![]() ![]() |
Jun 29 2009, 03:03 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 18 Joined: 29-June 09 Member No.: 86,469 Operating System: XP SP3 |
Need help. Intermediate user. Thanks |
|
|
|
Jul 1 2009, 03:36 AM
Post
#2
|
|
![]() SuperHelper Group: Classroom Teacher Posts: 5,093 Joined: 28-April 07 From: UK Member No.: 69,799 Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux |
Hi,
Does MalwareBytes' find anything? If so, please post a log. Please download DDS and save it to your desktop.
Download the GMER Rootkit Scanner. Unzip it to your Desktop. Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Right-click gmer.exe and select Run As Administrator. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised! If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
|
|
|
|
Jul 1 2009, 12:28 PM
Post
#3
|
|
|
New Member ![]() Group: Authentic Member Posts: 18 Joined: 29-June 09 Member No.: 86,469 Operating System: XP SP3 |
Thanks for the help. I will gladly donate as soon as look at the exchange rate (I only have uUSD $8.00 in my PayPal account).
MalWarebytes finds Vundo. I have run VundoFix from Atribune.org and it removes it? Norton dosen't find Vundo and it returns. I think I have complied with your requests, if not please let me know. Malwarebytes' Anti-Malware 1.38 Database version: 2358 Windows 5.1.2600 Service Pack 3 7/1/2009 2:12:27 PM mbam-log-2009-07-01 (14-12-02).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 20420 Time elapsed: 1 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{161b3614-fe54-4d30-8019-0d1e95dd4db1} (Trojan.Vundo.H) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kvedspul (Trojan.Vundo.H) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{161b3614-fe54-4d30-8019-0d1e95dd4db1} (Trojan.Vundo.H) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\ixqavxo.dll (Trojan.Vundo.H) -> No action taken. DDS (Ver_09-06-26.01) - NTFSx86 Run by Roy Bristow at 11:22:18.20 on Wed 07/01/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.178 [GMT -4:00] AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe C:\Program Files\Dell Network Assistant\hnm_svc.exe C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Documents and Settings\Roy Bristow\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe C:\Program Files\Microsoft Office\Office\OSA.EXE C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Roy Bristow\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://comcast.net/ uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb uDefault_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=0080514 uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us-smb mWinlogon: Userinit=c:\windows\system32\userinit.exe BHO: : {161b3614-fe54-4d30-8019-0d1e95dd4db1} - c:\windows\system32\ixqavxo.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.5.0.135\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.5.0.135\IPSBHO.DLL BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - No File TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.5.0.135\coIEPlg.dll TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter uRun: [Google Update] "c:\documents and settings\roy bristow\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office\FINDFAST.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} LSP: c:\windows\system32\lsp.dll Trusted Zone: download.com Trusted Zone: intuit.com DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} - hxxp://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxps://chat2.j2.com/Media/VisitorchatEnu/TLIEFlash.CAB DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton internet security\engine\16.5.0.135\CoIEPlg.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: igfxcui - igfxdev.dll Notify: kvedspul - ixqavxo.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll AppInit_DLLs: frgehi.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-25 64160] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [2009-1-28 17264] R0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys [2009-5-12 21888] R0 qrgfbrnh;qrgfbrnh;c:\windows\system32\drivers\qrgfbrnh.sys [2004-8-10 23424] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1005000.087\SymEFA.sys [2009-3-23 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nis\1005000.087\BHDrvx86.sys [2009-3-23 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1005000.087\cchpx86.sys [2009-3-23 482352] R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [2008-12-7 14336] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-4-28 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-4-28 72944] R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2008-11-13 13360] R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312] R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 953168] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-1-4 195856] R2 Norton Internet Security;Norton Internet Security;c:\program files\norton internet security\engine\16.5.0.135\ccSvcHst.exe [2009-3-23 115560] R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2008-11-13 69168] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-25 101936] R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [2008-12-7 8832] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2008-9-26 19096] R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090630.055\NAVENG.SYS [2009-7-1 89104] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090630.055\NAVEX15.SYS [2009-7-1 876144] S1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090625.003\IDSXpx86.sys [2009-6-30 276344] S2 gupdate1c9a2515ee9ac6;Google Update Service (gupdate1c9a2515ee9ac6);c:\program files\google\update\GoogleUpdate.exe [2009-3-11 133104] S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys [2009-5-12 9088] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-4-28 7408] S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2008-10-23 92464] =============== Created Last 30 ================ 2009-06-29 17:34 <DIR> --d----- c:\program files\Flip Words 2009-06-29 15:17 <DIR> --d----- c:\docume~1\roybri~1\applic~1\ZoomBrowser EX 2009-06-29 15:09 <DIR> --d----- c:\docume~1\roybri~1\applic~1\CameraWindowDC 2009-06-29 15:09 <DIR> --d----- c:\docume~1\roybri~1\applic~1\CANON INC 2009-06-22 14:17 <DIR> -cd-h--- c:\windows\ie8 2009-06-22 14:04 255,848 a------- c:\windows\system32\xactengine2_6.dll 2009-06-22 14:03 <DIR> --d-h--- c:\windows\msdownld.tmp 2009-06-22 14:02 <DIR> --d----- c:\windows\Logs 2009-06-21 19:27 16 a------- c:\documents and settings\roy bristow\FlipWords.dat 2009-06-21 14:14 293 a------- c:\windows\FlipWords.ini 2009-06-18 19:07 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ZoomBrowser 2009-06-18 19:07 <DIR> --d----- c:\program files\Canon 2009-06-18 19:04 <DIR> --d----- c:\program files\common files\Canon 2009-06-11 20:00 183,296 a------- c:\windows\system32\lsp.dll 2009-06-10 16:03 118 a------- c:\windows\system32\MRT.INI 2009-06-10 04:52 246,272 -------- c:\windows\system32\dllcache\ieproxy.dll 2009-06-10 04:52 12,800 -------- c:\windows\system32\dllcache\xpshims.dll 2009-06-09 15:37 <DIR> --dsh--- c:\documents and settings\roy bristow\IECompatCache 2009-06-03 23:24 <DIR> --dsh--- c:\documents and settings\roy bristow\PrivacIE 2009-06-03 23:21 <DIR> --dsh--- c:\documents and settings\roy bristow\IETldCache 2009-06-03 23:18 <DIR> --d----- c:\windows\ie8updates 2009-06-03 23:18 102,912 -------- c:\windows\system32\dllcache\iecompat.dll ==================== Find3M ==================== 2009-06-21 14:13 1,682 a--sh--- c:\windows\system32\KGyGaAvL.sys 2009-06-17 11:27 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 11:27 19,096 a------- c:\windows\system32\drivers\mbam.sys 2009-06-06 23:44 481,743 a------- c:\windows\system32\kungsfuvbrsvpj.dat 2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll 2009-05-13 01:15 915,456 a------- c:\windows\system32\wininet.dll 2009-05-13 01:15 5,936,128 -------- c:\windows\system32\dllcache\mshtml.dll 2009-05-13 01:15 915,456 -------- c:\windows\system32\dllcache\wininet.dll 2009-05-12 06:56 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf 2009-05-12 06:55 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf 2009-05-07 11:32 345,600 a------- c:\windows\system32\localspl.dll 2009-05-07 11:32 345,600 -------- c:\windows\system32\dllcache\localspl.dll 2009-04-30 17:22 1,985,024 -------- c:\windows\system32\dllcache\iertutil.dll 2009-04-30 17:22 11,064,832 -------- c:\windows\system32\dllcache\ieframe.dll 2009-04-30 17:22 1,207,808 -------- c:\windows\system32\dllcache\urlmon.dll 2009-04-30 17:22 25,600 -------- c:\windows\system32\dllcache\jsproxy.dll 2009-04-30 17:22 385,536 -------- c:\windows\system32\dllcache\iedkcs32.dll 2009-04-30 07:21 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe 2009-04-22 20:09 15,688 a------- c:\windows\system32\lsdelete.exe 2009-04-17 08:26 1,847,168 a------- c:\windows\system32\win32k.sys 2009-04-17 08:26 1,847,168 -------- c:\windows\system32\dllcache\win32k.sys 2009-04-15 10:51 585,216 a------- c:\windows\system32\rpcrt4.dll 2009-04-15 10:51 585,216 -------- c:\windows\system32\dllcache\rpcrt4.dll 2009-02-10 15:38 60,744 a------- c:\documents and settings\roy bristow\g2mdlhlpx.exe 2009-01-26 12:00 2,516 a--sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys 2009-01-26 12:00 88 ---shr-- c:\docume~1\alluse~1\applic~1\020AC935B7.sys 2008-07-07 09:56 81,920 a------- c:\docume~1\roybri~1\applic~1\ezpinst.exe 2008-07-07 09:56 47,360 a------- c:\docume~1\roybri~1\applic~1\pcouffin.sys 2008-12-07 21:55 56 ---shr-- c:\windows\system32\B735C90A02.sys 2008-09-23 20:59 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092320080924\index.dat ============= FINISH: 11:23:26.17 =============== GMER 1.0.15.14972 - http://www.gmer.net Rootkit scan 2009-07-01 12:44:33 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.15 ---- SSDT 86BC4270 ZwAlertResumeThread SSDT 865556B0 ZwAlertThread SSDT 86432A90 ZwAllocateVirtualMemory SSDT 86540050 ZwAssignProcessToJobObject SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA9D8B040] SSDT 86432288 ZwCreateMutant SSDT 86431CD0 ZwCreateSymbolicLinkObject SSDT 864B0720 ZwCreateThread SSDT 86541050 ZwDebugActiveProcess SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA9D8B2C0] SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA9D8B820] SSDT 86432BE8 ZwDuplicateObject SSDT spok.sys ZwEnumerateKey [0xF7411CA2] SSDT spok.sys ZwEnumerateValueKey [0xF7412030] SSDT 864328F0 ZwFreeVirtualMemory SSDT 86D5C068 ZwImpersonateAnonymousToken SSDT 86C3F268 ZwImpersonateThread SSDT 86543050 ZwLoadDriver SSDT 864A8878 ZwMapViewOfSection SSDT 8654D050 ZwOpenEvent SSDT spok.sys ZwOpenKey [0xF73F30C0] SSDT 86432D88 ZwOpenProcess SSDT 86BDF0B8 ZwOpenProcessToken SSDT 86544050 ZwOpenSection SSDT 86432CB8 ZwOpenThread SSDT 86431DA0 ZwProtectVirtualMemory SSDT spok.sys ZwQueryKey [0xF7412108] SSDT spok.sys ZwQueryValueKey [0xF7411F88] SSDT 86EF6850 ZwResumeThread SSDT 86EF0C08 ZwSetContextThread SSDT 86432710 ZwSetInformationProcess SSDT 86542050 ZwSetSystemInformation SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA9D8BA70] SSDT 8654C050 ZwSuspendProcess SSDT 86C3C158 ZwSuspendThread SSDT 86BD80B8 ZwTerminateProcess SSDT 86C67E50 ZwTerminateThread SSDT 86CDD378 ZwUnmapViewOfSection SSDT 864329C0 ZwWriteVirtualMemory INT 0x63 ? 86CB0F00 INT 0x73 ? 86FD6BF8 INT 0x73 ? 86FD6BF8 INT 0x73 ? 86FD6BF8 INT 0x73 ? 86FD6BF8 INT 0x73 ? 86CB0F00 INT 0x73 ? 86CB0F00 INT 0x73 ? 86FD6BF8 INT 0x94 ? 86CB0F00 INT 0xA4 ? 86CB0F00 ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2CD4 80504570 4 Bytes CALL 14D688A0 PAGE ntkrnlpa.exe!ObReferenceObjectByHandle + 44F 805BB8ED 7 Bytes JMP 86F63B40 ? spok.sys The system cannot find the file specified. ! ? SYMEFA.SYS The system cannot find the file specified. ! .text USBPORT.SYS!DllUnload F600E8AC 5 Bytes JMP 86CB04E0 ---- Kernel IAT/EAT - GMER 1.0.15 ---- IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73F4040] spok.sys IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73F413C] spok.sys IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73F40BE] spok.sys IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73F47FC] spok.sys IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73F46D2] spok.sys ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 86F661F8 AttachedDevice \FileSystem\Ntfs \Ntfs MPRIFL.SYS (My Private Folder driver/FSPro Labs) Device \Driver\usbehci \Device\USBPDO-0 86CD1500 Device \Driver\usbuhci \Device\USBPDO-1 86D4F1F8 Device \Driver\usbuhci \Device\USBPDO-2 86D4F1F8 Device \Driver\usbuhci \Device\USBPDO-3 86D4F1F8 Device \Driver\usbuhci \Device\USBPDO-4 86D4F1F8 AttachedDevice \Driver\Tcpip \Device\Tcp nnrnstdi.SYS (NNRNSTDI helper driver/The Nielsen Company) Device \Driver\usbuhci \Device\USBPDO-5 86D4F1F8 Device \Driver\usbuhci \Device\USBPDO-6 86D4F1F8 Device \Driver\Ftdisk \Device\HarddiskVolume1 86F681F8 Device \Driver\usbehci \Device\USBPDO-7 86CD1500 Device \Driver\Ftdisk \Device\HarddiskVolume2 86F681F8 Device \Driver\Cdrom \Device\CdRom0 86C08500 Device \Driver\NetBT \Device\NetBT_Tcpip_{28C8854A-4440-4535-9B10-CE5FEF99D1FE} 8655E500 Device \Driver\NetBT \Device\NetBt_Wins_Export 8655E500 Device \Driver\NetBT \Device\NetbiosSmb 8655E500 AttachedDevice \Driver\Tcpip \Device\RawIp nnrnstdi.SYS (NNRNSTDI helper driver/The Nielsen Company) Device \Driver\usbuhci \Device\USBFDO-0 86D4F1F8 Device \Driver\usbuhci \Device\USBFDO-1 86D4F1F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 865531F8 Device \Driver\usbuhci \Device\USBFDO-2 86D4F1F8 Device 865531F8 Device \Driver\usbehci \Device\USBFDO-3 86CD1500 Device \Driver\usbuhci \Device\USBFDO-4 86D4F1F8 Device \Driver\Ftdisk \Device\FtControl 86F681F8 Device \Driver\usbuhci \Device\USBFDO-5 86D4F1F8 Device \Driver\usbuhci \Device\USBFDO-6 86D4F1F8 Device \Driver\usbehci \Device\USBFDO-7 86CD1500 Device 863E61F8 Device A7EEF297 AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) Device \FileSystem\Cdfs \Cdfs 86401500 Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio) ---- Services - GMER 1.0.15 ---- Service system32\drivers\kungsfkvrndpsk.sys (*** hidden *** ) [SYSTEM] kungsfxjbqlxwn <-- ROOTKIT !!! Service system32\drivers\SKYNETxviwqjgq.sys (*** hidden *** ) [SYSTEM] SKYNETbdwptntr <-- ROOTKIT !!! ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn@start 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn@type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn@group file system Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn@imagepath \systemroot\system32\drivers\kungsfkvrndpsk.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main@aid 10096 Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main@sid 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main@cmddelay 7200 Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main\delete Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main\injector Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main\injector@* kungsfwsp.dll Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\main\tasks Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsfrk.sys \systemroot\system32\drivers\kungsfkvrndpsk.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsfcmd.dll \systemroot\system32\kungsfarmpydlv.dll Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsflog.dat \systemroot\system32\kungsfuvbrsvpj.dat Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsfwsp.dll \systemroot\system32\kungsfnbmqhhlj.dll Reg HKLM\SYSTEM\CurrentControlSet\Services\kungsfxjbqlxwn\modules@kungsf.dat \systemroot\system32\kungsfwrtlnkou.dat Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr@start 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr@type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr@group file system Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr@imagepath \systemroot\system32\drivers\SKYNETxviwqjgq.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\main Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\main\injector Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\modules Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETxviwqjgq.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETbdwptntr\modules@SKYNETcmd.dll \systemroot\system32\SKYNETxtiouodx.dll Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn@start 1 Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn@type 1 Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn@group file system Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn@imagepath \systemroot\system32\drivers\kungsfkvrndpsk.sys Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main@aid 10096 Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main@sid 0 Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main@cmddelay 7200 Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main\delete Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main\injector Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main\injector@* kungsfwsp.dll Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\main\tasks Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsfrk.sys \systemroot\system32\drivers\kungsfkvrndpsk.sys Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsfcmd.dll \systemroot\system32\kungsfarmpydlv.dll Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsflog.dat \systemroot\system32\kungsfuvbrsvpj.dat Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsfwsp.dll \systemroot\system32\kungsfnbmqhhlj.dll Reg HKLM\SYSTEM\ControlSet002\Services\kungsfxjbqlxwn\modules@kungsf.dat \systemroot\system32\kungsfwrtlnkou.dat Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr@start 1 Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr@type 1 Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr@group file system Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr@imagepath \systemroot\system32\drivers\SKYNETxviwqjgq.sys Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\main Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\main\injector Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\modules Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETxviwqjgq.sys Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETbdwptntr\modules@SKYNETcmd.dll \systemroot\system32\SKYNETxtiouodx.dll Reg HKLM\SOFTWARE\Classes\CLSID\{161B3614-FE54-4D30-8019-0D1E95DD4DB1}\ProgID@ Akzydiqq Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506} Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}@naiojgmabnolokncbdkabjolfgno 0x6A 0x61 0x62 0x6C ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}@macpdhjbficnaokdjnleaadhcf 0x6A 0x61 0x62 0x6C ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}@abedlckcohpbmiinnnoaocjeefpokfiloe 0x61 0x62 0x6C 0x6F ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}@mahdadeebgllhgadjcapkcnlnf 0x64 0x62 0x63 0x70 ... ---- Files - GMER 1.0.15 ---- File C:\Documents and Settings\Roy Bristow\My Documents\My Lockbox 0 bytes File C:\Documents and Settings\Roy Bristow\My Documents\My Lockbox\New Folder 0 bytes ---- EOF - GMER 1.0.15 ----
Attached File(s)
|
|
|
|
Jul 1 2009, 12:36 PM
Post
#4
|
|
![]() SuperHelper Group: Classroom Teacher Posts: 5,093 Joined: 28-April 07 From: UK Member No.: 69,799 Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux |
Looks like you've got a nasty Rootkit (or two) on board. Let's see if we can drag it out.
