Jump to content

Google Search Redirect


Recommended Posts

Hi,

When clicking on a link from a search result in Google I am taken to different unknow sites. For example, here is what I got when clicking on a search result for Malwarebytes......http://thecancerconspiracy.com/search.php. If I go back to the search page again it will give me another/different unknow site.

I ran Malwarebytes in Safe mode and it came up clean...in regular mode it gets stuck on desktop.ini.

Superantispyware scan also was clean as wA Spybot and Eset online scan. Kaspersky online scanner gets stuck. I downloaded the free version of it and a quick scan came up clean.

Any help would be greatly appreciated. Thanks.

Link to post
Share on other sites

My daughters laptop on the wireless network seems to also be affected?! Read on the net that sometimes the router needs to be reset/purged with this type of virus?!?!?

Here are my logs, and thanks a million!!

Logfile of random's system information tool 1.06 (written by random/random)

Run by Beatrice at 2009-10-12 10:08:11

Microsoft Windows XP Professional Service Pack 2

System drive C: has 599 MB (2%) free of 35 GB

Total RAM: 512 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:09:00 AM, on 10/12/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\WgaTray.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe

C:\Program Files\Dell Photo AIO Printer 926\memcard.exe

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Google\ggviewer81-53.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\dlcxcoms.exe

C:\Program Files\Eraser\eraser.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtblfs.exe

C:\Documents and Settings\Beatrice\My Documents\1 A Brad\Google Search Virus\RSIT.exe

C:\Program Files\trend micro\Beatrice.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home

O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Save - Flash - Player - {58112A01-1F24-4EFE-A6B2-297DC7CDFEF2} - C:\PROGRA~1\ycysoft\SAVEFL~1\IEFLAS~1.DLL (file missing)

O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s

O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"

O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"

O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16

O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"

O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide

O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201

O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204

O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203

O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll

O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll

O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe

O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab

O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/...can8/oscan8.cab

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab

O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: dlcx_device - - C:\WINDOWS\system32\dlcxcoms.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe

--

End of file - 8753 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

C:\WINDOWS\tasks\ParetoLogic Registration.job

C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]

Octh Class - C:\Program Files\Orbitdownloader\orbitcth.dll [2008-10-14 130248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]

AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]

IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll [2009-07-03 68112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]

SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2009-09-24 321312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]

Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-10 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]

Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll [2009-10-06 762864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]

Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-09-10 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-24 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]

FilterBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll [2009-10-07 264720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-09-24 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

{58112A01-1F24-4EFE-A6B2-297DC7CDFEF2} - Save - Flash - Player - C:\PROGRA~1\ycysoft\SAVEFL~1\IEFLAS~1.DLL []

{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - C:\Program Files\Orbitdownloader\GrabPro.dll [2008-10-14 437368]

{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-09-10 256112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]

"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-11-02 32768]

"FaxCenterServer"=C:\Program Files\Dell PC Fax\fm3032.exe [2006-06-15 307200]

"dlcxmon.exe"=C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe [2006-06-14 286720]

"MemoryCardManager"=C:\Program Files\Dell Photo AIO Printer 926\memcard.exe [2006-06-27 299008]

"ISUSPM Startup"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe -startup []

"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-06-10 81920]

"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-06-25 185896]

"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]

"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]

"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]

"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-09-24 149280]

"DLCXCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16 []

"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe [2009-07-03 303376]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]

"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2004-07-26 1867776]

"Aim6"= []

"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-09-04 39408]

"Eraser"=C:\Program Files\Eraser\eraser.exe [2003-07-25 536576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]

C:\Program Files\Eraser\eraser.exe [2003-07-25 536576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]

C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-04-06 356352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]

C:\WINDOWS\system32\klogon.dll [2009-07-03 219664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]

C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]

UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-04 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]

"SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

"dontdisplaylastusername"=0

"legalnoticecaption"=

"legalnoticetext"=

"shutdownwithoutlogon"=1

"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

"NoDriveAutoRun"=

"NoDriveTypeAutoRun"=

"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"

"C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVpnClient.exe"="C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVpnClient.exe:*:Enabled:SonicWALL Global VPN Client"

"C:\Program Files\SmartFTP\SmartFTP.exe"="C:\Program Files\SmartFTP\SmartFTP.exe:*:Enabled:SmartFTP"

"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"

"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"

"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"

"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"

"C:\Program Files\Common Files\AOL\1140457287\ee\aolsoftware.exe"="C:\Program Files\Common Files\AOL\1140457287\ee\aolsoftware.exe:*:Enabled:AOL Services"

"C:\Program Files\Common Files\AOL\1140457287\ee\aim6.exe"="C:\Program Files\Common Files\AOL\1140457287\ee\aim6.exe:*:Enabled:AIM"

"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"

"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"

"C:\Program Files\TVU Player\TVUPlayer.exe"="C:\Program Files\TVU Player\TVUPlayer.exe:*:Enabled:TVUPlayer"

"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"

"C:\WINDOWS\system32\dlcxcoms.exe"="C:\WINDOWS\system32\dlcxcoms.exe:*:Enabled:Lexmark Communications System"

"C:\Program Files\CoreFTP\coreftp.exe"="C:\Program Files\CoreFTP\coreftp.exe:*:Enabled:Core FTP App"

"C:\Program Files\Orbitdownloader\orbitdm.exe"="C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"

"C:\Program Files\Orbitdownloader\orbitnet.exe"="C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"

"C:\Program Files\Pando Networks\Pando\pando.exe"="C:\Program Files\Pando Networks\Pando\pando.exe:*:Enabled:Pando Application"

"C:\Program Files\eJamming\eJammingAUDiiO\eJammingAUDiiO.exe"="C:\Program Files\eJamming\eJammingAUDiiO\eJammingAUDiiO.exe:*:Enabled:eJammingAUDiiO"

"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"

"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"

"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"

"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:

Link to post
Share on other sites

Step 1

I have attached a file to this message called AvengerScript.txt which you should save on your desktop. After saving AvengerScript.txt, please download The Avenger from the following link:

Use The Avenger to open the AvengerScript text file that you saved on your desktop, and then click the 'Execute' button in The Avenger. It will restart your computer, and use the information in AvengerScript.txt to clean up your computer a bit.

Please refer to the following screenshot for the location of the 'Open' button:

avenger_open_script.png

After running The Avenger, please attach the log to a reply so that I know if it did it's job right.

Step 2

Update Malwarebytes' Anti-Malware and run a scan with Windows booted normally. You may need to add the following files to the exclusions list in your anti-virus:

  • C:\WINDOWS\system32\drivers\mbam.sys

  • C:\WINDOWS\system32\drivers\mbamswissarmy.sys

  • C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

  • C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

  • C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

Please remove anything that Malwarebytes' Anti-Malware finds, and attach the log to a reply.

Step 3

Reset your router just in case. Make sure that you write down all of the settings in your router that you will need to replace after it has been reset. If you do not know how to do this, then give me the make and model of the router and I will try to put together some instructions.

Also note that another common form of infection is for malware to spread using Windows File Sharing (even if it isn't set up). This allows one infected computer on your network to infect every other computer on your network. If you do not share files over a Windows network, then you may want to check and see if your router has a setting called "AP Isolation" which should prevent the computers connected to the router from seeing each other, and thus prevent malware from spreading in that fashion.

Step 4

Download RootRepeal from the link below, and extract it onto your desktop:

Run RootRepeal, click the 'Scan' button in the lower-left corner, and when it's done click the "Save Report" button in the lower-right corner. Attach that report to a reply.

