19-E6C078064C0D}\ARPPRODUCTICON.exe

2009-06-12 15:32 . 2009-06-12 15:32 10134 ----a-r- c:\documents and settings\ASM\Application Data\Microsoft\Installer\{93B6A615-555D-49FD-95DE-D8B7192F9A85}\ARPPRODUCTICON.exe

2009-06-12 15:09 . 2002-12-17 16:29 25898 ----a-w- c:\windows\system32\drivers\Dvd_2k.sys

2009-06-12 15:09 . 2002-12-17 16:29 30630 ----a-w- c:\windows\system32\drivers\Mmc_2k.sys

2009-06-12 15:09 . 2002-12-17 16:29 143834 ----a-w- c:\windows\system32\drivers\pwd_2K.sys

2009-06-12 15:09 . 2002-12-17 16:27 206464 ----a-w- c:\windows\system32\drivers\udfreadr_xp.sys

2009-06-12 15:09 . 2009-06-12 15:09 57344 ----a-w- c:\windows\uneng.exe

2009-06-12 14:02 . 2009-06-12 14:02 34056 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Interop.QBInstanceFinder.dll

2009-06-12 14:02 . 2009-06-12 14:02 192512 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\ICSharpCode.SharpZipLib.dll

2009-06-12 14:01 . 2009-06-12 14:01 499712 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\msvcp71.dll

2009-06-12 14:01 . 2009-06-12 14:01 348160 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\msvcr71.dll

2009-06-12 13:53 . 2009-06-12 13:53 127034 ------r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe

2009-06-12 12:31 . 2004-08-12 13:31 80896 ----a-w- c:\windows\system32\tlntsess.exe

2009-06-12 12:31 . 2004-08-12 13:30 76288 ----a-w- c:\windows\system32\telnet.exe

2009-06-12 00:54 . 2009-06-11 21:28 87263 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2009-06-11 21:25 . 2009-06-11 21:25 21640 ----a-w- c:\windows\system32\emptyregdb.dat

2009-06-11 16:28 . 2009-06-12 03:59 2475 ----a-w- C:\ARIBACKUP_AND_SHUTDOWN.bat

2009-06-10 14:13 . 2004-08-12 13:17 84992 ----a-w- c:\windows\system32\avifil32.dll

2009-06-10 13:19 . 2009-06-11 21:23 2066432 ----a-w- c:\windows\system32\mstscax.dll

2009-06-10 06:14 . 2004-08-12 13:33 132096 ----a-w- c:\windows\system32\wkssvc.dll

2009-06-05 15:42 . 2009-06-12 14:39 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys

2009-06-05 15:42 . 2009-06-12 14:39 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll

2009-06-05 12:44 . 2009-06-12 03:59 1288 ----a-w- C:\ARIHOMEBACKUP 1.bat

2009-06-03 19:09 . 2004-08-12 13:26 1291264 ----a-w- c:\windows\system32\quartz.dll

2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll

2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll

.

------- Sigcheck -------

[7] 2004-08-12 13:17 4224 DA1F27D85E0D1525F6621372E7B685E9 c:\windows\system32\dllcache\cache\beep.sys

c:\windows\system32\drivers\beep.sys ... is missing !!

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"cdloader"="c:\documents and settings\ASM\Application Data\mjusbsp\cdloader2.exe" [2009-04-10 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]

"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-10-26 921600]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Protection System

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XeroxRegistation

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=

"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=

"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\AltiGen\\AltiWare Administrator\\AltiWareAdmin.exe"=

"c:\\Program Files\\AltiGen\\JLIB15\\jre\\bin\\java.exe"=

"c:\\Program Files\\AltiGen\\JLIB15\\jre\\bin\\javaw.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Documents and Settings\\ASM\\Application Data\\mjusbsp\\magicJack.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2/6/2003 7:23 PM 59328]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

Contents of the 'Scheduled Tasks' folder

2009-08-30 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-09-01 c:\windows\Tasks\RegCure Program Check.job

- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-09-01 c:\windows\Tasks\RegCure Startup.job

- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-08-31 c:\windows\Tasks\RegCure.job

- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

.

- - - - ORPHANS REMOVED - - - -

BHO-{3cc166af-72ce-4e71-b242-05cfac10cae6} - c:\windows\system32\nufuhopa.dll

HKLM-Run-CPMf7ce910a - c:\windows\system32\zihimubi.dll

HKLM-Run-tewadigeja - c:\windows\system32\yovimuti.dll

.