Please delete any existing copies of ComboFix that you might have. Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop. Link 1 Link 2 Link 3 ![]() ![]() IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]()
![]()
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Notes: 1. Do not mouse-click Combofix's window while it is running. That may cause it to stall. 2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions. 3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser. 4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please advise. 5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine. This post has been edited by jpshortstuff: Jul 1 2009, 12:39 PM |
|
|
|
Jul 1 2009, 01:33 PM
Post
#5
|
|
|
New Member ![]() Group: Authentic Member Posts: 18 Joined: 29-June 09 Member No.: 86,469 Operating System: XP SP3 |
FYI - I received several warnings that the ComboFix site was a scam and it gave me the "real" sites. I was also advised that if I purchased ComboFix from other than the "real" sites I should ask my bank to stop the transaction.
ComboFix 09-07-01.01 - Roy Bristow 07/01/2009 15:11.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.475 [GMT -4:00] Running from: c:\documents and settings\Roy Bristow\Desktop\Combo-Fix.exe AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat c:\windows\Downloaded Program Files\ODCTOOLS c:\windows\system32\afexzso.dll c:\windows\system32\api.dat c:\windows\system32\dkiorkdm.ini c:\windows\system32\drivers\lafsmdxk.sys c:\windows\system32\drivers\qrgfbrnh.sys c:\windows\system32\gloltirm.ini c:\windows\system32\ixqavxo.dll c:\windows\system32\ixvokqiu.ini c:\windows\system32\kungsfuvbrsvpj.dat c:\windows\system32\lsp.dll c:\windows\system32\opfqebys.ini c:\windows\system32\pcgcnbjm.ini c:\windows\system32\pkffjqjf.dll c:\windows\Tasks\At1.job ----- BITS: Possible infected sites ----- hxxp://www.spiralfrog.com . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_QRGFBRNH -------\Service_kungsfxjbqlxwn -------\Service_qrgfbrnh -------\Service_SKYNETbdwptntr ((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 ))))))))))))))))))))))))))))))) . 2009-07-01 15:44 . 2009-02-19 09:00 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVENG.SYS 2009-07-01 15:44 . 2009-02-19 09:00 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVEX15.SYS 2009-07-01 15:44 . 2009-02-19 09:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVENG32.DLL 2009-07-01 15:44 . 2009-02-19 09:00 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVEX32A.DLL 2009-07-01 15:44 . 2009-02-25 09:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\EECTRL.SYS 2009-07-01 15:44 . 2009-02-25 09:00 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\CCERASER.DLL 2009-07-01 15:44 . 2009-02-25 09:00 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\ERASER.SYS 2009-07-01 15:44 . 2009-01-18 07:18 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\ECMSVR32.DLL 2009-06-30 21:57 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll 2009-06-30 21:57 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys 2009-06-30 21:57 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys 2009-06-30 21:57 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll 2009-06-30 21:57 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys 2009-06-29 21:34 . 2009-06-29 21:34 -------- d-----w- c:\program files\Flip Words 2009-06-29 19:17 . 2009-06-29 19:18 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ZoomBrowser EX 2009-06-29 19:09 . 2009-06-29 19:17 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CameraWindowDC 2009-06-29 19:09 . 2009-06-29 19:09 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CANON INC 2009-06-24 01:35 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\Scxpx86.dll 2009-06-24 01:35 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSXpx86.sys 2009-06-24 01:35 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSvix86.sys 2009-06-24 01:35 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSxpx86.dll 2009-06-24 01:35 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSviA64.sys 2009-06-23 21:28 . 2009-06-23 21:28 152576 ----a-w- c:\documents and settings\Roy Bristow\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-06-22 18:17 . 2009-06-22 18:20 -------- dc-h--w- c:\windows\ie8 2009-06-22 18:04 . 2007-01-24 19:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll 2009-06-22 18:03 . 2009-06-23 21:35 -------- d--h--w- c:\windows\msdownld.tmp 2009-06-22 18:02 . 2009-06-22 18:02 -------- d-----w- c:\windows\Logs 2009-06-21 23:27 . 2009-06-28 17:28 16 ----a-w- c:\documents and settings\Roy Bristow\FlipWords.dat 2009-06-21 18:55 . 2009-06-21 18:55 16 ----a-w- c:\documents and settings\Owen\FlipWords.dat 2009-06-20 20:46 . 2009-06-20 20:46 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-06-18 23:07 . 2009-06-18 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser 2009-06-18 23:07 . 2009-06-18 23:08 -------- d-----w- c:\program files\Canon 2009-06-18 23:04 . 2009-06-18 23:04 -------- d-----w- c:\program files\Common Files\Canon 2009-06-10 08:52 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll 2009-06-10 08:52 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-09 19:37 . 2009-06-09 19:37 -------- d-sh--w- c:\documents and settings\Roy Bristow\IECompatCache 2009-06-09 13:16 . 2009-06-09 13:16 -------- d-sh--w- c:\documents and settings\Margaret\PrivacIE 2009-06-08 22:22 . 2009-06-08 22:22 -------- d-sh--w- c:\documents and settings\Owen\PrivacIE 2009-06-08 21:06 . 2009-06-08 21:06 -------- d-----w- c:\documents and settings\Eden\Application Data\CyberLink 2009-06-08 11:49 . 2009-06-08 11:49 -------- d-----w- c:\documents and settings\Margaret\Local Settings\Application Data\Symantec 2009-06-07 15:18 . 2009-06-07 15:18 -------- d-sh--w- c:\documents and settings\Eden\PrivacIE 2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Logitech 2009-06-04 03:24 . 2009-06-04 03:24 -------- d-sh--w- c:\documents and settings\Roy Bristow\PrivacIE 2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2009-06-04 03:21 . 2009-06-04 03:21 -------- d-sh--w- c:\documents and settings\Roy Bristow\IETldCache 2009-06-04 03:18 . 2009-06-22 18:09 -------- d-----w- c:\windows\ie8updates 2009-06-04 03:18 . 2009-05-12 05:11 102912 ------w- c:\windows\system32\dllcache\iecompat.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-30 19:38 . 2009-03-11 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-06-28 17:29 . 2009-05-08 22:58 117760 ----a-w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-28 17:29 . 2009-05-08 21:10 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-06-28 17:14 . 2008-11-20 15:47 188501 ----a-w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard\CGGuard2.dll 2009-06-23 21:31 . 2008-05-14 14:57 -------- d-----w- c:\program files\Java 2009-06-21 18:13 . 2008-12-07 19:08 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-06-19 12:12 . 2008-11-20 15:47 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard 2009-06-19 01:23 . 2009-01-04 15:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-19 01:21 . 2009-01-05 03:07 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-06-17 15:27 . 2008-09-26 23:11 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 15:27 . 2008-09-26 23:11 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-15 01:48 . 2008-05-16 01:27 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\LimeWire 2009-06-14 20:01 . 2008-07-30 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-12 00:15 . 2008-06-05 01:14 -------- d-----w- c:\program files\SpiralFrog 2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Logitech 2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Sunbelt 2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Logitech 2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Sunbelt 2009-06-07 15:08 . 2009-06-07 15:07 73872 ----a-w- c:\documents and settings\Margaret\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Sunbelt 2009-05-21 15:33 . 2009-01-25 21:52 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-05-21 08:34 . 2008-05-14 15:01 -------- d-----w- c:\program files\Google 2009-05-13 05:15 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-12 12:16 . 2009-05-09 16:58 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-05-12 10:56 . 2009-05-12 10:56 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf 2009-05-12 10:55 . 2009-05-12 10:55 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf 2009-05-09 16:58 . 2009-05-09 16:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com 2009-05-09 15:08 . 2009-05-09 15:08 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq 2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com 2009-05-08 21:10 . 2008-05-22 00:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-05-08 17:12 . 2008-05-14 15:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-05-08 13:25 . 2009-05-08 13:25 -------- d-----w- c:\documents and settings\NetworkService\Application Data\gsdljreq 2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-28 00:08 . 2009-04-28 00:08 299352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe 2009-04-23 00:09 . 2009-05-08 10:43 15688 ----a-w- c:\windows\system32\lsdelete.exe 2009-04-23 00:09 . 2009-04-23 00:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll 2009-04-23 00:09 . 2009-04-23 00:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe 2009-04-23 00:09 . 2009-04-23 00:09 165728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll 2009-04-23 00:09 . 2009-04-23 00:09 343888 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll 2009-04-23 00:09 . 2009-04-23 00:09 289632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll 2009-04-23 00:09 . 2009-04-23 00:09 82784 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll 2009-04-23 00:08 . 