Link to post
Share on other sites

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)

Mon Oct 12 15:44:13 2009

15:44:13: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

//////////////////////////////////////////

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)

Mon Oct 12 15:44:39 2009

15:44:39: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

//////////////////////////////////////////

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)

Mon Oct 12 15:46:12 2009

15:46:12: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

//////////////////////////////////////////

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.

Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

No rootkits found!

Driver "MEMSWEEP2" deleted successfully.

Error: file "C:\WINDOWS\system32\7D7.tmp" not found!

Deletion of file "C:\WINDOWS\system32\7D7.tmp" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Completed script processing.

*******************

Finished! Terminate.

Link to post
Share on other sites

ComboFix 09-10-13.01 - Beatrice 10/13/2009 23:39.1.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.512.284 [GMT -4:00]

Running from: c:\documents and settings\Beatrice\Desktop\ComboFix.exe

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}

FW: Kaspersky Anti-Hacker *disabled* {0BB8CA15-F396-46C7-9A59-108D852CFEC0}

.

ADS - netcfgx.dll: deleted 68 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\program files\AskSearch\bin\DefaultSearch.dll

c:\windows\desktop

c:\windows\Downloaded Program Files\bdcore.dll

c:\windows\Downloaded Program Files\libfn.dll

c:\windows\Readme.txt

c:\windows\system32\open.ico

Infected copy of c:\windows\system32\drivers\ultra.sys was found and disinfected

Restored copy from - Kitty ate it :^)

.

((((((((((((((((((((((((( Files Created from 2009-09-14 to 2009-10-14 )))))))))))))))))))))))))))))))

.

2009-10-12 14:08 . 2009-10-12 14:09 -------- d-----w- c:\program files\trend micro

2009-10-12 14:08 . 2009-10-12 14:09 -------- d-----w- C:\rsit

2009-10-12 04:17 . 2009-10-12 04:49 -------- d-----w- c:\program files\Common Files\ParetoLogic

2009-10-12 04:17 . 2009-10-12 04:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic

2009-10-12 04:16 . 2009-10-12 04:16 -------- d-----w- c:\documents and settings\Beatrice\Local Settings\Application Data\Downloaded Installations

2009-10-11 02:52 . 2009-10-11 02:52 -------- d-----w- c:\program files\Sophos

2009-10-08 00:40 . 2009-10-08 00:40 -------- d-----w- c:\program files\SpywareBlaster

2009-10-07 11:51 . 2009-10-07 11:51 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat

2009-10-07 11:50 . 2009-10-07 11:55 95259 ----a-w- c:\windows\system32\drivers\klick.dat

2009-10-07 11:50 . 2009-10-07 11:55 107547 ----a-w- c:\windows\system32\drivers\klin.dat

2009-10-07 11:48 . 2009-10-14 04:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab

2009-10-07 11:08 . 2009-10-07 11:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

2009-10-06 19:25 . 2009-10-06 19:25 -------- d-----w- c:\program files\ESET

2009-10-06 15:56 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-10-06 15:56 . 2009-10-06 15:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-10-06 15:56 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-10-06 05:32 . 2009-10-06 05:32 -------- d-----w- c:\documents and settings\Bumblebea\Application Data\Malwarebytes

2009-09-29 21:27 . 2009-09-29 21:27 -------- d-----w- c:\documents and settings\Michy\Application Data\AdobeUM

2009-09-29 21:25 . 2009-09-29 21:27 -------- d-----w- c:\documents and settings\Michy\Local Settings\Application Data\Adobe

2009-09-29 21:18 . 2009-09-29 21:18 -------- d-----w- c:\documents and settings\Michy\Local Settings\Application Data\WMTools Downloaded Files

2009-09-29 21:18 . 2009-09-29 21:18 -------- d-----w- c:\documents and settings\Michy\Application Data\Malwarebytes

2009-09-29 16:13 . 2009-09-29 16:25 -------- d-----w- c:\program files\VideoSpirit Pro

2009-09-26 19:32 . 2009-09-26 19:32 286720 ----a-w- c:\windows\iun505.exe

2009-09-26 19:32 . 2009-09-26 19:32 -------- d-----w- c:\program files\PC Drummer Trial Edition

2009-09-25 17:00 . 2009-09-25 17:00 -------- d-----w- c:\program files\HammerHead

2009-09-25 03:10 . 2009-09-25 03:10 -------- d-----w- c:\documents and settings\Beatrice\Application Data\Malwarebytes

2009-09-25 03:10 . 2009-09-25 03:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-09-25 03:06 . 2009-09-25 03:05 411368 ----a-w- c:\windows\system32\deploytk.dll

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-10-14 04:15 . 2007-04-15 19:31 -------- d-----w- c:\program files\dl_cats

2009-10-14 03:26 . 2009-05-26 01:41 -------- d-----w- c:\program files\Eraser

2009-10-11 14:24 . 2005-03-30 15:04 -------- d-----w- c:\program files\hjt

2009-10-07 11:48 . 2005-09-06 13:36 -------- d-----w- c:\program files\Kaspersky Lab

2009-10-07 01:15 . 2005-08-21 17:30 1744 ----a-w- c:\windows\system32\d3d9caps.dat

2009-10-06 22:57 . 2006-06-28 20:27 -------- d-----w- c:\program files\TVU Player

2009-10-06 05:20 . 2008-12-09 15:21 -------- d-----w- c:\program files\SUPERAntiSpyware

2009-09-30 00:59 . 2008-05-19 17:34 -------- d-----w- c:\documents and settings\Beatrice\Application Data\Orbit

2009-09-29 21:27 . 2009-02-20 15:33 -------- d-----w- c:\documents and settings\Michy\Application Data\Orbit

2009-09-29 02:17 . 2005-03-19 19:45 33872 ----a-w- c:\documents and settings\Beatrice\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-09-25 12:48 . 2008-12-09 03:06 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)

2009-09-25 04:06 . 2005-03-20 17:48 -------- d-----w- c:\program files\Java

2009-09-24 02:18 . 2008-05-02 23:10 -------- d-----w- c:\program files\The Learning Company

2009-09-20 13:20 . 2009-08-19 01:07 -------- d-----w- c:\documents and settings\Beatrice\Application Data\uTorrent

2009-09-09 04:26 . 2009-09-09 03:05 -------- d-----w- c:\documents and settings\Beatrice\Application Data\ICAClient

2009-09-09 03:05 . 2009-09-09 03:05 -------- d-----w- c:\program files\Citrix

2009-09-05 22:17 . 2007-05-07 12:48 -------- d-----w- c:\documents and settings\Beatrice\Application Data\CoreFTP

2009-09-02 13:01 . 2009-09-02 13:01 86016 ----a-w- c:\windows\system32\DirShowEXDD.dll

2009-08-19 01:07 . 2009-08-19 01:07 -------- d-----w- c:\program files\AskSearch

2009-08-06 23:24 . 2004-08-03 19:02 327896 ----a-w- c:\windows\system32\wucltui.dll

2009-08-06 23:24 . 2004-08-03 18:59 209632 ----a-w- c:\windows\system32\wuweb.dll

2009-08-06 23:24 . 2005-08-05 17:40 44768 ----a-w- c:\windows\system32\wups2.dll

2009-08-06 23:24 . 2004-08-03 18:59 35552 ----a-w- c:\windows\system32\wups.dll

2009-08-06 23:24 . 2005-03-19 17:15 53472 ----a-w- c:\windows\system32\wuauclt.exe

2009-08-06 23:24 . 2001-08-23 15:00 96480 ----a-w- c:\windows\system32\cdm.dll

2009-08-06 23:23 . 2004-08-03 19:00 575704 ----a-w- c:\windows\system32\wuapi.dll