------- Supplementary Scan -------

.

uStart Page = about:blank

mStart Page = about:blank

uInternet Settings,ProxyOverride = *.local

IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll

DPF: {46D8BEE7-0B27-4466-ABA2-A5F1E157971C} - hxxp://66.192.110.33:100/RemoteWeb.cab

DPF: {5FFDFC21-AE40-4C7C-955C-415A1ACE01C8} - hxxp://66.192.110.33:100/VideoViewer.ocx

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

DPF: {F91AB7B8-EE67-42AF-A5AA-8E232C396A04} - hxxps://www.amerinfor.com/cabs/htmlprint.cab

FF - ProfilePath - c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\

FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/|http://www.google.com//

FF - component: c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\{22119944-ED35-4ab1-910B-E619EA06A115}\components\rfproxy_31.dll

FF - component: c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\components\coolirisstub.dll

FF - plugin: c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-09-01 14:58

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(936)

c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(3444)

c:\windows\system32\WININET.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\WLTRYSVC.EXE

c:\windows\system32\BCMWLTRY.EXE

c:\windows\system32\scardsvr.exe

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

c:\windows\system32\nvsvc32.exe

c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2009-09-01 15:05 - machine was rebooted

ComboFix-quarantined-files.txt 2009-09-01 19:05

ComboFix2.txt 2009-08-11 03:24

Pre-Run: 19,981,459,456 bytes free

Post-Run: 19,982,897,152 bytes free

343 --- E O F --- 2009-08-26 03:57

Link to post
Share on other sites

Great job arismorse :)

Let's continue on...

------------------

Step 1:

------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

KillAll::

File::
c:\windows\system32\wingenocx.dll
C:\dumprep.exe
C:\helpsvc.exe
C:\eventlog.dll
C:\newtool.exe
c:\windows\DCEBoot.exe
C:\qbuf.exe
C:\enurmyv.exe
C:\svfp.exe
C:\osps.exe

Folder::
C:\newtool
C:\Softexer
c:\program files\newtool
C:\New Folder

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

------------------

Step 2:

------------------

Click on Start->Run, and copy-paste the following command into the "Open:" box, and click OK.

"%userprofile%\desktop\win32kdiag.exe" -f -r

When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.

------------------

Step 3:

------------------

Uninstall Malwarebytes if you have it installed and re-download it.

mbamicontw5.gif Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

------------------

Step 4:

------------------

Please post back with the following:

  • How your machine is running
  • C:\ComboFix.txt
  • Win32kDiag.txt
  • MBAM log

Link to post
Share on other sites

Okay, so here is what I have so far:

Combofix:

ComboFix 09-08-31.04 - ASM 09/01/2009 15:39.3.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.698 [GMT -4:00]

Running from: c:\documents and settings\ASM\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\ASM\Desktop\CFScript.txt

FILE ::

"C:\dumprep.exe"

"C:\enurmyv.exe"

"C:\eventlog.dll"

"C:\helpsvc.exe"

"C:\newtool.exe"

"C:\osps.exe"

"C:\qbuf.exe"

"C:\svfp.exe"

"c:\windows\DCEBoot.exe"

"c:\windows\system32\wingenocx.dll"

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\dumprep.exe

C:\enurmyv.exe

C:\eventlog.dll

C:\helpsvc.exe

C:\New Folder

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_04_37_57_755_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_04_38_09_492_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_05_14_57_186_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_05_38_09_037_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_05_48_01_930_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_05_49_58_097_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_05_50_36_883_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_05_50_57_623_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_09_25_23_557_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_10_29_36_127_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_10_30_48_501_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_10_32_38_830_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_10_32_41_023_035.DAT