2009-04-23 00:08 1629024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll 2009-04-23 00:08 . 2009-04-23 00:08 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll 2009-04-23 00:08 . 2009-04-23 00:08 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll 2009-04-23 00:08 . 2009-04-23 00:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys 2009-04-23 00:08 . 2009-02-26 01:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-04-23 00:08 . 2009-04-23 00:08 632680 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll 2009-04-23 00:08 . 2009-04-23 00:08 539512 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe 2009-04-23 00:08 . 2009-04-23 00:08 552808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe 2009-04-23 00:08 . 2009-04-23 00:08 2324808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe 2009-04-23 00:08 . 2009-04-23 00:08 626000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe 2009-04-23 00:08 . 2009-04-23 00:08 516440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe 2009-04-23 00:08 . 2009-04-23 00:08 953168 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe 2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2008-12-08 01:55 . 2008-12-07 19:08 56 --sh--r- c:\windows\system32\B735C90A02.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064] "Google Update"="c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-06 133104] "RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-05-22 160592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-06-17 414992] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-23 805392] Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-7-11 111376] Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-7-11 51984] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-05-02 06:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"= "c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10421:UDP"= 10421:UDP:SingleClick Discovery Protocol "10426:UDP"= 10426:UDP:SingleClick ICC R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/25/2009 9:08 PM 64160] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [1/28/2009 1:58 PM 17264] R0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys [5/12/2009 6:55 AM 21888] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [3/23/2009 11:39 AM 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [3/23/2009 11:39 AM 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [3/23/2009 11:39 AM 482352] R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [12/7/2008 2:41 PM 14336] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944] R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [11/13/2008 7:20 PM 13360] R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [1/11/2008 6:50 PM 30312] R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 953168] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/4/2009 11:20 AM 195856] R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [3/23/2009 11:39 AM 115560] R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [11/13/2008 7:20 PM 69168] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/25/2009 5:00 AM 101936] R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [12/7/2008 2:41 PM 8832] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/26/2008 7:11 PM 19096] R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712] S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [6/30/2009 5:57 PM 276344] S2 gupdate1c9a2515ee9ac6;Google Update Service (gupdate1c9a2515ee9ac6);c:\program files\Google\Update\GoogleUpdate.exe [3/11/2009 9:55 AM 133104] S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys [5/12/2009 6:55 AM 9088] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 4:22 PM 34064] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408] S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/23/2008 5:09 AM 92464] --- Other Services/Drivers In Memory --- *NewlyCreated* - QRGFBRNH *Deregistered* - qrgfbrnh HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs yogtgxzm [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-06-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 00:08] 2008-05-22 c:\windows\Tasks\Ad-Aware.job - c:\progra~1\Lavasoft\Ad-Aware\Ad-Aware.exe [2009-01-18 00:08] 2009-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57] 2009-07-01 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-11 16:29] 2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55] 2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55] 2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006Core.job - c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35] 2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006UA.job - c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35] 2009-05-30 c:\windows\Tasks\SmartDefrag.job - c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-01-04 05:07] 2009-07-01 c:\windows\Tasks\User_Feed_Synchronization-{F028BE97-6493-45D6-98BA-3C4460D4AD4D}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31] . - - - - ORPHANS REMOVED - - - - SafeBoot-SBAMSvc . ------- Supplementary Scan ------- . uStart Page = hxxp://comcast.net/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html Trusted Zone: download.com Trusted Zone: intuit.com . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-01 15:20 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security] "ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr] "ImagePath"="-" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT] "ImagePath"="-" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc] "ImagePath"="-" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI] "ImagePath"="-" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) "naiojgmabnolokncbdkabjolfgno"=hex:6a,61,62,6c,67,64,63,6e,6f,64,63,68,6c,65, 6f,61,63,67,6e,6d,00,00 "macpdhjbficnaokdjnleaadhcf"=hex:6a,61,62,6c,67,64,63,6e,6f,64,63,68,6c,65,6f, 61,63,67,6e,6d,00,56 "abedlckcohpbmiinnnoaocjeefpokfiloe"=hex:61,62,6c,6f,6d,66,6a,6b,61,6c,70,69, 6d,6d,6b,6f,62,67,6f,6b,6c,6e,68,67,65,6d,67,6d,68,68,6c,64,65,63,00,7e "mahdadeebgllhgadjcapkcnlnf"=hex:64,62,63,70,66,6b,6a,6a,62,6a,64,70,70,69,6f, 70,68,6a,61,70,68,6b,68,6b,62,64,62,6f,69,64,63,66,62,6a,63,62,68,61,6e,6e,\ [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync] "Name"="ActiveSync" "DisplayName"="Microsoft ActiveSync" "Param1"="ActiveSync" "Type"="wellknown" "Order"=dword:00000000 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings] "Name"="IESettings" "Type"="IESettings" "Order"=dword:00000003 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles] "Name"="MediaFiles" "Type"="MediaFiles" "Order"=dword:00000002 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW] "Name"="NPW" "Param1"="NPW" "Type"="wellknown" "Order"=dword:00000001 "State"=dword:0000000b [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{161B3614-FE54-4D30-8019-0D1E95DD4DB1}\ProgID] @DACL=(02 0000) @="Akzydiqq" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1152) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll c:\program files\common files\logishrd\bluetooth\LBTServ.dll - - - - - - - > 'explorer.exe'(2156) c:\windows\system32\WININET.dll c:\program files\Logitech\SetPoint\lgscroll.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Roxio\Drag-to-Disc\Shellex.dll c:\windows\system32\DLAAPI_W.DLL c:\windows\system32\CDRTC.DLL c:\program files\Roxio\Drag-to-Disc\ShellRes.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Dell Network Assistant\hnm_svc.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe c:\program files\Canon\CAL\CALMAIN.exe c:\windows\system32\wbem\unsecapp.exe c:\windows\system32\wscntfy.exe c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe c:\program files\Lavasoft\Ad-Aware\AAWTray.exe . ************************************************************************** . Completion time: 2009-07-01 15:25 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-01 19:25 Pre-Run: 132,412,030,976 bytes free Post-Run: 138,492,420,096 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect 372 --- E O F --- 2009-06-14 20:01 |
|
|
|
Jul 1 2009, 02:09 PM
Post
#6
|
|
![]() SuperHelper Group: Classroom Teacher Posts: 5,093 Joined: 28-April 07 From: UK Member No.: 69,799 Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux |
Hi,
Please click Start >> Control Panel >> Add/Remove Programs, and then find and Remove these old versions of Java: J2SE Runtime Environment 5.0 Update 6 Java 6 Update 5 Java 6 Update 7 (Leave update 14 as it is the latest) While you are there, I recommend you consider removing Limewire - its a great way to get yourself infected. Please disable Spybot TeaTimer via its System Tray icon. For more info, check here. 1. Please open Notepad
2. Now copy/paste the entire content of the codebox below into the Notepad window: CODE FileLook:: c:\windows\system32\B735C90A02.sys c:\windows\system32\drivers\nnrnstdi.sys DirLook:: c:\documents and settings\Roy Bristow\Application Data\gsdljreq c:\documents and settings\NetworkService\Application Data\gsdljreq NetSvcs:: yogtgxzm RegNull:: [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}*] RegLockDel:: [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{497E4387-4D07-A6B3-4E45-A2088163E506}*] [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{161B3614-FE54-4D30-8019-0D1E95DD4DB1}] 3. Save the above as CFScript.txt 4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. ![]() 5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
Next, let's check for any leftovers. Please go to Kaspersky website and perform an online antivirus scan.
|
|
|
|
Jul 1 2009, 02:47 PM
Post
#7
|
|
|
New Member ![]() Group: Authentic Member Posts: 18 Joined: 29-June 09 Member No.: 86,469 Operating System: XP SP3 |
Before I go further - I removed J2SE, Java 6 Update 5, Java 6 update 7 and Limewire. I do not have Spybot listed in Add/Remove. Found a Spybot folder in C:\ but cannot delete it.