2009-08-06 23:23 . 2005-03-19 17:15 1929952 ----a-w- c:\windows\system32\wuaueng.dll

2009-08-05 09:11 . 2001-08-23 15:00 204800 ------w- c:\windows\system32\mswebdvd.dll

2009-07-17 18:55 . 2001-08-23 15:00 58880 ----a-w- c:\windows\system32\atl.dll

2005-08-15 16:21 . 2005-08-15 16:21 13500200 ----a-w- c:\program files\kav5.0trial_personalen.exe

2008-12-19 17:52 . 2006-02-12 15:11 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll

2008-12-19 17:52 . 2006-02-12 15:11 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll

2008-12-19 17:52 . 2007-08-10 13:02 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll

2008-12-19 17:52 . 2007-08-10 13:02 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll

2008-12-19 17:52 . 2006-02-12 15:11 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll

2008-08-16 21:42 . 2008-08-16 21:42 13112 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll

2008-08-16 21:42 . 2008-08-16 21:42 70456 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll

2008-08-16 21:42 . 2008-08-16 21:42 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll

2008-08-16 21:42 . 2008-08-16 21:42 20800 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll

2008-08-16 21:43 . 2008-08-16 21:43 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll

2008-08-16 21:42 . 2008-08-16 21:42 31032 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll

2008-08-16 21:42 . 2008-08-16 21:42 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll

2008-05-21 12:41 . 2008-05-21 12:41 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll

2008-05-21 12:41 . 2008-05-21 12:41 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll

2008-05-21 12:41 . 2008-05-21 12:41 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll

2008-06-05 17:58 . 2008-06-05 17:58 648504 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll

2008-08-16 21:42 . 2008-08-16 21:42 23864 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll

2007-04-16 02:29 . 2007-04-16 00:52 56 --sh--r- c:\windows\system32\05A597BF8C.sys

2005-07-14 19:31 . 2006-05-24 17:37 27648 --sha-w- c:\windows\system32\AVSredirect.dll

2007-04-16 02:29 . 2007-04-16 00:52 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 1867776]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-05 39408]

"Eraser"="c:\program files\Eraser\eraser.exe" [2003-07-25 536576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]

"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-06-15 307200]

"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 286720]

"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 299008]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-26 185896]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-25 149280]

"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 106496]

"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-20 113664]

Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-04-06 16:25 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiHacker]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=

"c:\\Program Files\\SmartFTP\\SmartFTP.exe"=

"c:\\Program Files\\AIM\\aim.exe"=

"c:\\WINDOWS\\system32\\mmc.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Program Files\\TVU Player\\TVUPlayer.exe"=

"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"c:\\WINDOWS\\system32\\dlcxcoms.exe"=

"c:\\Program Files\\CoreFTP\\coreftp.exe"=

"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=

"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\AIM6\\aim6.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"57462:TCP"= 57462:TCP:Pando P2P TCP Listening Port

"57462:UDP"= 57462:UDP:Pando P2P UDP Listening Port

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [12/15/2008 8:41 PM 33808]

R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2/12/2007 3:58 PM 10240]

R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [7/13/2005 11:31 AM 78032]

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [12/4/2008 2:50 PM 9968]

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 2:50 PM 55024]

R3 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/13/2009 5:46 PM 31760]

R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [5/16/2009 8:59 PM 19472]

R3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [7/13/2005 11:27 AM 23180]

R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);c:\windows\system32\drivers\adm8830.sys [3/19/2005 8:01 AM 747392]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/7/2009 10:21 PM 133104]

S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 2:50 PM 7408]

S3 scrcap;scrcap;c:\windows\system32\DRIVERS\scrcap.sys --> c:\windows\system32\DRIVERS\scrcap.sys [?]

S3 WipeFile;WipeFile;c:\windows\system32\drivers\WipeFile.sys [3/3/2007 7:20 PM 57472]

.

Contents of the 'Scheduled Tasks' folder

2009-10-08 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]

2009-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-08 02:21]

2009-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-08 02:21]

2009-10-14 c:\windows\Tasks\WGASetup.job

- c:\windows\system32\KB905474\wgasetup.exe [2009-05-12 02:18]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.optonline.net/Home

uSearch Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com/ie

mStart Page = hxxp://www.msn.com

mDefault_Search_URL = hxxp://www.google.com/ie

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

mSearchAssistant = hxxp://www.google.com/ie

IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201

IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204

IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203

IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

FF - ProfilePath - c:\documents and settings\Beatrice\Application Data\Mozilla\Firefox\Profiles\ob3clmij.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official

FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll

FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll

FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll

.

- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)

HKLM-Run-ISUSPM Startup - c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

AddRemove-Arthur's Birthday - c:\program files\Living Books\DeIsL1.isu

AddRemove-Convert XLS_is1 - c:\program files\Softinterface

AddRemove-Finale NotePad 2005a - c:\windows\unvise32.exe

AddRemove-RollerCoaster Tycoon Setup - c:\windows\UniFish3.exe

AddRemove-TVUPlayer - c:\program files\TVU Player\uninst.exe

AddRemove-uTorrent - c:\program files\uTorrent\uTorrent.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-10-14 00:13

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1856)

c:\program files\SUPERAntiSpyware\SASWINLO.DLL

- - - - - - - > 'explorer.exe'(3096)

c:\progra~1\Google\GGTASK~1.DLL

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\wdfmgr.exe

c:\windows\system32\MsPMSPSv.exe

c:\windows\system32\WgaTray.exe

c:\windows\system32\dlcxcoms.exe

c:\program files\Google\ggviewer81-53.exe

c:\program files\iPod\bin\iPodService.exe

.

**************************************************************************

.

Completion time: 2009-10-14 0:26 - machine was rebooted

ComboFix-quarantined-files.txt 2009-10-14 04:26

Pre-Run: 241,811,456 bytes free

Post-Run: 565,919,744 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

266 --- E O F --- 2009-09-10 03:54

Link to post
Share on other sites

I have attached a file to this message called CFScript.txt which will tell ComboFix how to remove some of the bad things I saw in your ComboFix log. Please save CFScript onto your desktop, and then download a fresh copy of ComboFix from the link below, and make sure to save it on your desktop as well. Once you have both CFScript and ComboFix saved to your desktop, hold down the left mouse button on top of the icon for CFScript, and drag it on top of the ComboFix icon, and then let go. This should start ComboFix again. Make sure, when it finishes, to attach the new log to a reply so that I can verify that it deleted what it was supposed to.

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

CFScript.txt

Link to post
Share on other sites

ComboFix 09-10-14.01 - Beatrice 10/14/2009 16:29.2.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.512.234 [GMT -4:00]

Running from: c:\documents and settings\Beatrice\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\Beatrice\Desktop\CFScript.txt

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}

FW: Kaspersky Anti-Hacker *disabled* {0BB8CA15-F396-46C7-9A59-108D852CFEC0}

.

((((((((((((((((((((((((( Files Created from 2009-09-14 to 2009-10-14 )))))))))))))))))))))))))))))))

.