c:\new folder\backup\TSC_GENCLEAN_2009_08_31_12_12_39_923_035.DAT

c:\new folder\CFAIL.LOG

c:\new folder\CLEAN.LOG

c:\new folder\debug\TSCDebug.log

c:\new folder\DETECT.LOG

c:\new folder\lpt$vpn.407

c:\new folder\lpt407.zip

c:\new folder\manifest.lst

c:\new folder\readme.txt

c:\new folder\REPORT.LOG

c:\new folder\report\20090831.log

c:\new folder\ssapi32.dll

c:\new folder\ssapiptn.da5

c:\new folder\sscan32.bin

c:\new folder\stinger1001624.exe

c:\new folder\stinger1001624.opt

c:\new folder\sysclean.com

c:\new folder\sysclean.exe

c:\new folder\sysclean.log

c:\new folder\tmcomm.sys

c:\new folder\TmEngDrv.dll

c:\new folder\tsc.bin

c:\new folder\tsc.ini

c:\new folder\tsc.ptn

c:\new folder\TSC_Temp\backup\DEADLINK_NOVIRUS_2009_08_31_06_37_20_085_035.DAT

c:\new folder\TSC_Temp\backup\DEADLINK_NOVIRUS_2009_08_31_11_18_11_710_035.DAT

c:\new folder\TSC_Temp\backup\DEADLINK_NOVIRUS_2009_08_31_13_20_43_254_035.DAT

c:\new folder\TSC_Temp\debug\TSCDebug.log

c:\new folder\TSC_Temp\report\20090831.log

c:\new folder\TSC_Temp\tsc.exe

c:\new folder\TSC_Temp\tsc.ini

c:\new folder\TSC_Temp\tsc.ptn

c:\new folder\vsapi32.dll

c:\new folder\vscantm.bin

c:\new folder\whatsnew.txt

C:\newtool

C:\newtool.exe

c:\newtool\changes.rtf

c:\newtool\Languages\albanian.lng

c:\newtool\Languages\arabic.lng

c:\newtool\Languages\bosnian.lng

c:\newtool\Languages\bulgarian.lng

c:\newtool\Languages\catalan.lng

c:\newtool\Languages\chineseSI.lng

c:\newtool\Languages\chineseTR.lng

c:\newtool\Languages\croatian.lng

c:\newtool\Languages\czech.lng

c:\newtool\Languages\danish.lng

c:\newtool\Languages\dutch.lng

c:\newtool\Languages\english.lng

c:\newtool\Languages\estonian.lng

c:\newtool\Languages\finnish.lng

c:\newtool\Languages\french.lng

c:\newtool\Languages\german.lng

c:\newtool\Languages\greek.lng

c:\newtool\Languages\hungarian.lng

c:\newtool\Languages\italian.lng

c:\newtool\Languages\korean.lng

c:\newtool\Languages\latvian.lng

c:\newtool\Languages\macedonian.lng

c:\newtool\Languages\norwegian.lng

c:\newtool\Languages\polish.lng

c:\newtool\Languages\portugueseBR.lng

c:\newtool\Languages\portuguesePT.lng

c:\newtool\Languages\romanian.lng

c:\newtool\Languages\russian.lng

c:\newtool\Languages\serbian.lng

c:\newtool\Languages\slovak.lng

c:\newtool\Languages\slovenian.lng

c:\newtool\Languages\spanish.lng

c:\newtool\Languages\swedish.lng

c:\newtool\Languages\turkish.lng

c:\newtool\Languages\ukrainian.lng

c:\newtool\license.txt

c:\newtool\mbam-dor.exe

c:\newtool\mbam.chm

c:\newtool\mbam.dll

c:\newtool\mbam.exe

c:\newtool\mbamext.dll

c:\newtool\mbamgui.exe

c:\newtool\mbamservice.exe

c:\newtool\ssubtmr6.dll

c:\newtool\unins000.dat

c:\newtool\unins000.exe

c:\newtool\unins000.msg

c:\newtool\vbalsgrid6.ocx

c:\newtool\zlib.dll

C:\osps.exe

c:\program files\newtool

c:\program files\newtool\changes.rtf

c:\program files\newtool\Languages\albanian.lng

c:\program files\newtool\Languages\arabic.lng

c:\program files\newtool\Languages\bosnian.lng

c:\program files\newtool\Languages\bulgarian.lng

c:\program files\newtool\Languages\catalan.lng

c:\program files\newtool\Languages\chineseSI.lng

c:\program files\newtool\Languages\chineseTR.lng

c:\program files\newtool\Languages\croatian.lng

c:\program files\newtool\Languages\czech.lng

c:\program files\newtool\Languages\danish.lng

c:\program files\newtool\Languages\dutch.lng

c:\program files\newtool\Languages\english.lng

c:\program files\newtool\Languages\estonian.lng

c:\program files\newtool\Languages\finnish.lng

c:\program files\newtool\Languages\french.lng

c:\program files\newtool\Languages\german.lng

c:\program files\newtool\Languages\greek.lng

c:\program files\newtool\Languages\hungarian.lng

c:\program files\newtool\Languages\italian.lng

c:\program files\newtool\Languages\korean.lng

c:\program files\newtool\Languages\latvian.lng

c:\program files\newtool\Languages\macedonian.lng

c:\program files\newtool\Languages\norwegian.lng

c:\program files\newtool\Languages\polish.lng

c:\program files\newtool\Languages\portugueseBR.lng

c:\program files\newtool\Languages\portuguesePT.lng

c:\program files\newtool\Languages\romanian.lng

c:\program files\newtool\Languages\russian.lng

c:\program files\newtool\Languages\serbian.lng

c:\program files\newtool\Languages\slovak.lng

c:\program files\newtool\Languages\slovenian.lng

c:\program files\newtool\Languages\spanish.lng

c:\program files\newtool\Languages\swedish.lng

c:\program files\newtool\Languages\turkish.lng