Please advise. Thanks |
|
|
|
Jul 1 2009, 02:51 PM
Post
#8
|
|
![]() SuperHelper Group: Classroom Teacher Posts: 5,093 Joined: 28-April 07 From: UK Member No.: 69,799 Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux |
Hi,
You don't need to delete Spybot, just disable it.
|
|
|
|
Jul 1 2009, 02:56 PM
Post
#9
|
|
|
New Member ![]() Group: Authentic Member Posts: 18 Joined: 29-June 09 Member No.: 86,469 Operating System: XP SP3 |
I wasn't clear. Spybot is no longer a program on my computer. Left over is a folder with TeaTimer.exe in it but you cannot launch it or delete it.
Thanks |
|
|
|
Jul 1 2009, 02:57 PM
Post
#10
|
|
|
New Member ![]() Group: Authentic Member Posts: 18 Joined: 29-June 09 Member No.: 86,469 Operating System: XP SP3 |
I wasn't clear. Spybot is no longer a program on my computer. Left over is a folder with TeaTimer.exe in it but you cannot launch it or delete it.
Thanks |
|
|
|
Jul 1 2009, 02:59 PM
Post
#11
|
|
![]() SuperHelper Group: Classroom Teacher Posts: 5,093 Joined: 28-April 07 From: UK Member No.: 69,799 Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux |
Ah, I understand. In which case, you don't have to worry about it, we will remove it later if you still can't delete it.
|
|
|
|
Jul 1 2009, 06:21 PM
Post
#12
|
|
|
New Member ![]() Group: Authentic Member Posts: 18 Joined: 29-June 09 Member No.: 86,469 Operating System: XP SP3 |
I must go for the evening. My machine still works so if you need to help others please do.
Thanks so far. ComboFix 09-07-01.01 - Roy Bristow 07/01/2009 17:05.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.497 [GMT -4:00] Running from: c:\documents and settings\Roy Bristow\Desktop\Combo-Fix.exe Command switches used :: c:\documents and settings\Roy Bristow\Desktop\CFScript.txt AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} . ((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 ))))))))))))))))))))))))))))))) . 2009-07-01 15:44 . 2009-02-19 09:00 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVENG.SYS 2009-07-01 15:44 . 2009-02-19 09:00 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVEX15.SYS 2009-07-01 15:44 . 2009-02-19 09:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVENG32.DLL 2009-07-01 15:44 . 2009-02-19 09:00 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\NAVEX32A.DLL 2009-07-01 15:44 . 2009-02-25 09:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\EECTRL.SYS 2009-07-01 15:44 . 2009-02-25 09:00 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\CCERASER.DLL 2009-07-01 15:44 . 2009-02-25 09:00 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\ERASER.SYS 2009-07-01 15:44 . 2009-01-18 07:18 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.004\ECMSVR32.DLL 2009-06-30 21:57 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll 2009-06-30 21:57 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys 2009-06-30 21:57 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys 2009-06-30 21:57 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll 2009-06-30 21:57 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys 2009-06-29 21:34 . 2009-06-29 21:34 -------- d-----w- c:\program files\Flip Words 2009-06-29 19:17 . 2009-06-29 19:18 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ZoomBrowser EX 2009-06-29 19:09 . 2009-06-29 19:17 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CameraWindowDC 2009-06-29 19:09 . 2009-06-29 19:09 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CANON INC 2009-06-24 01:35 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\Scxpx86.dll 2009-06-24 01:35 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSXpx86.sys 2009-06-24 01:35 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSvix86.sys 2009-06-24 01:35 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSxpx86.dll 2009-06-24 01:35 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSviA64.sys 2009-06-23 21:28 . 2009-06-23 21:28 152576 ----a-w- c:\documents and settings\Roy Bristow\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-06-22 18:17 . 2009-06-22 18:20 -------- dc-h--w- c:\windows\ie8 2009-06-22 18:04 . 2007-01-24 19:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll 2009-06-22 18:03 . 2009-06-23 21:35 -------- d--h--w- c:\windows\msdownld.tmp 2009-06-22 18:02 . 2009-06-22 18:02 -------- d-----w- c:\windows\Logs 2009-06-21 23:27 . 2009-06-28 17:28 16 ----a-w- c:\documents and settings\Roy Bristow\FlipWords.dat 2009-06-21 18:55 . 2009-06-21 18:55 16 ----a-w- c:\documents and settings\Owen\FlipWords.dat 2009-06-20 20:46 . 2009-06-20 20:46 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-06-18 23:07 . 2009-06-18 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser 2009-06-18 23:07 . 2009-06-18 23:08 -------- d-----w- c:\program files\Canon 2009-06-18 23:04 . 2009-06-18 23:04 -------- d-----w- c:\program files\Common Files\Canon 2009-06-10 08:52 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll 2009-06-10 08:52 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-09 19:37 . 2009-06-09 19:37 -------- d-sh--w- c:\documents and settings\Roy Bristow\IECompatCache 2009-06-09 13:16 . 2009-06-09 13:16 -------- d-sh--w- c:\documents and settings\Margaret\PrivacIE 2009-06-08 22:22 . 2009-06-08 22:22 -------- d-sh--w- c:\documents and settings\Owen\PrivacIE 2009-06-08 21:06 . 2009-06-08 21:06 -------- d-----w- c:\documents and settings\Eden\Application Data\CyberLink 2009-06-08 11:49 . 2009-06-08 11:49 -------- d-----w- c:\documents and settings\Margaret\Local Settings\Application Data\Symantec 2009-06-07 15:18 . 2009-06-07 15:18 -------- d-sh--w- c:\documents and settings\Eden\PrivacIE 2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Logitech 2009-06-04 03:24 . 2009-06-04 03:24 -------- d-sh--w- c:\documents and settings\Roy Bristow\PrivacIE 2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2009-06-04 03:21 . 2009-06-04 03:21 -------- d-sh--w- c:\documents and settings\Roy Bristow\IETldCache 2009-06-04 03:18 . 2009-06-22 18:09 -------- d-----w- c:\windows\ie8updates 2009-06-04 03:18 . 2009-05-12 05:11 102912 ------w- c:\windows\system32\dllcache\iecompat.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-01 20:39 . 2009-03-11 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-07-01 20:31 . 2008-05-16 01:27 -------- d-----w- c:\program files\LimeWire 2009-07-01 20:31 . 2008-05-14 14:57 -------- d-----w- c:\program files\Java 2009-06-28 17:29 . 2009-05-08 22:58 117760 ----a-w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-28 17:29 . 2009-05-08 21:10 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-06-28 17:14 . 2008-11-20 15:47 188501 ----a-w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard\CGGuard2.dll 2009-06-21 18:13 . 2008-12-07 19:08 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-06-19 12:12 . 2008-11-20 15:47 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard 2009-06-19 01:23 . 2009-01-04 15:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-19 01:21 . 2009-01-05 03:07 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-06-17 15:27 . 2008-09-26 23:11 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 15:27 . 2008-09-26 23:11 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-15 01:48 . 2008-05-16 01:27 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\LimeWire 2009-06-14 20:01 . 2008-07-30 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-12 00:15 . 2008-06-05 01:14 -------- d-----w- c:\program files\SpiralFrog 2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Logitech 2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Sunbelt 2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Logitech 2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Sunbelt 2009-06-07 15:08 . 2009-06-07 15:07 73872 ----a-w- c:\documents and settings\Margaret\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Sunbelt 2009-05-21 15:33 . 2009-01-25 21:52 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-05-21 08:34 . 2008-05-14 15:01 -------- d-----w- c:\program files\Google 2009-05-13 05:15 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-12 12:16 . 2009-05-09 16:58 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-05-12 10:56 . 2009-05-12 10:56 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf 2009-05-12 10:55 . 2009-05-12 10:55 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf 2009-05-09 16:58 . 2009-05-09 16:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com 2009-05-09 15:08 . 2009-05-09 15:08 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq 2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com 2009-05-08 21:10 . 2008-05-22 00:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-05-08 17:12 . 2008-05-14 15:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-05-08 13:25 . 2009-05-08 13:25 -------- d-----w- c:\documents and settings\NetworkService\Application Data\gsdljreq 2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-28 00:08 . 2009-04-28 00:08 299352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe 2009-04-23 00:09 . 2009-05-08 10:43 15688 ----a-w- c:\windows\system32\lsdelete.exe 2009-04-23 00:09 . 2009-04-23 00:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll 2009-04-23 00:09 . 2009-04-23 00:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe 2009-04-23 00:09 . 2009-04-23 00:09 165728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll 2009-04-23 00:09 . 2009-04-23 00:09 343888 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll 2009-04-23 00:09 . 2009-04-23 00:09 289632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll 2009-04-23 00:09 . 2009-04-23 00:09 82784 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll 2009-04-23 00:08 . 2009-04-23 00:08 1629024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll 2009-04-23 00:08 . 2009-04-23 00:08 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll 2009-04-23 00:08 . 2009-04-23 00:08 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll 2009-04-23 00:08 . 2009-04-23 00:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys 2009-04-23 00:08 . 2009-02-26 01:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-04-23 00:08 . 2009-04-23 00:08 632680 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll 2009-04-23 00:08 . 