2009-10-12 14:08 . 2009-10-12 14:09 -------- d-----w- c:\program files\trend micro

2009-10-12 14:08 . 2009-10-12 14:09 -------- d-----w- C:\rsit

2009-10-12 04:17 . 2009-10-12 04:49 -------- d-----w- c:\program files\Common Files\ParetoLogic

2009-10-12 04:17 . 2009-10-12 04:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic

2009-10-12 04:16 . 2009-10-12 04:16 -------- d-----w- c:\documents and settings\Beatrice\Local Settings\Application Data\Downloaded Installations

2009-10-11 02:52 . 2009-10-11 02:52 -------- d-----w- c:\program files\Sophos

2009-10-08 00:40 . 2009-10-08 00:40 -------- d-----w- c:\program files\SpywareBlaster

2009-10-07 11:51 . 2009-10-07 11:51 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat

2009-10-07 11:50 . 2009-10-14 13:15 108059 ----a-w- c:\windows\system32\drivers\klin.dat

2009-10-07 11:50 . 2009-10-14 13:15 95259 ----a-w- c:\windows\system32\drivers\klick.dat

2009-10-07 11:48 . 2009-10-14 20:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab

2009-10-07 11:08 . 2009-10-07 11:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

2009-10-06 19:25 . 2009-10-06 19:25 -------- d-----w- c:\program files\ESET

2009-10-06 15:56 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-10-06 15:56 . 2009-10-06 15:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-10-06 15:56 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-10-06 05:32 . 2009-10-06 05:32 -------- d-----w- c:\documents and settings\Bumblebea\Application Data\Malwarebytes

2009-09-29 21:27 . 2009-09-29 21:27 -------- d-----w- c:\documents and settings\Michy\Application Data\AdobeUM

2009-09-29 21:25 . 2009-09-29 21:27 -------- d-----w- c:\documents and settings\Michy\Local Settings\Application Data\Adobe

2009-09-29 21:18 . 2009-09-29 21:18 -------- d-----w- c:\documents and settings\Michy\Local Settings\Application Data\WMTools Downloaded Files

2009-09-29 21:18 . 2009-09-29 21:18 -------- d-----w- c:\documents and settings\Michy\Application Data\Malwarebytes

2009-09-29 16:13 . 2009-09-29 16:25 -------- d-----w- c:\program files\VideoSpirit Pro

2009-09-26 19:32 . 2009-09-26 19:32 286720 ----a-w- c:\windows\iun505.exe

2009-09-26 19:32 . 2009-09-26 19:32 -------- d-----w- c:\program files\PC Drummer Trial Edition

2009-09-25 17:00 . 2009-09-25 17:00 -------- d-----w- c:\program files\HammerHead

2009-09-25 03:10 . 2009-09-25 03:10 -------- d-----w- c:\documents and settings\Beatrice\Application Data\Malwarebytes

2009-09-25 03:10 . 2009-09-25 03:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-09-25 03:06 . 2009-09-25 03:05 411368 ----a-w- c:\windows\system32\deploytk.dll

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-10-14 20:51 . 2007-04-15 19:31 -------- d-----w- c:\program files\dl_cats

2009-10-14 05:02 . 2009-05-26 01:41 -------- d-----w- c:\program files\Eraser

2009-10-11 14:24 . 2005-03-30 15:04 -------- d-----w- c:\program files\hjt

2009-10-07 11:48 . 2005-09-06 13:36 -------- d-----w- c:\program files\Kaspersky Lab

2009-10-07 01:15 . 2005-08-21 17:30 1744 ----a-w- c:\windows\system32\d3d9caps.dat

2009-10-06 22:57 . 2006-06-28 20:27 -------- d-----w- c:\program files\TVU Player

2009-10-06 05:20 . 2008-12-09 15:21 -------- d-----w- c:\program files\SUPERAntiSpyware

2009-09-30 00:59 . 2008-05-19 17:34 -------- d-----w- c:\documents and settings\Beatrice\Application Data\Orbit

2009-09-29 21:27 . 2009-02-20 15:33 -------- d-----w- c:\documents and settings\Michy\Application Data\Orbit

2009-09-29 02:17 . 2005-03-19 19:45 33872 ----a-w- c:\documents and settings\Beatrice\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-09-25 12:48 . 2008-12-09 03:06 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)

2009-09-25 05:56 . 2004-01-08 20:23 662016 ----a-w- c:\windows\system32\wininet.dll

2009-09-25 05:56 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll

2009-09-25 04:06 . 2005-03-20 17:48 -------- d-----w- c:\program files\Java

2009-09-24 02:18 . 2008-05-02 23:10 -------- d-----w- c:\program files\The Learning Company

2009-09-20 13:20 . 2009-08-19 01:07 -------- d-----w- c:\documents and settings\Beatrice\Application Data\uTorrent

2009-09-11 14:33 . 2001-08-23 15:00 133632 ----a-w- c:\windows\system32\msv1_0.dll

2009-09-09 04:26 . 2009-09-09 03:05 -------- d-----w- c:\documents and settings\Beatrice\Application Data\ICAClient

2009-09-09 03:05 . 2009-09-09 03:05 -------- d-----w- c:\program files\Citrix

2009-09-05 22:17 . 2007-05-07 12:48 -------- d-----w- c:\documents and settings\Beatrice\Application Data\CoreFTP

2009-09-04 20:45 . 2001-08-23 15:00 58880 ----a-w- c:\windows\system32\msasn1.dll

2009-09-02 13:01 . 2009-09-02 13:01 86016 ----a-w- c:\windows\system32\DirShowEXDD.dll

2009-08-26 08:16 . 2001-08-23 15:00 247326 ------w- c:\windows\system32\strmdll.dll

2009-08-19 01:07 . 2009-08-19 01:07 -------- d-----w- c:\program files\AskSearch

2009-08-06 23:24 . 2004-08-03 19:02 327896 ----a-w- c:\windows\system32\wucltui.dll

2009-08-06 23:24 . 2004-08-03 18:59 209632 ----a-w- c:\windows\system32\wuweb.dll

2009-08-06 23:24 . 2005-08-05 17:40 44768 ----a-w- c:\windows\system32\wups2.dll

2009-08-06 23:24 . 2004-08-03 18:59 35552 ----a-w- c:\windows\system32\wups.dll

2009-08-06 23:24 . 2005-03-19 17:15 53472 ------w- c:\windows\system32\wuauclt.exe

2009-08-06 23:24 . 2001-08-23 15:00 96480 ----a-w- c:\windows\system32\cdm.dll

2009-08-06 23:23 . 2004-08-03 19:00 575704 ----a-w- c:\windows\system32\wuapi.dll

2009-08-06 23:23 . 2005-03-19 17:15 1929952 ----a-w- c:\windows\system32\wuaueng.dll

2009-08-05 09:11 . 2001-08-23 15:00 204800 ------w- c:\windows\system32\mswebdvd.dll

2009-08-04 14:00 . 2001-08-23 15:00 2180352 ------w- c:\windows\system32\ntoskrnl.exe

2009-08-04 13:13 . 2001-08-17 13:48 2057728 ------w- c:\windows\system32\ntkrnlpa.exe

2009-07-17 18:55 . 2001-08-23 15:00 58880 ----a-w- c:\windows\system32\atl.dll

2009-07-17 16:27 . 2001-08-23 15:00 1435648 ------w- c:\windows\system32\query.dll

2005-08-15 16:21 . 2005-08-15 16:21 13500200 ----a-w- c:\program files\kav5.0trial_personalen.exe

2008-12-19 17:52 . 2006-02-12 15:11 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll

2008-12-19 17:52 . 2006-02-12 15:11 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll

2008-12-19 17:52 . 2007-08-10 13:02 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll

2008-12-19 17:52 . 2007-08-10 13:02 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll

2008-12-19 17:52 . 2006-02-12 15:11 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll

2008-08-16 21:42 . 2008-08-16 21:42 13112 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll

2008-08-16 21:42 . 2008-08-16 21:42 70456 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll

2008-08-16 21:42 . 2008-08-16 21:42 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll

2008-08-16 21:42 . 2008-08-16 21:42 20800 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll

2008-08-16 21:43 . 2008-08-16 21:43 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll

2008-08-16 21:42 . 2008-08-16 21:42 31032 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll

2008-08-16 21:42 . 2008-08-16 21:42 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll

2008-05-21 12:41 . 2008-05-21 12:41 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll

2008-05-21 12:41 . 2008-05-21 12:41 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll

2008-05-21 12:41 . 2008-05-21 12:41 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll

2008-06-05 17:58 . 2008-06-05 17:58 648504 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll

2008-08-16 21:42 . 2008-08-16 21:42 23864 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll

2007-04-16 02:29 . 2007-04-16 00:52 56 --sh--r- c:\windows\system32\05A597BF8C.sys

2005-07-14 19:31 . 2006-05-24 17:37 27648 --sha-w- c:\windows\system32\AVSredirect.dll

2007-04-16 02:29 . 2007-04-16 00:52 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys

.