c:\program files\newtool\Languages\ukrainian.lng

c:\program files\newtool\license.txt

c:\program files\newtool\mbam-dor.exe

c:\program files\newtool\mbam.chm

c:\program files\newtool\mbam.dll

c:\program files\newtool\mbamext.dll

c:\program files\newtool\mbamgui.exe

c:\program files\newtool\mbamservice.exe

c:\program files\newtool\ssubtmr6.dll

c:\program files\newtool\unins000.dat

c:\program files\newtool\unins000.exe

c:\program files\newtool\unins000.msg

c:\program files\newtool\vbalsgrid6.ocx

c:\program files\newtool\xxx.exe

c:\program files\newtool\zlib.dll

C:\qbuf.exe

C:\Softexer

c:\softexer\0_days.htm

c:\softexer\1_days.htm

c:\softexer\15_days.htm

c:\softexer\2_days.htm

c:\softexer\30_days.htm

c:\softexer\5_days.htm

c:\softexer\autoupdate.dll

c:\softexer\database.db

c:\softexer\expired.htm

c:\softexer\greenforgo.exe

c:\softexer\Images\10x10.gif

c:\softexer\Images\10x10tile.gif

c:\softexer\Images\back.bmp

c:\softexer\Images\bottompanel.gif

c:\softexer\Images\BottomRemine.bmp

c:\softexer\Images\Button_BACK_D.bmp

c:\softexer\Images\Button_BACK_N.bmp

c:\softexer\Images\Button_BACK_O.bmp

c:\softexer\Images\Button_Small_D.bmp

c:\softexer\Images\Button_Small_N.bmp

c:\softexer\Images\Button_Small_O.bmp

c:\softexer\Images\buttonfill.jpg

c:\softexer\Images\buttonfill_mo.jpg

c:\softexer\Images\buttonfilldown.jpg

c:\softexer\Images\contentwrapper.gif

c:\softexer\Images\flash.bmp

c:\softexer\Images\footerbar.gif

c:\softexer\Images\info_bubble.jpg

c:\softexer\Images\main_bt_focus.bmp

c:\softexer\Images\main_bt_normal.bmp

c:\softexer\Images\main_bt_normal1.bmp

c:\softexer\Images\main_bt_selected.bmp

c:\softexer\Images\poweredby.bmp

c:\softexer\Images\startpageback.bmp

c:\softexer\Images\subtitlebar.gif

c:\softexer\Images\tile_titlebar.jpg

c:\softexer\Images\toppanel.gif

c:\softexer\Images\width.bmp

c:\softexer\LogSettings.xml

c:\softexer\main.css

c:\softexer\resources.dll

c:\softexer\settings.xml

c:\softexer\trial.htm

c:\softexer\uninstall.exe

c:\softexer\welcome.htm

c:\softexer\Xoftspy.ico

c:\softexer\zlibwapi.dll

C:\svfp.exe

c:\windows\DCEBoot.exe

c:\windows\system32\wingenocx.dll

.

((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))

.

2009-08-31 14:56 . 2009-08-31 14:56 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure

2009-08-31 14:42 . 2009-08-31 14:56 -------- d-----w- c:\program files\RegCure

2009-08-31 12:24 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-08-31 12:24 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-08-31 12:21 . 2009-09-01 15:55 -------- d-----w- c:\program files\Protection System

2009-08-31 05:53 . 2009-08-31 05:53 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE

2009-08-17 14:24 . 2009-08-17 14:24 570672 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlhttps10.dll

2009-08-17 14:24 . 2009-08-17 14:24 496944 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlrsa10.dll

2009-08-17 14:24 . 2009-08-17 14:24 296240 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlsock10.dll

2009-08-17 14:24 . 2009-08-17 14:24 263472 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\mlcrsa10.dll

2009-08-17 14:24 . 2009-08-17 14:24 787760 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dblgen10.dll

2009-08-17 14:24 . 2009-08-17 14:24 423216 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dbmlsync.exe

2009-08-17 14:24 . 2009-08-17 14:24 2151728 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\iAnywhere.Data.SQLAnywhere.dll

2009-08-17 14:24 . 2009-08-17 14:24 1152304 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dbtool10.dll

2009-08-17 14:24 . 2009-08-17 14:24 850736 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\dblgen11.dll

2009-08-17 14:24 . 2009-08-17 14:24 763184 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dblib10.dll

2009-08-17 14:24 . 2009-08-17 14:24 394544 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Sybase10\dbcon10.dll

2009-08-12 21:18 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll

2009-08-11 02:19 . 2009-08-11 02:19 0 ----a-w- c:\documents and settings\ASM\settings.dat

2009-08-10 19:41 . 2006-11-02 00:48 33664 ----a-w- c:\windows\system32\drivers\BCMWLNPF.SYS

2009-08-10 19:41 . 2006-11-02 00:48 86016 ----a-w- c:\windows\system32\preflib.dll

2009-08-10 19:41 . 2006-11-02 00:48 69632 ----a-w- c:\windows\system32\bcmwlpkt.dll

2009-08-10 19:41 . 2006-11-02 00:48 2129920 ----a-w- c:\windows\system32\WLBCGCBPRO731.DLL

2009-08-10 19:41 . 2006-11-02 00:48 757760 ----a-w- c:\windows\system32\bcm1xsup.dll