2009-04-23 00:08 539512 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe 2009-04-23 00:08 . 2009-04-23 00:08 552808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe 2009-04-23 00:08 . 2009-04-23 00:08 2324808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe 2009-04-23 00:08 . 2009-04-23 00:08 626000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe 2009-04-23 00:08 . 2009-04-23 00:08 516440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe 2009-04-23 00:08 . 2009-04-23 00:08 953168 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe 2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2008-12-08 01:55 . 2008-12-07 19:08 56 --sh--r- c:\windows\system32\B735C90A02.sys . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . --- c:\windows\system32\B735C90A02.sys --- Company: ------ File Description: ------ File Version: ------ Product Name: ------ Copyright: ------ Original Filename: ------ File size: 56 Created time: 2008-12-07 19:08 Modified time: 2008-12-08 01:55 MD5: AC554BEF1249849DD1567F07B13B947C SHA1: 4A8B2537D53957B4F1D60446B3E500D23FC76B8E --- c:\windows\system32\drivers\nnrnstdi.sys --- Company: The Nielsen Company File Description: NNRNSTDI helper driver File Version: 5.1.3.15r Product Name: NielsenOnline Copyright: Copyright © 1997-2007 The Nielsen Company Original Filename: nnrnstdi.sys File size: 14336 Created time: 2008-12-07 18:41 Modified time: 2008-08-22 19:37 MD5: BA285D9D8F9C650BB1C8713E5A6D94DC SHA1: 2BB5A832522AB0F034E9C484DBBCFBB3E0D00BC6 ---- Directory of c:\documents and settings\NetworkService\Application Data\gsdljreq ---- 2009-05-08 13:25 . 2009-05-08 13:25 569 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\localstore.rdf 2009-05-08 13:25 . 2009-05-08 13:25 8598 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\pluginreg.dat 2009-05-08 13:25 . 2009-05-08 13:25 2048 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\webappsstore.sqlite 2009-05-08 13:25 . 2009-05-08 13:25 4096 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\formhistory.sqlite 2009-05-08 13:25 . 2009-05-08 13:25 131072 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\places.sqlite 2009-05-08 13:25 . 2009-05-08 13:26 0 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\places.sqlite-journal 2009-05-08 13:25 . 2009-05-08 13:25 16384 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\key3.db 2009-05-08 13:25 . 2009-05-08 13:25 65536 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\cert8.db 2009-05-08 13:25 . 2009-05-08 13:25 16384 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\secmod.db 2009-05-08 13:25 . 2009-05-08 13:27 2048 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\cookies.sqlite 2009-05-08 13:25 . 2009-05-08 13:25 2048 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\permissions.sqlite 2009-05-08 13:25 . 2009-05-08 13:25 367 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\prefs.js 2009-05-08 13:25 . 2009-05-08 13:25 127820 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\compreg.dat 2009-05-08 13:25 . 2009-05-08 13:25 96173 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\xpti.dat 2009-05-08 13:25 . 2009-05-08 13:25 207 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\compatibility.ini 2009-05-08 13:25 . 2009-05-08 13:25 111 ----a-w- c:\documents and settings\NetworkService\Application Data\gsdljreq\profiles.ini ---- Directory of c:\documents and settings\Roy Bristow\Application Data\gsdljreq ---- 2009-05-09 15:09 . 2009-05-09 15:09 569 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\localstore.rdf 2009-05-09 15:09 . 2009-05-09 15:09 8598 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\pluginreg.dat 2009-05-09 15:09 . 2009-05-09 15:09 2048 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\webappsstore.sqlite 2009-05-09 15:09 . 2009-05-09 15:09 4096 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\formhistory.sqlite 2009-05-09 15:09 . 2009-05-09 15:09 131072 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\places.sqlite 2009-05-09 15:09 . 2009-05-09 15:09 0 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\places.sqlite-journal 2009-05-09 15:09 . 2009-05-09 15:09 16384 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\key3.db 2009-05-09 15:09 . 2009-05-09 15:20 65536 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\cert8.db 2009-05-09 15:09 . 2009-05-09 15:09 16384 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\secmod.db 2009-05-09 15:09 . 2009-05-09 15:20 2048 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\cookies.sqlite 2009-05-09 15:09 . 2009-05-09 15:09 2048 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\permissions.sqlite 2009-05-09 15:09 . 2009-05-09 15:09 367 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\prefs.js 2009-05-09 15:09 . 2009-05-09 15:09 127820 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\compreg.dat 2009-05-09 15:09 . 2009-05-09 15:09 96173 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\xpti.dat 2009-05-09 15:08 . 2009-05-09 15:08 207 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\compatibility.ini 2009-05-09 15:08 . 2009-05-09 15:08 111 ----a-w- c:\documents and settings\Roy Bristow\Application Data\gsdljreq\profiles.ini ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064] "Google Update"="c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-06 133104] "RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-05-22 160592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-06-17 414992] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-23 805392] Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-7-11 111376] Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-7-11 51984] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-05-02 06:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"= "c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10421:UDP"= 10421:UDP:SingleClick Discovery Protocol "10426:UDP"= 10426:UDP:SingleClick ICC R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/25/2009 9:08 PM 64160] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [1/28/2009 1:58 PM 17264] R0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys [5/12/2009 6:55 AM 21888] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [3/23/2009 11:39 AM 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [3/23/2009 11:39 AM 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [3/23/2009 11:39 AM 482352] R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [12/7/2008 2:41 PM 14336] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944] R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [11/13/2008 7:20 PM 13360] R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [1/11/2008 6:50 PM 30312] R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 953168] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/4/2009 11:20 AM 195856] R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [3/23/2009 11:39 AM 115560] R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [11/13/2008 7:20 PM 69168] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/25/2009 5:00 AM 101936] R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [12/7/2008 2:41 PM 8832] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/26/2008 7:11 PM 19096] R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712] S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [6/30/2009 5:57 PM 276344] S2 gupdate1c9a2515ee9ac6;Google Update Service (gupdate1c9a2515ee9ac6);c:\program files\Google\Update\GoogleUpdate.exe [3/11/2009 9:55 AM 133104] S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys [5/12/2009 6:55 AM 9088] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 4:22 PM 34064] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408] S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/23/2008 5:09 AM 92464] --- Other Services/Drivers In Memory --- *NewlyCreated* - APPMGMT *NewlyCreated* - QRGFBRNH *Deregistered* - qrgfbrnh HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs yogtgxzm [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-06-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 00:08] 2008-05-22 c:\windows\Tasks\Ad-Aware.job - c:\progra~1\Lavasoft\Ad-Aware\Ad-Aware.exe [2009-01-18 00:08] 2009-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57] 2009-07-01 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-11 16:29] 2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55] 2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55] 2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006Core.job - c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35] 2009-07-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006UA.job - c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35] 2009-07-01 c:\windows\Tasks\User_Feed_Synchronization-{F028BE97-6493-45D6-98BA-3C4460D4AD4D}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://comcast.net/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html Trusted Zone: download.com Trusted Zone: intuit.com . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-01 17:09 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security] "ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr] "ImagePath"="-" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT] "ImagePath"="-" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc] "ImagePath"="-" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI] "ImagePath"="-" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync] "Name"="ActiveSync" "DisplayName"="Microsoft ActiveSync" "Param1"="ActiveSync" "Type"="wellknown" "Order"=dword:00000000 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings] "Name"="IESettings" "Type"="IESettings" "Order"=dword:00000003 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles] "Name"="MediaFiles" "Type"="MediaFiles" "Order"=dword:00000002 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW] "Name"="NPW" "Param1"="NPW" "Type"="wellknown" "Order"=dword:00000001 "State"=dword:0000000b . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1152) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll c:\program files\common files\logishrd\bluetooth\LBTServ.dll - - - - - - - > 'explorer.exe'(2172) c:\windows\system32\WININET.dll c:\program files\Logitech\SetPoint\lgscroll.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2009-07-01 17:12 ComboFix-quarantined-files.txt 2009-07-01 21:12 ComboFix2.txt 2009-07-01 19:25 Pre-Run: 138,699,505,664 bytes free Post-Run: 138,680,795,136 bytes free 362 --- E O F --- 2009-06-14 20:01 -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Wednesday, July 1, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, July 01, 2009 20:50:31 Records in database: 2412125 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 80221 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 01:26:48 File name / Threat name / Threats count C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_qrgfbrnh_.sys.zip Infected: Trojan.Win32.BHO.ext 1 The selected area was scanned. |