((((((((((((((((((((((((((((( SnapShot@2009-10-14_04.15.36 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-10-14 20:49 . 2009-10-14 20:49 16384 c:\windows\temp\Perflib_Perfdata_1dc.dat

- 2007-01-13 23:14 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll

+ 2007-01-13 23:14 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll

+ 2003-08-15 18:31 . 2009-09-25 05:56 39424 c:\windows\system32\pngfilt.dll

- 2003-08-15 18:31 . 2009-06-26 16:18 39424 c:\windows\system32\pngfilt.dll

+ 2001-08-23 15:00 . 2009-09-25 05:56 16384 c:\windows\system32\jsproxy.dll

- 2001-08-23 15:00 . 2009-06-26 16:18 16384 c:\windows\system32\jsproxy.dll

- 2004-08-26 16:17 . 2009-06-26 16:18 96256 c:\windows\system32\inseng.dll

+ 2004-08-26 16:17 . 2009-09-25 05:56 96256 c:\windows\system32\inseng.dll

- 2004-08-04 07:56 . 2009-06-26 16:18 55808 c:\windows\system32\extmgr.dll

+ 2004-08-04 07:56 . 2009-09-25 05:56 55808 c:\windows\system32\extmgr.dll

- 2006-05-10 05:23 . 2009-06-26 16:18 39424 c:\windows\system32\dllcache\pngfilt.dll

+ 2006-05-10 05:23 . 2009-09-25 05:56 39424 c:\windows\system32\dllcache\pngfilt.dll

+ 2009-09-04 20:45 . 2009-09-04 20:45 58880 c:\windows\system32\dllcache\msasn1.dll

+ 2006-05-10 05:22 . 2009-09-25 05:56 16384 c:\windows\system32\dllcache\jsproxy.dll

- 2006-05-10 05:22 . 2009-06-26 16:18 16384 c:\windows\system32\dllcache\jsproxy.dll

- 2006-05-10 05:22 . 2009-06-26 16:18 96256 c:\windows\system32\dllcache\inseng.dll

+ 2006-05-10 05:22 . 2009-09-25 05:56 96256 c:\windows\system32\dllcache\inseng.dll

+ 2009-02-20 08:30 . 2009-09-25 05:56 81920 c:\windows\system32\dllcache\ieencode.dll

- 2009-02-20 08:30 . 2009-06-26 16:18 81920 c:\windows\system32\dllcache\ieencode.dll

+ 2006-05-09 11:00 . 2009-09-18 09:56 18432 c:\windows\system32\dllcache\iedw.exe

- 2006-05-09 11:00 . 2009-06-22 11:38 18432 c:\windows\system32\dllcache\iedw.exe

- 2006-05-10 05:22 . 2009-06-26 16:18 55808 c:\windows\system32\dllcache\extmgr.dll

+ 2006-05-10 05:22 . 2009-09-25 05:56 55808 c:\windows\system32\dllcache\extmgr.dll

+ 2005-05-17 00:25 . 2009-09-18 09:33 352768 c:\windows\system32\xpsp3res.dll

- 2005-05-17 00:25 . 2009-06-22 11:26 352768 c:\windows\system32\xpsp3res.dll

+ 2004-08-04 07:56 . 2009-04-10 05:01 530280 c:\windows\system32\wmspdmod.dll

+ 2004-09-23 21:07 . 2009-09-25 05:56 624640 c:\windows\system32\urlmon.dll

+ 2004-08-20 21:41 . 2009-09-25 05:56 473600 c:\windows\system32\shlwapi.dll

+ 2001-08-23 15:00 . 2009-09-25 05:56 532480 c:\windows\system32\mstime.dll

- 2001-08-23 15:00 . 2009-06-26 16:18 532480 c:\windows\system32\mstime.dll

- 2001-08-23 15:00 . 2009-06-26 16:18 146432 c:\windows\system32\msrating.dll

+ 2001-08-23 15:00 . 2009-09-25 05:56 146432 c:\windows\system32\msrating.dll

+ 2001-08-23 15:00 . 2009-09-25 05:56 449024 c:\windows\system32\mshtmled.dll

- 2001-08-23 15:00 . 2009-06-26 16:18 449024 c:\windows\system32\mshtmled.dll

- 2001-08-23 15:00 . 2009-06-26 16:18 251392 c:\windows\system32\iepeers.dll

+ 2001-08-23 15:00 . 2009-09-25 05:56 251392 c:\windows\system32\iepeers.dll

- 2001-08-23 15:00 . 2009-06-26 16:18 205312 c:\windows\system32\dxtrans.dll

+ 2001-08-23 15:00 . 2009-09-25 05:56 205312 c:\windows\system32\dxtrans.dll

+ 2001-08-23 15:00 . 2009-09-25 05:56 357888 c:\windows\system32\dxtmsft.dll

- 2001-08-23 15:00 . 2009-06-26 16:18 357888 c:\windows\system32\dxtmsft.dll

+ 2004-08-04 07:56 . 2009-04-10 05:01 530280 c:\windows\system32\dllcache\wmspdmod.dll

+ 2006-05-10 05:23 . 2009-09-25 05:56 662016 c:\windows\system32\dllcache\wininet.dll

+ 2006-05-10 05:23 . 2009-09-25 05:56 624640 c:\windows\system32\dllcache\urlmon.dll

- 2006-08-21 14:52 . 2008-10-03 10:15 247326 c:\windows\system32\dllcache\strmdll.dll

+ 2006-08-21 14:52 . 2009-08-26 08:16 247326 c:\windows\system32\dllcache\strmdll.dll

+ 2006-05-10 05:23 . 2009-09-25 05:56 473600 c:\windows\system32\dllcache\shlwapi.dll

- 2009-06-25 08:44 . 2009-06-25 08:44 133632 c:\windows\system32\dllcache\msv1_0.dll

+ 2009-06-25 08:44 . 2009-09-11 14:33 133632 c:\windows\system32\dllcache\msv1_0.dll

- 2006-05-10 05:23 . 2009-06-26 16:18 532480 c:\windows\system32\dllcache\mstime.dll

+ 2006-05-10 05:23 . 2009-09-25 05:56 532480 c:\windows\system32\dllcache\mstime.dll

+ 2006-05-10 05:23 . 2009-09-25 05:56 146432 c:\windows\system32\dllcache\msrating.dll

- 2006-05-10 05:23 . 2009-06-26 16:18 146432 c:\windows\system32\dllcache\msrating.dll

+ 2006-05-10 05:23 . 2009-09-25 05:56 449024 c:\windows\system32\dllcache\mshtmled.dll

- 2006-05-10 05:23 . 2009-06-26 16:18 449024 c:\windows\system32\dllcache\mshtmled.dll