2009-08-10 19:41 . 2009-08-10 19:41 -------- d-----w- c:\program files\Dell

2009-08-10 19:41 . 2009-08-11 12:53 -------- d-----w- c:\documents and settings\ASM\Local Settings\Application Data\ApplicationHistory

2009-08-10 19:39 . 2009-08-10 19:39 -------- d-----w- c:\windows\system32\URTTEMP

2009-08-09 20:22 . 2009-08-09 20:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

2009-08-05 19:54 . 2009-08-05 19:54 -------- d-----w- c:\documents and settings\ASM\Local Settings\Application Data\Identities

2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll

2009-08-03 21:45 . 2009-08-03 21:45 -------- d-----w- c:\windows\system32\XPSViewer

2009-08-03 21:45 . 2009-08-03 21:45 -------- d-----w- c:\program files\MSBuild

2009-08-03 21:45 . 2009-08-03 21:45 -------- d-----w- c:\program files\Reference Assemblies

2009-08-03 21:44 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll

2009-08-03 21:44 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll

2009-08-03 21:44 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll

2009-08-03 21:44 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll

2009-08-03 21:44 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe

2009-08-03 21:44 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll

2009-08-03 21:44 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll

2009-08-03 21:44 . 2009-09-01 15:16 -------- d-----w- c:\windows\SxsCaPendDel

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-09-01 18:46 . 2004-08-12 13:19 56320 ------w- c:\windows\system32\eventlog.dll

2009-09-01 13:34 . 2009-06-12 03:59 2818 ----a-w- C:\ARIBACKUP.bat

2009-09-01 13:27 . 2009-06-12 14:19 3798 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\qbbackup.sys

2009-08-31 17:23 . 2009-06-11 22:04 19911 ----a-w- c:\windows\system32\nvModes.dat

2009-08-31 10:43 . 2009-08-31 10:43 16943 ----a-w- c:\program files\Common Files\azyx.lib

2009-08-31 10:38 . 2009-06-18 13:06 -------- d-----w- c:\program files\Family Tree Maker 2005

2009-08-23 20:25 . 2009-06-24 20:28 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet

2009-08-17 14:24 . 2009-06-12 14:02 976648 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManager.exe

2009-08-17 14:24 . 2009-06-12 14:02 195848 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\IntuitSyncManagerPatch.exe

2009-08-17 14:21 . 2009-06-12 14:01 869640 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\qbpatch.exe

2009-08-16 01:38 . 2009-06-12 01:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2009-08-13 12:37 . 2009-06-12 03:59 374 ----a-w- C:\Newresearcher.bat

2009-08-11 02:35 . 2009-06-12 19:40 -------- d-----w- c:\documents and settings\ASM\Application Data\SmartDraw

2009-08-05 15:59 . 2009-06-12 14:41 -------- d-----w- c:\documents and settings\ASM\Application Data\Apple Computer

2009-08-05 09:01 . 2004-08-12 13:23 204800 ----a-w- c:\windows\system32\mswebdvd.dll

2009-08-04 12:19 . 2009-06-11 22:21 180144 ----a-w- c:\documents and settings\ASM\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-08-03 21:32 . 2009-06-12 01:35 -------- d-----w- c:\program files\Microsoft Works

2009-07-31 19:24 . 2009-07-31 19:24 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Xerox

2009-07-30 21:08 . 2009-07-30 21:08 -------- d-----w- c:\documents and settings\LocalService\Application Data\Xerox

2009-07-26 02:46 . 2009-07-26 02:45 -------- d-----w- c:\program files\iTunes

2009-07-26 02:45 . 2009-07-26 02:45 -------- d-----w- c:\program files\iPod

2009-07-26 02:45 . 2009-06-12 14:39 -------- d-----w- c:\program files\Common Files\Apple

2009-07-26 02:36 . 2009-07-26 02:36 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe

2009-07-23 17:59 . 2009-07-23 17:59 -------- d-----w- c:\documents and settings\ASM\Application Data\LiveChatNow!

2009-07-23 17:58 . 2009-07-23 17:58 -------- d-----w- c:\program files\LiveChatNow! v4

2009-07-22 17:44 . 2009-07-22 17:44 726008 ----a-w- c:\documents and settings\ASM\gotomypc_438.exe

2009-07-17 19:01 . 2004-08-12 13:17 58880 ----a-w- c:\windows\system32\atl.dll

2009-07-14 22:10 . 2009-07-14 22:01 -------- d-----w- c:\program files\Timelog

2009-07-14 03:43 . 2004-08-12 13:34 286208 ----a-w- c:\windows\system32\wmpdxm.dll

2009-07-10 20:36 . 2009-06-18 12:43 -------- d-----w- c:\documents and settings\ASM\Application Data\mjusbsp

2009-07-08 15:54 . 2009-07-08 15:54 -------- d-----w- c:\documents and settings\ASM\Application Data\Malwarebytes