|
|
|
Jul 2 2009, 04:33 AM
Post
#13
|
|
![]() SuperHelper Group: Classroom Teacher Posts: 5,093 Joined: 28-April 07 From: UK Member No.: 69,799 Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux |
Hi,
I've got another CFScript for you to run, do the same as before: CODE File:: c:\windows\system32\B735C90A02.sys Folder:: c:\documents and settings\NetworkService\Application Data\gsdljreq c:\documents and settings\Roy Bristow\Application Data\gsdljreq Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"=- Your logs are looking good. Are you having any more problems? What happens if you try and delete that Spybot folder now? Please give the error message if it still doesn't work. |
|
|
|
Jul 2 2009, 11:42 AM
Post
#14
|
|
|
New Member ![]() Group: Authentic Member Posts: 18 Joined: 29-June 09 Member No.: 86,469 Operating System: XP SP3 |
Hi
Spybot folder deleted without problems. Here is my lastest log. Thanks ComboFix 09-07-01.01 - Roy Bristow 07/02/2009 13:27.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.498 [GMT -4:00] Running from: c:\documents and settings\Roy Bristow\Desktop\Combo-Fix.exe Command switches used :: c:\documents and settings\Roy Bristow\Desktop\CFScript.txt AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} FILE :: "c:\windows\system32\B735C90A02.sys" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\NetworkService\Application Data\gsdljreq c:\documents and settings\NetworkService\Application Data\gsdljreq\profiles.ini c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\cert8.db c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\compatibility.ini c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\compreg.dat c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\cookies.sqlite c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\formhistory.sqlite c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\key3.db c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\localstore.rdf c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\permissions.sqlite c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\places.sqlite-journal c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\places.sqlite c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\pluginreg.dat c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\prefs.js c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\secmod.db c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\webappsstore.sqlite c:\documents and settings\NetworkService\Application Data\gsdljreq\Profiles\o1ho3i2m.default\xpti.dat c:\documents and settings\Roy Bristow\Application Data\gsdljreq c:\documents and settings\Roy Bristow\Application Data\gsdljreq\profiles.ini c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\cert8.db c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\compatibility.ini c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\compreg.dat c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\cookies.sqlite c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\formhistory.sqlite c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\key3.db c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\localstore.rdf c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\permissions.sqlite c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\places.sqlite-journal c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\places.sqlite c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\pluginreg.dat c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\prefs.js c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\secmod.db c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\webappsstore.sqlite c:\documents and settings\Roy Bristow\Application Data\gsdljreq\Profiles\g9c6uyfo.default\xpti.dat c:\windows\system32\B735C90A02.sys . ((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 ))))))))))))))))))))))))))))))) . 2009-07-02 12:05 . 2009-02-25 09:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\EECTRL.SYS 2009-07-02 12:05 . 2009-02-25 09:00 2414128 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\CCERASER.DLL 2009-07-02 12:05 . 2009-02-25 09:00 101936 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\ERASER.SYS 2009-07-02 12:05 . 2009-02-19 09:00 89104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVENG.SYS 2009-07-02 12:05 . 2009-02-19 09:00 876144 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVEX15.SYS 2009-07-02 12:05 . 2009-02-19 09:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVENG32.DLL 2009-07-02 12:05 . 2009-02-19 09:00 1181040 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\NAVEX32A.DLL 2009-07-02 12:05 . 2009-01-18 07:18 259368 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090701.048\ECMSVR32.DLL 2009-06-30 21:57 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\Scxpx86.dll 2009-06-30 21:57 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys 2009-06-30 21:57 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSvix86.sys 2009-06-30 21:57 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSxpx86.dll 2009-06-30 21:57 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSviA64.sys 2009-06-29 21:34 . 2009-06-29 21:34 -------- d-----w- c:\program files\Flip Words 2009-06-29 19:17 . 2009-06-29 19:18 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ZoomBrowser EX 2009-06-29 19:09 . 2009-06-29 19:17 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CameraWindowDC 2009-06-29 19:09 . 2009-06-29 19:09 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\CANON INC 2009-06-24 01:35 . 2009-03-16 20:03 533880 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\Scxpx86.dll 2009-06-24 01:35 . 2009-01-29 21:50 276344 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSXpx86.sys 2009-06-24 01:35 . 2009-01-29 21:50 292912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSvix86.sys 2009-06-24 01:35 . 2009-01-29 21:50 447864 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSxpx86.dll 2009-06-24 01:35 . 2009-01-29 21:50 396848 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090623.001\IDSviA64.sys 2009-06-23 21:28 . 2009-06-23 21:28 152576 ----a-w- c:\documents and settings\Roy Bristow\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-06-22 18:17 . 2009-06-22 18:20 -------- dc-h--w- c:\windows\ie8 2009-06-22 18:04 . 2007-01-24 19:27 255848 ----a-w- c:\windows\system32\xactengine2_6.dll 2009-06-22 18:03 . 2009-06-23 21:35 -------- d--h--w- c:\windows\msdownld.tmp 2009-06-22 18:02 . 2009-06-22 18:02 -------- d-----w- c:\windows\Logs 2009-06-21 23:27 . 2009-06-28 17:28 16 ----a-w- c:\documents and settings\Roy Bristow\FlipWords.dat 2009-06-21 18:55 . 2009-06-21 18:55 16 ----a-w- c:\documents and settings\Owen\FlipWords.dat 2009-06-20 20:46 . 2009-06-20 20:46 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-06-18 23:07 . 2009-06-18 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser 2009-06-18 23:07 . 2009-06-18 23:08 -------- d-----w- c:\program files\Canon 2009-06-18 23:04 . 2009-06-18 23:04 -------- d-----w- c:\program files\Common Files\Canon 2009-06-10 08:52 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll 2009-06-10 08:52 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll 2009-06-09 19:37 . 2009-06-09 19:37 -------- d-sh--w- c:\documents and settings\Roy Bristow\IECompatCache 2009-06-09 13:16 . 2009-06-09 13:16 -------- d-sh--w- c:\documents and settings\Margaret\PrivacIE 2009-06-08 22:22 . 2009-06-08 22:22 -------- d-sh--w- c:\documents and settings\Owen\PrivacIE 2009-06-08 21:06 . 2009-06-08 21:06 -------- d-----w- c:\documents and settings\Eden\Application Data\CyberLink 2009-06-08 11:49 . 2009-06-08 11:49 -------- d-----w- c:\documents and settings\Margaret\Local Settings\Application Data\Symantec 2009-06-07 15:18 . 2009-06-07 15:18 -------- d-sh--w- c:\documents and settings\Eden\PrivacIE 2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Logitech 2009-06-04 03:24 . 2009-06-04 03:24 -------- d-sh--w- c:\documents and settings\Roy Bristow\PrivacIE 2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-06-04 03:22 . 2009-06-04 03:22 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2009-06-04 03:21 . 2009-06-04 03:21 -------- d-sh--w- c:\documents and settings\Roy Bristow\IETldCache 2009-06-04 03:18 . 2009-06-22 18:09 -------- d-----w- c:\windows\ie8updates 2009-06-04 03:18 . 2009-05-12 05:11 102912 ------w- c:\windows\system32\dllcache\iecompat.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-01 20:39 . 2009-03-11 13:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-07-01 20:31 . 2008-05-16 01:27 -------- d-----w- c:\program files\LimeWire 2009-07-01 20:31 . 2008-05-14 14:57 -------- d-----w- c:\program files\Java 2009-06-28 17:29 . 2009-05-08 22:58 117760 ----a-w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-28 17:29 . 2009-05-08 21:10 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-06-28 17:14 . 2008-11-20 15:47 188501 ----a-w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard\CGGuard2.dll 2009-06-21 18:13 . 2008-12-07 19:08 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys 2009-06-19 12:12 . 2008-11-20 15:47 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\ContentGuard 2009-06-19 01:23 . 2009-01-04 15:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-19 01:21 . 2009-01-05 03:07 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-06-17 15:27 . 2008-09-26 23:11 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 15:27 . 2008-09-26 23:11 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-15 01:48 . 