- 2006-05-10 05:22 . 2009-06-26 16:18 251392 c:\windows\system32\dllcache\iepeers.dll

+ 2006-05-10 05:22 . 2009-09-25 05:56 251392 c:\windows\system32\dllcache\iepeers.dll

- 2006-05-10 05:22 . 2009-06-26 16:18 205312 c:\windows\system32\dllcache\dxtrans.dll

+ 2006-05-10 05:22 . 2009-09-25 05:56 205312 c:\windows\system32\dllcache\dxtrans.dll

+ 2006-05-10 05:22 . 2009-09-25 05:56 357888 c:\windows\system32\dllcache\dxtmsft.dll

- 2006-05-10 05:22 . 2009-06-26 16:18 357888 c:\windows\system32\dllcache\dxtmsft.dll

+ 2006-05-10 05:22 . 2009-09-25 05:56 151040 c:\windows\system32\dllcache\cdfview.dll

- 2006-05-10 05:22 . 2009-06-26 16:18 151040 c:\windows\system32\dllcache\cdfview.dll

- 2001-08-23 15:00 . 2009-06-26 16:18 151040 c:\windows\system32\cdfview.dll

+ 2001-08-23 15:00 . 2009-09-25 05:56 151040 c:\windows\system32\cdfview.dll

+ 2009-10-13 18:26 . 2009-08-13 13:55 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll

+ 2004-08-27 17:57 . 2009-09-25 05:56 1506304 c:\windows\system32\shdocvw.dll

- 2004-08-27 17:57 . 2009-07-18 16:20 1506304 c:\windows\system32\shdocvw.dll

+ 2004-09-29 06:45 . 2009-09-25 05:56 3063296 c:\windows\system32\mshtml.dll

- 2006-05-29 15:30 . 2009-07-18 16:20 1506304 c:\windows\system32\dllcache\shdocvw.dll

+ 2006-05-29 15:30 . 2009-09-25 05:56 1506304 c:\windows\system32\dllcache\shdocvw.dll

+ 2006-06-22 05:06 . 2009-07-17 16:27 1435648 c:\windows\system32\dllcache\query.dll

- 2006-06-22 05:06 . 2006-06-22 05:06 1435648 c:\windows\system32\dllcache\query.dll

+ 2006-12-19 14:17 . 2009-08-04 14:00 2180352 c:\windows\system32\dllcache\ntoskrnl.exe

- 2006-12-19 12:55 . 2009-02-06 16:49 2015744 c:\windows\system32\dllcache\ntkrpamp.exe

+ 2006-12-19 12:55 . 2009-08-04 13:13 2015744 c:\windows\system32\dllcache\ntkrpamp.exe

- 2006-12-19 12:55 . 2009-02-06 16:49 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe

+ 2006-12-19 12:55 . 2009-08-04 13:13 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe

- 2006-12-19 14:15 . 2009-02-06 17:22 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe

+ 2006-12-19 14:15 . 2009-08-04 13:58 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe

+ 2006-05-19 15:08 . 2009-09-25 05:56 3063296 c:\windows\system32\dllcache\mshtml.dll

- 2006-05-10 05:22 . 2009-06-26 16:18 1054208 c:\windows\system32\dllcache\danim.dll

+ 2006-05-10 05:22 . 2009-09-25 05:56 1054208 c:\windows\system32\dllcache\danim.dll

+ 2006-05-10 05:22 . 2009-09-25 05:56 1023488 c:\windows\system32\dllcache\browseui.dll

- 2006-05-10 05:22 . 2009-06-26 16:18 1023488 c:\windows\system32\dllcache\browseui.dll

- 2001-08-23 15:00 . 2009-06-26 16:18 1054208 c:\windows\system32\danim.dll

+ 2001-08-23 15:00 . 2009-09-25 05:56 1054208 c:\windows\system32\danim.dll

+ 2004-01-16 09:29 . 2009-09-25 05:56 1023488 c:\windows\system32\browseui.dll

- 2004-01-16 09:29 . 2009-06-26 16:18 1023488 c:\windows\system32\browseui.dll

+ 2005-03-02 00:59 . 2009-08-04 14:00 2180352 c:\windows\Driver Cache\i386\ntoskrnl.exe

+ 2005-03-02 00:34 . 2009-08-04 13:13 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe

- 2005-03-02 00:34 . 2009-02-06 16:49 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe

- 2005-03-02 00:34 . 2009-02-06 16:49 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe

+ 2005-03-02 00:34 . 2009-08-04 13:13 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe

+ 2005-03-02 00:57 . 2009-08-04 13:58 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe

- 2005-03-02 00:57 . 2009-02-06 17:22 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 1867776]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-05 39408]

"Eraser"="c:\program files\Eraser\eraser.exe" [2003-07-25 536576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]

"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-06-15 307200]

"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 286720]

"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 299008]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-26 185896]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-25 149280]

"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 106496]

"avp"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-20 113664]

Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-04-06 16:25 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiHacker]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=

"c:\\Program Files\\SmartFTP\\SmartFTP.exe"=

"c:\\Program Files\\AIM\\aim.exe"=

"c:\\WINDOWS\\system32\\mmc.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Program Files\\TVU Player\\TVUPlayer.exe"=

"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"c:\\WINDOWS\\system32\\dlcxcoms.exe"=

"c:\\Program Files\\CoreFTP\\coreftp.exe"=

"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=

"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\AIM6\\aim6.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"57462:TCP"= 57462:TCP:Pando P2P TCP Listening Port

"57462:UDP"= 57462:UDP:Pando P2P UDP Listening Port

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [12/15/2008 8:41 PM 33808]

R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2/12/2007 3:58 PM 10240]

R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [7/13/2005 11:31 AM 78032]

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [12/4/2008 2:50 PM 9968]

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 2:50 PM 55024]

R3 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/13/2009 5:46 PM 31760]

R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [5/16/2009 8:59 PM 19472]

R3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [7/13/2005 11:27 AM 23180]

R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);c:\windows\system32\drivers\adm8830.sys [3/19/2005 8:01 AM 747392]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/7/2009 10:21 PM 133104]

S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 2:50 PM 7408]

S3 scrcap;scrcap;c:\windows\system32\DRIVERS\scrcap.sys --> c:\windows\system32\DRIVERS\scrcap.sys [?]

S3 WipeFile;WipeFile;c:\windows\system32\drivers\WipeFile.sys [3/3/2007 7:20 PM 57472]

.

Contents of the 'Scheduled Tasks' folder

2009-10-08 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]

2009-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-08 02:21]

2009-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-08 02:21]

2009-10-14 c:\windows\Tasks\WGASetup.job

- c:\windows\system32\KB905474\wgasetup.exe [2009-05-12 02:18]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.optonline.net/Home

uSearch Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com/ie

mStart Page = hxxp://www.msn.com

mDefault_Search_URL = hxxp://www.google.com/ie

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

mSearchAssistant = hxxp://www.google.com/ie

IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201

IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204

IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203

IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

FF - ProfilePath - c:\documents and settings\Beatrice\Application Data\Mozilla\Firefox\Profiles\ob3clmij.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official

FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll

FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll

FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-10-14 16:50

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1852)

c:\program files\SUPERAntiSpyware\SASWINLO.DLL

- - - - - - - > 'explorer.exe'(3412)

c:\progra~1\Google\GGTASK~1.DLL

c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\wdfmgr.exe

c:\windows\system32\MsPMSPSv.exe

c:\windows\system32\WgaTray.exe

c:\program files\Google\ggviewer81-53.exe

c:\windows\system32\dlcxcoms.exe

c:\program files\iPod\bin\iPodService.exe

.