2009-07-08 15:54 . 2009-07-08 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-07-07 02:44 . 2009-07-16 20:39 937984 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe

2009-07-07 02:44 . 2009-07-16 20:39 65536 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\components\coolirisstub.dll

2009-07-07 02:44 . 2009-07-16 20:39 106496 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll

2009-07-07 02:44 . 2009-07-16 20:39 103424 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\libs\pixomatic.dll

2009-07-07 02:44 . 2009-07-16 20:39 4722688 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\libs\cooliris19.dll

2009-07-07 02:44 . 2009-07-16 20:39 344064 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe

2009-07-06 14:27 . 2009-07-06 04:13 -------- d-----w- c:\documents and settings\ASM\Application Data\DivX

2009-07-05 22:58 . 2009-07-05 22:58 -------- d-----w- c:\program files\DivX

2009-07-05 22:58 . 2009-07-05 22:58 -------- d-----w- c:\program files\Common Files\DivX Shared

2009-07-03 21:08 . 2009-07-03 21:08 726008 ----a-w- c:\documents and settings\ASM\gotomypc_437.exe

2009-07-03 17:09 . 2004-08-12 13:33 915456 ------w- c:\windows\system32\wininet.dll

2009-06-30 13:23 . 2009-06-30 13:23 167376 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\FlashGot.exe

2009-06-25 08:25 . 2004-08-12 13:32 54272 ----a-w- c:\windows\system32\wdigest.dll

2009-06-25 08:25 . 2004-08-12 13:28 56832 ----a-w- c:\windows\system32\secur32.dll

2009-06-25 08:25 . 2004-08-12 13:27 147456 ----a-w- c:\windows\system32\schannel.dll

2009-06-25 08:25 . 2004-08-12 13:23 136192 ----a-w- c:\windows\system32\msv1_0.dll

2009-06-25 08:25 . 2004-08-12 13:21 730112 ----a-w- c:\windows\system32\lsasrv.dll

2009-06-25 08:25 . 2004-08-12 13:20 301568 ----a-w- c:\windows\system32\kerberos.dll

2009-06-24 11:18 . 2004-08-12 13:20 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys

2009-06-22 16:02 . 2009-06-22 16:02 410984 ----a-w- c:\windows\system32\deploytk.dll

2009-06-22 15:30 . 2009-06-22 15:30 0 ----a-w- c:\windows\nsreg.dat

2009-06-19 21:28 . 2009-06-30 13:57 532480 ----a-w- c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\{22119944-ED35-4ab1-910B-E619EA06A115}\components\rfproxy_31.dll

2009-06-16 14:36 . 2004-08-12 13:30 119808 ----a-w- c:\windows\system32\t2embed.dll

2009-06-16 14:36 . 2004-08-12 13:19 81920 ----a-w- c:\windows\system32\fontsub.dll

2009-06-12 16:26 . 2009-06-12 16:26 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe

2009-06-12 15:41 . 2009-06-12 15:41 1078 ----a-r- c:\documents and settings\ASM\Application Data\Microsoft\Installer\{EDEA8AB7-7683-4ED2-AA19-E6C078064C0D}\DocumentationShortcu_EDEA8AB776834ED2AA19E6C078064C0D.exe

2009-06-12 15:41 . 2009-06-12 15:41 10134 ----a-r- c:\documents and settings\ASM\Application Data\Microsoft\Installer\{EDEA8AB7-7683-4ED2-AA19-E6C078064C0D}\ARPPRODUCTICON.exe

2009-06-12 15:32 . 2009-06-12 15:32 10134 ----a-r- c:\documents and settings\ASM\Application Data\Microsoft\Installer\{93B6A615-555D-49FD-95DE-D8B7192F9A85}\ARPPRODUCTICON.exe

2009-06-12 15:09 . 2002-12-17 16:29 25898 ----a-w- c:\windows\system32\drivers\Dvd_2k.sys

2009-06-12 15:09 . 2002-12-17 16:29 30630 ----a-w- c:\windows\system32\drivers\Mmc_2k.sys

2009-06-12 15:09 . 2002-12-17 16:29 143834 ----a-w- c:\windows\system32\drivers\pwd_2K.sys

2009-06-12 15:09 . 2002-12-17 16:27 206464 ----a-w- c:\windows\system32\drivers\udfreadr_xp.sys

2009-06-12 15:09 . 2009-06-12 15:09 57344 ----a-w- c:\windows\uneng.exe

2009-06-12 14:02 . 2009-06-12 14:02 34056 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\Interop.QBInstanceFinder.dll

2009-06-12 14:02 . 2009-06-12 14:02 192512 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\SyncMgr\OCD\ICSharpCode.SharpZipLib.dll

2009-06-12 14:01 . 2009-06-12 14:01 499712 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\msvcp71.dll

2009-06-12 14:01 . 2009-06-12 14:01 348160 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\msvcr71.dll