2008-05-16 01:27 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\LimeWire 2009-06-14 20:01 . 2008-07-30 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-12 00:15 . 2008-06-05 01:14 -------- d-----w- c:\program files\SpiralFrog 2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Logitech 2009-06-08 22:21 . 2009-06-08 22:21 -------- d-----w- c:\documents and settings\Owen\Application Data\Sunbelt 2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Logitech 2009-06-07 15:16 . 2009-06-07 15:16 -------- d-----w- c:\documents and settings\Eden\Application Data\Sunbelt 2009-06-07 15:08 . 2009-06-07 15:07 73872 ----a-w- c:\documents and settings\Margaret\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\Margaret\Application Data\Sunbelt 2009-05-21 15:33 . 2009-01-25 21:52 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-05-21 08:34 . 2008-05-14 15:01 -------- d-----w- c:\program files\Google 2009-05-13 05:15 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-12 12:16 . 2009-05-09 16:58 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-05-12 10:56 . 2009-05-12 10:56 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf 2009-05-12 10:55 . 2009-05-12 10:55 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf 2009-05-09 16:58 . 2009-05-09 16:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com 2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-05-08 21:10 . 2009-05-08 21:10 -------- d-----w- c:\documents and settings\Roy Bristow\Application Data\SUPERAntiSpyware.com 2009-05-08 21:10 . 2008-05-22 00:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-05-08 17:12 . 2008-05-14 15:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-28 00:08 . 2009-04-28 00:08 299352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe 2009-04-23 00:09 . 2009-05-08 10:43 15688 ----a-w- c:\windows\system32\lsdelete.exe 2009-04-23 00:09 . 2009-04-23 00:09 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll 2009-04-23 00:09 . 2009-04-23 00:09 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe 2009-04-23 00:09 . 2009-04-23 00:09 165728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll 2009-04-23 00:09 . 2009-04-23 00:09 343888 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll 2009-04-23 00:09 . 2009-04-23 00:09 289632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll 2009-04-23 00:09 . 2009-04-23 00:09 82784 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll 2009-04-23 00:08 . 2009-04-23 00:08 1629024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll 2009-04-23 00:08 . 2009-04-23 00:08 212848 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll 2009-04-23 00:08 . 2009-04-23 00:08 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll 2009-04-23 00:08 . 2009-04-23 00:08 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys 2009-04-23 00:08 . 2009-02-26 01:08 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-04-23 00:08 . 2009-04-23 00:08 632680 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll 2009-04-23 00:08 . 2009-04-23 00:08 539512 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe 2009-04-23 00:08 . 2009-04-23 00:08 552808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe 2009-04-23 00:08 . 2009-04-23 00:08 2324808 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe 2009-04-23 00:08 . 2009-04-23 00:08 626000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe 2009-04-23 00:08 . 2009-04-23 00:08 516440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe 2009-04-23 00:08 . 2009-04-23 00:08 953168 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe 2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll . ((((((((((((((((((((((((((((( SnapShot@2009-07-01_19.21.11 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-02 16:57 . 2009-07-02 16:57 16384 c:\windows\Temp\Perflib_Perfdata_598.dat + 2009-07-02 16:56 . 2009-07-02 16:56 16384 c:\windows\Temp\Perflib_Perfdata_4c4.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064] "Google Update"="c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-06 133104] "RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-05-22 160592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-06-17 414992] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-23 805392] Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-7-11 111376] Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-7-11 51984] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-05-02 06:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"= "c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "10421:UDP"= 10421:UDP:SingleClick Discovery Protocol "10426:UDP"= 10426:UDP:SingleClick ICC R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/25/2009 9:08 PM 64160] R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [1/28/2009 1:58 PM 17264] R0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys [5/12/2009 6:55 AM 21888] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1005000.087\SymEFA.sys [3/23/2009 11:39 AM 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1005000.087\BHDrvx86.sys [3/23/2009 11:39 AM 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1005000.087\cchpx86.sys [3/23/2009 11:39 AM 482352] R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [12/7/2008 2:41 PM 14336] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944] R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [11/13/2008 7:20 PM 13360] R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [1/11/2008 6:50 PM 30312] R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 5:34 PM 953168] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/4/2009 11:20 AM 195856] R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [3/23/2009 11:39 AM 115560] R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [11/13/2008 7:20 PM 69168] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/25/2009 5:00 AM 101936] R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [12/7/2008 2:41 PM 8832] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/26/2008 7:11 PM 19096] R3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712] S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090625.003\IDSXpx86.sys [6/30/2009 5:57 PM 276344] S2 gupdate1c9a2515ee9ac6;Google Update Service (gupdate1c9a2515ee9ac6);c:\program files\Google\Update\GoogleUpdate.exe [3/11/2009 9:55 AM 133104] S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys [5/12/2009 6:55 AM 9088] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 4:22 PM 34064] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408] S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/23/2008 5:09 AM 92464] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs yogtgxzm [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-07-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 00:08] 2008-05-22 c:\windows\Tasks\Ad-Aware.job - c:\progra~1\Lavasoft\Ad-Aware\Ad-Aware.exe [2009-01-18 00:08] 2009-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57] 2009-07-02 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-11 16:29] 2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55] 2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-11 13:55] 2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006Core.job - c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35] 2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1362977303-1881232705-3471229379-1006UA.job - c:\documents and settings\Roy Bristow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-22 06:35] 2009-07-02 c:\windows\Tasks\User_Feed_Synchronization-{F028BE97-6493-45D6-98BA-3C4460D4AD4D}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://comcast.net/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html Trusted Zone: download.com Trusted Zone: intuit.com . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-02 13:33 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security] "ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr] "ImagePath"="-" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT] "ImagePath"="-" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc] "ImagePath"="-" [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI] "ImagePath"="-" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync] "Name"="ActiveSync" "DisplayName"="Microsoft ActiveSync" "Param1"="ActiveSync" "Type"="wellknown" "Order"=dword:00000000 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings] "Name"="IESettings" "Type"="IESettings" "Order"=dword:00000003 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles] "Name"="MediaFiles" "Type"="MediaFiles" "Order"=dword:00000002 "State"=dword:0000000b [HKEY_USERS\S-1-5-21-1362977303-1881232705-3471229379-1006\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW] "Name"="NPW" "Param1"="NPW" "Type"="wellknown" "Order"=dword:00000001 "State"=dword:0000000b . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1140) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll c:\program files\common files\logishrd\bluetooth\LBTServ.dll . Completion time: 2009-07-02 13:35 ComboFix-quarantined-files.txt 2009-07-02 17:35 ComboFix2.txt 2009-07-01 21:12 ComboFix3.txt 2009-07-01 19:25 Pre-Run: 138,628,837,376 bytes free Post-Run: 138,694,291,456 bytes free 331 --- E O F --- 2009-06-14 20:01 |
|
|
|
Jul 3 2009, 02:32 AM
Post
#15
|
|
![]() SuperHelper Group: Classroom Teacher Posts: 5,093 Joined: 28-April 07 From: UK Member No.: 69,799 Operating System: Windows XP (Professional), Windows Vista (Home Business), Windows 7 (Ultimate), Ubuntu Linux |
Hi,
Something keeps coming back. Please delete your existing copy of ComboFix, and download a new one (there have been some updates recently that may be pertinent to what we are trying to remove). Then, run the new ComboFix with this CFScript: CODE Driver:: Let me know how things are running after that, and please show me the new ComboFix log.
yogtgxzm NetSvc:: yogtgxzm |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
4 | MiNdHaBiTs | 44 | Yesterday, 03:57 PM Last post by: CatByte |
|||
![]() |
20 | Wakenaam | 366 | Yesterday, 09:54 AM Last post by: Tomk |
|||
![]() |
0 | tombombca | 24 | Yesterday, 09:42 AM Last post by: tombombca |
|||
![]() |
13 | florinhelp | 217 | Yesterday, 07:30 AM Last post by: CatByte |
|||
|
Time is now: 21st November 2009 - 10:47 AM |