**************************************************************************

.

Completion time: 2009-10-14 17:02 - machine was rebooted

ComboFix-quarantined-files.txt 2009-10-14 21:02

ComboFix2.txt 2009-10-14 04:26

Pre-Run: 304,488,448 bytes free

Post-Run: 340,660,224 bytes free

350 --- E O F --- 2009-10-14 05:10

Link to post
Share on other sites

I have attached a file to this message called AvengerScript.txt which you should save on your desktop. After saving AvengerScript.txt, please download The Avenger from the following link:

http://swandog46.geekstogo.com/avenger2/download.php

Use The Avenger to open the AvengerScript text file that you saved on your desktop, and then click the 'Execute' button in The Avenger. It will restart your computer, and use the information in AvengerScript.txt to clean up your computer a bit.

If you cannot find the 'Open' button, then please refer to the screenshot linked below:

http://malwarebytes.gt500.org/screenshots/...open_script.png

AvengerScript.txt

Link to post
Share on other sites

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)

Mon Oct 12 15:44:13 2009

15:44:13: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

//////////////////////////////////////////

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)

Mon Oct 12 15:44:39 2009

15:44:39: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

//////////////////////////////////////////

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)

Mon Oct 12 15:46:12 2009

15:46:12: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

//////////////////////////////////////////

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.

Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

No rootkits found!

Driver "MEMSWEEP2" deleted successfully.

Error: file "C:\WINDOWS\system32\7D7.tmp" not found!

Deletion of file "C:\WINDOWS\system32\7D7.tmp" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Completed script processing.

*******************

Finished! Terminate.

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)

Wed Oct 14 22:54:09 2009

22:54:09: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

//////////////////////////////////////////

//////////////////////////////////////////

Avenger Pre-Processor log

//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)

Wed Oct 14 22:54:49 2009

22:54:49: Error: Invalid script. A valid script must begin with a command directive.

Aborting execution!

//////////////////////////////////////////

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.

Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

No rootkits found!

File "c:\windows\system32\05A597BF8C.sys" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

Link to post
Share on other sites

No problem. Thanks so much for your help!

ComboFix 09-10-15.01 - Beatrice 10/15/2009 15:43.3.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.512.285 [GMT -4:00]

Running from: c:\documents and settings\Beatrice\Desktop\ComboFix.exe

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}

FW: Kaspersky Anti-Hacker *disabled* {0BB8CA15-F396-46C7-9A59-108D852CFEC0}

.

((((((((((((((((((((((((( Files Created from 2009-09-15 to 2009-10-15 )))))))))))))))))))))))))))))))

.

2009-10-12 14:08 . 2009-10-12 14:09 -------- d-----w- c:\program files\trend micro

2009-10-12 14:08 . 2009-10-12 14:09 -------- d-----w- C:\rsit

2009-10-12 04:17 . 2009-10-12 04:49 -------- d-----w- c:\program files\Common Files\ParetoLogic

2009-10-12 04:17 . 2009-10-12 04:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic

2009-10-12 04:16 . 2009-10-12 04:16 -------- d-----w- c:\documents and settings\Beatrice\Local Settings\Application Data\Downloaded Installations

2009-10-11 02:52 . 2009-10-11 02:52 -------- d-----w- c:\program files\Sophos

2009-10-08 00:40 . 2009-10-08 00:40 -------- d-----w- c:\program files\SpywareBlaster

2009-10-07 11:51 . 2009-10-07 11:51 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat

2009-10-07 11:50 . 2009-10-14 13:15 108059 ----a-w- c:\windows\system32\drivers\klin.dat

2009-10-07 11:50 . 2009-10-14 13:15 95259 ----a-w- c:\windows\system32\drivers\klick.dat

2009-10-07 11:48 . 2009-10-15 10:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab

2009-10-07 11:08 . 2009-10-07 11:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

2009-10-06 19:25 . 2009-10-06 19:25 -------- d-----w- c:\program files\ESET

2009-10-06 15:56 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-10-06 15:56 . 2009-10-06 15:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-10-06 15:56 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-10-06 05:32 . 2009-10-06 05:32 -------- d-----w- c:\documents and settings\Bumblebea\Application Data\Malwarebytes

2009-09-29 21:27 . 2009-09-29 21:27 -------- d-----w- c:\documents and settings\Michy\Application Data\AdobeUM

2009-09-29 21:25 . 2009-09-29 21:27 -------- d-----w- c:\documents and settings\Michy\Local Settings\Application Data\Adobe

2009-09-29 21:18 . 2009-09-29 21:18 -------- d-----w- c:\documents and settings\Michy\Local Settings\Application Data\WMTools Downloaded Files

2009-09-29 21:18 . 2009-09-29 21:18 -------- d-----w- c:\documents and settings\Michy\Application Data\Malwarebytes

2009-09-29 16:13 . 2009-09-29 16:25 -------- d-----w- c:\program files\VideoSpirit Pro

2009-09-26 19:32 . 2009-09-26 19:32 286720 ----a-w- c:\windows\iun505.exe

2009-09-26 19:32 . 2009-09-26 19:32 -------- d-----w- c:\program files\PC Drummer Trial Edition

2009-09-25 17:00 . 2009-09-25 17:00 -------- d-----w- c:\program files\HammerHead

2009-09-25 03:10 . 2009-09-25 03:10 -------- d-----w- c:\documents and settings\Beatrice\Application Data\Malwarebytes

2009-09-25 03:10 . 2009-09-25 03:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-09-25 03:06 . 2009-09-25 03:05 411368 ----a-w- c:\windows\system32\deploytk.dll

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-10-15 11:29 . 2005-08-21 17:30 1744 ----a-w- c:\windows\system32\d3d9caps.dat

2009-10-15 10:41 . 2007-04-15 19:31 -------- d-----w- c:\program files\dl_cats

2009-10-15 05:43 . 2009-05-26 01:41 -------- d-----w- c:\program files\Eraser

2009-10-11 14:24 . 2005-03-30 15:04 -------- d-----w- c:\program files\hjt

2009-10-07 11:48 . 2005-09-06 13:36 -------- d-----w- c:\program files\Kaspersky Lab

2009-10-06 22:57 . 2006-06-28 20:27 -------- d-----w- c:\program files\TVU Player

2009-10-06 05:20 . 2008-12-09 15:21 -------- d-----w- c:\program files\SUPERAntiSpyware

2009-09-30 00:59 . 2008-05-19 17:34 -------- d-----w- c:\documents and settings\Beatrice\Application Data\Orbit

2009-09-29 21:27 . 2009-02-20 15:33 -------- d-----w- c:\documents and settings\Michy\Application Data\Orbit

2009-09-29 02:17 . 2005-03-19 19:45 33872 ----a-w- c:\documents and settings\Beatrice\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2009-09-25 12:48 . 2008-12-09 03:06 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)

2009-09-25 05:56 . 2004-01-08 20:23 662016 ------w- c:\windows\system32\wininet.dll

2009-09-25 05:56 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll

2009-09-25 04:06 . 2005-03-20 17:48 -------- d-----w- c:\program files\Java

2009-09-24 02:18 . 2008-05-02 23:10 -------- d-----w- c:\program files\The Learning Company

2009-09-20 13:20 . 2009-08-19 01:07 -------- d-----w- c:\documents and settings\Beatrice\Application Data\uTorrent

2009-09-11 14:33 . 2001-08-23 15:00 133632 ----a-w- c:\windows\system32\msv1_0.dll

2009-09-09 04:26 . 2009-09-09 03:05 -------- d-----w- c:\documents and settings\Beatrice\Application Data\ICAClient