2009-06-12 13:53 . 2009-06-12 13:53 127034 ------r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe

2009-06-12 12:31 . 2004-08-12 13:31 80896 ----a-w- c:\windows\system32\tlntsess.exe

2009-06-12 12:31 . 2004-08-12 13:30 76288 ----a-w- c:\windows\system32\telnet.exe

2009-06-12 00:54 . 2009-06-11 21:28 87263 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2009-06-11 21:25 . 2009-06-11 21:25 21640 ----a-w- c:\windows\system32\emptyregdb.dat

2009-06-11 16:28 . 2009-06-12 03:59 2475 ----a-w- C:\ARIBACKUP_AND_SHUTDOWN.bat

2009-06-10 14:13 . 2004-08-12 13:17 84992 ----a-w- c:\windows\system32\avifil32.dll

2009-06-10 13:19 . 2009-06-11 21:23 2066432 ----a-w- c:\windows\system32\mstscax.dll

2009-06-10 06:14 . 2004-08-12 13:33 132096 ----a-w- c:\windows\system32\wkssvc.dll

2009-06-05 15:42 . 2009-06-12 14:39 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys

2009-06-05 15:42 . 2009-06-12 14:39 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll

2009-06-05 12:44 . 2009-06-12 03:59 1288 ----a-w- C:\ARIHOMEBACKUP 1.bat

2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll

2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll

.

------- Sigcheck -------

[7] 2004-08-12 13:17 4224 DA1F27D85E0D1525F6621372E7B685E9 c:\windows\system32\dllcache\cache\beep.sys

c:\windows\system32\drivers\beep.sys ... is missing !!

.

((((((((((((((((((((((((((((( SnapShot@2009-09-01_18.58.50 )))))))))))))))))))))))))))))))))))))))))

.

+ 2004-08-12 13:26 . 2009-09-01 19:02 72248 c:\windows\system32\perfc009.dat

- 2004-08-12 13:26 . 2009-09-01 18:53 72248 c:\windows\system32\perfc009.dat

+ 2004-08-12 13:26 . 2009-09-01 19:02 444156 c:\windows\system32\perfh009.dat

- 2004-08-12 13:26 . 2009-09-01 18:53 444156 c:\windows\system32\perfh009.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"cdloader"="c:\documents and settings\ASM\Application Data\mjusbsp\cdloader2.exe" [2009-04-10 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]

"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-10-26 921600]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=

"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=

"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\AltiGen\\AltiWare Administrator\\AltiWareAdmin.exe"=

"c:\\Program Files\\AltiGen\\JLIB15\\jre\\bin\\java.exe"=

"c:\\Program Files\\AltiGen\\JLIB15\\jre\\bin\\javaw.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Documents and Settings\\ASM\\Application Data\\mjusbsp\\magicJack.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2/6/2003 7:23 PM 59328]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

Contents of the 'Scheduled Tasks' folder

2009-08-30 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-09-01 c:\windows\Tasks\RegCure Program Check.job

- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-09-01 c:\windows\Tasks\RegCure Startup.job

- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-08-31 c:\windows\Tasks\RegCure.job

- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

.

.

------- Supplementary Scan -------

.

uStart Page = about:blank

mStart Page = about:blank

uInternet Settings,ProxyOverride = *.local

IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html

IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html

IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html

Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll

DPF: {46D8BEE7-0B27-4466-ABA2-A5F1E157971C} - hxxp://66.192.110.33:100/RemoteWeb.cab

DPF: {5FFDFC21-AE40-4C7C-955C-415A1ACE01C8} - hxxp://66.192.110.33:100/VideoViewer.ocx

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

DPF: {F91AB7B8-EE67-42AF-A5AA-8E232C396A04} - hxxps://www.amerinfor.com/cabs/htmlprint.cab

FF - ProfilePath - c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\

FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/|http://www.google.com//

FF - component: c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\{22119944-ED35-4ab1-910B-E619EA06A115}\components\rfproxy_31.dll

FF - component: c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\components\coolirisstub.dll

FF - plugin: c:\documents and settings\ASM\Application Data\Mozilla\Firefox\Profiles\p59kb9b4.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-09-01 15:44

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(932)

c:\windows\System32\BCMLogon.dll

- - - - - - - > 'explorer.exe'(3304)

c:\windows\system32\WININET.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\WLTRYSVC.EXE

c:\windows\system32\BCMWLTRY.EXE

c:\windows\system32\scardsvr.exe

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

c:\windows\system32\nvsvc32.exe

c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2009-09-01 15:51 - machine was rebooted

ComboFix-quarantined-files.txt 2009-09-01 19:50

ComboFix2.txt 2009-09-01 19:05

ComboFix3.txt 2009-08-11 03:24

Pre-Run: 19,998,285,824 bytes free

Post-Run: 19,925,123,072 bytes free

486 --- E O F --- 2009-08-26 03:57

Win32kdiag:

I messed up the log on this....I then went to redo it and the log was very short with nothing in it. Sorry about this error

Malwarebytes (Thankfully we got this working):

Malwarebytes' Anti-Malware 1.40

Database version: 2727

Windows 5.1.2600 Service Pack 3

9/1/2009 4:06:33 PM

mbam-log-2009-09-01 (16-06-33).txt

Scan type: Quick Scan

Objects scanned: 89962

Time elapsed: 4 minute(s), 18 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 1

Registry Keys Infected: 2

Registry Values Infected: 2

Registry Data Items Infected: 0

Folders Infected: 2

Files Infected: 10

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

C:\Program Files\Protection System\coreext.dll (Rogue.ProtectionSystem) -> Delete on reboot.

Registry Keys Infected:

HKEY_CLASSES_ROOT\CLSID\{5e2121ee-0300-11d4-8d3b-444553540000} (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\protection system (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5e2121ee-0300-11d4-8d3b-444553540000} (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

C:\Program Files\Protection System (Rogue.ProtectionSystem) -> Delete on reboot.

C:\Documents and Settings\All Users\Start Menu\Programs\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

Files Infected:

C:\Program Files\Protection System\blacklist.cga (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

C:\Program Files\Protection System\core.cga (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

C:\Program Files\Protection System\coreext.dll (Rogue.ProtectionSystem) -> Delete on reboot.

C:\Program Files\Protection System\firewall.dll (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

C:\Program Files\Protection System\help.ico (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

C:\Program Files\Protection System\psystem.exe (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

C:\Program Files\Protection System\uninstall.exe (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users\Start Menu\Programs\Protection System\Protection System Support.lnk (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users\Start Menu\Programs\Protection System\Protection System.lnk (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

C:\Documents and Settings\All Users\Start Menu\Programs\Protection System\Uninstall Protection System.lnk (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

Link to post
Share on other sites

Great! How is your pc running?

I'd like to do another scan to see if we have anything left.

------------------

Step 1:

------------------

Please download JavaRa to your desktop and unzip it to its own folder

  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

------------------

Step 2:

------------------

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:

  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.

3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.

Please be patient as this can take quite a long time to download.

  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:

    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases

    [*]Click on My Computer under the green Scan bar to the left to start the scan.

    [*]Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [*]Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

    [*]Click View report... at the bottom.

    [*] Click the Save report... button.

    KasReport.png

    [*] Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply

------------------

Step 3:

------------------

Please post back with the following:

  • How your machine is running
  • KasReport.txt

Link to post
Share on other sites

Good Morning and Thank you for logging in yesterday evening! I can't tell you how much I appreciate it.

The computer is running much smoother -no pop ups, not irritating virus warnings and no icons with pornography on my desktop.

Here is the kapersky log:

--------------------------------------------------------------------------------

KASPERSKY ONLINE SCANNER 7.0: scan report

Wednesday, September 2, 2009

Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)

Kaspersky Online Scanner version: 7.0.26.13

Last database update: Wednesday, September 02, 2009 02:21:04

Records in database: 2738720

--------------------------------------------------------------------------------

Scan settings:

scan using the following database: extended

Scan archives: yes

Scan e-mail databases: yes

Scan area - My Computer:

C:\

D:\

Scan statistics:

Objects scanned: 139996

Threats found: 6

Infected objects found: 9

Suspicious objects found: 0

Scan duration: 04:12:27

File name / Threat / Threats count

C:\Documents and Settings\ASM\Desktop\Miscellaneous\astlog.exe Infected: not-a-virus:PSWTool.Win32.Asterisk.c 1

C:\Documents and Settings\ASM\Desktop\Miscellaneous\astlog.zip Infected: not-a-virus:PSWTool.Win32.Asterisk.c 1

C:\Qoobox\Quarantine\C\WINDOWS\system32\UACwyrgknmqlv.dll.vir Infected: Packed.Win32.TDSS.y 1

C:\Qoobox\Quarantine\C\WINDOWS\system32\UACxjuxcvrnmt.dll.vir Infected: Packed.Win32.TDSS.y 1

C:\Qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir Infected: Packed.Win32.Krap.x 1

C:\Qoobox\Quarantine\[4]-Submit_2009-09-01_15.39.05.zip Infected: Trojan.Win32.Agent2.chuf 1

C:\Qoobox\Quarantine\[4]-Submit_2009-09-01_15.39.05.zip Infected: Backdoor.Win32.NewRest.an 1

C:\Qoobox\Quarantine\[4]-Submit_2009-09-01_15.39.05.zip Infected: Trojan.Win32.Tdss.ajeo 1

C:\System Volume Information\_restore{228887C1-8B0B-44D2-9AEA-7A71DF59C725}\RP1\A0000047.exe Infected: Packed.Win32.Krap.x 1

Selected area has been scanned.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.