2009-09-09 03:05 . 2009-09-09 03:05 -------- d-----w- c:\program files\Citrix

2009-09-05 22:17 . 2007-05-07 12:48 -------- d-----w- c:\documents and settings\Beatrice\Application Data\CoreFTP

2009-09-04 20:45 . 2001-08-23 15:00 58880 ----a-w- c:\windows\system32\msasn1.dll

2009-09-02 13:01 . 2009-09-02 13:01 86016 ----a-w- c:\windows\system32\DirShowEXDD.dll

2009-08-26 08:16 . 2001-08-23 15:00 247326 ------w- c:\windows\system32\strmdll.dll

2009-08-19 01:07 . 2009-08-19 01:07 -------- d-----w- c:\program files\AskSearch

2009-08-06 23:24 . 2004-08-03 19:02 327896 ----a-w- c:\windows\system32\wucltui.dll

2009-08-06 23:24 . 2004-08-03 18:59 209632 ----a-w- c:\windows\system32\wuweb.dll

2009-08-06 23:24 . 2005-08-05 17:40 44768 ----a-w- c:\windows\system32\wups2.dll

2009-08-06 23:24 . 2004-08-03 18:59 35552 ----a-w- c:\windows\system32\wups.dll

2009-08-06 23:24 . 2005-03-19 17:15 53472 ------w- c:\windows\system32\wuauclt.exe

2009-08-06 23:24 . 2001-08-23 15:00 96480 ----a-w- c:\windows\system32\cdm.dll

2009-08-06 23:23 . 2004-08-03 19:00 575704 ----a-w- c:\windows\system32\wuapi.dll

2009-08-06 23:23 . 2005-03-19 17:15 1929952 ----a-w- c:\windows\system32\wuaueng.dll

2009-08-05 09:11 . 2001-08-23 15:00 204800 ------w- c:\windows\system32\mswebdvd.dll

2009-08-04 14:00 . 2001-08-23 15:00 2180352 ------w- c:\windows\system32\ntoskrnl.exe

2009-08-04 13:13 . 2001-08-17 13:48 2057728 ------w- c:\windows\system32\ntkrnlpa.exe

2005-08-15 16:21 . 2005-08-15 16:21 13500200 ----a-w- c:\program files\kav5.0trial_personalen.exe

2008-12-19 17:52 . 2006-02-12 15:11 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll

2008-12-19 17:52 . 2006-02-12 15:11 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll

2008-12-19 17:52 . 2007-08-10 13:02 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll

2008-12-19 17:52 . 2007-08-10 13:02 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll

2008-12-19 17:52 . 2006-02-12 15:11 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll

2008-08-16 21:42 . 2008-08-16 21:42 13112 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll

2008-08-16 21:42 . 2008-08-16 21:42 70456 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll

2008-08-16 21:42 . 2008-08-16 21:42 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll

2008-08-16 21:42 . 2008-08-16 21:42 20800 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll

2008-08-16 21:43 . 2008-08-16 21:43 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll

2008-08-16 21:42 . 2008-08-16 21:42 31032 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll

2008-08-16 21:42 . 2008-08-16 21:42 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll

2008-05-21 12:41 . 2008-05-21 12:41 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll

2008-05-21 12:41 . 2008-05-21 12:41 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll

2008-05-21 12:41 . 2008-05-21 12:41 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll

2008-06-05 17:58 . 2008-06-05 17:58 648504 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll

2008-08-16 21:42 . 2008-08-16 21:42 23864 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll

2005-07-14 19:31 . 2006-05-24 17:37 27648 --sha-w- c:\windows\system32\AVSredirect.dll

2007-04-16 02:29 . 2007-04-16 00:52 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 1867776]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-05 39408]

"Eraser"="c:\program files\Eraser\eraser.exe" [2003-07-25 536576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]

"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-06-15 307200]

"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 286720]

"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 299008]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-26 185896]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]

"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-25 149280]

"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 106496]

"avp"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-20 113664]

Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-04-06 16:25 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiHacker]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=

"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=

"c:\\Program Files\\SmartFTP\\SmartFTP.exe"=

"c:\\Program Files\\AIM\\aim.exe"=

"c:\\WINDOWS\\system32\\mmc.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\WINDOWS\\system32\\dpvsetup.exe"=

"c:\\Program Files\\TVU Player\\TVUPlayer.exe"=

"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"c:\\WINDOWS\\system32\\dlcxcoms.exe"=

"c:\\Program Files\\CoreFTP\\coreftp.exe"=

"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=

"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\AIM6\\aim6.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"57462:TCP"= 57462:TCP:Pando P2P TCP Listening Port

"57462:UDP"= 57462:UDP:Pando P2P UDP Listening Port

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [12/15/2008 8:41 PM 33808]

R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2/12/2007 3:58 PM 10240]

R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [7/13/2005 11:31 AM 78032]

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [12/4/2008 2:50 PM 9968]

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 2:50 PM 55024]

R3 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/13/2009 5:46 PM 31760]

R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [5/16/2009 8:59 PM 19472]

R3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [7/13/2005 11:27 AM 23180]

R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);c:\windows\system32\drivers\adm8830.sys [3/19/2005 8:01 AM 747392]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/7/2009 10:21 PM 133104]

S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 2:50 PM 7408]

S3 scrcap;scrcap;c:\windows\system32\DRIVERS\scrcap.sys --> c:\windows\system32\DRIVERS\scrcap.sys [?]

S3 WipeFile;WipeFile;c:\windows\system32\drivers\WipeFile.sys [3/3/2007 7:20 PM 57472]

.

Contents of the 'Scheduled Tasks' folder

2009-10-15 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]

2009-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-08 02:21]

2009-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-08 02:21]

2009-10-15 c:\windows\Tasks\WGASetup.job

- c:\windows\system32\KB905474\wgasetup.exe [2009-05-12 02:18]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.optonline.net/Home

uSearch Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com/ie

mStart Page = hxxp://www.msn.com

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201

IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204

IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203

IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

FF - ProfilePath - c:\documents and settings\Beatrice\Application Data\Mozilla\Firefox\Profiles\ob3clmij.default\

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official

FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll

FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll

FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-10-15 16:02

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1856)

c:\program files\SUPERAntiSpyware\SASWINLO.DLL

- - - - - - - > 'explorer.exe'(888)

c:\progra~1\Google\GGTASK~1.DLL

.

Completion time: 2009-10-15 16:08

ComboFix-quarantined-files.txt 2009-10-15 20:08

ComboFix2.txt 2009-10-14 21:02

ComboFix3.txt 2009-10-14 04:26

Pre-Run: 228,331,520 bytes free

Post-Run: 277,209,088 bytes free

228 --- E O F --- 2009-10-14 05:10

Link to post
Share on other sites

That's looking much better.

Let's run an online virus scan through ESET. Here are the steps:

1) Turn off your anti-virus software.

2) Click on the following link:

http://www.eset.com/onlinescan/

3) Click on the "ESET Online Scanner" button.

4) Put a check in the box that says "YES, I accept the Terms of Use."

5) Click the 'Start' button just to the right of the checkbox.

6) Uncheck the box that says "Remove found threats" (this is very important).

7) Click on "Advanced settings".

8) Put a check in the box that says "Scan for potentially unsafe applications".

9) Verify that "Scan for potentially unwanted applications" is also checked.

10) Verify that "Enable Anti-Stealth technology" is also checked.

11) Click the 'Start' button in the lower-right corner of the page, and it will begin downloading it's database, and then it will start scanning.

12) When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."

13) Save that text file on your desktop, and then attach it to a reply for me.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.